CyberGhosT's "No-Sig" Configuration

Status
Not open for further replies.

_CyberGhosT_

Level 53
Thread author
Verified
Honorary Member
Top Poster
Content Creator
Well-known
Aug 2, 2015
4,286
Now see, in between VS and W.A.R I have room to play, I am playing with IObit MalwareFighter,
but I can run HMP.A between the two, and I do that often, or EAM.
Set up like I have it I can add light traditional Anti Malware programs to test.
I like the room this config gives me, both for tinkering, and as a gamer ;)
TB_SS.png

And it "IMF" can fail miserably and my system will be fine as I clone before major changes, and I
have VS and W.A.R on patrol.
 
Last edited:

HarborFront

Level 72
Verified
Top Poster
Content Creator
Oct 9, 2016
6,140
No, I have not had any issues,
View attachment 144708
I mainly run it in conjunction with VS because I can block many exe's or native windows processes with W.A.R
that I cant with VS or its just a pain with other software. I just white list VS in program settings in W.A.R
and they seem to play nice, and I have used that duo for quite some time.
Thanks for asking.
To date I have not received any conflicting alerts or notifications, I do use W.A.R to keep WDefender from starting and every time I boot I get an alert that WAR has blocked an element of WDefender, even though it's off in GP, the registry, and through settings.
For that alone I like that it enforces my settings and keeps windows honest :)
Alternative set up

1) Permanently disable WD
2) Use VS
3) Use a free 2-way firewall like Xvirus Personal Firewall

Can achieve the same performance?
 
  • Like
Reactions: SHvFl

_CyberGhosT_

Level 53
Thread author
Verified
Honorary Member
Top Poster
Content Creator
Well-known
Aug 2, 2015
4,286
I really like the convenience of Kerish Doctor and its Start-up Monitor. Do you have its protection turned on? Is it effective? Has it been tested?
Yes I do, and I found it early on, so I have been using it for sometime.
I think I have like 6yrs left on my current subscription.
And I have everything turned on ;)
 

SHvFl

Level 35
Verified
Honorary Member
Top Poster
Content Creator
Well-known
Nov 19, 2014
2,350

HarborFront

Level 72
Verified
Top Poster
Content Creator
Oct 9, 2016
6,140

Evjl's Rain

Level 47
Verified
Honorary Member
Top Poster
Content Creator
Malware Hunter
Apr 18, 2016
3,684
Anyway to look pictorally in the program to see what rules are block/allow without going into Windows?

Thanks
there is no UI of the app. 1 right-click and it will automatically allow/block/remove rules from windows firewall. If you want to see which app are blocked/allowed (oh, because you have to right-click on the app and decide to block/allow them so you should know it), you have to go to windows firewall advanced settings and look at it
the only good thing is this app is a just a script to help you to create rules for WF with ease without clicking so much

index.php
 

Parsh

Level 25
Verified
Honorary Member
Top Poster
Malware Hunter
Well-known
Dec 27, 2016
1,480
I really like the convenience of Kerish Doctor and its Start-up Monitor. Do you have its protection turned on? Is it effective? Has it been tested?
A single experience with Kerish's antimalware protection:
To install Emsi IS trial, I uninstalled my KIS and used Kaspersky Removal Tool.
After reboot, for removal of the leftovers, one of the files of that Remover Tool ran from temp directory and Kerish detected it on grounds of suspicious behaviour and asked to quarantine.

So it does have some (decent) behaviour blocker/alerter, though it was an FP in this case. It didn't block any other safe software installation/removal that day.

I'd enabled its virus..trojan.. behaviour protection only for that day and it seems to be nice for commentary protection.
 

Winter Soldier

Level 25
Verified
Top Poster
Well-known
Feb 13, 2017
1,486
A single experience with Kerish's antimalware protection:
To install Emsi IS trial, I uninstalled my KIS and used Kaspersky Removal Tool.
After reboot, for removal of the leftovers, one of the files of that Remover Tool ran from temp directory and Kerish detected it on grounds of suspicious behaviour and asked to quarantine.

So it does have some (decent) behaviour blocker/alerter, though it was an FP in this case. It didn't block any other safe software installation/removal that day.

I'd enabled its virus..trojan.. behaviour protection only for that day and it seems to be nice for commentary protection.
I used KD and I got good impressions, do you know if they use in-house or third-party anti-malware engine?
 

_CyberGhosT_

Level 53
Thread author
Verified
Honorary Member
Top Poster
Content Creator
Well-known
Aug 2, 2015
4,286
A single experience with Kerish's antimalware protection:
To install Emsi IS trial, I uninstalled my KIS and used Kaspersky Removal Tool.
After reboot, for removal of the leftovers, one of the files of that Remover Tool ran from temp directory and Kerish detected it on grounds of suspicious behaviour and asked to quarantine.

So it does have some (decent) behaviour blocker/alerter, though it was an FP in this case. It didn't block any other safe software installation/removal that day.

I'd enabled its virus..trojan.. behaviour protection only for that day and it seems to be nice for commentary protection.
Yes, it alerts to alot but leaves it up to me, and that is a good thing for the days I turn my girls loose on my PC, I am never far away
so I hear the alert and use it to show them, and teach them what effects stuff has on a system. Kerish is so much more than some folks know.
 
Status
Not open for further replies.

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top