A security suite that features a behavior blocker (AntiVirProActiv) should stop all (or at least most) threats. Unfortunately this is not the case. The behavior blocker probably needs more work. The firewall should have a setting to allow trusted signed executables by default (whitelisting). WebGuard did a good job.