Wilders Security Forums  

Go Back   Wilders Security Forums > Security Products > other anti-malware software
User Name
Password
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

 
 
Thread Tools Search this Thread
  #451  
Old May 12th, 2012, 12:21 AM
The Hammer's Avatar
The Hammer The Hammer is offline
Massive Poster
 
Join Date: May 2005
Location: Toronto Canada
Posts: 5,091
Default Re: Post your x64 Security Setup

Thanks 1chaoticadult.
__________________
Desktop -Win 7 Home Premium 64 bit, NAT Router Firewall, Windows Firewall, Avira Antivirus Premium V13, MBAM PRO 1.75 , WOT, Win 7's System imaging. Netbook-Avira Antivirus Premium V13 , MBAM PRO 1.75, WOT.
  #452  
Old May 12th, 2012, 12:23 AM
1chaoticadult's Avatar
1chaoticadult 1chaoticadult is offline
Very Frequent Poster
 
Join Date: Oct 2010
Location: Chaotic Land
Posts: 2,219
Default Re: Post your x64 Security Setup

Quote:
Originally Posted by The Hammer
Thanks 1chaoticadult.

No problem
__________________
Built-in OS Security + EMET + HitmanPro
  #453  
Old May 17th, 2012, 01:56 PM
Fly Fly is offline
Very Frequent Poster
 
Join Date: Nov 2007
Posts: 1,865
Default Re: Post your x64 Security Setup

On WIN XP I usually 'rely' on a security suite.
'Rely' isn't the best word since I use common sense, a lot of caution and an imaging setup.

Still, a suite (mostly a firewall plus AV) offers some protection.

On WIN 7 64 bit this type of software is less effective because the AV vendors have limited or no access to the kernel.
I understand a HIPS can be bypassed.

If I wanted to 'rely' on a security suite for my WIN 7 64 bit PRO, what measures could I take to deal with these shortcomings without making things complicated ?

Opinions ?
  #454  
Old May 18th, 2012, 12:55 AM
No_script No_script is offline
Regular Poster
 
Join Date: May 2012
Posts: 97
Default Re: Post your x64 Security Setup

Quote:
what measures could I take to deal with these shortcomings without making things complicated ?

Uninstall Windows if you want to be safer. If someone is out to get you, not much you can do.
  #455  
Old May 20th, 2012, 05:12 PM
Kees1958's Avatar
Kees1958 Kees1958 is offline
Massive Poster
 
Join Date: Jul 2006
Posts: 5,857
Default Re: Post your x64 Security Setup

Quote:
Originally Posted by Fly
On WIN XP I usually 'rely' on a security suite.
'Rely' isn't the best word since I use common sense, a lot of caution and an imaging setup.

Still, a suite (mostly a firewall plus AV) offers some protection.

On WIN 7 64 bit this type of software is less effective because the AV vendors have limited or no access to the kernel.
I understand a HIPS can be bypassed.

If I wanted to 'rely' on a security suite for my WIN 7 64 bit PRO, what measures could I take to deal with these shortcomings without making things complicated ?

Opinions ?

Use Software restriction policy (your on PRO might as well use it) in the following settings:

Security Levels: set basic user as default
Additonal rules: none use the default
Enforcement
- All software files
- All users except Admins
- Ignore certificate rules
Designated file types: don't change, use the default
Trusted Publishers: dont change, use the default

Add registry trick to install MSI's as ADMIN (safe text below as MSIasADMIN.REG)
----------------------------------------
Windows Registry Editor Version 5.00

[HKEY_CLASSES_ROOT\Msi.Package\Shell\runas]
"HasLUAShield"=""

[HKEY_CLASSES_ROOT\Msi.Package\shell\runas\Command]
@=hex(2):22,00,25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,74,\
00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,6d,00,\
73,00,69,00,65,00,78,00,65,00,63,00,2e,00,65,00,78,00,65,00,22,00,20,00,2f,\
00,69,00,20,00,22,00,25,00,31,00,22,00,20,00,25,00,2a,00,00,00
----------------------------------------
===> effect you can only install software by running it as ADMIN, no risk for shoot in the foot (social engineering) or drive by's

Install EMET 3.0 for all internet facing software and plug-ins (e.g Adobe Reader).
===> effect you are pretty good secured against memory based intrusions

Install 64 bit version of MSE
===> effect, same company AV, Moneysoft should know how to deal with kernel limitation

Use IE64, make some adjustments in GPEDIT to harden IE (see picture)
===> effect, no fiddling with security features of IE


You are done with your Microsoft suite
Attached Thumbnails
Click image for larger version

Name:	Untitled.png
Views:	14
Size:	72.8 KB
ID:	232965  


Last edited by Kees1958 : May 20th, 2012 at 05:26 PM.
  #456  
Old June 10th, 2012, 06:02 AM
zip's Avatar
zip zip is offline
Frequent Poster
 
Join Date: Apr 2007
Posts: 324
Default Re: Post your x64 Security Setup

It's in my sig.
__________________
Bitdefender Free Edition | Norton ConnectSafe | Mbam Pro | WinPatrol Plus | Windows Firewall | 7 64bit |

router firewall

"If you want to make a Conservative angry, tell him a lie. If you want to make a Liberal angry, tell him the truth." - Rush Limbaugh
  #457  
Old June 10th, 2012, 08:21 AM
nikanthpromod's Avatar
nikanthpromod nikanthpromod is offline
Very Frequent Poster
 
Join Date: Oct 2009
Location: India
Posts: 1,368
Default Re: Post your x64 Security Setup

my first post in this thread
windows 7 home premium
Eset AV 5
Rollback RX
Hitmanpro
SUMo
Firefox with ABP and FB
__________________
Windows 7 Home premium x64
WEBROOT Secure Anywhere Complete

  #458  
Old June 10th, 2012, 09:43 AM
IBadget IBadget is offline
Regular Poster
 
Join Date: Jan 2009
Location: Waipahu, HI
Posts: 59
Default Re: Post your x64 Security Setup

On Win 7 x64 I am using AdAware Antivirus Free and BufferZone Pro Free.
  #459  
Old June 10th, 2012, 11:25 AM
STONEMAN's Avatar
STONEMAN STONEMAN is offline
Regular Poster
 
Join Date: Jan 2009
Location: London,South Of The River
Posts: 91
Default Re: Post your x64 Security Setup

Webroot SecureAnywhere Essentials
Sandboxie
ShadowDefender
__________________
Windows 7 64bit
Appguard---Sandboxie
Shadowdefender---Looknstop Firewall
  #460  
Old June 10th, 2012, 11:42 AM
1chaoticadult's Avatar
1chaoticadult 1chaoticadult is offline
Very Frequent Poster
 
Join Date: Oct 2010
Location: Chaotic Land
Posts: 2,219
Default Re: Post your x64 Security Setup

Network:
Router
SPI firewall turned on
Norton ConnectSafe

Realtime Protection:
Windows SmartScreen
Windows Defender
Windows Firewall

System Hardening -- Windows 8 64bit:
UAC on Max
Disabled some services
EMET:
DEP Always On
SEHOP Always On
ASLR Always On
Certain exe's forced with EMET

Internet Explorer 10 Release Preview
Fanboy Adblock & Tracking TPLs
Enhanced Protection Mode
SmartScreen Filter
Block Third-Party Cookies
DuckDuckGo Default Search Provider

Backup:
Windows Backup & Restore
Cobian Backup
__________________
Built-in OS Security + EMET + HitmanPro
  #461  
Old June 18th, 2012, 07:11 PM
zip's Avatar
zip zip is offline
Frequent Poster
 
Join Date: Apr 2007
Posts: 324
Default Re: Post your x64 Security Setup

I've upgraded from Mbam free to Mbam Pro.

I can't wait for Mbam 64bit Pro.
__________________
Bitdefender Free Edition | Norton ConnectSafe | Mbam Pro | WinPatrol Plus | Windows Firewall | 7 64bit |

router firewall

"If you want to make a Conservative angry, tell him a lie. If you want to make a Liberal angry, tell him the truth." - Rush Limbaugh
  #462  
Old June 18th, 2012, 07:21 PM
trjam's Avatar
trjam trjam is offline
Incredibly Massive Poster
 
Join Date: Aug 2006
Location: North Carolina
Posts: 8,620
Default Re: Post your x64 Security Setup

still with my favorite 2.
__________________
Webroot SecureAnywhere
  #463  
Old June 18th, 2012, 09:25 PM
blasev's Avatar
blasev blasev is offline
Frequent Poster
 
Join Date: Oct 2010
Posts: 640
Default Re: Post your x64 Security Setup

Its late but Thx for the tweak kees1958
I always amaze with your registry knowledge
  #464  
Old June 18th, 2012, 09:26 PM
Function Function is offline
Regular Poster
 
Join Date: Feb 2012
Location: UK
Posts: 64
Default Re: Post your x64 Security Setup

Quote:
Originally Posted by zip
I've upgraded from Mbam free to Mbam Pro.

I can't wait for Mbam 64bit Pro.

Is there a release date for it? I have the paid 32 bit version at the moment.
  #465  
Old June 19th, 2012, 08:31 AM
IBadget IBadget is offline
Regular Poster
 
Join Date: Jan 2009
Location: Waipahu, HI
Posts: 59
Default Re: Post your x64 Security Setup

I dropped BufferZone Pro Free because it was causing Silverlight to hang. I now use AVG Free. I trust AVG Linkscanner to stop exploits cold.
  #466  
Old June 30th, 2012, 11:53 PM
zip's Avatar
zip zip is offline
Frequent Poster
 
Join Date: Apr 2007
Posts: 324
Default Re: Post your x64 Security Setup

I'm very happy to be back with Opera!

Mouse gesters were the cause of my "problems" with Opera. Disabled them.

I'm running Opera 64 bit.

BTW, there is no substitute for Opera!
__________________
Bitdefender Free Edition | Norton ConnectSafe | Mbam Pro | WinPatrol Plus | Windows Firewall | 7 64bit |

router firewall

"If you want to make a Conservative angry, tell him a lie. If you want to make a Liberal angry, tell him the truth." - Rush Limbaugh

Last edited by zip : July 1st, 2012 at 12:09 AM.
  #467  
Old July 1st, 2012, 09:28 AM
newbino newbino is offline
Frequent Poster
 
Join Date: Aug 2007
Posts: 270
Default Re: Post your x64 Security Setup

Win 7 Pro
Windows Firewall + Windows Firewall Notifier
EMET
Sandboxie
AppGuard
MSE incoming (write) only
+
HitmanPro on demand, daily scan
MBAM on demand, weekly scan
  #468  
Old July 6th, 2012, 08:22 PM
ShockWaves's Avatar
ShockWaves ShockWaves is offline
Infrequent Poster
 
Join Date: Jul 2012
Location: United States
Posts: 12
Default Re: Post your x64 Security Setup

Mine is in my signature.
  #469  
Old July 6th, 2012, 08:32 PM
jjc225's Avatar
jjc225 jjc225 is offline
Regular Poster
 
Join Date: Nov 2010
Posts: 69
Default Re: Post your x64 Security Setup

I have a Compaq pc that is Windows 7 and 64-bit. I use ESET NOD32, Superantispyware Pro, and the regular Windows firewall. So far so good. Really like ESET.
  #470  
Old July 6th, 2012, 08:51 PM
IBadget IBadget is offline
Regular Poster
 
Join Date: Jan 2009
Location: Waipahu, HI
Posts: 59
Default Re: Post your x64 Security Setup

I dropped AVG because their LinkScanner was preventing Java from working properly. Now I'm using Comodo Internet Security 5.10 with Enhanced Protection enabled.
  #471  
Old July 6th, 2012, 11:38 PM
boonie's Avatar
boonie boonie is offline
Frequent Poster
 
Join Date: Aug 2007
Posts: 238
Default Re: Post your x64 Security Setup

Making the switch away from 32bit (and DefenseWall and Zemana).
So for right now:

Resident and Sandboxing:
MBAM Pro (trial)
SandBoxie Paid

On Demand
EAM
Hitman Pro
SARDU Boot Disc

System Hardening
UAC Silent
EMET
Spyware Blaster

Backup/Recovery
IFW for Imaging

Wanted to test SpyShelter, but I can't connect to the site. Down?
__________________
Rudeness is the weak man's imitation of strength.
Eric Hoffer
  #472  
Old July 7th, 2012, 12:45 AM
digmor crusher's Avatar
digmor crusher digmor crusher is offline
Infrequent Poster
 
Join Date: Jul 2012
Location: Canada
Posts: 37
Default Re: Post your x64 Security Setup

See my sig.
__________________
Avast 8 free, MBAM Pro, Win Patrol Plus, OA free, SUMO, CCleaner, Router firewall, LastPass, AdBlock Plus, Do Not Track Me, Traffic Light,
  #473  
Old July 7th, 2012, 08:42 AM
zip's Avatar
zip zip is offline
Frequent Poster
 
Join Date: Apr 2007
Posts: 324
Default Re: Post your x64 Security Setup

I use the antirootkit built into MSE. (If any)
__________________
Bitdefender Free Edition | Norton ConnectSafe | Mbam Pro | WinPatrol Plus | Windows Firewall | 7 64bit |

router firewall

"If you want to make a Conservative angry, tell him a lie. If you want to make a Liberal angry, tell him the truth." - Rush Limbaugh
  #474  
Old July 7th, 2012, 01:36 PM
Noob's Avatar
Noob Noob is offline
Massive Poster
 
Join Date: Nov 2009
Posts: 5,252
Default Re: Post your x64 Security Setup

Quote:
Originally Posted by Kees1958
Use Software restriction policy (your on PRO might as well use it) in the following settings:

Security Levels: set basic user as default
Additonal rules: none use the default
Enforcement
- All software files
- All users except Admins
- Ignore certificate rules
Designated file types: don't change, use the default
Trusted Publishers: dont change, use the default

Add registry trick to install MSI's as ADMIN (safe text below as MSIasADMIN.REG)
----------------------------------------
Windows Registry Editor Version 5.00

[HKEY_CLASSES_ROOT\Msi.Package\Shell\runas]
"HasLUAShield"=""

[HKEY_CLASSES_ROOT\Msi.Package\shell\runas\Command]
@=hex(2):22,00,25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,74,\
00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,6d,00,\
73,00,69,00,65,00,78,00,65,00,63,00,2e,00,65,00,78,00,65,00,22,00,20,00,2f,\
00,69,00,20,00,22,00,25,00,31,00,22,00,20,00,25,00,2a,00,00,00
----------------------------------------
===> effect you can only install software by running it as ADMIN, no risk for shoot in the foot (social engineering) or drive by's

Install EMET 3.0 for all internet facing software and plug-ins (e.g Adobe Reader).
===> effect you are pretty good secured against memory based intrusions

Install 64 bit version of MSE
===> effect, same company AV, Moneysoft should know how to deal with kernel limitation

Use IE64, make some adjustments in GPEDIT to harden IE (see picture)
===> effect, no fiddling with security features of IE


You are done with your Microsoft suite
I didn't know the admin part :O:O
*Bookmarked*
__________________
Emsisoft Anti-Malware v7.0.0.21 - Online Armor 6.0.0.1736
SRP - UAC - EMET

Browser: Google Chrome v25.xx

Windows 7 Ultimate x64
  #475  
Old July 7th, 2012, 03:31 PM
ESQ_ERRANT ESQ_ERRANT is offline
Regular Poster
 
Join Date: Jul 2006
Posts: 72
Default Re: Post your x64 Security Setup

Quote:
Originally Posted by elstupido
According to Tzuk at Sandboxie, a kernel patch from MS may cause sandboxie to BSOD.
I tried SANDBOXIE on my WIN7 PRO x64. The software destroyed my OS. I had to reformat. For me, I find it best to use my VMWARE WORKSTATION if I am going to be doing much websurfing.

Last edited by ESQ_ERRANT : July 7th, 2012 at 03:41 PM.
 

Wilders Security Forums > Security Products > other anti-malware software « Previous Thread | Next Thread »

Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Settings
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump


All times are GMT -4. The time now is 06:20 AM.


Powered by vBulletin® Copyright ©2000 - 2013, Jelsoft Enterprises Ltd.
Copyright ©2002 - 2013, Wilders Security Forums