What is your security setup these days?

Discussion in 'other anti-malware software' started by dja2k, Dec 15, 2005.

  1. Rasheed187

    Rasheed187 Registered Member

    Joined:
    Jul 10, 2004
    Posts:
    17,561
    Location:
    The Netherlands
    Yes it's a bit boring and I think also a bit cryptic to most people. I believe that most want to see what type of security tools people are using. Instead you're posting about how you have hardened Windows, over and over again. :D
     
  2. Rasheed187

    Rasheed187 Registered Member

    Joined:
    Jul 10, 2004
    Posts:
    17,561
    Location:
    The Netherlands
    Then perhaps I will give it a try, because you seem to be using even more tools, thanks for the feedback.
     
  3. Minimalist

    Minimalist Registered Member

    Joined:
    Jan 6, 2014
    Posts:
    14,883
    Location:
    Slovenia, EU
    @Windows_Security if you've finished with security on Windows, maybe you could explore privacy part also. I moved my focus to that part and it's also interesting :)
     
  4. These are the Safe Admin registry tweaks (last post :))

    Disable access to shell and scripts

    Disable 16-bits (32 bits)

    http://smallvoid.com/article/winnt-ntvdm-subsystem.html

    HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\AppCompat]

    Create a reg dword (DWORD): VDMDisallowed = 0


    Disable command prompt and scipts

    http://www.computerstepbystep.com/command_promt_windows_7.html

    [HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\System]

    Create a reg dword (DWORD): DisableCMD = 1 (Default = 0)


    Disable powershell script execution

    https://www.cogmotive.com/blog/powershell/allowing-powershell-scripts-to-execute

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PowerShell\1\ShellIds\Microsoft.PowerShell]

    Create a string value (REG_SZ): ExecutionPolicy = Restricted

    [HKEY_LOCAL_MACHINE \Software\Policies\Microsoft\Windows\System]

    Create a reg dword (DWORD): EnableScripts = 0 (Off)


    Disable windows script host

    http://www.thewindowsclub.com/windows-script-host-access-is-disabled-on-this-machine

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Script Host\Settings]

    Create a reg dword (DWORD): Enabled = 0 (Off)



    Mitigate threats

    Block unsigned drivers (system 32)

    https://support.microsoft.com/en-us/kb/298503

    [HKEY_LOCAL_MACHINE \SOFTWARE \Microsoft\Driver Signing]

    Create a reg binary (Binary Value): Policy=2


    Block elevation of unsigned executables

    https://msdn.microsoft.com/en-us/library/cc232764.aspx

    [HKEY_LOCAL_MACHINE \ SOFTWARE \Microsoft\Windows \Policies\System]

    Create a reg dword (DWORD): ValidateAdminCodeSignatures=1 (Disabled = 0, Enabled = 1)


    Protect system DLL's

    http://smallvoid.com/article/winnt-secure-system-dll.html

    [HKEY_LOCAL_MACHINE \SYSTEM \CurrentControlSet \Control \Session Manager]

    Create a reg dword (DWORD): ProtectionMode=1 (Disabled = 0, Enabled = 1)

    [HKEY_LOCAL_MACHINE \SYSTEM \CurrentControlSet \Control \Session Manager]

    Create a reg dword (DWORD): SafeProcessSearchMode = 1 (Default = 0)


    Memory Mitigations

    https://www.wilderssecurity.com/thre...xperience-toolkit.344631/page-50#post-2542857

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\Kernel]

    Create a reg qword 64 bits (QWORD): MitigationOptions =5000000000055
     
    Last edited by a moderator: Nov 19, 2015
  5. justenough

    justenough Registered Member

    Joined:
    May 13, 2010
    Posts:
    1,549
    I haven't been able to get an anti-exploit to run correctly on my 7 x64 machine, but still try the latest version of HMP.A every few months. I like NVT-EXE Radar Pro with Sandboxie, it's fast and problem-free.
     
    Last edited: Nov 19, 2015
  6. Rasheed187

    Rasheed187 Registered Member

    Joined:
    Jul 10, 2004
    Posts:
    17,561
    Location:
    The Netherlands
    MBAE Premium worked just fine combined with ERP and Sandboxie on Win 8.1 64 bit, but I suspect ERP is causing shutdown problems when combined with certain security tools, even after putting it in "learning mode". ERP + SpyShelter gave the same problem, it's a bit frustrating.
     
  7. justenough

    justenough Registered Member

    Joined:
    May 13, 2010
    Posts:
    1,549
    Both MBAE and HMP.A gave me problems with just Sandboxie running. But I am considering what Windows_Security just posted about the Chrome sandbox, and thinking about other combinations including his methods (which for the most part are over my head).
     
    Last edited: Nov 19, 2015
  8. ropchain

    ropchain Registered Member

    Joined:
    Mar 26, 2015
    Posts:
    335
    MBAE and HMPA didn't give you problems, stacking multiple security tools gave you problems.
     
  9. justenough

    justenough Registered Member

    Joined:
    May 13, 2010
    Posts:
    1,549
    MBAE and HMP.A weren't installed at the same time.


    I'm going back to pairing AppGuard with Sandboxie, and will probably stay with that for a good while.
     
    Last edited: Nov 21, 2015
  10. Solarlynx

    Solarlynx Registered Member

    Joined:
    Jun 25, 2011
    Posts:
    2,015
    Reverted to a year old snapshot where Online Armor was installed. As usually it promptly updated its bases and some components. Emsisoft still maintains it (till March 31, 2016). So here's my farewell to OA setup:

    UAC max
    SUA

    Online Armor free
    WinPatrol free
    MalwareBytes AntiExploit

    WP is a nice addition to OA free as the latter doesn't protect the registry (if my memory doesn't let me down).
     
    Last edited: Nov 21, 2015
  11. test

    test Registered Member

    Joined:
    Feb 15, 2010
    Posts:
    499
    Location:
    italy
    10 Pro X64 TH2

    UAC max
    SUA
    Defender off

    HitmanPro Alert 3.1
    Macrium Reflect 6 Free
     
  12. digmor crusher

    digmor crusher Registered Member

    Joined:
    Jul 6, 2012
    Posts:
    1,171
    Location:
    Canada
    Giving KeyScrambler a try.
     
  13. Securon

    Securon Registered Member

    Joined:
    Jan 11, 2009
    Posts:
    1,960
    Location:
    London On
    Good Evening! Renewed WSA Security Plus...50% Off Black Friday Sale...ZAM Pro...Heimdal Pro...in baseball parlance...a Triple Play! Sincerely...Securon
     
  14. imdb

    imdb Registered Member

    Joined:
    Nov 2, 2011
    Posts:
    4,208
    @Securon
    do you really need zam along with wsa +? i thought wsa had it all covered.
     
  15. digmor crusher

    digmor crusher Registered Member

    Joined:
    Jul 6, 2012
    Posts:
    1,171
    Location:
    Canada
    Works great but uninstalled, I'm thinking that the only time anyone would need to encrypt their keyboard is if they have a keylogger unknowingly installed on their computer. I think with my protection, especially EAM's behaviour blocker, that this will never happen.
     
  16. Solarlynx

    Solarlynx Registered Member

    Joined:
    Jun 25, 2011
    Posts:
    2,015
    I added Sandboxie to my setup. Small workout for MBAE to work with SBIE. So far so good.
     
  17. luciddream

    luciddream Registered Member

    Joined:
    Mar 22, 2007
    Posts:
    2,545
    Works for me... his approach is exactly what I'm looking for since migrating over to Win7 Ult. x86. It was always my approach with XP and is always my mainline defense with an OS. I do still supplement my hardening with 3'rd party software, but only after reducing attacking surface as much as possible first and using integrated means to do as much as I can.

    I can't thank him enough...
     
  18. luciddream

    luciddream Registered Member

    Joined:
    Mar 22, 2007
    Posts:
    2,545
    I've found it works much better together with v1.06 of MBAE. After updating it I had all sorts of problems getting SBIE startup processes to autostart at Windows boot, along with other startup processes as well. Another reminded of why when I find a solid version of a product I stick with it.

    MBAE 1.06 & SBIE 3.76 work great together (on XP anyway).
     
  19. Page42

    Page42 Registered Member

    Joined:
    Jun 18, 2007
    Posts:
    6,941
    Location:
    USA
    Sandboxie, HitmanPro.Alert, MBAM Premium and some other stuff, on a couple of 7x64 machines.
     
  20. Page42

    Page42 Registered Member

    Joined:
    Jun 18, 2007
    Posts:
    6,941
    Location:
    USA
    Ditto :thumb:
     
  21. Foxes

    Foxes Registered Member

    Joined:
    Nov 28, 2015
    Posts:
    8
    Location:
    USA
    • MBAM Home Premium, IOBit Advanced SystemCare 8.1 Pro, Avast Premier (Probably going to switch this soon).
    • Browser is Chrome with uBlock Origin, Disconnect.me, and HTTPS Everywhere.
    • Misc tools include VeraCrypt and CCleaner.
    I frequently feel like I'm not using the right software to get maximum protection.. but it's really hard to tell which **** is the best.
     
  22. Overkill

    Overkill Registered Member

    Joined:
    Mar 16, 2012
    Posts:
    2,343
    Location:
    USA
    Has anyone ran MBAE alongside HMP.Alert?
     
  23. ropchain

    ropchain Registered Member

    Joined:
    Mar 26, 2015
    Posts:
    335
    Just don't, you'll only create compatibility issues.
    It's up to you to decide whether you want to run MBAE or HMPA.
     
  24. J_L

    J_L Registered Member

    Joined:
    Nov 6, 2009
    Posts:
    8,738
    I did try the free versions (HMP.A free doesn't have exploit mitigation) and they seemed to work OK.
     
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.