PDA

View Full Version : Advice on additions to CIS


a320ca
May 1st, 2009, 02:59 PM
Currently running CIS RC2 and SandboxIE 3.36.04, but looking for suggestions on what other additions would be beneficial from the "knowledged" here.

Looking for "light and effective" applications.

renegade08
May 1st, 2009, 03:06 PM
Shouldn't be this in the polls?

http://www.wilderssecurity.com/forumdisplay.php?f=46

a320ca
May 1st, 2009, 03:13 PM
-{ Quote: "Shouldn't be this in the polls?

http://www.wilderssecurity.com/forumdisplay.php?f=46" }-

Yeah, didn't realize there was a "poll" section. Thanks.

Mods please move as needed.

Warklen
May 1st, 2009, 07:58 PM
Looks good and light the way it is...imo

aigle
May 1st, 2009, 08:23 PM
Hmm.... it,s more than enough infact. I wish if u could add TF but it will slow things down unacceptably.

renegade08
May 2nd, 2009, 07:55 AM
-{ Quote: "Hmm.... it,s more than enough infact. I wish if u could add TF but it will slow things down unacceptably." }-

I can't agree more.

Let it that way.

Maybe should consider of Shadow Defender as another layer of defense.
You can run all the time turned on, and only once a day you will go out of shadow mode and update security apps, and then you can go in the shadow mode again.
Sandboxie is a good software, and with Shadow defender you should be protected enough. With every restart everything that is on PC will be erased (same as Sandboxie).
The things that will pass Sandboxie will be stopped by Shadow Defender.

And possible you should consider of some anti-keylogger as Zemana (paid) or Keyscrambler (free).

raven211
May 2nd, 2009, 09:28 AM
-{ Quote: "I wish if u could add TF but it will slow things down unacceptably." }-

... for some people like aigle. ;D

aigle
May 2nd, 2009, 09:32 AM
...yep. ;D

raakii
May 2nd, 2009, 11:55 AM
Add shadow defender or wait until Comodo time machine is released as addon of CIS.

a320ca
May 2nd, 2009, 12:13 PM
-{ Quote: "I can't agree more.

Let it that way.

Maybe should consider of Shadow Defender as another layer of defense.
You can run all the time turned on, and only once a day you will go out of shadow mode and update security apps, and then you can go in the shadow mode again.
Sandboxie is a good software, and with Shadow defender you should be protected enough. With every restart everything that is on PC will be erased (same as Sandboxie).
The things that will pass Sandboxie will be stopped by Shadow Defender.

And possible you should consider of some anti-keylogger as Zemana (paid) or Keyscrambler (free)." }-

Thanks. Have added Zemana AntiLogger 1.8.2.993 (paid). I have SD and SB on another system. When venturing into unknown territory I shadow first, then open my SB'd browser. Works great!

a320ca
May 2nd, 2009, 12:16 PM
-{ Quote: "Hmm.... it,s more than enough infact. I wish if u could add TF but it will slow things down unacceptably." }-

Thanks. I would appreciate it if someone could break down the differences in the following for a non-expert like me...

Threatfire
Prevx 3.0
Defensewall

Signature based? Behavior??

Thanks.

raven211
May 2nd, 2009, 12:44 PM
-{ Quote: "Thanks. I would appreciate it if someone could break down the differences in the following for a non-expert like me...

Threatfire
Prevx 3.0
Defensewall

Signature based? Behavior??

Thanks." }-

ThreatFire: Pure behavior blocker. Once it sees unexpected/suspicious/forbidden behavior, it'll finally look in its cloud-db. If it's in the whitelist, it can simply let it pass. If it's in the blacklist, it'll automatically quarantine and give the user the information. Finally, if it's in neither list, it'll prompt the user to make a decision. Unlike HIPS, which will prompt for everything, TF uses a huge set of actions that should normally not happen, and the white- and blacklists are only managed by the creators of the software, so no risk for rating from average Joe in a community-db. Since it hooks what's running instantly, it's very fast in its detection and is uncommon to FPs.

Prevx 3.0: Completely managed server-side in its protection. It features a gigantic database online with data not already included instantly added when found. The database also features advanced heuristical capabilities that the devs. can change level of depending on situation (e.g. higher when high-risk for Conficker-infections). Sadly more common with FPs lately - lost many users for it, incl. me, but the company behind the program is amazing and so is the support from them. They really listen to their users unlike any company I've seen so far.


Someone else will have to write for DefenseWall - I've no experience with it really. :P ;D

aigle
May 3rd, 2009, 12:15 PM
-{ Quote: "Thanks. Have added Zemana AntiLogger 1.8.2.993 (paid). " }-Not needed at all with CIS.

tipstir
May 5th, 2009, 12:28 PM
I've used all except the DefenseWall. Light on the system PrevX, and these two (MBM, SAS with SmithFaudfix in safe mode) clean-up.

PsychEroc
May 5th, 2009, 02:47 PM
In my new Win 7 virtual machine I'm running CIS (3.9.75615.498_RC2 with AntiVirus disabled) and Avira AntiVir Personal. I think AA has a better detection record than CIS AntiVirus. No problems so far, everything appears to working quickly and light. I haven't tried adding Sandboxie yet, but will soon.

a320ca
May 6th, 2009, 02:40 PM
...playing around with this NEWLY REVISED setup. So far no issues...

a320ca
May 10th, 2009, 03:41 AM
-{ Quote: "a320ca, excellent setup there. A few comments and queries:

1. Is MBAM real-time protection really needed?
2. Are you using Comodo Antivirus? If so, I would ask you to consider switching to Avira Free (especially if you have a multi-core processor which Avira will take advantage of)
3. Is Zemana Antilogger needed? You have Defense+ running in real-time don't you?
4. Sandboxie AND Shadow Defender. That's very comprehensive! It's a pity Shadow Defender can't maintain a virtualised session across reboots though.
5. Do you have any evidence showing how effective Hitman Pro is?" }-

No longer running MBAM in realtime.

Back to A-Squared for AV/AM.

Zemana and Hitman Pro are really light. I don't even know they're there.