What is your security setup these days?

Discussion in 'other anti-malware software' started by dja2k, Dec 15, 2005.

  1. @Mister X When you are a real security hard liner you could

    Use MemProtect and Pumpernickel to limit memory and disk access of Chrome. Set a deny execute/traverse folder ACL to all folders Chrome has write access to. Come to think of it, this might be a nice play project with Christmas holiday ;)
     
  2. Mr.X

    Mr.X Registered Member

    Joined:
    Aug 10, 2013
    Posts:
    4,814
    Location:
    .
    Thanks again. Yes, I'm going to think of it.
     
  3. Djigi

    Djigi Registered Member

    Joined:
    Aug 13, 2012
    Posts:
    554
    Location:
    Croatia
    If I make ACL for C:\Users\Djigi\AppData, how to add Temp folder (C:\Users\Djigi\AppData\Local\Temp) to exemption?
     
  4. Minimalist

    Minimalist Registered Member

    Joined:
    Jan 6, 2014
    Posts:
    14,885
    Location:
    Slovenia, EU
    You can use steps explained by Kees on Temp folder and set allow instead of deny.
     
  5. Djigi

    Djigi Registered Member

    Joined:
    Aug 13, 2012
    Posts:
    554
    Location:
    Croatia
    Like this:

    Clipboard02.jpg
     
  6. Here you go

    upload_2016-11-21_15-17-19.png
     
  7. Djigi

    Djigi Registered Member

    Joined:
    Aug 13, 2012
    Posts:
    554
    Location:
    Croatia
  8. Surreal90

    Surreal90 Registered Member

    Joined:
    Jan 15, 2016
    Posts:
    19
    Hey everyone, I just got a 1 year license for Trend Micro Antivirus+ 11 (2017), and was wondering what I could (or should) add to it, thanks! :thumb:.
    OS: Windows 10 Enterprise x64 v.1607.
     
  9. plat1098

    plat1098 Guest

    TrendMicro did fairly well in recent comparative tests, according to this source:

    http://www.pcmag.com/article2/0,2817,2372364,00.asp

    Perhaps you can consider adding a standalone anti-exploit, though HitmanPro Alert/Sophos Intercept, while probably the best, is rather expensive and there's no free version, just trial. Like you I also have Windows 1607 but didn't fare so well with third party antivirus when it first came out, so I'm using Windows Defender (meh)/firewall (good) in conjunction with an anti exploit and anti executable (Alert and VoodooShield) and several Firefox browser security extensions like uBlock Origin. As a result, the only threat I'm currently grappling with is Microsoft. :rolleyes:
     
  10. JohnMult

    JohnMult Registered Member

    Joined:
    Mar 26, 2012
    Posts:
    133
    Location:
    Greece
    Windows 10 pro 64bit
    1. Standard account
    2. Windows Defender
    3. EMET 5.5
    4. Simple Software Restriction Policy
    5. UAC blocks elevation of unsigned programs (thanks Windows_Security)
    6. Norton DNS
    7. Chrome in AppContainer with uBlock Origin
    8. SpywareBlaster and Unchecky
    I think its simple, quite and effective...
     
  11. Daveski17

    Daveski17 Registered Member

    Joined:
    Nov 11, 2008
    Posts:
    10,239
    Location:
    Lloegyr
    Windows 7

    Panda Protection (Free)
    SpywareBlaster
    SUPERAntiSpyware (on demand)
    MBAE
    MBAM (on demand)
    Macrium Reflect
    Browser Hardening where applicable (JS Switch, uBlock Origin, Flagfox, Decentraleyes)

    Ubuntu Trusty Tahr LTS

    Browser Hardening (JS Switch, uBlock Origin, Flagfox, Decentraleyes)
     
  12. trjam

    trjam Registered Member

    Joined:
    Aug 18, 2006
    Posts:
    9,102
    Location:
    North Carolina USA
    Bitdefender Antivirus Plus 2017

    been using it for a few weeks and have to admit, the best yet
     
  13. Page42

    Page42 Registered Member

    Joined:
    Jun 18, 2007
    Posts:
    6,944
    Location:
    USA
    • Windows 7 Ultimate
    • Sandboxie
    • HitmanPro.Alert
    • MBAM Premium
    • ESET NOD32 AV
    • SpywareBlaster
    • KeePass
    • Macrium Reflect
     
  14. Crystal_Lake_Camper

    Crystal_Lake_Camper Registered Member

    Joined:
    Mar 20, 2016
    Posts:
    121
    windows 10 x64 : KPN veilig ( fsecure safe 2016 rebrand ) - Malwarebytes anti exploit free - spywareblaster - unchecky - shadowdefender ( on demand )

    google chrome : webrtc control - https everywhere - popblocker pro - adguard - stealth mode - windscribe vpn
     
    Last edited: Dec 2, 2016
  15. JohnMult

    JohnMult Registered Member

    Joined:
    Mar 26, 2012
    Posts:
    133
    Location:
    Greece
    Small changes:
    Windows 10 pro 64bit
    1. Standard account
    2. Windows Defender
    3. EMET 5.5
    4. Simple Software Restriction Policy
    5. Yandex DNS
    6. Chrome in AppContainer with Adguard AdBlocker
    7. SpywareBlaster and Unchecky
    I think its set and forget, simple, quite and effective...
     
  16. Djigi

    Djigi Registered Member

    Joined:
    Aug 13, 2012
    Posts:
    554
    Location:
    Croatia
    Any special settings about that or is set default?
     
  17. No just set it to require Admin consent (requires entering admin password in my case), that is all
     
  18. Djigi

    Djigi Registered Member

    Joined:
    Aug 13, 2012
    Posts:
    554
    Location:
    Croatia
  19. @Djigi There used to be a higher level for Smartscreen (see picture), but it is gone now, so you have the correct one (default)

    Old option, now gone
    upload_2016-12-5_23-13-16.png
     
  20. Djigi

    Djigi Registered Member

    Joined:
    Aug 13, 2012
    Posts:
    554
    Location:
    Croatia
    Do you think this is a step down from old one (for security)?
    Why did Microsoft do that?
     
  21. plat1098

    plat1098 Guest

    Hmmm, I notice the word "administrator" is conspicuously missing...lol. I looked around for an answer as to why the one option is missing and couldn't find anything whatsoever. I even looked on the social technet forums. I have Smart Screen enabled also and yes, only those two options: yes or no.

    I also noticed the "some info about files and apps you run" on their, I mean, your PC is sent to Microsoft at the bottom of the window. Nice and vague, well, hopefully the data that is harvested will contribute to Defender's improved performance in the upcoming Creators Build. Don't you all think the name "Windows Defender" should be changed to something else? Something more modern and farther removed?
     
    Last edited by a moderator: Dec 5, 2016
  22. Solarlynx

    Solarlynx Registered Member

    Joined:
    Jun 25, 2011
    Posts:
    2,015
    Windows 7 Ultimate x64

    Standard User Account

    User Account Control at max

    Windows 10 Firewall Control Plus (SphinxSoftware) free in default deny mode

    VoodooShield in Smart mode

    Zemana AntiLogger Pro in RT with Pandora

    MalwareBytes Anti-Exploit with additional shields for some routine apps

    MalwareBytes Anti-Malware in RT and Malicious Website Protection

    This setup feels lite on my PC.
     
  23. guest

    guest Guest

    Windows 10 Home Built-in security :

    Machine hardening:
    - BIOS Password

    System Hardening:
    - SUA
    - UAC Max with credentials prompts.
    - Deny elevation of unsigned executables.
    - Windows Defender with PUP Enabled.
    - Javascript disabled.
    - Windows Features removed: Internet Explorer, XPS; SMB, Legacy Features, Media Features, etc...
    - several services disabled.

    Network Hardening
    - Windows Firewall with customized settings : all profile's connections blocked + disabled/added rules , etc...
    - IPv6, homegroup, tunneling, -related features removed/disabled.
    - Simple DNSCrypt

    Privacy Hardening: (for the fun)
    - unused Win10 setting related to privacy disabled.
    - O&O Shutup 10 customized
    - Softether VPN with VPNgate

    3rd Party Security Softs:
    - ReHIPS : Isolation + application control
    - AppGuard : Corporate grade anti-executable
    - HMPA: Anti-exploit (mostly used for its anti-forking and keystroke encryption)
    - Adguard for Desktop: Adblocker with custom filter and "stealth" features

    System Recovery
    - Rollback RX
    - Windows Backup
     
    Last edited by a moderator: Dec 6, 2016
  24. Windows 10 64bit

    Windows Firewall with Advanced Security
    Windows Defender
    Smartscreen & UAC
    Appguard
    Voodooshield Beta 3.45

    Portable Zemana
    Portable Emsisoft Emergency Kit
    Portable Process Explorer
    Portable Autoruns
    Portable TCPview
     
  25. guest

    guest Guest

    elevation in all user accounts will be denied

    there the code , you have to create a .reg file, name it like "block unsigned elevation" and double click on it, you should have a prompt then a confirmation.

    Code:
    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System]
    "ValidateAdminCodeSignatures"=dword:00000001
     
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.