Wilders Security Forums  

Go Back   Wilders Security Forums > Security Products > other anti-malware software
User Name
Password
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

 
 
Thread Tools Search this Thread
  #1  
Old December 13th, 2007, 04:09 AM
Kees1958's Avatar
Kees1958 Kees1958 is offline
Massive Poster
 
Join Date: Jul 2006
Posts: 5,857
Default Free light XP security combo

Hi all,

On the 'play with security PC' I have run for the last months a very light combo of freeware security

Samourai HIPS
Only select the following options:
a) enable rootkit protection,
b) disable anonymous sessions
c) disable guest account

Effect
==> Will warn you when a driver tries to install

ScriptDefender
Install scriptdefender

Effect
==> Will warn you when a script is run

Online Armor free
Run it out of the box with the following option
a) Go to the process guard and select the 'run safer' option for all your internet facing applications, like your e-mail client (eg. Outlook express), webbrowser (e.g. Internet Explorer), P2P program (eg LimeWire), messenger (e.g. Windows messenger)
b) Also run scriptdefender with limited rights (run safer)

Effect
==> Easy to use firewall and anti executable (the default setup)
==> All internet facing aps will run with limited rights (option A)
==> All scripts will run with limited righst (option B)

WinPooch
Download the attached filter in this post, http://www.wilderssecurity.com/showthread.php?t=186829 Open with Notepad and save as ANSI file with the WFP extention instead off TXT. Install WinPooch without the freeware Clamwin antivirus. Open Winpooch configuration, see http://www.softpedia.com/screenshots/Winpooch_3.png and import this filter

Effect
==> Will warn you when a sensitive registry key is changed (should be very quiet, meaning no popups)
==> Will warn you when a sensitive OS file is changed (should ve very quiet also)

Dealing with pop-ups
Samourai warning
When you are installing a legitemate application choose allow or otherwise block.

WinPooch
When you are installing a legitemate application choose "let process through". When you are updating (e.g. Antivirus) and WinPooch might pop-up, choose new filter (choose accept and quiet/silent in the next screen)

OA Armor
See help file
  #2  
Old December 13th, 2007, 04:22 AM
solcroft solcroft is offline
Very Frequent Poster
 
Join Date: Jun 2006
Posts: 1,639
Default Re: Free light XP security combo

Not bad, but try Limited User Account + XP access permissions + Windows Firewall. For all the vulnerabilities of a 5-year-old unpatched XP system, I've been browsing malware-free for the past week despite my best attempts to get infected.
  #3  
Old December 13th, 2007, 04:32 AM
RejZoR's Avatar
RejZoR RejZoR is offline
Polymorphic Sheep
 
Join Date: May 2004
Location: Europe/Slovenia/Ljubljana
Posts: 5,366
Default Re: Free light XP security combo

Forget all the crap. avast!+ThreatFire or AntiVir+ThreatFire.
You can add in some free firewall like PCTools Firewall or Comodo Firewall.
Thats all you'll ever need.
__________________
RejZoR's Little Secrets
  #4  
Old December 13th, 2007, 05:14 AM
Kees1958's Avatar
Kees1958 Kees1958 is offline
Massive Poster
 
Join Date: Jul 2006
Posts: 5,857
Default Re: Free light XP security combo

Quote:
Originally Posted by solcroft
Not bad, but try Limited User Account + XP access permissions + Windows Firewall. For all the vulnerabilities of a 5-year-old unpatched XP system, I've been browsing malware-free for the past week despite my best attempts to get infected.

LUA = 95% of the problems gone. This easy solution seems as hard to sell to people as getting them out of their cars. The feeling of being in control and freedom when your stuck in a traffic jam sitting in your car. :-)
  #5  
Old December 13th, 2007, 05:15 AM
Kees1958's Avatar
Kees1958 Kees1958 is offline
Massive Poster
 
Join Date: Jul 2006
Posts: 5,857
Default Re: Free light XP security combo

Quote:
Originally Posted by RejZoR
Forget all the crap. avast!+ThreatFire or AntiVir+ThreatFire.
You can add in some free firewall like PCTools Firewall or Comodo Firewall.
Thats all you'll ever need.

OA crap?
  #6  
Old December 13th, 2007, 09:12 AM
Pedro's Avatar
Pedro Pedro is offline
Massive Poster
 
Join Date: Nov 2006
Posts: 3,492
Default Re: Free light XP security combo

Why Script Defender when you have OA?
http://www.online-armor.com/worm_protection.html
  #7  
Old December 13th, 2007, 10:17 AM
Kees1958's Avatar
Kees1958 Kees1958 is offline
Massive Poster
 
Join Date: Jul 2006
Posts: 5,857
Default Re: Free light XP security combo

Pedro,

You are right but: see Mike's reply http://www.wilderssecurity.com/showp...&postcount=184 In the PM he send me he also mentioned Webbrowsers. So I was unsure whether the reduced rights option of webbrowser was still on as mentioned on this page http://www.online-armor.com/worm_protection.html

Only reason is to force scripts running with limited rights.

Regards
  #8  
Old December 13th, 2007, 10:30 AM
Kees1958's Avatar
Kees1958 Kees1958 is offline
Massive Poster
 
Join Date: Jul 2006
Posts: 5,857
Default Re: Free light XP security combo

All,

When you feel naked running without a AV, downloasd Avast and disable the standard shield, enable all others. This way you will have incoming data streams checked before they can write to disk.

HTTP AV's tend to slow down browsers a little. With Opera (use vista_skin-2_12) and the setting shown in the picture you will gain back this speed reduction (brwosing will be faster due to Opera and writing temporary internet data to memory in stead disk).

Select Extra (in Opera), select Preferences (Voorkeuren), CLick History (Geschiedenis) and choose these settings (Uit = OFF)
Attached Images
 
  #9  
Old December 13th, 2007, 12:39 PM
lucas1985's Avatar
lucas1985 lucas1985 is offline
Global Moderator
 
Join Date: Nov 2006
Location: France, May 1968
Posts: 4,047
Default Re: Free light XP security combo

Quote:
Originally Posted by solcroft
all the vulnerabilities of a 5-year-old unpatched XP system
SP1 (?)
__________________
"Pouvoir à l'Imagination. Power to the imagination. La imaginación al poder".

"Perfect is the enemy of good enough". Voltaire.
  #10  
Old December 14th, 2007, 08:16 AM
subset's Avatar
subset subset is offline
Frequent Poster
 
Join Date: Nov 2007
Location: Austria
Posts: 824
Default Re: Free light XP security combo

Seems like many found the Holy XP Security Grail

But it was found before.
http://www.sonypictures.com/cthe/montypython/

Handle with care...
  #11  
Old December 14th, 2007, 11:15 AM
Franklin's Avatar
Franklin Franklin is offline
Very Frequent Poster
 
Join Date: May 2005
Location: West Aussie
Posts: 2,517
Default Re: Free light XP security combo

Amd your PC still works with all those crappy security apps?
  #12  
Old December 14th, 2007, 12:32 PM
solcroft solcroft is offline
Very Frequent Poster
 
Join Date: Jun 2006
Posts: 1,639
Default Re: Free light XP security combo

Quote:
Originally Posted by Franklin
Amd your PC still works with all those crappy security apps?
If your PC will work with YOUR security apps, I don't see any reason why Kees' shouldn't.
  #13  
Old December 14th, 2007, 02:21 PM
Mrkvonic Mrkvonic is online now
Linux Systems Expert
 
Join Date: May 2005
Posts: 7,428
Default Re: Free light XP security combo

Hello,

A firewall, a light one (Kerio 2.1.5, Sygate, Jetico, GhostWall)
An anti-virus, a light one (AVG, Antivir)
Firefox / Opera

Maybe a few security policies.

You're set.

Mrk
__________________
http://www.dedoimedo.com

All your base are belong to us

Linux Systems Expert / Systems Programmer, Linux System Administrator, LPIC-1, LPIC-2 (WIP), GSEC, CCHD, CCHA
  #14  
Old December 14th, 2007, 09:35 PM
Kees1958's Avatar
Kees1958 Kees1958 is offline
Massive Poster
 
Join Date: Jul 2006
Posts: 5,857
Default Re: Free light XP security combo

Quote:
Originally Posted by Mrkvonic
Hello,

A firewall, a light one (Kerio 2.1.5, Sygate, Jetico, GhostWall)
An anti-virus, a light one (AVG, Antivir)
Firefox / Opera

Maybe a few security policies.

You're set.

Mrk

In stead of making security policies I would choose running as Limited User
  #15  
Old December 14th, 2007, 09:42 PM
Kees1958's Avatar
Kees1958 Kees1958 is offline
Massive Poster
 
Join Date: Jul 2006
Posts: 5,857
Default Re: Free light XP security combo

Quote:
Originally Posted by Franklin
Amd your PC still works with all those crappy security apps?

Why not, no Antivirus.

Opera startup (initial, uncached, connecting to google) is <2 sec on an AMD Athlon 3400 with 1 GB, cached startups <1 sec

Not bad I think
  #16  
Old December 14th, 2007, 10:21 PM
Arup
 
Posts: n/a
Default Re: Free light XP security combo

Quote:
Originally Posted by RejZoR
Forget all the crap. avast!+ThreatFire or AntiVir+ThreatFire.
You can add in some free firewall like PCTools Firewall or Comodo Firewall.
Thats all you'll ever need.


I would go with that except that Threat Fire is OK for high mem latest machines. Not recommended for P-III PCs running 512MB ram.
  #17  
Old December 15th, 2007, 04:13 AM
SpikeyB SpikeyB is offline
Frequent Poster
 
Join Date: Mar 2005
Posts: 464
Default Re: Free light XP security combo

Quote:
Originally Posted by Kees1958
In stead of making security policies I would choose running as Limited User
Limited user and software restrictions work together very well. An example is shown here: http://www.mechbgon.com/srp/
  #18  
Old December 15th, 2007, 07:03 AM
Kees1958's Avatar
Kees1958 Kees1958 is offline
Massive Poster
 
Join Date: Jul 2006
Posts: 5,857
Default Re: Free light XP security combo

Quote:
Originally Posted by SpikeyB
Limited user and software restrictions work together very well. An example is shown here: http://www.mechbgon.com/srp/
Yep,

But not on XP home
 

Wilders Security Forums > Security Products > other anti-malware software « Previous Thread | Next Thread »

Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Settings
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump


All times are GMT -4. The time now is 01:06 PM.


Powered by vBulletin® Copyright ©2000 - 2013, Jelsoft Enterprises Ltd.
Copyright ©2002 - 2013, Wilders Security Forums