Open MalwareTips from your Home Screen or desktop. Follow discussions, find answers and pick up where you left off.
If you cannot find an install option, update your browser or use its bookmark option to keep MalwareTips close.
After installation, open the app and sign in. Enable push notifications in Preferences if you want alerts. On iPhone and iPad, push requires a Home Screen web app and iOS or iPadOS 16.4 or later.
Sign in to manage notificationsInstallation is optional. Your notification settings stay under your control.
Which options do not work well in your opinion?Hi guys I like to know if configure defender work well whith 19h1. I know some options does not work well but i see everything enabled. ¿what problems have with configure defender and windows 19h1?
WD Tamper Protection blocks disabling two ConfigureDefender options which should not be disabled by the user anyway. So, this is not an issue. You can use ConfigureDefender without any problem....I read some coments who says have to disable tampper protection but i do not understand why. Can you explain me? (not english native).
None....
I have one simple cuestion.
If i use config defender and not disable tampper protection what risk or problems or loss protection can i expect?
Hello! I just found out about Windows Firewall Control (binisoft), and it looks like an interesting GUI. Is it compatible with ConfigureDefender?
Thanks!
I'm on the older 5.3.1.0 Version of WFC. For this version, I can say it works without any problems for me.Hello! I just found out about Windows Firewall Control (binisoft), and it looks like an interesting GUI. Is it compatible with ConfigureDefender?
Thanks!
Event[0]:
*****************************************
*****************************************
Date: 2019-02-23 Time: 06:36:25.315
Event ID: 5007
(Changed Windows Defender settings)
*****************************************
*****************************************
User Name: NT AUTHORITY\SYSTEM
Computer: DESKTOP-5HUB7VC
Description:
Windows Defender Antivirus Configuration has changed. If this is an unexpected event you should review the settings as this may be the result of malware.
Old value: HKLM\SOFTWARE\Microsoft\Windows Defender\InstallLocation = C:\ProgramData\Microsoft\Windows Defender\platform\4.18.1812.3-0\
New value: HKLM\SOFTWARE\Microsoft\Windows Defender\InstallLocation = C:\ProgramData\Microsoft\Windows Defender\platform\4.18.1902.2-0\
Event[1]:
*****************************************
*****************************************
Date: 2019-02-23 Time: 06:33:43.581
Event ID: 1121
(Blocked by ASR rule)
*****************************************
*****************************************
User Name: NT AUTHORITY\SYSTEM
Computer: DESKTOP-5HUB7VC
Description:
Windows Defender Antivirus has blocked an operation that is not allowed by your IT administrator.
For more information please contact your IT administrator.
ID: d1e49aac-8f56-4280-b9ba-993a6d77406c
ConfigureDefender option: Block process creations originating from PSExec and WMI commands
Detection time: 2019-02-23T14:33:43.580Z
User: NT AUTHORITY\NETWORK SERVICE
Path: C:\Windows\System32\cmd.exe
Process Name: C:\Windows\System32\wbem\WmiPrvSE.exe
Signature Version: 1.287.606.0
Engine Version: 1.1.15700.8
Product Version: 4.18.1812.3
Event[2]:
*****************************************
*****************************************
Date: 2019-02-23 Time: 06:23:54.221
Event ID: 5007
(Changed Windows Defender settings)
*****************************************
*****************************************
User Name: NT AUTHORITY\SYSTEM
Computer: DESKTOP-5HUB7VC
Description:
Windows Defender Antivirus Configuration has changed. If this is an unexpected event you should review the settings as this may be the result of malware.
Old value:
New value: HKLM\SOFTWARE\Microsoft\Windows Defender\Windows Defender Exploit Guard\ASR\Rules\d1e49aac-8f56-4280-b9ba-993a6d77406c
ConfigureDefender option: Block process creations originating from PSExec and WMI commands = 0x1
Event[3]:
*****************************************
*****************************************
Date: 2019-02-23 Time: 06:09:15.534
Event ID: 5004
(Changed Windows Defender settings)
*****************************************
*****************************************
User Name: NT AUTHORITY\SYSTEM
Computer: DESKTOP-5HUB7VC
Description:
Windows Defender Antivirus Real-time Protection feature configuration has changed.
Feature: Network Inspection System
Configuration: 0
Event[4]:
*****************************************
*****************************************
Date: 2019-02-23 Time: 06:09:15.533
Event ID: 5007
(Changed Windows Defender settings)
*****************************************
*****************************************
User Name: NT AUTHORITY\SYSTEM
Computer: DESKTOP-5HUB7VC
Description:
Windows Defender Antivirus Configuration has changed. If this is an unexpected event you should review the settings as this may be the result of malware.
Old value: HKLM\SOFTWARE\Microsoft\Windows Defender\NIS\Consumers\IPS\DisableBmNetworkSensor = 0x1
New value: Default\NIS\Consumers\IPS\DisableBmNetworkSensor = 0x0
Event[5]:
*****************************************
*****************************************
Date: 2019-02-23 Time: 06:08:55.665
Event ID: 5004
(Changed Windows Defender settings)
*****************************************
*****************************************
User Name: NT AUTHORITY\SYSTEM
Computer: DESKTOP-5HUB7VC
Description:
Windows Defender Antivirus Real-time Protection feature configuration has changed.
Feature: Network Inspection System
Configuration: 1
Event[6]:
*****************************************
*****************************************
Date: 2019-02-23 Time: 06:08:55.663
Event ID: 5007
(Changed Windows Defender settings)
*****************************************
*****************************************
User Name: NT AUTHORITY\SYSTEM
Computer: DESKTOP-5HUB7VC
Description:
Windows Defender Antivirus Configuration has changed. If this is an unexpected event you should review the settings as this may be the result of malware.
Old value: Default\NIS\Consumers\IPS\DisableBmNetworkSensor = 0x0
New value: HKLM\SOFTWARE\Microsoft\Windows Defender\NIS\Consumers\IPS\DisableBmNetworkSensor = 0x1
Event[7]:
*****************************************
*****************************************
Date: 2019-02-10 Time: 15:40:51.108
Event ID: 1122
(Audited by ASR rule)
*****************************************
*****************************************
User Name: NT AUTHORITY\SYSTEM
Computer: DESKTOP-5HUB7VC
Description:
Windows Defender Antivirus audited an operation that is not allowed by your IT administrator.
For more information please contact your IT administrator.
ID: 9e6c4e1f-7d60-472f-ba1a-a39ef669e4b2
ConfigureDefender option: Block credential stealing from the Windows local security authority subsystem (lsass.exe)
Detection time: 2019-02-10T23:40:51.106Z
User: NT AUTHORITY\SYSTEM
Path: C:\Windows\System32\lsass.exe
Process Name: C:\Windows\System32\VBoxService.exe
Signature Version: 1.285.1306.0
Engine Version: 1.1.15600.4
Product Version: 4.18.1812.3
Will be pushed soon (ver. 2.0.0.1)Hey what is the newest version, my infertace not are the same
On my monitor DPI is not a problem (fonts and boxes are rescaled properly), but on monitors with small display size and low screen resolution, it can be a problem with the help window. For example, on a 10-inch monitor, the help window is well visible with resolution 1920x1080 and 100% DPI. On 21 inch monitor, the minimal resolution for 125 DPI will be 800x600. What are your display parameters? Could you also post a screenshot?Does 2.0.0.1 have any DPI improvements? I've noticed that currently CF does not play nice when Windows is set to 125% DPI, which is a pretty common setting for many people. Issues I get are Text getting cutoff and not fitting properly in the boxes.
It's a good question and I haven't seen any hard test results about it that I can remember. Maybe Andy knows. But a general rule of thumb is that the more alerts you see during normal computer usage, the more aggressive and paranoid your security config is. Accordingly, Windows Defender at high settings is stronger than Kaspersky at default settings.Hi, for me it works excellent, i only have one cuestion ¿What do you think about the protection level in comparision whith another products?, for me whith high seetings feel very good, i dont see anything extrange. Defender works silently and smooth, i see some alerts when i try to copy text in word from internet files or docs, but, it make me feel secure. I see more protection options than another security products. Can we say Defender high seetings give a protection comparable whith Kaspersky security cloud free or emsisoft antimalware? Do you think use configure defender higth seetings and comodo firewall was a exageration?
WD at high settings will be probably better (due to ASR rules) in the real-world scenario, because most of the real-world threats are delivered via malicious documents and scripts.Hi, for me it works excellent, i only have one cuestion ¿What do you think about the protection level in comparision whith another products?, for me whith high seetings feel very good, i dont see anything extrange. Defender works silently and smooth, i see some alerts when i try to copy text in word from internet files or docs, but, it make me feel secure. I see more protection options than another security products. Can we say Defender high seetings give a protection comparable whith Kaspersky security cloud free or emsisoft antimalware? Do you think use configure defender higth seetings and comodo firewall was a exageration?
Yes, as you have posted already, the boxes and labels are not rescaled properly. It seems that in your case the DPI rescaling is not fully compatible with AutoIt GUI. Unfortunately, I cannot do much to solve this problem, because it is related to the built-in AutoIt GUI programming features.![]()
My monitors are 1600x1200 @ 125% DPI. As you can see the "Disabled" parts have the "d" cut off as well as the letters that hang such as letters g, p, y. etc.
It is valid for any popular browser.Forgive me for my ignorance. I tried to look through this whole thread and on github, but I’m still unsure. Does “Scan all downloaded files and attachments” scan downloads regardless of what browser you use, or does it only work with edge? Or, is it specific to the default download folder?
Members who viewed this thread in the last 5 minutes