<?xml version='1.0' encoding='UTF-8'?><?xml-stylesheet href="http://www.blogger.com/styles/atom.css" type="text/css"?><feed xmlns='http://www.w3.org/2005/Atom' xmlns:openSearch='http://a9.com/-/spec/opensearchrss/1.0/' xmlns:georss='http://www.georss.org/georss' xmlns:gd='http://schemas.google.com/g/2005' xmlns:thr='http://purl.org/syndication/thread/1.0'><id>tag:blogger.com,1999:blog-31650060</id><updated>2012-02-17T05:31:07.102+03:30</updated><title type='text'>Neoava Guard</title><subtitle type='html'>Neoava Guard is a Host-based Intrusion Prevention System (HIPS) software, which helps you protect your computer against malicious softwares. Neoava Guard allows you to completely control any suspicious action in your computer. By the way, Neoava has some innovative features to let you experience better protection and less wrong alerts.</subtitle><link rel='http://schemas.google.com/g/2005#feed' type='application/atom+xml' href='http://neoava.blogspot.com/feeds/posts/default'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/31650060/posts/default?max-results=100'/><link rel='alternate' type='text/html' href='http://neoava.blogspot.com/'/><link rel='hub' href='http://pubsubhubbub.appspot.com/'/><author><name>Arman Nayyeri</name><uri>http://www.blogger.com/profile/02442221103322416642</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='30' height='32' src='http://www.4rman.com/myneedles.jpg'/></author><generator version='7.00' uri='http://www.blogger.com'>Blogger</generator><openSearch:totalResults>36</openSearch:totalResults><openSearch:startIndex>1</openSearch:startIndex><openSearch:itemsPerPage>100</openSearch:itemsPerPage><entry><id>tag:blogger.com,1999:blog-31650060.post-3258955272572276335</id><published>2007-10-28T09:49:00.000+03:30</published><updated>2007-10-28T09:56:47.987+03:30</updated><title type='text'>Suspending NG development</title><content type='html'>&lt;p&gt;I'm sorry to say this but after trying to continue NG development along with my new work and my new life, finally I decided to suspend NG development for a few months untill I have more time to spend on it. Cuz NG development needs my mind to be focused on it and currently this is impossible.&lt;/p&gt;&lt;p&gt;And to all NG fans: Don't worry this is not an end to NG project, its development will continue, be sure.&lt;/p&gt;This is your help and support which keep me from ending this project. I will do my best to respond your support by developing the NG, the best free HIPS.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/31650060-3258955272572276335?l=neoava.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://neoava.blogspot.com/feeds/3258955272572276335/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=31650060&amp;postID=3258955272572276335&amp;isPopup=true' title='2 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/31650060/posts/default/3258955272572276335'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/31650060/posts/default/3258955272572276335'/><link rel='alternate' type='text/html' href='http://neoava.blogspot.com/2007/10/suspending-ng-development.html' title='Suspending NG development'/><author><name>Arman Nayyeri</name><uri>http://www.blogger.com/profile/02442221103322416642</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='30' height='32' src='http://www.4rman.com/myneedles.jpg'/></author><thr:total>2</thr:total></entry><entry><id>tag:blogger.com,1999:blog-31650060.post-726159811769765110</id><published>2007-08-20T12:52:00.000+03:30</published><updated>2007-08-20T13:24:10.654+03:30</updated><title type='text'>Still debugging....</title><content type='html'>Its been a long time from my last post, NG beta 3 debugging is still countinues and also some requested features in the support forum added to Beta 3. If you have any suggestion/request or bug report you can post it in &lt;a href="http://www.smokey-services.eu/forum/index.php?c=16"&gt;support forum&lt;/a&gt;. Many bugs fixed but still a lot more testing is needed to have a stable version, I ask anyone interested in HIPS to download and install latest build of NG from support forum, test it and post any bug, suggestion or feature request there.&lt;br /&gt;&lt;br /&gt;Here is a copy of Neoava Guard Beta 3 progress log:&lt;br /&gt;&lt;br /&gt;&lt;span class="postbody"&gt;&lt;div id="p_18644_message" style="DISPLAY: inline"&gt;&lt;span style="font-size:85%;"&gt;&lt;span style="FONT-WEIGHT: bold"&gt;Features:&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;Adding more registry keys for protection - &lt;span style="color:green;"&gt;[COMPLETED]&lt;/span&gt;&lt;br /&gt;Kernel debugging protection - &lt;span style="color:green;"&gt;[COMPLETED]&lt;/span&gt;&lt;br /&gt;Protection against disabling task manager and regedit - &lt;span style="color:green;"&gt;[COMPLETED]&lt;/span&gt;&lt;br /&gt;&lt;strike&gt;Change execution alert to High risk - &lt;span style="color:green;"&gt;[COMPLETED]&lt;/span&gt;&lt;/strike&gt;&lt;br /&gt;Hide empty Groups - &lt;span style="color:green;"&gt;[COMPLETED]&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="FONT-WEIGHT: bold"&gt;Update (05 Aug 2007):&lt;/span&gt;&lt;br /&gt;Learning-Mode option for Wizard - &lt;span style="color:green;"&gt;[COMPLETED]&lt;/span&gt;&lt;br /&gt;Removing outbound connection - &lt;span style="color:green;"&gt;[COMPLETED]&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="FONT-WEIGHT: bold"&gt;Update (18 Aug 2007):&lt;/span&gt;&lt;br /&gt;Debug output - &lt;span style="color:green;"&gt;[COMPLETED]&lt;/span&gt;&lt;br /&gt;Silent mode - &lt;span style="color:green;"&gt;[COMPLETED]&lt;/span&gt;&lt;br /&gt;Adding dll name to Global hook alert - &lt;span style="color:green;"&gt;[COMPLETED]&lt;/span&gt;&lt;br /&gt;Installation warning about alerted windows file - &lt;span style="color:green;"&gt;[COMPLETED]&lt;/span&gt;&lt;br /&gt;Fix icons - &lt;span style="color:green;"&gt;[COMPLETED]&lt;/span&gt;&lt;br /&gt;Terminate option in alert window - &lt;span style="color:green;"&gt;[COMPLETED]&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;Executable modified alert - &lt;span style="color:red;"&gt;[PENDING]&lt;/span&gt;&lt;br /&gt;An option to skip scanning programs in Wizard - &lt;span style="color:red;"&gt;[PENDING]&lt;/span&gt;&lt;br /&gt;Adding hot-keys - &lt;span style="color:red;"&gt;[PENDING]&lt;/span&gt;&lt;br /&gt;Configure button in wizard to add more executables - &lt;span style="color:red;"&gt;[PENDING]&lt;/span&gt;&lt;br /&gt;Option to import and export all rules and configuration - &lt;span style="color:red;"&gt;[PENDING]&lt;/span&gt;&lt;br /&gt;Reverse alert name and risk (also service) - &lt;span style="color:red;"&gt;[PENDING]&lt;/span&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;/span&gt;&lt;br /&gt;&lt;span class="postbody"&gt;&lt;div style="DISPLAY: inline"&gt;&lt;span style="font-size:85%;"&gt;Graphical guide - &lt;span style="color:red;"&gt;[PENDING]&lt;/span&gt;&lt;br /&gt;Help file - &lt;span style="color:red;"&gt;[PENDING]&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="FONT-WEIGHT: bold"&gt;Bugs:&lt;/span&gt;&lt;br /&gt;Isearch adware BSOD - &lt;span style="color:green;"&gt;[FIXED]&lt;/span&gt;&lt;br /&gt;Service status error - &lt;span style="color:green;"&gt;[MOST_LIKELY_FIXED]&lt;/span&gt;&lt;br /&gt;"Clear log" bug - &lt;span style="color:green;"&gt;[MOST_LIKELY_FIXED]&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="FONT-WEIGHT: bold"&gt;Update (05 Aug 2007):&lt;/span&gt;&lt;br /&gt;Prueba trojan freeze - &lt;span style="color:green;"&gt;[FIXED]&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="FONT-WEIGHT: bold"&gt;Update (18 Aug 2007):&lt;/span&gt;&lt;br /&gt;BSOD on startup - &lt;span style="color:green;"&gt;[MOST_LIKELY_FIXED]&lt;/span&gt;&lt;br /&gt;Tray icon bugs - &lt;span style="color:green;"&gt;[MOST_LIKELY_FIXED]&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;MS File sharing bug - &lt;span style="color:red;"&gt;[PENDING]&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;span class="postbody"&gt;&lt;/span&gt;&lt;br /&gt;&lt;span class="postbody"&gt;You can check latest progress from &lt;a href="http://www.smokey-services.eu/forum/viewtopic.php?t=6479"&gt;this thread&lt;/a&gt;.&lt;br /&gt;&lt;/span&gt;&lt;span class="postbody"&gt;&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/31650060-726159811769765110?l=neoava.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://neoava.blogspot.com/feeds/726159811769765110/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=31650060&amp;postID=726159811769765110&amp;isPopup=true' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/31650060/posts/default/726159811769765110'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/31650060/posts/default/726159811769765110'/><link rel='alternate' type='text/html' href='http://neoava.blogspot.com/2007/08/still-debugging.html' title='Still debugging....'/><author><name>Arman Nayyeri</name><uri>http://www.blogger.com/profile/02442221103322416642</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='30' height='32' src='http://www.4rman.com/myneedles.jpg'/></author><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-31650060.post-7934854732058976971</id><published>2007-07-22T11:27:00.000+03:30</published><updated>2007-07-22T12:36:20.814+03:30</updated><title type='text'>NG Beta 3 being tested by Smokey's forum users</title><content type='html'>&lt;div&gt;OK, after a long hard work, NG gets ready for a harder test by Smokey's security forums users. I'm inviting all my NG serious users to download it from Smokey's forums in this thread. Of course you can join there if you are not a member yet. &lt;/div&gt;&lt;br /&gt;&lt;div&gt;Having a support forum makes things a lot easier, especially for reporting bugs and debugging them while everyone can see others problems and tell if they have such problem or not. It is also very good for other kind of feedback, for example when a user suggests some feature or option other users can tell me their opinion about them so I can decide better.&lt;/div&gt;&lt;br /&gt;&lt;div&gt;Nothing more to say, just a screenshot from Neoava Guard extension for Explorer.&lt;/div&gt;&lt;br /&gt;&lt;div&gt;&lt;/div&gt;&lt;img id="BLOGGER_PHOTO_ID_5089944796417679810" style="DISPLAY: block; MARGIN: 0px auto 10px; CURSOR: hand; TEXT-ALIGN: center" alt="" src="http://3.bp.blogspot.com/_Lk0AARdMfp8/RqMd0xzS4cI/AAAAAAAAAC4/_hfuAym8Rrc/s320/NeoavaExt.jpg" border="0" /&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/31650060-7934854732058976971?l=neoava.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://neoava.blogspot.com/feeds/7934854732058976971/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=31650060&amp;postID=7934854732058976971&amp;isPopup=true' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/31650060/posts/default/7934854732058976971'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/31650060/posts/default/7934854732058976971'/><link rel='alternate' type='text/html' href='http://neoava.blogspot.com/2007/07/ng-beta-3-being-tested-by-smokeys-forum.html' title='NG Beta 3 being tested by Smokey&apos;s forum users'/><author><name>Arman Nayyeri</name><uri>http://www.blogger.com/profile/02442221103322416642</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='30' height='32' src='http://www.4rman.com/myneedles.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://3.bp.blogspot.com/_Lk0AARdMfp8/RqMd0xzS4cI/AAAAAAAAAC4/_hfuAym8Rrc/s72-c/NeoavaExt.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-31650060.post-7009182371017050223</id><published>2007-07-02T21:29:00.000+03:30</published><updated>2007-07-02T21:42:54.631+03:30</updated><title type='text'>Neoava Guard Support Forum</title><content type='html'>As NG Beta 3 is almost ready for the release, NG Support Forum started on Smokey's Security Forums.&lt;br /&gt;&lt;br /&gt;NG forums on Smokey's Security Forums consists of 3 parts:&lt;br /&gt;&lt;ul&gt;&lt;li&gt;&lt;a class="forumlink" href="http://www.smokey-services.eu/forum/viewforum.php?f=67"&gt;Neoava Guard Support&lt;/a&gt; Neoava Guard Related Issues, with exception of discovered bugs. Please report bugs in the special Bug Reports Forum.&lt;/li&gt;&lt;li&gt;&lt;a class="forumlink" href="http://www.smokey-services.eu/forum/viewforum.php?f=68"&gt;Neoava Guard Knowledge Base&lt;/a&gt; Neoava Guard Knowledge Base/FAQ Forum. Users can start here multiple topics but cannot reply in others. Please read the Neoava Guard Knowledge Base Forum Rules before posting.&lt;/li&gt;&lt;li&gt;&lt;a class="forumlink" href="http://www.smokey-services.eu/forum/viewforum.php?f=69"&gt;Neoava Guard Bug Reports&lt;/a&gt; Please report here all Neoava Guard bugs.&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;Smokey's Security Forums:&lt;br /&gt;&lt;a href="http://www.smokey-services.eu/forum/index.php"&gt;http://www.smokey-services.eu/forum/index.php&lt;/a&gt;&lt;/p&gt;&lt;p&gt;You can join Smokey's Security Forums and post bug reports or questions about NG there.&lt;/p&gt;&lt;p&gt;I hope to see you there.&lt;/p&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/31650060-7009182371017050223?l=neoava.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://neoava.blogspot.com/feeds/7009182371017050223/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=31650060&amp;postID=7009182371017050223&amp;isPopup=true' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/31650060/posts/default/7009182371017050223'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/31650060/posts/default/7009182371017050223'/><link rel='alternate' type='text/html' href='http://neoava.blogspot.com/2007/07/neoava-guard-support-forum.html' title='Neoava Guard Support Forum'/><author><name>Arman Nayyeri</name><uri>http://www.blogger.com/profile/02442221103322416642</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='30' height='32' src='http://www.4rman.com/myneedles.jpg'/></author><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-31650060.post-3952486827449202990</id><published>2007-06-19T04:30:00.000+03:30</published><updated>2007-06-19T04:48:34.183+03:30</updated><title type='text'>Configuration Tab</title><content type='html'>&lt;div&gt;Configuration Tab was almost finished a week ago, but I encountered some problems and bugs that took a week for debugging and coding some parts again.&lt;br /&gt;&lt;div&gt;&lt;br /&gt;&lt;div&gt;&lt;/div&gt;&lt;div&gt;Another thing is that I decided to remove Processes tab in order to finish this beta as soon as possible, cause this tab needs some changes in NG driver code and I don't want to change it in the last minute and don't have enough time to test driver completely again.&lt;/div&gt;&lt;br /&gt;&lt;div&gt;&lt;/div&gt;&lt;div&gt;here is some snapshots (I hope you enjoy it)&lt;/div&gt;&lt;br /&gt;&lt;div&gt;&lt;/div&gt;&lt;img id="BLOGGER_PHOTO_ID_5077577528073519074" style="DISPLAY: block; MARGIN: 0px auto 10px; CURSOR: hand; TEXT-ALIGN: center" alt="" src="http://1.bp.blogspot.com/_Lk0AARdMfp8/Rnct3BBT_-I/AAAAAAAAACI/UOX9G5LV5Iw/s320/ConfigTab001.jpg" border="0" /&gt;&lt;br /&gt;&lt;img id="BLOGGER_PHOTO_ID_5077577532368486386" style="DISPLAY: block; MARGIN: 0px auto 10px; CURSOR: hand; TEXT-ALIGN: center" alt="" src="http://2.bp.blogspot.com/_Lk0AARdMfp8/Rnct3RBT__I/AAAAAAAAACQ/ZmjWqJpJ0-4/s320/ConfigTab002.jpg" border="0" /&gt;&lt;br /&gt;&lt;img id="BLOGGER_PHOTO_ID_5077577532368486402" style="DISPLAY: block; MARGIN: 0px auto 10px; CURSOR: hand; TEXT-ALIGN: center" alt="" src="http://3.bp.blogspot.com/_Lk0AARdMfp8/Rnct3RBUAAI/AAAAAAAAACY/AEYjIquM1Zo/s320/ConfigTab003.jpg" border="0" /&gt;&lt;br /&gt;&lt;div&gt;&lt;/div&gt;&lt;br /&gt;&lt;img id="BLOGGER_PHOTO_ID_5077577532368486418" style="DISPLAY: block; MARGIN: 0px auto 10px; CURSOR: hand; TEXT-ALIGN: center" alt="" src="http://3.bp.blogspot.com/_Lk0AARdMfp8/Rnct3RBUABI/AAAAAAAAACg/NN5uCYYfdT8/s320/ConfigTab004.jpg" border="0" /&gt;&lt;br /&gt;&lt;div&gt;&lt;img id="BLOGGER_PHOTO_ID_5077577536663453730" style="DISPLAY: block; MARGIN: 0px auto 10px; CURSOR: hand; TEXT-ALIGN: center" alt="" src="http://4.bp.blogspot.com/_Lk0AARdMfp8/Rnct3hBUACI/AAAAAAAAACo/4QDCAkN91uQ/s320/ConfigTab005.jpg" border="0" /&gt;&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;&lt;br /&gt;&lt;p&gt;&lt;img id="BLOGGER_PHOTO_ID_5077577966160183346" style="DISPLAY: block; MARGIN: 0px auto 10px; CURSOR: hand; TEXT-ALIGN: center" alt="" src="http://4.bp.blogspot.com/_Lk0AARdMfp8/RncuQhBUADI/AAAAAAAAACw/U2PssKP_SRs/s320/ConfigTab006.jpg" border="0" /&gt;&lt;/p&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/31650060-3952486827449202990?l=neoava.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://neoava.blogspot.com/feeds/3952486827449202990/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=31650060&amp;postID=3952486827449202990&amp;isPopup=true' title='2 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/31650060/posts/default/3952486827449202990'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/31650060/posts/default/3952486827449202990'/><link rel='alternate' type='text/html' href='http://neoava.blogspot.com/2007/06/configuration-tab.html' title='Configuration Tab'/><author><name>Arman Nayyeri</name><uri>http://www.blogger.com/profile/02442221103322416642</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='30' height='32' src='http://www.4rman.com/myneedles.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://1.bp.blogspot.com/_Lk0AARdMfp8/Rnct3BBT_-I/AAAAAAAAACI/UOX9G5LV5Iw/s72-c/ConfigTab001.jpg' height='72' width='72'/><thr:total>2</thr:total></entry><entry><id>tag:blogger.com,1999:blog-31650060.post-7510490112291552347</id><published>2007-05-20T19:48:00.000+03:30</published><updated>2007-05-20T20:01:52.257+03:30</updated><title type='text'>Applications Tab</title><content type='html'>Sorry I forgot to put Applications tab snapshots, Applications tab was ready a few days ago.&lt;br /&gt;&lt;br /&gt;I'm currently working on configuration tab and there will be a little delay in release.&lt;br /&gt;&lt;br /&gt;Here is the snapshots:&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://2.bp.blogspot.com/_Lk0AARdMfp8/RlB3p_W4ElI/AAAAAAAAABQ/P4cO35Qbq5k/s1600-h/AppsTab01.jpg"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer;" src="http://2.bp.blogspot.com/_Lk0AARdMfp8/RlB3p_W4ElI/AAAAAAAAABQ/P4cO35Qbq5k/s320/AppsTab01.jpg" alt="" id="BLOGGER_PHOTO_ID_5066681144057533010" border="0" /&gt;&lt;/a&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://3.bp.blogspot.com/_Lk0AARdMfp8/RlB3qPW4EmI/AAAAAAAAABY/hUosR7bAA70/s1600-h/AppsTab02.jpg"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer;" src="http://3.bp.blogspot.com/_Lk0AARdMfp8/RlB3qPW4EmI/AAAAAAAAABY/hUosR7bAA70/s320/AppsTab02.jpg" alt="" id="BLOGGER_PHOTO_ID_5066681148352500322" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;Thank you for your suggestions, ideas and support.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/31650060-7510490112291552347?l=neoava.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://neoava.blogspot.com/feeds/7510490112291552347/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=31650060&amp;postID=7510490112291552347&amp;isPopup=true' title='3 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/31650060/posts/default/7510490112291552347'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/31650060/posts/default/7510490112291552347'/><link rel='alternate' type='text/html' href='http://neoava.blogspot.com/2007/05/applications-tab.html' title='Applications Tab'/><author><name>Arman Nayyeri</name><uri>http://www.blogger.com/profile/02442221103322416642</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='30' height='32' src='http://www.4rman.com/myneedles.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://2.bp.blogspot.com/_Lk0AARdMfp8/RlB3p_W4ElI/AAAAAAAAABQ/P4cO35Qbq5k/s72-c/AppsTab01.jpg' height='72' width='72'/><thr:total>3</thr:total></entry><entry><id>tag:blogger.com,1999:blog-31650060.post-5238247697576937248</id><published>2007-05-08T17:17:00.000+03:30</published><updated>2007-05-08T17:29:44.392+03:30</updated><title type='text'>NG beta 3 development progress</title><content type='html'>OK, as some asked about NG progress and not sending any new snapshots, now I want to describe it:&lt;br /&gt;&lt;br /&gt;The progress was nice about 12 days ago when I had a cold and was unable to work hard on NG and this cold later causes a middle-ear infection and becomes a real problem for me. Today I'm okay and started working hard on NG again. This event may cause a delay on release but Im trying my best to release NG beta 3 as soon as possible. I apologize for another delay in release, I hope beta 3 satisfy NG users.&lt;br /&gt;&lt;br /&gt;Executables tab is complete, I will send a few snapshot in the next few days.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/31650060-5238247697576937248?l=neoava.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://neoava.blogspot.com/feeds/5238247697576937248/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=31650060&amp;postID=5238247697576937248&amp;isPopup=true' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/31650060/posts/default/5238247697576937248'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/31650060/posts/default/5238247697576937248'/><link rel='alternate' type='text/html' href='http://neoava.blogspot.com/2007/05/ng-beta-3-development-progress.html' title='NG beta 3 development progress'/><author><name>Arman Nayyeri</name><uri>http://www.blogger.com/profile/02442221103322416642</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='30' height='32' src='http://www.4rman.com/myneedles.jpg'/></author><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-31650060.post-6696290727235621231</id><published>2007-04-12T15:30:00.000+03:30</published><updated>2007-04-12T16:10:06.789+03:30</updated><title type='text'>Alert dialog</title><content type='html'>Hi,&lt;br /&gt;&lt;br /&gt;Alert dialog finished, here is some snapshots:&lt;br /&gt;&lt;br /&gt;&lt;div style="text-align: center;"&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://3.bp.blogspot.com/_Lk0AARdMfp8/Rh4nM3nvgfI/AAAAAAAAAAw/d6Vmmg9KhJA/s1600-h/AlertCapture5.jpg"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer;" src="http://3.bp.blogspot.com/_Lk0AARdMfp8/Rh4nM3nvgfI/AAAAAAAAAAw/d6Vmmg9KhJA/s320/AlertCapture5.jpg" alt="" id="BLOGGER_PHOTO_ID_5052518933998830066" border="0" /&gt;&lt;/a&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://4.bp.blogspot.com/_Lk0AARdMfp8/Rh4oQHnvghI/AAAAAAAAABA/gtf7RDSZQ-I/s1600-h/AlertCapture7.jpg"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer;" src="http://4.bp.blogspot.com/_Lk0AARdMfp8/Rh4oQHnvghI/AAAAAAAAABA/gtf7RDSZQ-I/s320/AlertCapture7.jpg" alt="" id="BLOGGER_PHOTO_ID_5052520089345032722" border="0" /&gt;&lt;/a&gt;&lt;span style="font-size:85%;"&gt;Note: GUI is in Advanced mode&lt;/span&gt;&lt;br /&gt;&lt;/div&gt;&lt;br /&gt;It is small window that will be displayed with a Always-On-Top property, but if the client GUI was not loaded yet (e.g before user login)  then the old alert window will be displayed by NG service.&lt;br /&gt;&lt;br /&gt;With this dialog I've tried to make it easier for users to configure their executables and rules with just a few clicks.&lt;br /&gt;&lt;br /&gt;Send your suggestion/ideas.&lt;br /&gt;&lt;br /&gt;Thanks&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/31650060-6696290727235621231?l=neoava.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://neoava.blogspot.com/feeds/6696290727235621231/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=31650060&amp;postID=6696290727235621231&amp;isPopup=true' title='10 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/31650060/posts/default/6696290727235621231'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/31650060/posts/default/6696290727235621231'/><link rel='alternate' type='text/html' href='http://neoava.blogspot.com/2007/04/alert-dialog.html' title='Alert dialog'/><author><name>Arman Nayyeri</name><uri>http://www.blogger.com/profile/02442221103322416642</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='30' height='32' src='http://www.4rman.com/myneedles.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://3.bp.blogspot.com/_Lk0AARdMfp8/Rh4nM3nvgfI/AAAAAAAAAAw/d6Vmmg9KhJA/s72-c/AlertCapture5.jpg' height='72' width='72'/><thr:total>10</thr:total></entry><entry><id>tag:blogger.com,1999:blog-31650060.post-5822967121966901424</id><published>2007-03-12T16:10:00.000+03:30</published><updated>2007-03-13T22:08:24.799+03:30</updated><title type='text'>events tab</title><content type='html'>&lt;span style="font-size:85%;"&gt;Here is a snapshot from events tab of new GUI. It is not complete yet&lt;/span&gt;.&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://3.bp.blogspot.com/_Lk0AARdMfp8/RfVKjjoJ4cI/AAAAAAAAAAk/uxMQYBhiTA8/s1600-h/logpage-opt.jpg"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer;" src="http://3.bp.blogspot.com/_Lk0AARdMfp8/RfVKjjoJ4cI/AAAAAAAAAAk/uxMQYBhiTA8/s320/logpage-opt.jpg" alt="" id="BLOGGER_PHOTO_ID_5041017332630675906" border="0" /&gt;&lt;/a&gt;&lt;span style="font-size:85%;"&gt;&lt;span style="font-size:85%;"&gt;("More options" is not shown cause i'm still working on it, it should display details about the selected event.)&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-size:100%;"&gt;This snapshot shows a log from NG protection against &lt;a href="http://syssafety.com/leaktests.html"&gt;spt.exe&lt;/a&gt;, NG protects against all kind of attacks. APT tool by diamondcs is also completely covered in the new NG version, so NG will provide the same kind of defense against process termination as ProcessGuard.&lt;br /&gt;&lt;br /&gt;Note that window is horizontally resizable, so user can see all columns without scrolling.&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;Please feel free to send your suggestions to me.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/31650060-5822967121966901424?l=neoava.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://neoava.blogspot.com/feeds/5822967121966901424/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=31650060&amp;postID=5822967121966901424&amp;isPopup=true' title='3 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/31650060/posts/default/5822967121966901424'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/31650060/posts/default/5822967121966901424'/><link rel='alternate' type='text/html' href='http://neoava.blogspot.com/2007/03/events-tab.html' title='events tab'/><author><name>Arman Nayyeri</name><uri>http://www.blogger.com/profile/02442221103322416642</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='30' height='32' src='http://www.4rman.com/myneedles.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://3.bp.blogspot.com/_Lk0AARdMfp8/RfVKjjoJ4cI/AAAAAAAAAAk/uxMQYBhiTA8/s72-c/logpage-opt.jpg' height='72' width='72'/><thr:total>3</thr:total></entry><entry><id>tag:blogger.com,1999:blog-31650060.post-6319759189990052663</id><published>2007-03-12T15:51:00.000+03:30</published><updated>2007-03-13T00:10:24.440+03:30</updated><title type='text'>suggestions</title><content type='html'>Thanks to MaB69 for his suggestions, here is answers which may help other people learn about NG.&lt;span style="color: rgb(192, 192, 192);font-size:85%;" &gt;&lt;span style="font-size:180%;"&gt;&lt;br /&gt;&lt;span style="color: rgb(153, 153, 153);font-size:78%;" &gt;&lt;br /&gt;&lt;span style="font-size:85%;"&gt;Maintenance task to delete rules related to non existant executables&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;the non-existent executables will stay in database but not shown for configuration, this way the application permissions will be available if the same executable executed again.&lt;br /&gt;&lt;br /&gt;&lt;span style="color: rgb(153, 153, 153);font-size:85%;" &gt;Self protection for the service and in case of attack, the service could relaunch the UI process&lt;/span&gt;&lt;br /&gt;In the new NG UI will be shown by client (executed as user login) and it is protected against termination.&lt;br /&gt;&lt;br /&gt;&lt;span style="color: rgb(153, 153, 153);font-size:85%;" &gt;Hidden files/process detection&lt;/span&gt;&lt;br /&gt;It is something which will be done by root-kits after they load into kernel, althought it is possible to detect hidden files/process in some cases but it is not possible to control a kernel-mode driver as it already had the highest possible access to system.&lt;br /&gt;&lt;br /&gt;&lt;span style="color: rgb(153, 153, 153);font-size:85%;" &gt;More Registry keys monitoring ( like IE settings or system settings (regedit actived/disabled))&lt;/span&gt;&lt;br /&gt;It is easy to add more keys but currently the work is just too much for me. Thanks it will be in future versions.&lt;br /&gt;&lt;br /&gt;&lt;span style="color: rgb(153, 153, 153);font-size:85%;" &gt;Keylogging detection (GetKeyState, GetAsyncKeyState and DirectX request interception)&lt;/span&gt;&lt;br /&gt;New NG protects against all kind of keylogging except DirectX, which till now I was unable to find a way to filter it. If anyone knows any technical details about inner work of this function contact me.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/31650060-6319759189990052663?l=neoava.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://neoava.blogspot.com/feeds/6319759189990052663/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=31650060&amp;postID=6319759189990052663&amp;isPopup=true' title='7 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/31650060/posts/default/6319759189990052663'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/31650060/posts/default/6319759189990052663'/><link rel='alternate' type='text/html' href='http://neoava.blogspot.com/2007/03/suggestions.html' title='suggestions'/><author><name>Arman Nayyeri</name><uri>http://www.blogger.com/profile/02442221103322416642</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='30' height='32' src='http://www.4rman.com/myneedles.jpg'/></author><thr:total>7</thr:total></entry><entry><id>tag:blogger.com,1999:blog-31650060.post-947831863957019896</id><published>2007-02-25T20:27:00.000+03:30</published><updated>2007-02-25T21:15:03.315+03:30</updated><title type='text'>Look at the new version</title><content type='html'>Although GUI is still under development but the new version should look like this:&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://2.bp.blogspot.com/_Lk0AARdMfp8/ReHGOv1kR-I/AAAAAAAAAAU/zwxeO3groqs/s1600-h/NGbetax002.jpg"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer;" src="http://2.bp.blogspot.com/_Lk0AARdMfp8/ReHGOv1kR-I/AAAAAAAAAAU/zwxeO3groqs/s400/NGbetax002.jpg" alt="" id="BLOGGER_PHOTO_ID_5035523815038535650" border="0" /&gt;&lt;/a&gt; the best way to help me is sending your ideas/suggestions.&lt;br /&gt;more pictures coming soon....&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/31650060-947831863957019896?l=neoava.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://neoava.blogspot.com/feeds/947831863957019896/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=31650060&amp;postID=947831863957019896&amp;isPopup=true' title='3 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/31650060/posts/default/947831863957019896'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/31650060/posts/default/947831863957019896'/><link rel='alternate' type='text/html' href='http://neoava.blogspot.com/2007/02/look-at-new-version.html' title='Look at the new version'/><author><name>Arman Nayyeri</name><uri>http://www.blogger.com/profile/02442221103322416642</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='30' height='32' src='http://www.4rman.com/myneedles.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://2.bp.blogspot.com/_Lk0AARdMfp8/ReHGOv1kR-I/AAAAAAAAAAU/zwxeO3groqs/s72-c/NGbetax002.jpg' height='72' width='72'/><thr:total>3</thr:total></entry><entry><id>tag:blogger.com,1999:blog-31650060.post-206240175082902907</id><published>2007-01-19T20:28:00.000+03:30</published><updated>2007-01-20T21:06:16.973+03:30</updated><title type='text'>News</title><content type='html'>Neoava.com is up and running, everything is OK!&lt;br /&gt;&lt;br /&gt;The news is that the new version of Neoava Guard will have some amazingly innovative stuff which make the this HIPS unique in ease of use among other HIPS.&lt;br /&gt;&lt;br /&gt;Against the last two beta's which focused on just protecting against more attack ways, this time features added to comfort beginner users, and also provide a highly flexible configuration for advanced users.&lt;br /&gt;&lt;br /&gt;In previous versions most users can't find a lot of configs etc.., but in next version everything can be configured from several places, the new interface allow users to change options/rules by few clicks.&lt;br /&gt;&lt;br /&gt;4 completely new concepts added to increase ease of use, integration to system and installed programs, Internet attacks protection and overall protection. This completely new features allow NG to minimize alerts and most things automatically done (although can be configured not to be done automatically).&lt;br /&gt;&lt;br /&gt;There will be a little visual tutorial along with NG next version to help people just know how to protect their computer using NG.&lt;br /&gt;&lt;br /&gt;I will publish the new beta version to public and will update it every 2 weeks or so until no more bugs reported. Then the first non-beta version will be released.&lt;br /&gt;&lt;br /&gt;I estimate the new beta to be ready for public release around mid March.&lt;br /&gt;&lt;br /&gt;This time I promise the new version can make it as the best HIPS available on net, not only among the free ones but also others.&lt;br /&gt;&lt;br /&gt;I will just keep it free, not to help people protect their computers (which will be done anyways) but to show how powerful Neoava Guard is and how creative I am in programming.&lt;br /&gt;&lt;br /&gt;Just wait and see, cuz u aint seen nothin yet!&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/31650060-206240175082902907?l=neoava.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://neoava.blogspot.com/feeds/206240175082902907/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=31650060&amp;postID=206240175082902907&amp;isPopup=true' title='3 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/31650060/posts/default/206240175082902907'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/31650060/posts/default/206240175082902907'/><link rel='alternate' type='text/html' href='http://neoava.blogspot.com/2007/01/news.html' title='News'/><author><name>Arman Nayyeri</name><uri>http://www.blogger.com/profile/02442221103322416642</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='30' height='32' src='http://www.4rman.com/myneedles.jpg'/></author><thr:total>3</thr:total></entry><entry><id>tag:blogger.com,1999:blog-31650060.post-2246652276284923712</id><published>2007-01-15T08:41:00.000+03:30</published><updated>2007-01-15T10:18:56.436+03:30</updated><title type='text'>neoava.com is down</title><content type='html'>&lt;span onclick="BLOG_clickHandler(this)" class="blsp-spelling-error" id="SPELLING_ERROR_0"&gt;Neoava&lt;/span&gt;.com is down (for the last few days) due to hosting problems and it will come back online soon.&lt;br /&gt;&lt;br /&gt;&lt;span onclick="BLOG_clickHandler(this)" class="blsp-spelling-error" id="SPELLING_ERROR_1"&gt;NG&lt;/span&gt; progress is good but due to a series of changes in &lt;span onclick="BLOG_clickHandler(this)" class="blsp-spelling-error" id="SPELLING_ERROR_2"&gt;NG&lt;/span&gt; driver it needs a lot of time for testing and a lot of work on GUI, so the GUI show what the driver can offer to user.&lt;br /&gt;&lt;br /&gt;anyway, sorry I can't update &lt;span onclick="BLOG_clickHandler(this)" class="blsp-spelling-error" id="SPELLING_ERROR_3"&gt;NG&lt;/span&gt; blog regularly cause I'm very busy.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/31650060-2246652276284923712?l=neoava.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://neoava.blogspot.com/feeds/2246652276284923712/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=31650060&amp;postID=2246652276284923712&amp;isPopup=true' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/31650060/posts/default/2246652276284923712'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/31650060/posts/default/2246652276284923712'/><link rel='alternate' type='text/html' href='http://neoava.blogspot.com/2007/01/neoavacom-is-down.html' title='neoava.com is down'/><author><name>Arman Nayyeri</name><uri>http://www.blogger.com/profile/02442221103322416642</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='30' height='32' src='http://www.4rman.com/myneedles.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-31650060.post-116367327165143062</id><published>2006-11-16T14:00:00.000+03:30</published><updated>2007-01-15T10:19:53.833+03:30</updated><title type='text'>New GUI</title><content type='html'>GUI is going to be completely new, I was working (for 3 weeks) on changing old GUI but  decided to start from ZERO to have a completely new and optimized GUI.&lt;br /&gt;&lt;br /&gt;Anyway, I'm not going to post so many things in new future cause I'm very busy working on it.&lt;br /&gt;&lt;br /&gt;Hope for a user-friendly, simple and effective GUI.&lt;br /&gt;&lt;br /&gt;I'll post some pics ASAP.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/31650060-116367327165143062?l=neoava.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://neoava.blogspot.com/feeds/116367327165143062/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=31650060&amp;postID=116367327165143062&amp;isPopup=true' title='2 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/31650060/posts/default/116367327165143062'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/31650060/posts/default/116367327165143062'/><link rel='alternate' type='text/html' href='http://neoava.blogspot.com/2006/11/new-gui.html' title='New GUI'/><author><name>Arman Nayyeri</name><uri>http://www.blogger.com/profile/02442221103322416642</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='30' height='32' src='http://www.4rman.com/myneedles.jpg'/></author><thr:total>2</thr:total></entry><entry><id>tag:blogger.com,1999:blog-31650060.post-116111858137926467</id><published>2006-10-18T00:26:00.000+03:30</published><updated>2006-11-27T22:17:22.776+03:30</updated><title type='text'>Beta 2 public release</title><content type='html'>And finally NG v1.0 Beta 2  publicly released.&lt;br /&gt;&lt;br /&gt;for more info visit NG's website:&lt;a href="http://www.neoava.com"&gt; http://www.neoava.com&lt;/a&gt;&lt;br /&gt;or download page: &lt;a href="http://www.neoava.com/download.htm"&gt;http://www.neoava.com/download.htm&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;please report bugs to feedback [at] neoava [dot] com&lt;br /&gt;&lt;br /&gt;I will publish a list of new features on the website.&lt;br /&gt;I have to work on its graphic parts and will publish first version as soon as it seems to be complete.&lt;br /&gt;&lt;br /&gt;for now, download NG beta 2 and&lt;br /&gt;Enjoy!&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/31650060-116111858137926467?l=neoava.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://neoava.blogspot.com/feeds/116111858137926467/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=31650060&amp;postID=116111858137926467&amp;isPopup=true' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/31650060/posts/default/116111858137926467'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/31650060/posts/default/116111858137926467'/><link rel='alternate' type='text/html' href='http://neoava.blogspot.com/2006/10/beta-2-public-release.html' title='Beta 2 public release'/><author><name>Arman Nayyeri</name><uri>http://www.blogger.com/profile/02442221103322416642</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='30' height='32' src='http://www.4rman.com/myneedles.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-31650060.post-116012701182179519</id><published>2006-10-06T12:41:00.000+03:30</published><updated>2006-10-06T13:00:11.906+03:30</updated><title type='text'>Beta-testing final steps</title><content type='html'>The NG beta 2 is almost ready for public release.&lt;br /&gt;&lt;br /&gt;beta-testers reported several bugs (including 1 BSOD triggering bug) all of them debugged successfully and NG beta 2 is now more stable and better.&lt;br /&gt;&lt;br /&gt;I've received a lot of suggestions most them either related to GUI (which is going to be changed after beta 2 public release) or requires a lot of change in NG code, that may produce more bugs as a result of added functionality. So I saved them for future versions.&lt;br /&gt;&lt;br /&gt;thanks to all beta-testers the NG is going to be released by the next week.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/31650060-116012701182179519?l=neoava.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://neoava.blogspot.com/feeds/116012701182179519/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=31650060&amp;postID=116012701182179519&amp;isPopup=true' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/31650060/posts/default/116012701182179519'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/31650060/posts/default/116012701182179519'/><link rel='alternate' type='text/html' href='http://neoava.blogspot.com/2006/10/beta-testing-final-steps.html' title='Beta-testing final steps'/><author><name>Arman Nayyeri</name><uri>http://www.blogger.com/profile/02442221103322416642</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='30' height='32' src='http://www.4rman.com/myneedles.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-31650060.post-115951314380640369</id><published>2006-09-29T10:22:00.000+03:30</published><updated>2006-09-29T10:29:03.813+03:30</updated><title type='text'>Testing Beta 2</title><content type='html'>The beta 2 version has been sent to beta-testers.&lt;br /&gt;&lt;br /&gt;I'm working with them debugging NG beta 2.&lt;br /&gt;&lt;br /&gt;thanks to all beta testers.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/31650060-115951314380640369?l=neoava.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://neoava.blogspot.com/feeds/115951314380640369/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=31650060&amp;postID=115951314380640369&amp;isPopup=true' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/31650060/posts/default/115951314380640369'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/31650060/posts/default/115951314380640369'/><link rel='alternate' type='text/html' href='http://neoava.blogspot.com/2006/09/testing-beta-2.html' title='Testing Beta 2'/><author><name>Arman Nayyeri</name><uri>http://www.blogger.com/profile/02442221103322416642</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='30' height='32' src='http://www.4rman.com/myneedles.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-31650060.post-115895874661665271</id><published>2006-09-23T00:26:00.000+03:30</published><updated>2006-09-23T00:29:06.616+03:30</updated><title type='text'>Beta 2</title><content type='html'>The beta is ready, but the last minute bug caused a delay.&lt;br /&gt;&lt;br /&gt;I'll will work to debug it tomorrow and send it for beta-testers.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/31650060-115895874661665271?l=neoava.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://neoava.blogspot.com/feeds/115895874661665271/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=31650060&amp;postID=115895874661665271&amp;isPopup=true' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/31650060/posts/default/115895874661665271'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/31650060/posts/default/115895874661665271'/><link rel='alternate' type='text/html' href='http://neoava.blogspot.com/2006/09/beta-2.html' title='Beta 2'/><author><name>Arman Nayyeri</name><uri>http://www.blogger.com/profile/02442221103322416642</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='30' height='32' src='http://www.4rman.com/myneedles.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-31650060.post-115791549400753117</id><published>2006-09-10T22:32:00.000+03:30</published><updated>2006-09-10T22:41:34.040+03:30</updated><title type='text'>Testing learning-mode</title><content type='html'>And the learning-mode finished,&lt;br /&gt;&lt;br /&gt;I finally decided to make the Learning-Mode (LM) as simple as possible,&lt;br /&gt;as it may cause complications if I use a complex routine to decide whether or not to add a particular application to trusted-mode while on LM.&lt;br /&gt;&lt;br /&gt;so the LM just a state in which driver adds all executables executed into trusted apps, so the driver is actually not protecting against anything. By default, the LM is enabled for 5 hours of working with computer after installation (can be chosen to be disabled).&lt;br /&gt;&lt;br /&gt;I'm currently testing it, cause it made a lot of change in several parts.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/31650060-115791549400753117?l=neoava.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://neoava.blogspot.com/feeds/115791549400753117/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=31650060&amp;postID=115791549400753117&amp;isPopup=true' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/31650060/posts/default/115791549400753117'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/31650060/posts/default/115791549400753117'/><link rel='alternate' type='text/html' href='http://neoava.blogspot.com/2006/09/testing-learning-mode.html' title='Testing learning-mode'/><author><name>Arman Nayyeri</name><uri>http://www.blogger.com/profile/02442221103322416642</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='30' height='32' src='http://www.4rman.com/myneedles.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-31650060.post-115753063169553503</id><published>2006-09-06T11:21:00.000+03:30</published><updated>2006-09-06T12:46:47.606+03:30</updated><title type='text'>busy</title><content type='html'>hi,&lt;br /&gt;&lt;br /&gt;in the last 5-6 days I was busy working on another thing, so I have to start working on learning-mode from today.&lt;br /&gt;&lt;br /&gt;but I have some ideas on how to design the learning-mode part, its going to be very unique.&lt;br /&gt;&lt;br /&gt;im really sorry, ill work on NG beta 2 as hard as possible.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/31650060-115753063169553503?l=neoava.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://neoava.blogspot.com/feeds/115753063169553503/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=31650060&amp;postID=115753063169553503&amp;isPopup=true' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/31650060/posts/default/115753063169553503'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/31650060/posts/default/115753063169553503'/><link rel='alternate' type='text/html' href='http://neoava.blogspot.com/2006/09/busy.html' title='busy'/><author><name>Arman Nayyeri</name><uri>http://www.blogger.com/profile/02442221103322416642</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='30' height='32' src='http://www.4rman.com/myneedles.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-31650060.post-115676052428111241</id><published>2006-08-28T13:43:00.000+03:30</published><updated>2006-08-28T14:03:03.736+03:30</updated><title type='text'>learning-mode</title><content type='html'>after some testing and installating NG, I decided to add another thing to NG beta 2: a learning-mode.&lt;br /&gt;&lt;br /&gt;that makes the first days of NG installation a lot easier for user.&lt;br /&gt;&lt;br /&gt;I think it takes at least 1 week.&lt;br /&gt;&lt;br /&gt;BTW, the number of beta-testers is getting a little bit more in these days and its really good.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/31650060-115676052428111241?l=neoava.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://neoava.blogspot.com/feeds/115676052428111241/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=31650060&amp;postID=115676052428111241&amp;isPopup=true' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/31650060/posts/default/115676052428111241'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/31650060/posts/default/115676052428111241'/><link rel='alternate' type='text/html' href='http://neoava.blogspot.com/2006/08/learning-mode.html' title='learning-mode'/><author><name>Arman Nayyeri</name><uri>http://www.blogger.com/profile/02442221103322416642</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='30' height='32' src='http://www.4rman.com/myneedles.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-31650060.post-115657075716255905</id><published>2006-08-26T08:54:00.000+03:30</published><updated>2006-12-13T21:07:00.690+03:30</updated><title type='text'>driver file modification protection</title><content type='html'>I've done the driver file modification filter, and yesterday was a new record for me, working for 13 hours.&lt;br /&gt;&lt;br /&gt;i'm preparing the NG wizard and setup and I will send the debug version of NG beta 2 to beta-testers, in the next few days.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/31650060-115657075716255905?l=neoava.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://neoava.blogspot.com/feeds/115657075716255905/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=31650060&amp;postID=115657075716255905&amp;isPopup=true' title='3 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/31650060/posts/default/115657075716255905'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/31650060/posts/default/115657075716255905'/><link rel='alternate' type='text/html' href='http://neoava.blogspot.com/2006/08/driver-file-modification-protection.html' title='driver file modification protection'/><author><name>Arman Nayyeri</name><uri>http://www.blogger.com/profile/02442221103322416642</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='30' height='32' src='http://www.4rman.com/myneedles.jpg'/></author><thr:total>3</thr:total></entry><entry><id>tag:blogger.com,1999:blog-31650060.post-115649428526331857</id><published>2006-08-25T11:39:00.000+03:30</published><updated>2006-08-25T12:34:01.726+03:30</updated><title type='text'>Direct physical memory access &amp; driver loading</title><content type='html'>number 4 and 5 from the previous post is done.&lt;br /&gt;&lt;br /&gt;just want to note that the protection against direct memory writing also helps defend against restoring SDT. the method described in &lt;span style="color: rgb(0, 0, 0);font-size:100%;" &gt;&lt;a href="http://www.security.org.sg/code/sdtrestore.html"&gt;&lt;span style="color: rgb(0, 128, 0);"&gt;www.security.org.sg/code/sdtrestore.html&lt;/span&gt;&lt;/a&gt;&lt;/span&gt;&lt;span style=""&gt;&lt;span style="color: rgb(0, 128, 0);"&gt;&lt;span style="font-size:100%;"&gt;. &lt;/span&gt;&lt;span style="color: rgb(0, 0, 0);"&gt;&lt;span style="font-size:100%;"&gt;This method uses the physical memory access too (\device\physicalmemory). So, by applying this filter we effectively stop SDTrestore from gaining write access to physical memory.&lt;br /&gt;&lt;br /&gt;Now, I will work for number 7, modifying driver files on disk.&lt;br /&gt;thats going to be a little bit hard.&lt;/span&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/31650060-115649428526331857?l=neoava.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://neoava.blogspot.com/feeds/115649428526331857/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=31650060&amp;postID=115649428526331857&amp;isPopup=true' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/31650060/posts/default/115649428526331857'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/31650060/posts/default/115649428526331857'/><link rel='alternate' type='text/html' href='http://neoava.blogspot.com/2006/08/direct-physical-memory-access-driver.html' title='Direct physical memory access &amp; driver loading'/><author><name>Arman Nayyeri</name><uri>http://www.blogger.com/profile/02442221103322416642</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='30' height='32' src='http://www.4rman.com/myneedles.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-31650060.post-115615384812335338</id><published>2006-08-21T12:46:00.000+03:30</published><updated>2006-08-23T11:27:31.140+03:30</updated><title type='text'>Attacking Host-based Intrusion Prevention Systems</title><content type='html'>Few days ago Thomas emailed me a document about Attacking HIPS. (thanks thomas)&lt;br /&gt;the document written by Eugene Tsyrklevich from SecurityArchitects.com . It is a very interesting article and covers some interesting attacking methods to bypass HIPS. Here is a list of the attacks related to my HIPS:&lt;br /&gt;&lt;br /&gt;&lt;ol&gt;&lt;li&gt;Using Symbolic Links to bypass filters&lt;br /&gt;NG is actually protected against this kind of attack as it is designed to completely resolve all names before checking them against filters&lt;br /&gt;&lt;br /&gt;&lt;/li&gt;&lt;li&gt;Using Service Control Manager (SCM) to install drivers or something&lt;br /&gt;NG detects all requests to SCM and check them against service &amp; driver creation/modification settings/filter and can allow or deny them&lt;br /&gt;&lt;br /&gt;&lt;/li&gt;&lt;li&gt;ZwLoadDriver()&lt;br /&gt;This one is also already protected by NG.&lt;br /&gt;&lt;br /&gt;&lt;/li&gt;&lt;li&gt;Using ZwSetSystemInformation's SystemLoadAndCallImage &amp;amp; SystemLoadImage to load drivers&lt;br /&gt;I'm currently working on protecting NG's users from this kind of attack (takes some time)&lt;br /&gt;&lt;br /&gt;&lt;/li&gt;&lt;li&gt;Inject code by directly modifying the kernel memory (\Device\PhysicalMemory)&lt;br /&gt;NG is not protected against this attack, I will work on this one after zwsetsysinfo one, it takes little time.&lt;br /&gt;&lt;br /&gt;&lt;/li&gt;&lt;li&gt;If a trusted system process is still allowed to load kernel drivers, use DLL injection to inject userland code into the trusted process and then load a malicious kernel driver&lt;br /&gt;NG protect processes against DLL injection.&lt;br /&gt;&lt;br /&gt;&lt;/li&gt;&lt;li&gt;Modify an existing kernel driver in disk&lt;br /&gt;It is also possible against NG protection, I'll work on it in the next few days.&lt;/li&gt;&lt;/ol&gt;I think thats enough description about attacks,&lt;br /&gt;I'll work on them and report back.&lt;br /&gt;&lt;br /&gt;document link:&lt;span style="font-size:-1;"&gt;&lt;span style="color:#008000;"&gt; &lt;a href="http://www.blackhat.com/presentations/bh-usa-04/bh-us-04-tsyrklevich.pdf"&gt;http://www.blackhat.com/presentations/&lt;/a&gt;&lt;wbr&gt;&lt;a href="http://www.blackhat.com/presentations/bh-usa-04/bh-us-04-tsyrklevich.pdf"&gt;bh-usa-04/bh-us-04-tsyrklevich.pdf&lt;/a&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/31650060-115615384812335338?l=neoava.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://neoava.blogspot.com/feeds/115615384812335338/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=31650060&amp;postID=115615384812335338&amp;isPopup=true' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/31650060/posts/default/115615384812335338'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/31650060/posts/default/115615384812335338'/><link rel='alternate' type='text/html' href='http://neoava.blogspot.com/2006/08/attacking-host-based-intrusion.html' title='Attacking Host-based Intrusion Prevention Systems'/><author><name>Arman Nayyeri</name><uri>http://www.blogger.com/profile/02442221103322416642</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='30' height='32' src='http://www.4rman.com/myneedles.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-31650060.post-115597758570087265</id><published>2006-08-19T10:59:00.000+03:30</published><updated>2006-08-19T12:30:31.383+03:30</updated><title type='text'>partition table protection done</title><content type='html'>low-level disk access filter done, now all applications trying to access harddisk directly can be detected.&lt;br /&gt;&lt;br /&gt;the beta-testing will start next week cause there is a couple of things I want to add, I will write about it in next post.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/31650060-115597758570087265?l=neoava.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://neoava.blogspot.com/feeds/115597758570087265/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=31650060&amp;postID=115597758570087265&amp;isPopup=true' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/31650060/posts/default/115597758570087265'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/31650060/posts/default/115597758570087265'/><link rel='alternate' type='text/html' href='http://neoava.blogspot.com/2006/08/partition-table-protection-done.html' title='partition table protection done'/><author><name>Arman Nayyeri</name><uri>http://www.blogger.com/profile/02442221103322416642</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='30' height='32' src='http://www.4rman.com/myneedles.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-31650060.post-115584069844935286</id><published>2006-08-17T22:16:00.000+03:30</published><updated>2006-08-17T22:21:38.450+03:30</updated><title type='text'>low-level disk access</title><content type='html'>thanks Krazaf,&lt;br /&gt;&lt;br /&gt;after a new sample from Krazaf, I successfully found how this kind of attack can be detected.&lt;br /&gt;&lt;br /&gt;it is not hard to implement and should take some hours/1 day.&lt;br /&gt;&lt;br /&gt;I'll work on it, tomorrow.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/31650060-115584069844935286?l=neoava.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://neoava.blogspot.com/feeds/115584069844935286/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=31650060&amp;postID=115584069844935286&amp;isPopup=true' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/31650060/posts/default/115584069844935286'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/31650060/posts/default/115584069844935286'/><link rel='alternate' type='text/html' href='http://neoava.blogspot.com/2006/08/low-level-disk-access.html' title='low-level disk access'/><author><name>Arman Nayyeri</name><uri>http://www.blogger.com/profile/02442221103322416642</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='30' height='32' src='http://www.4rman.com/myneedles.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-31650060.post-115584031304777016</id><published>2006-08-17T22:01:00.000+03:30</published><updated>2006-08-17T22:15:13.056+03:30</updated><title type='text'>GeSwall incompatibility</title><content type='html'>While running GeSwall along with NG, a BSOD triggers on almost random times, debug analysis didn't show anything, I think I should leave it and recommend not to use NG and GeSwall together.&lt;br /&gt;&lt;br /&gt;as the BSOD triggered very rarely on my system, its harder to debug it.&lt;br /&gt;So I give up on debugging this incompatibility issue.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/31650060-115584031304777016?l=neoava.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://neoava.blogspot.com/feeds/115584031304777016/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=31650060&amp;postID=115584031304777016&amp;isPopup=true' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/31650060/posts/default/115584031304777016'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/31650060/posts/default/115584031304777016'/><link rel='alternate' type='text/html' href='http://neoava.blogspot.com/2006/08/geswall-incompatibility.html' title='GeSwall incompatibility'/><author><name>Arman Nayyeri</name><uri>http://www.blogger.com/profile/02442221103322416642</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='30' height='32' src='http://www.4rman.com/myneedles.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-31650060.post-115514648095507744</id><published>2006-08-09T20:54:00.000+03:30</published><updated>2006-08-09T21:54:19.506+03:30</updated><title type='text'>everything is fine</title><content type='html'>there was just a couple of bugs.&lt;br /&gt;&lt;br /&gt;they are ok now, but Im still looking for bugs.&lt;br /&gt;&lt;br /&gt;20 Aug, the new beta 2 is going to start its tests by beta-testers who decided to help me debug NG b2.&lt;br /&gt;&lt;br /&gt;till then I will work alone on debugging.&lt;br /&gt;&lt;br /&gt;I have enabled a couple of features which was disabled, or I was decided to disable them in beta 2. I think I have enough ideas to keep future versions interesting.&lt;br /&gt;&lt;br /&gt;BTW, I will keep NG free. and I don't keep it free to help people protect their systems or fight against malwares but to show the power of my software to everyone and to become famous. thats all.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/31650060-115514648095507744?l=neoava.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://neoava.blogspot.com/feeds/115514648095507744/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=31650060&amp;postID=115514648095507744&amp;isPopup=true' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/31650060/posts/default/115514648095507744'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/31650060/posts/default/115514648095507744'/><link rel='alternate' type='text/html' href='http://neoava.blogspot.com/2006/08/everything-is-fine.html' title='everything is fine'/><author><name>Arman Nayyeri</name><uri>http://www.blogger.com/profile/02442221103322416642</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='30' height='32' src='http://www.4rman.com/myneedles.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-31650060.post-115442149442969720</id><published>2006-08-01T11:49:00.000+03:30</published><updated>2006-08-01T12:08:14.436+03:30</updated><title type='text'>debugging</title><content type='html'>as several incompatibility and bugs reported while using NG along with some other firewalls,  anti-viruses, etc... . I have decided to run them on my computer and test them throughly, this is going to be the last step in NG beta 2 development.&lt;br /&gt;&lt;br /&gt;I'll report bugs.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/31650060-115442149442969720?l=neoava.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://neoava.blogspot.com/feeds/115442149442969720/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=31650060&amp;postID=115442149442969720&amp;isPopup=true' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/31650060/posts/default/115442149442969720'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/31650060/posts/default/115442149442969720'/><link rel='alternate' type='text/html' href='http://neoava.blogspot.com/2006/08/debugging.html' title='debugging'/><author><name>Arman Nayyeri</name><uri>http://www.blogger.com/profile/02442221103322416642</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='30' height='32' src='http://www.4rman.com/myneedles.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-31650060.post-115436987347001128</id><published>2006-07-31T21:32:00.000+03:30</published><updated>2006-07-31T21:47:53.486+03:30</updated><title type='text'>program execution filter done</title><content type='html'>phew,&lt;br /&gt;&lt;br /&gt;well after a lot of where-is-the-bug stuff, I've done program execution filter, and I have to say that it looks great, not just only for its main purpose (which is preventing malwares from running) but it also can be used by user to easily add her new executables to Trusted Executables, as it will prompt user when a new, untrusted executable going to be executed.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;I should mention this method of adding programs to trust somewhere in help and in the new GUI's Graphical User Guide.&lt;br /&gt;&lt;br /&gt;and yes, thats another new feature which can make using NG easier for end-users by showing them how they can do something with NG.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/31650060-115436987347001128?l=neoava.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://neoava.blogspot.com/feeds/115436987347001128/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=31650060&amp;postID=115436987347001128&amp;isPopup=true' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/31650060/posts/default/115436987347001128'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/31650060/posts/default/115436987347001128'/><link rel='alternate' type='text/html' href='http://neoava.blogspot.com/2006/07/program-execution-filter-done.html' title='program execution filter done'/><author><name>Arman Nayyeri</name><uri>http://www.blogger.com/profile/02442221103322416642</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='30' height='32' src='http://www.4rman.com/myneedles.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-31650060.post-115420110053248983</id><published>2006-07-29T22:34:00.000+03:30</published><updated>2006-07-29T22:55:00.540+03:30</updated><title type='text'>old suggestion</title><content type='html'>there is an old and cool suggestion I have recieved by website's feedback form.&lt;br /&gt;&lt;br /&gt;Kevin suggested:&lt;br /&gt;&lt;span style="font-style: italic;font-size:85%;" &gt;&lt;br /&gt;Neoava should also have a filter that prompts the user for launching  executables. This can prevent malicious programs from starting.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;Actually I've been thinking about this one when begin working on NG project but for some reason (that I can't remember now) ignores it. But this should be a part of every HIPS software.&lt;br /&gt;I'll work on this one from tomorrow after finishing the "driver &amp;amp; services" tests.&lt;br /&gt;&lt;br /&gt;i'll report back when it is finished,&lt;br /&gt;thanks Kevin.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/31650060-115420110053248983?l=neoava.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://neoava.blogspot.com/feeds/115420110053248983/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=31650060&amp;postID=115420110053248983&amp;isPopup=true' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/31650060/posts/default/115420110053248983'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/31650060/posts/default/115420110053248983'/><link rel='alternate' type='text/html' href='http://neoava.blogspot.com/2006/07/old-suggestion.html' title='old suggestion'/><author><name>Arman Nayyeri</name><uri>http://www.blogger.com/profile/02442221103322416642</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='30' height='32' src='http://www.4rman.com/myneedles.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-31650060.post-115419989122349467</id><published>2006-07-29T22:24:00.000+03:30</published><updated>2006-07-29T22:34:51.253+03:30</updated><title type='text'>busy</title><content type='html'>I've been really busy working for seperating Drivers &amp; Services in NG's configurations, settings, alerts and prompts.&lt;br /&gt;&lt;br /&gt;and its almost done, but I have to test it, I think it takes a couple of hours.&lt;br /&gt;&lt;br /&gt;right now I feel that nice headache, that I have when programming for 11+ hours in one day.&lt;br /&gt;So I've decided to leave the rest of the work for tomorrow.&lt;br /&gt;&lt;br /&gt;regarding another Navin's suggestion:&lt;br /&gt;&lt;br /&gt;&lt;span style="font-size:85%;"&gt;&lt;span style="font-style: italic;"&gt;If possible perhaps you can make NG´s driver load as a boot&lt;/span&gt;&lt;br /&gt;&lt;span style="font-style: italic;"&gt;driver, this way  it protects the system from the start.&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;I have to say that a System driver protects everything, and there is no need for Boot driver as  a driver can do anything from there, for example a driver can bypass NG's protection. I think this applies to all HIPS softwares.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/31650060-115419989122349467?l=neoava.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://neoava.blogspot.com/feeds/115419989122349467/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=31650060&amp;postID=115419989122349467&amp;isPopup=true' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/31650060/posts/default/115419989122349467'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/31650060/posts/default/115419989122349467'/><link rel='alternate' type='text/html' href='http://neoava.blogspot.com/2006/07/busy.html' title='busy'/><author><name>Arman Nayyeri</name><uri>http://www.blogger.com/profile/02442221103322416642</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='30' height='32' src='http://www.4rman.com/myneedles.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-31650060.post-115407115698468599</id><published>2006-07-28T10:47:00.000+03:30</published><updated>2006-09-29T20:18:36.766+03:30</updated><title type='text'>Monitoring Low-level disk access</title><content type='html'>Also thanks Krazaf for reminding me the low-level access monitoring.&lt;br /&gt;&lt;br /&gt;I've researched a little bit about this kind of access but still can't find information necessary for protection. If anyone (including Krazaf) have a Trojan, virus (or any malware) file which uses low-level access to do damage, please contact me.&lt;br /&gt;&lt;br /&gt;If you know exactly how these kind of malwares access and modify MBR or something (that needs low-level access) in Windows NT family, please leave a comment here.&lt;br /&gt;&lt;br /&gt;my busy days are just starting, hoping for better&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/31650060-115407115698468599?l=neoava.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://neoava.blogspot.com/feeds/115407115698468599/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=31650060&amp;postID=115407115698468599&amp;isPopup=true' title='2 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/31650060/posts/default/115407115698468599'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/31650060/posts/default/115407115698468599'/><link rel='alternate' type='text/html' href='http://neoava.blogspot.com/2006/07/monitoring-low-level-disk-access.html' title='Monitoring Low-level disk access'/><author><name>Arman Nayyeri</name><uri>http://www.blogger.com/profile/02442221103322416642</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='30' height='32' src='http://www.4rman.com/myneedles.jpg'/></author><thr:total>2</thr:total></entry><entry><id>tag:blogger.com,1999:blog-31650060.post-115407104231355098</id><published>2006-07-28T10:19:00.000+03:30</published><updated>2006-08-16T04:50:12.830+03:30</updated><title type='text'>suggestions</title><content type='html'>&lt;span style="font-size:100%;"&gt;there is a dozen of suggestion from Navin, I leave the completely GUI-related suggestions for the first release version as I plan to make big changes in GUI for first non-beta release.&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style="font-style: italic;font-size:100%;" &gt;&lt;span style="font-size:85%;"&gt;- It might be a conflict but often the "Executable options" can´t load,  I get  the following error: "error ReadRegString failed". And  then Neoavaguard.exe will crash. This is quite a serious bug.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style="font-size:100%;"&gt;It's debugged before.&lt;/span&gt;&lt;span style="font-style: italic;font-size:100%;" &gt;&lt;br /&gt;&lt;/span&gt;&lt;span style="font-size:100%;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style="font-style: italic;font-size:85%;" &gt;- I see that there isn´t a way to delete an entry from the  "Executable&lt;/span&gt;&lt;span style="font-size:100%;"&gt;&lt;span style="font-size:85%;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style="font-style: italic;font-size:85%;" &gt;options" window? This should be changed. I mean if a process is  not trusted&lt;/span&gt;&lt;span style="font-size:85%;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style="font-style: italic;font-size:85%;" &gt;or does not have any special permissions (or violations) it  should not be&lt;/span&gt;&lt;span style="font-size:85%;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style="font-style: italic;font-size:85%;" &gt;on the list constantly.&lt;br /&gt;&lt;/span&gt;&lt;span style="font-style: italic;font-size:85%;" &gt;-  About "My Protected Files", isn´t it a good idea to make this work  like&lt;/span&gt;&lt;span style="font-size:85%;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style="font-style: italic;font-size:85%;" &gt;Hide Folders XP? I´m not sure if it´s working correctly at the moment  and&lt;/span&gt;&lt;span style="font-size:85%;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style="font-style: italic;font-size:85%;" &gt;it can even be dangerous, because if not correctly used,  the OS will  not&lt;/span&gt;&lt;span style="font-size:85%;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style="font-style: italic;font-size:85%;" &gt;start anymore.&lt;/span&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style="font-size:100%;"&gt;&lt;span style="font-style: italic;"&gt;&lt;br /&gt;&lt;/span&gt;They will be fixed by changing GUI, the first one is actally something which can be is easily done as it is supported by lower parts. Actually there will be clean-up option, which will also automatically ask user to remove these executable entries.&lt;br /&gt;The second one needs some filters so it does not allow critical files to become unaccessible by system processes.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-style: italic;font-size:85%;" &gt;- You should have the ability to password protect Neoava Guard´s GUI,  with&lt;/span&gt;&lt;span style="font-size:85%;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style="font-style: italic;font-size:85%;" &gt;that I mean that as a non-admin you should be able to see the settings  but&lt;/span&gt;&lt;span style="font-size:85%;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style="font-style: italic;font-size:85%;" &gt;you shouldn´t be able to change anything and can´t allow (only  deny)&lt;/span&gt;&lt;span style="font-size:85%;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style="font-style: italic;"&gt;&lt;span style="font-size:85%;"&gt;certain behavior when prompted by an alert, unless you have a password.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;This is also a very good feature which will be applied by new GUI.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-style: italic;font-size:85%;" &gt;- I think you should make a difference between "Services" and&lt;/span&gt;&lt;span style="font-size:85%;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style="font-style: italic;font-size:85%;" &gt;"Drivers" in the  "Custom security" settings. If I´m correct drivers (.sys&lt;/span&gt;&lt;span style="font-size:85%;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style="font-style: italic;font-size:85%;" &gt;files) are used to  install rootkits and can be more dangerous than Services&lt;/span&gt;&lt;span style="font-size:85%;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style="font-style: italic;font-size:85%;" &gt;(.exe files).&lt;/span&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style="font-size:85%;"&gt;&lt;span style="font-size:100%;"&gt;&lt;br /&gt;Thats right, I will try to apply this today, I'll report back.&lt;br /&gt;&lt;br /&gt;thank you Navin!&lt;/span&gt;&lt;span style="font-style: italic;"&gt;&lt;/span&gt;&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/31650060-115407104231355098?l=neoava.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://neoava.blogspot.com/feeds/115407104231355098/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=31650060&amp;postID=115407104231355098&amp;isPopup=true' title='2 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/31650060/posts/default/115407104231355098'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/31650060/posts/default/115407104231355098'/><link rel='alternate' type='text/html' href='http://neoava.blogspot.com/2006/07/suggestions.html' title='suggestions'/><author><name>Arman Nayyeri</name><uri>http://www.blogger.com/profile/02442221103322416642</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='30' height='32' src='http://www.4rman.com/myneedles.jpg'/></author><thr:total>2</thr:total></entry><entry><id>tag:blogger.com,1999:blog-31650060.post-115386639407594837</id><published>2006-07-26T01:46:00.000+03:30</published><updated>2006-08-18T00:49:46.633+03:30</updated><title type='text'>Currently working on...</title><content type='html'>I'm working on Beta 2 version, the GUI is the same as Beta 1 but debugged and it contains a new feature which the user can choose during Wizard so NG will add all programs in computer to trusted applications so after reboot there will be very little amount of alerts (if any).&lt;br /&gt;&lt;br /&gt;tomorrow I'm going to start GUI part of this feature.&lt;br /&gt;&lt;br /&gt;BTW,&lt;br /&gt;those of you who are interested in beta-testing NG, please send me an email at arman@neoava.com and also write a little bit about yourself.&lt;br /&gt;&lt;br /&gt;I'll write about some bugs which is now corrected. I will write about other HIPS softwares here ASAP.&lt;br /&gt;&lt;br /&gt;I'm very positive about NG, it does have very nice performance by considering very detailed filtering.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/31650060-115386639407594837?l=neoava.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://neoava.blogspot.com/feeds/115386639407594837/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=31650060&amp;postID=115386639407594837&amp;isPopup=true' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/31650060/posts/default/115386639407594837'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/31650060/posts/default/115386639407594837'/><link rel='alternate' type='text/html' href='http://neoava.blogspot.com/2006/07/currently-working-on.html' title='Currently working on...'/><author><name>Arman Nayyeri</name><uri>http://www.blogger.com/profile/02442221103322416642</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='30' height='32' src='http://www.4rman.com/myneedles.jpg'/></author><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-31650060.post-115385264306053907</id><published>2006-07-25T21:02:00.000+03:30</published><updated>2006-08-18T01:43:20.760+03:30</updated><title type='text'>Creating this weblog</title><content type='html'>Hi,&lt;br /&gt;&lt;br /&gt;My name is Arman Nayyeri,  Im the author of Neoava Guard.&lt;br /&gt;&lt;br /&gt;I decided to create this weblog to stay in touch with everyone and publish news, updates, bugs and debugging information to this weblog for those who are interested in Neoava Guard (or HIPS softwares).&lt;br /&gt;&lt;br /&gt;For more info visit official Neoava Guard website:&lt;br /&gt;http://www.neoava.com&lt;br /&gt;&lt;br /&gt;For more info about myself:&lt;br /&gt;http://www.4rman.com&lt;br /&gt;&lt;br /&gt;I'll be back&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/31650060-115385264306053907?l=neoava.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://neoava.blogspot.com/feeds/115385264306053907/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=31650060&amp;postID=115385264306053907&amp;isPopup=true' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/31650060/posts/default/115385264306053907'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/31650060/posts/default/115385264306053907'/><link rel='alternate' type='text/html' href='http://neoava.blogspot.com/2006/07/creating-this-weblog.html' title='Creating this weblog'/><author><name>Arman Nayyeri</name><uri>http://www.blogger.com/profile/02442221103322416642</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='30' height='32' src='http://www.4rman.com/myneedles.jpg'/></author><thr:total>0</thr:total></entry></feed>
