@cruelsister's recommended settings are simple, yet effective.
Unfortunately, CIS HIPS can cause novice to apply incorrect rule(s) and therefore permits infection on system. This shortcoming is one of HIPS alert design and unclear CIS HIPS functionality; the net result is poorly implemented protection because of user misunderstanding and the subsequent mistakes they make via the HIPS alerts.
Do you have an AV? Because CF doesn't have real-time AV protection (real-time scanner/on-access scan/auto scan).
Adguard doesn't count because it is mainly an adblocker with web protection. A true AV will scan a file when you open it (or in case of a worm/sneaky malware, opening it itself) and deny access to your computer if it matches with its blacklist or behaves like an AV.
Sorry hips is disabled and sandbox is set to run unknown virtually as untrusted. Firewall is set to block unknown. This has worked very well on this family computer. HitmanPro and occasional scans with Emsisoft Emergency Kit have never shown a reason for concern. I have run a couple different antiviruses for periods of time and really never had them do anything.
I think you may consider Voodoshield or SecureAplus as your mutli-engine to be your primary AV or companion reference which you have no worries to bypass when one engine fail to do so. + Whitelisting as your hardening protection.