What is your security setup these days?

Discussion in 'other anti-malware software' started by dja2k, Dec 15, 2005.

  1. soulfood

    soulfood Registered Member

    Joined:
    Nov 11, 2008
    Posts:
    10
    Location:
    Northern California
    What is HIPS, and which one would you recommend I try? Thanks.
     
  2. n8chavez

    n8chavez Registered Member

    Joined:
    Jul 19, 2003
    Posts:
    3,357
    Location:
    Location Unknown
    Host Intrusion Prevention System

    That would be a god idea, except that you are a newbie. I don't think that those products are for people with little experience. They can be quite powerful yet quite complicated. Essentially it is up to the user to provide rules for what can and cannot be done on your system. If you want to wet your feet a little try Threatfire or Mamuntu, a behavioral HIPS. But, stay away from rule-based ones for now.

    There are many way of dealing with system security. I prefer the sandbox/virtualization method, where ther is little to no user intervention after getting everything configured.
     
  3. LoneWolf

    LoneWolf Registered Member

    Joined:
    Jan 2, 2006
    Posts:
    3,785
  4. n8chavez

    n8chavez Registered Member

    Joined:
    Jul 19, 2003
    Posts:
    3,357
    Location:
    Location Unknown
  5. LoneWolf

    LoneWolf Registered Member

    Joined:
    Jan 2, 2006
    Posts:
    3,785
    Did'nt know it was a race. :D
     
  6. EASTER

    EASTER Registered Member

    Joined:
    Jul 28, 2007
    Posts:
    11,126
    Location:
    U.S.A. (South)
    Threatfire 4 is making positive advances IMO which are welcome indeed but MAMUTU is leading the charge so far, not to take anything away from TF. I meant what i said, TF is working on being historic and i wish them all the best.

    EASTER
     
  7. jmonge

    jmonge Registered Member

    Joined:
    Mar 20, 2008
    Posts:
    13,744
    Location:
    Canada
    MalWare Defender Beta:thumb:
    Ashampoo AtiSpyWare 2 Guard trial(40 days):D
     
  8. Kees1958

    Kees1958 Registered Member

    Joined:
    Jul 8, 2006
    Posts:
    5,857
    Trying a lighter than light set up on the home PC (E5200@3Ghz, 2 GB RAM)

    General security features
    1. Behind a properly configured hardware router/firewall
    2. Image backup's and data backup to external harddisk (connected only at backup)

    PC specific feature
    XP PRO Policy restriction Is configured as s (special) Limited User with extra Power User rights to change some system wide settings
    - power user, with tweak to add limited user rights as extra option in SRP
    - additional rules:
    a) removed default rules of unlimited access to root, root *.exe and system32 *.exe
    b) changed default rule of unlimited access of program dirs to limited user
    c) reduced rights of data directories to limited user
    d) set block to all temp + P2P directories (on D:\)

    Spyberus (to guard installation of software in poweruser/user mode space), works well for this purpose

    AVG Free
    - default setting + tracking cookies

    Security versus system performance
    Although security now with two aps instead of one (was ThreatFire), everything runs real light because
    a) Policy restriction is build in XP Pro (no extra)
    b) Spyberus uses few CPU, it protects file and registry changes as a file driver (plus hook setting, driver loading and injection protection), so only when these change Spyberus uses overhead
    c) AVG is fast on dual core machines with surprisingly little I/O

    Using IE7 as browser
     
    Last edited: Nov 13, 2008
  9. O.Alexander

    O.Alexander Guest

    Active:
    Defensewall HIPS 2.45
    Windows Vista built-in security (AS,FW,UAC,DEP)

    On-Demand:
    Dr.Web Cureit!

    Can anyone recommend me a nice AV for on-demand scanner only?
    (not using any resources just like cureit?)
     
  10. jmonge

    jmonge Registered Member

    Joined:
    Mar 20, 2008
    Posts:
    13,744
    Location:
    Canada
    it is a Host Intrution Prevention System which one of main purpose it is to prevent or it is intended to protect critical areas of your pc like:application,files and registry in real time applying restrictions to get the best protection as posible:thumb: i will recomend EQSecure and Malware Defender:thumb:
     
  11. n8chavez

    n8chavez Registered Member

    Joined:
    Jul 19, 2003
    Posts:
    3,357
    Location:
    Location Unknown
    As good as those products are, and they are, I do not recommend that people new and unfamilar with HIPS products use any kind of rule-based HIPS. EQSecure is perhaps the best of its breed but it is extremely difficult to set up. If you are not absollutely ceratin what you are doing you could end up 'fubaring' your system.
     
  12. n8chavez

    n8chavez Registered Member

    Joined:
    Jul 19, 2003
    Posts:
    3,357
    Location:
    Location Unknown
    You could try AVP. If is an on-demand scanner from Kaspersky. It's quite good.
    There are other ways to rid yourself of malware. Try some of the online scans, such as NOD32, or Housecall. They will require no instalations.
     
  13. jmonge

    jmonge Registered Member

    Joined:
    Mar 20, 2008
    Posts:
    13,744
    Location:
    Canada
    i am a new with this aproach too and i have to learn if i want to be protected for my own good,and now i understand it,if soulfood take time to read he/she will learn and dont need bunch of security apps(mediocre) in place or insted of a real time shield as a hips:thumb: one day he/she has to learn anyway if interested.my only advice is read and try to understand and if you feel(soulfood)it is hard for you go simple with just with antivirus/antispyware:cool:
     
  14. n8chavez

    n8chavez Registered Member

    Joined:
    Jul 19, 2003
    Posts:
    3,357
    Location:
    Location Unknown
    Areed. Learning is a process. Start simple. Then, when you're ready, evolve.
     
  15. jmonge

    jmonge Registered Member

    Joined:
    Mar 20, 2008
    Posts:
    13,744
    Location:
    Canada
    to be honest it takes time and some times couple of blue screens:D to the menu:cool: i also started simple too with only avira:D (free antivirus)
     
  16. Long View

    Long View Registered Member

    Joined:
    Apr 30, 2004
    Posts:
    2,295
    Location:
    Cromwell Country
    and when you've evolved you realize it's ok to go back to being simple :D
     
  17. jmonge

    jmonge Registered Member

    Joined:
    Mar 20, 2008
    Posts:
    13,744
    Location:
    Canada
    for me to be simple is 2 layer a well configure hips program and me:D in charge:thumb:
     
  18. Sully

    Sully Registered Member

    Joined:
    Dec 23, 2005
    Posts:
    3,719
    Oh is this ever true. But to find the apps that KISS and provide moderate to good protection is the problem.

    Sul.
     
  19. Cerxes

    Cerxes Registered Member

    Joined:
    Sep 6, 2005
    Posts:
    581
    Location:
    Northern Europe
    My current setup are the following (Win XP Pro):

    LUA
    SRP (restricting choosen fileextensions and WSH)
    DEP "AlwaysOn"
    Comodo Memory Firewall
    Avast (minor problem with the DEP "AlwaysOn" switch)
    SuRun
    Sandboxie
    KeyScrambler
    WinPatrol
    Windows Defender (HIPS activated)

    Even if I at times tries out different security applications/tools, those above mentioned are the ones I have kept for a longer period now. Regarding redundancy among these, then it would be between WinPatrol and Windows Defender (the HIPS part). But since they are both very light (CPU) and runs well together without any conflict (even at detection), I have kept them both on my system.

    /C.
     
  20. hammerman

    hammerman Registered Member

    Joined:
    Jul 14, 2007
    Posts:
    283
    Location:
    UK
    Active

    Online-Armor 3 Build 190
    AntiVir 8
    Defensewall 2.45
    EQS3.41
    SandboxIE 3.30
    Returnil
    Mamutu - removed

    On demand

    MBAM
    SAS (paid)
    RootRepeal
    IceSword
    GMER
    A-Squared
    TinyWatcher
    FileChangeAlarm
    MJ Registry Watcher
    Spyware Blaster
    AVZ
    Runscanner
    FingerPrint
    What's Running
    RegShot

    Backup

    FD-ISR
    True Image 10
    DriveImageXML
     
  21. Ed_H

    Ed_H Registered Member

    Joined:
    Nov 10, 2004
    Posts:
    662
    Location:
    Chicago, IL
    No conflicts or slowdowns with 3 HIPS programs running?
     
  22. hammerman

    hammerman Registered Member

    Joined:
    Jul 14, 2007
    Posts:
    283
    Location:
    UK
    Fortunately no. I've been running the same setup for a few months and occasionally tried TF and Mamutu. Not really convinced by these behavioural blockers though.
     
  23. evilscribble

    evilscribble Registered Member

    Joined:
    Apr 30, 2008
    Posts:
    48
    The real slowdown is when they pop up about everything and waste your time.
     
  24. hammerman

    hammerman Registered Member

    Joined:
    Jul 14, 2007
    Posts:
    283
    Location:
    UK
    Fortunately Defensewall is extremely quiet. OA is not too bad for pop-up's but to be honest, EQS can be quite a pain sometimes. Especially as it sometimes take 2 or more Allow's before EQS accepts a rule. In Wife mode, I have to disable EQS or my mouse may get implanted!
     
  25. Subgud

    Subgud Registered Member

    Joined:
    Nov 6, 2008
    Posts:
    151
    Location:
    Norway
    MAMUTU?? What kind of program is that? i know of A-squared 4. But is MAMUTU a product with HIPS?

    I use GDATA IS 2009. I dont think the firewall has HIPS. Is there a program i can use that has it? I use SAS PRO realtime and MBAM for scanning sometimes.
     
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.