What is your security setup these days?

Discussion in 'other anti-malware software' started by dja2k, Dec 15, 2005.

  1. adam993

    adam993 Registered Member

    Joined:
    Jul 22, 2009
    Posts:
    203
    Location:
    Poland
    Little change: I added Norton Antivirus and Mcafee SiteAdvisor (instead of Norton Security Toolbar in NIS).
     
  2. Kernelwars

    Kernelwars Registered Member

    Joined:
    Aug 12, 2010
    Posts:
    2,155
    Location:
    TX
    Did u try WOT?:D
     
  3. ViVek

    ViVek Registered Member

    Joined:
    Aug 7, 2008
    Posts:
    584
    Location:
    Moon
    Defensewall Personal Firewall + KeyScrambler Premium + Hitman Pro
     
  4. Kees1958

    Kees1958 Registered Member

    Joined:
    Jul 8, 2006
    Posts:
    5,857
    Downgraded from Windows7 Ultimate to Vista Business (both x32) on my wife's laptop (old drivers were the reason)

    For Admin's Vista is the best deal, all the SRP goodies of XP and icacls (ACE/DACL) of Windows7.

    UAC:
    a) disable intelligent installer detection for programs with no manifest
    b) auto elevate only from safe locations
    c) only elevate signed executables
    d) Admin approval on Quiet (elevate without prompt)

    SRP
    a) deny execute on
    - public users
    - windows mail, microsoft works, games, side bar etc (all things she does not use)
    - driver letters of USB devices

    b) run as basic user (paths)
    - Office
    - Internet Explorer
    - Windows Media Player
    - Movie maker
    - PDF Printer
    - Adobe (reader)
    - data partition

    GPO
    - autoruns disabled on CD/USB, default autorun mode is no execution
    - disabled alternative programs list at logon and legacy list
    - deny unsigned drivers to install
    - deny user to create new tasks with task scheduler
    - deny messenger to run
    - hardened IE8 security settings

    ACL
    - deny create in user startup folder
    - deny execute of Mail folder and Download directory

    EMET2 (all systemssettings green)
    - Adobe reader
    - WMP
    - IE8
    - Outlook

    Reg_file in startmenu (1806)
    - Deny Download of executables with IE8
    - Allow Download of executabkes with IE8

    Comodo Time Machine
    PrevXSafeOnline Facebook version (with my usual settings)
    Browsing with IE8 smartscreen filter on
    Hitman Pro on demand

    Regards Kees
     
    Last edited: Oct 25, 2010
  5. adam993

    adam993 Registered Member

    Joined:
    Jul 22, 2009
    Posts:
    203
    Location:
    Poland
    No, I didn't but WOT is really interesting solution. I can test it.
     
  6. justenough

    justenough Registered Member

    Joined:
    May 13, 2010
    Posts:
    1,549
    After trying lots of different AVs, ESET NOD32 is going to be my long-term choice.:thumb:
     
  7. justenough

    justenough Registered Member

    Joined:
    May 13, 2010
    Posts:
    1,549
    Welcome blasev. Hitman Pro would be a valuable addition to your on-demand (non-active) security software. I have it set up to scan on boot.

    Another site that helped me when getting started with Windows security is Gizmo's Freeware Reviews: http://www.techsupportalert.com/
    They have a list of security software there that you wouldn't believe. It is called, naturally, "Probably the Best Free Security List in the World". I consult it frequently.
     
  8. dja2k

    dja2k Registered Member

    Joined:
    Feb 15, 2005
    Posts:
    2,121
    Location:
    South Texas, USA
    Welcome aboard blasev!

    Hey any of you guys used Chrome 7 with Sandboxie before? Can't seem to get them working together.

    dja2k
     
  9. atomomega

    atomomega Registered Member

    Joined:
    Jul 27, 2010
    Posts:
    1,290
    Same here. After upgrading to latest Chrome version, it started to crash and gave me system hangs. It's been almost a week like this... I really don't mind that much. I personally consider Chrome a secure enough browser.
     
  10. Jav

    Jav Guest

    Just why?
    When SRP (which you already use) can easily deny those kinds of executions anyway?
    Why have 2 same protection?

    Edit: oh, I see, you are propably on admin account then?
     
  11. trjam

    trjam Registered Member

    Joined:
    Aug 18, 2006
    Posts:
    9,102
    Location:
    North Carolina USA
    still Avast ;)
     
  12. dja2k

    dja2k Registered Member

    Joined:
    Feb 15, 2005
    Posts:
    2,121
    Location:
    South Texas, USA
    Seems my problem wasn't Chrome with Sandboxie, but rather Online Armor. I've had enough testing Chrome, so I went back to Firefox.

    dja2k
     
  13. safeguy

    safeguy Registered Member

    Joined:
    Jun 14, 2010
    Posts:
    1,795
    Mine currently is a non-typical security setup...definitely not for the average home user. (overkill) I'm pushing the limits to see how different security technologies work together. Redundancies in this setup have been minimized and performance impact is relatively medium compared to a fresh install of Windows.

    Caution: Don't follow my footsteps unless you have nothing else to do:p

    Prevention against unauthorized code by denying initial execution
    Windows Hardening (LUA, SRP, EMET, SuRun, etc)
    Light Browser and Network Hardening/Immunization (e.g. specialized DNS service)

    Light Virtualization/Containment - prevention against running code on the real system
    Shadow Defender - ShadowMode for C:drive only and with Exclusion List (Reasons to use Shadow Defender)
    Sandboxie (for launching untrusted new executable or test new apps)

    Detection when running new code on the real system:
    Panda Cloud Pro
    Avast [Making Avast the lowest overhead AV available ]
    - only File System Shield and Behavior Shield
    (all checks off - using the OS internals to invoke a scan when executed)

    Control the degree of trust/behavior of programs once you let them run on your real system:
    Comodo Firewall with Defense+ Enabled, Sandbox enabled
    Using "AlwaysSandbox" feature to restrict media players and PDF reader.
    WinPatrol Plus (lock down the hosts file and file types + custom registry monitoring)

    And not to forget the core basics: common_sense_RC.exe and brain_Beta.exe.;)

    A few future consideration:
    MSE when the newer version is out of beta.
    Windows Firewall with Advanced Security

    P.S. I've loaded Mamutu for a few days once again but unfortunately, it doesn't play nice on my laptop. It was causing a drag on my machine even with exclusion settings. I've checked and found relatively high I/O read and write values. Uninstalled.
     
  14. firzen771

    firzen771 Registered Member

    Joined:
    Oct 29, 2007
    Posts:
    4,815
    Location:
    Canada
    installed MSE on parents PC, running smoothly
     
  15. Kernelwars

    Kernelwars Registered Member

    Joined:
    Aug 12, 2010
    Posts:
    2,155
    Location:
    TX
    using avast
     
  16. jmonge

    jmonge Registered Member

    Joined:
    Mar 20, 2008
    Posts:
    13,744
    Location:
    Canada
    hey a friend of mine gave me 2 licences of ESET NOD32 antivirus:D so why not:)
     
  17. Kernelwars

    Kernelwars Registered Member

    Joined:
    Aug 12, 2010
    Posts:
    2,155
    Location:
    TX
    looking good:thumb:
     
  18. trjam

    trjam Registered Member

    Joined:
    Aug 18, 2006
    Posts:
    9,102
    Location:
    North Carolina USA
    added SpyShelter:thumb:
     
  19. gery

    gery Registered Member

    Joined:
    Mar 8, 2008
    Posts:
    2,175
    AVG Internet Security 2011 (antispam not installed)
    MBAM pro , SafeReturner Pro
     
  20. boonie

    boonie Registered Member

    Joined:
    Aug 5, 2007
    Posts:
    238
    Windows 7 Ultimate

    Resident:
    Avira Premium
    WinPatrol Plus

    OA++

    System/Browser Hardening:
    UAC
    DEP
    SEHOP
    APPLocker - No execute from Downloads folder
    Spyware Blaster
    Firefox with NoScript. Adblock Plus, LinkExtend
    SandBoxie

    On Demand:
    MBAM
    Hitman Pro

    Backup/Recovery:
    FD-Rescue
    IFW
     
  21. jmonge

    jmonge Registered Member

    Joined:
    Mar 20, 2008
    Posts:
    13,744
    Location:
    Canada
    ESET NOD32 AntiVirus gave me some problems in my pc so i left it in 1 pc only:D
     
  22. blasev

    blasev Registered Member

    Joined:
    Oct 25, 2010
    Posts:
    763
    thx for the warm welcome :D
    I have tried hitman pro, it just too much for my tiny bandwidth.
    Since I use slow and very unstable connection, everything with cloud base will not be an option.
    but will try hitman again in the future :)
     
  23. ReverseGear

    ReverseGear Guest

    System -
    Windows x64 Ultimate
    UAC -disabled
    Dep SEHOp and all other short form crap on default

    Real Time -
    MSE
    Online armor free
    Winpatrol free

    On Demand -
    Hitman pro
    Mbam free
    Emsisoft emergency kit

    Browsers -
    Mozilla [Safe run from oa , adblock , wot , ghostery ]
    IE 8 [ safe run from oa + adblock ]

    Backup -
    Macrium reflect free
    Comodo time machine [ just in case ]

    Other stuff -
    Ccleaner
    Filehippo update checker
     
  24. Konata Izumi

    Konata Izumi Registered Member

    Joined:
    Nov 23, 2008
    Posts:
    1,557
    Windows 7 PRO 32-bit
    in my comodo time machine snapshot for gaming and family use i have:

    modified lots of GPO settings.
    Avast Free (file and behavior shield on / only invoked scan on execution via GPO)
    GesWall Free
    Trusteer Rapport
    EMET 2
    Google Chrome browser
     
  25. icr

    icr Registered Member

    Joined:
    Sep 6, 2008
    Posts:
    1,589
    Location:
    UK

    Your friend is so generous:D
     
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.