What is your security setup these days?

Discussion in 'other anti-malware software' started by dja2k, Dec 15, 2005.

  1. KelvinW4

    KelvinW4 Registered Member

    Joined:
    Oct 11, 2011
    Posts:
    1,199
    Location:
    Los Angeles, California
    Im using Comodo Internet Security. Any reason why cmdagent.exe has CPU spikes?
     
  2. BG

    BG Registered Member

    Joined:
    Jun 14, 2003
    Posts:
    214
    The little I ran both I had no problem or slow down. I just wanted to see how WSA reacted with little or no interference from another AM so uninstalled MBAM.
     
  3. Kees1958

    Kees1958 Registered Member

    Joined:
    Jul 8, 2006
    Posts:
    5,857
  4. wat0114

    wat0114 Guest

    @Kees,

    not too shabby a setup you have :) Just a few questins regarding the Deny elevation of unsigned programs:

    1. does it cause some delay when you elevate a pocess (it did for me)?

    2. how does the PKI (Public Key Infrastructure) come in to play with it?
     
  5. Kees1958

    Kees1958 Registered Member

    Joined:
    Jul 8, 2006
    Posts:
    5,857
    Nope, I have set UAC to elevate silently. Don't use PKI. In the old days of usefull SRP (run as basic cuser) with certificate rules caused delays in a simular way, so maybe you use AppLocker (which works in a simular way)?
     
  6. wat0114

    wat0114 Guest

    Well, I don't know, maybe I don't understand the PKI aspect of it. Doesn't there have to be an approved certification path validation before UAC elevates an executable when this option is enabled?

    If you take a look at the ss, doesn't all this have to be set up for that UAC option to work properly?
     

    Attached Files:

  7. jmonge

    jmonge Registered Member

    Joined:
    Mar 20, 2008
    Posts:
    13,744
    Location:
    Canada
    made some changes in my own 32 system uninstall nod antivirus and very soon i will introduce
    NoVirusThanks EXE Radar Pro;) :thumb:
     
  8. wat0114

    wat0114 Guest

    If I may ask, how did you do that? Did you adjust the UAC slider to a lower setting?

    But when you enable the option: "only elevate signed executables that are signed and validated", it enforces PKI signature checks on any executable that attempts to elevate, so I don't think there's a choice to decline it.

    I temporarily cleared the AppLocker policy, but there's still a delay when attempting to elevate with that option ("only elevate signed executables that are signed and validated") enabled.
     
  9. Dark Shadow

    Dark Shadow Registered Member

    Joined:
    Oct 11, 2007
    Posts:
    4,553
    Location:
    USA
    Added Geswall back and added it in the AppGuards,Guarded App list.
     
  10. jmonge

    jmonge Registered Member

    Joined:
    Mar 20, 2008
    Posts:
    13,744
    Location:
    Canada
    GesWall Pro is so powerfull that sandboxie and appguard are not needed;)
    i hope they update it soon;)
     
  11. mrfargoreed

    mrfargoreed Registered Member

    Joined:
    Jun 16, 2006
    Posts:
    356
    Panda Cloud Free
    Sandboxie
    Shadow Defender
    Keriver Free
    Mailwasher
    LastPass
     
  12. Kees1958

    Kees1958 Registered Member

    Joined:
    Jul 8, 2006
    Posts:
    5,857
    Yes can be done though group policy, regedit or the UAC slider.

    Just try UAC with the PKI, download winrar and try to install for instance
     
  13. wat0114

    wat0114 Guest

    I set the UAC slider to lowest (is this where you have yours set at?), then enabled the "only elevate executables that are signed" option, then when I try to execute a non-signed executable, I get a pop-up "A referral was returned from the server" message and the executable won't launch. I go this anyway when I had UAC at max. This isn't a bad option to enable, I guess, but it does introduce a considerable lag before the executable either launches or the message appears, unless it's a Windows signed executable, then the lag isn't there.

    It makes sense, to me at least, if you keep UAC at "Default" along with that option to elevate only signed executables, because this way UAC will auto-elevate Windows signed executables only that are in secure locations (where Users can't write to) and in some cases UAC will even check for a "autoElevate" property in the executable's manifest. This should give you a niice combination of UAC benefits because you will retain the UIPI integrity mechanisms, while not having to manually elevate signed Windows processes.

    Anyway, I will keep things status quo, with UAC at Max. Thanks for your help :)
     
  14. jmonge

    jmonge Registered Member

    Joined:
    Mar 20, 2008
    Posts:
    13,744
    Location:
    Canada
    set the UAC slider to the max;)
     
  15. moontan

    moontan Registered Member

    Joined:
    Sep 11, 2010
    Posts:
    3,931
    Location:
    Québec
    you only get protection for Windows and Program Files folders with UAC at default or maximum.
     
  16. jmonge

    jmonge Registered Member

    Joined:
    Mar 20, 2008
    Posts:
    13,744
    Location:
    Canada
    ofcourse plus spyshelter,Nod antivirus and mbam pro and hitman pro:D ;)
     
  17. Dark Shadow

    Dark Shadow Registered Member

    Joined:
    Oct 11, 2007
    Posts:
    4,553
    Location:
    USA
    I agree that its powerfull as it is but I hope its not being abandon.I set up my sons pc with Geswall and Eset Smart Security 5 trial and he loves this set up. Its Fast, light and pretty secure IMO.
     
  18. jmonge

    jmonge Registered Member

    Joined:
    Mar 20, 2008
    Posts:
    13,744
    Location:
    Canada
  19. m00nbl00d

    m00nbl00d Registered Member

    Joined:
    Jan 4, 2009
    Posts:
    6,623
    There is a difference between lowering UAC protection, using the slider, and allowing silent elevation for administrators.

    Those changes are not the same.

    http://technet.microsoft.com/en-us/library/dd835540(WS.10).aspx
     
  20. wat0114

    wat0114 Guest

    Right, I understand that. I'm just trying to figure out what Kees is doing :)
     
  21. Kees1958

    Kees1958 Registered Member

    Joined:
    Jul 8, 2006
    Posts:
    5,857
    See GPO settings
     

    Attached Files:

  22. Kees1958

    Kees1958 Registered Member

    Joined:
    Jul 8, 2006
    Posts:
    5,857
    SecPol (software restriction policies)
     

    Attached Files:

  23. Kees1958

    Kees1958 Registered Member

    Joined:
    Jul 8, 2006
    Posts:
    5,857
    GPO settings, my banking Pin code is 1958 :)P )
     

    Attached Files:

  24. wat0114

    wat0114 Guest

    That clarifies things perfectly, Kees, thanks!

    CONGRATULATIONS!! You just posted the one millionth quote on Wilders Security. All you need to do to collect your Grand prize is to mail me your bank card to pay a small processing fee...:D :p
     
  25. x942

    x942 Guest

    Fedora 16 and SeLinux + Sandboxing. Running nice and light. :D
     
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.