Question Easy setup for security aware user

Max90

Level 8
Thread author
Nov 9, 2022
378
Hi, today Microsoft Defender started to "eat" shortcuts from start and the taskbar on my wife's laptop, because an ASR was triggered. It started with office macro warnings (while I have used Andy's Documents Anti-Exploit and disabled macros' etc in Office trustcenter) and it got worse. She was working on Office documents for work, which she had gotten from a supplier. Because I needed a quick fix I set MD to default and rebooted and the problem was gone. Did a quick Sophos Scan & Clean check and all was good.

I quickly installed Avira Free and Neushield data Sentinel free. I use Andy Full's SWH because I remembered from the tests of Shadowra that Avira does not do well against script based malware. I also remembered that Cruel Sister gave a thumbs up for Neushield Data Sentinel (and Avira has no free anti-ransomware module). I already have Sophos scan & Clean which I will use from time to time to clean up left overs.

I have added some MD exploit Protection hardening on her PC also (like Office apps only allowed to load Microoft signed DLL's and not allowing starting child processes), so AV's injecting DLL's as part of their behavioral blocker or exploit protection will fail to load (like Avast and Bitdefender).

Question: any (other) free easy to use and non-chatty software which you recommend?
 
Last edited:

ScandinavianFish

Level 6
Verified
Dec 12, 2021
297
4bed323f8a35c670a67880160db3ed75.png

Happened to me too, seems like it may have been an faulty security intelligence update that caused it.
 

pxxb1

Level 8
Verified
Well-known
Jan 17, 2018
357
Hi, today Microsoft Defender started to "eat" shortcuts from start and the taskbar on my wife's laptop, because an ASR was triggered. It started with office macro warnings (while I have used Andy's Documents Anti-Exploit and disabled macros' etc in Office trustcenter) and it got worse. She was working on Office documents for work, which she had gotten from a supplier. Because I needed a quick fix I set MD to default and rebooted and the problem was gone. Did a quick Sophos Scan & Clean check and all was good.

I quickly installed Avira Free and Neushield data Sentinel free. I use Andy Full's SWH because I remember Avira does not do well against script based attacks. I also remembered that Cruel Sister gave a thumbs up for Neushield Data Sentinel (and Avira has no free anti-ransomware module). I like Avira over Avast, because I have added some MD exploit Protection hardening on her PC also (like Office apps only allowed to load Microoft signed DLL's and not allowing starting child processes).

Question: any (other) free easy to use and non-chatty software which you recommend?

Someone else over at Wilders also had problems with shortcuts - W10.

Easy non-chatty, look in the WiseVectorStopx thread here at M-tips.
 

Stopspying

Level 19
Verified
Top Poster
Well-known
Jan 21, 2018
922
.....I quickly installed Avira Free and Neushield data Sentinel free.........
How do you find NeuShield Data Sentinel?

I ask because I tried it, wanting to like it, but found like some of those who posted in the linked thread that it really slowed things down and proved to be a right pain when uninstalling it. Is it better than that now?
 

Max90

Level 8
Thread author
Nov 9, 2022
378
How do you find NeuShield Data Sentinel?

I ask because I tried it, wanting to like it, but found like some of those who posted in the linked thread that it really slowed things down and proved to be a right pain when uninstalling it. Is it better than that now?
:unsure: Uhh no problems yet, and have not tried to uninstall it. I was not aware of those problems, thanks for warning me and doubting my decision :eek:

EDIT: de-installs without problems showing a progress bar,. Seems solved (y)

Why not stick with SWH instead of adding another app?
I have SWH implemented, only through registry tweaks (added those locations in favourites of regedit, so I can easily manage them). But you make a valid point. (y)

So now I have on wife's laptop
1. Avira Free
2. Simple Windows Hardening + H_C adviced sponsor blocks
3. MD Exploit protection; Code Integrity Guard + Deny child processes for Word/Excel/PowerPoint
 
Last edited:

Andrezj

Level 6
Nov 21, 2022
273
to restore:

disable in configure defender "block win32 api calls from office macros"

go to C:\Program Files (x86)\Microsoft\Edge\Application > msedge.exe > right-click > additional options > add to taskbar

stay in C:\Program Files (x86)\Microsoft\Edge\Application > msedge.exe > right-click > additional options > create shortcut > save to desktop

rename shortcut to "microsoft edge"

move renamed shortcut to C:\ProgramData\Microsoft\Windows\Start Menu\Programs

reboot system

when microsoft fixes it, then re-enable "block win32 api calls from office macros"
 
Last edited:

Max90

Level 8
Thread author
Nov 9, 2022
378
On my Desktop, I just removed the faulty ASR and added the icons again. There is only one strange quirk. WindowsApp icons don't show in the taskbar. I disabled all security, and problem still remains, so when someone has a suggestion, feel free to post.
 

Max90

Level 8
Thread author
Nov 9, 2022
378
You can manually pin them to the taskbar.
Yes, I could pin them, but they were transparant tile's. I also could start them, but on that empty spot only the taskbar background color was visible.

Personally, I am running Avast Premium with hardened mode enabled on all of my family devices. Avast Free has hardened mode. Thus, Avast is my recommendation.
Yes, but Avast injects DLL's and I have Office, explorer and Edge hardened with MD Exploit Protection (which still works when people install a third-party AV which disables MD virus protection). Some people have problems choosing a printer, but strangely with our printer it is not (when enabling Code Integrity Guard and blocking child processes in Exploit Protection for Office and Edge). That is why I have Avira Free installed (all Avira bloatware can be deinstalled using the uninstallers of those modules).
 

Divine_Barakah

Level 29
Verified
Top Poster
Well-known
May 10, 2019
1,868
Yes, but Avast injects DLL's and I have Office, explorer and Edge hardened with MD Exploit Protection (which still works when people install a third-party AV which disables MD virus protection). Some people have problems choosing a printer, but strangely with our printer it is not (when enabling Code Integrity Guard and blocking child processes in Exploit Protection for Office and Edge). That is why I have Avira Free installed (all Avira bloatware can be deinstalled using the uninstallers of those modules).
Well I have almost never relied on MS protection and Avast/AVG on its own protected my family. Personally, I would rely only on Avast security. Before that I relied upon Kaspersky TAM, but that did not protect from PUPs. So overall, Avast, for me, is the best setup for family who are not tech savvy.

Edit.

Personally I would not use Avira. F-Secure offers better protection and is bloat-free.
 

Max90

Level 8
Thread author
Nov 9, 2022
378
Update: Avira only annoys their customers with a small dot in the umbrella systemtray icon. When you hover over the icon, it says it found a few issues (which keep coming back over and over again).

Since my wife followed a security awareness training for her work, she is very cautious and neatly responds to the instructions given by the security programs. Withing a day she asked me to remove that annoying AntiVira and put the previous security program back again.

So I put the old config on her laptop again: Malware Defender with ConfugureDefender on MAX and Hard_Configurator in SimpleWindowsHardening mode with some sponsors blocked (H_C enhanced + Microsoft recommended) and Firewall Hardening (recommended)
 

oldschool

Level 74
Verified
Top Poster
Well-known
Mar 29, 2018
6,392
Since my wife followed a security awareness training for her work, she is very cautious and neatly responds to the instructions given by the security programs. Withing a day she asked me to remove that annoying AntiVira and put the previous security program back again.
It's difficult to find a non-annoying 3rd party AV, especially if you don't want HTTPS scanning.
 

Max90

Level 8
Thread author
Nov 9, 2022
378
Personally, I am running Avast Premium with hardened mode enabled on all of my family devices. Avast Free has hardened mode. Thus, Avast is my recommendation.
OKAY, I will try out your advice and disabled Code Integrity guard and installed Avast Free with following features enabled:
1.Rootkitscan + exploit protection (whatever that maybe, probably blocking vulnarable drivers to install)
2. File shield (hardened mode)
3. Behavioral shield
4. Web shield
5. E-mail shield
6. Ramsomware shield (smart mode)
7. Firewall (smart mode)

Disabled smart scan and no personalisation nor offerings based on usage (to reduce upgrade annoyances).

I kept H_C in SWH mode blocking H_C enhanced and MS recommended sponsors (I recall some tests of Cruel Sister where Avast in hardened mode missed script based worms).
 
Last edited:
  • Applause
Reactions: Divine_Barakah

Divine_Barakah

Level 29
Verified
Top Poster
Well-known
May 10, 2019
1,868
OKAY, disabled Code Integrity guard and installed Avast Free with following features enabled:
1. rootkitscan + exploit protection (whatever that maybe, probably blocking vulnarable drivers to install)
2. File shield (hardened mode)
3. Behavioral shield
4. Web shield
5. E-mail shield
6. Ramsomware shield (smart mode)
7. Firewall (smart mode)

Disabled smart scan and no personalisation nor offerings based on usage (to reduce upgrade annoyances)
I would disable https scanning and rely on a extension to cover the gap. Regarding ramsomware shield, I prefer it on agressive mode or block mode (forgot the exact name), but be ready for some notifications. Other thank that everything is optimal.

If you store passwords in your browser, then I recommend you install Password Protection module.
 
  • Like
  • Thanks
Reactions: plat and Max90

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top