Gnosis's UPDATED (11-29-13) CONFIGURATION

Gnosis

Level 5
Thread author
Apr 26, 2011
2,779
RE: Gnosis's CONFIGURATION

No I have not. It is an option that I will definitely keep in mind. What I would rather do, other than have PC Tools Av with TF + Malware Defender, is to have the new G Data (AV only) free edition (if was such a thing) with TF and Malware Defender.
 

Overkill

Level 31
Verified
Honorary Member
Feb 15, 2012
2,128
RE: ZOU'S CONFIGURATION

That would be nice, if I remember right pctools av is a bit heavy
 

Gnosis

Level 5
Thread author
Apr 26, 2011
2,779
RE: Gnosis's Updated CONFIGURATION

I heard it was not too heavy. Who knows? haha

I wish someone would take a tool like Threatfire and blend it with Malware Defender, less the firewall, and make a wicked, nice behavior blocker/HIPS hybrid. Make it lean and mean and nearly as light as TF is.

I am finding that I don't want to mess with firewalls to make them more effective. I don't want the ones that are not trained either, as they seem to not do much good. I would much rather train a HIPS and behavior blocker, with the assistance of a "learning mode", and call it a day.

I like to keep my real-time security lean and mean.
 

Gnosis

Level 5
Thread author
Apr 26, 2011
2,779
RE: Gnosis's UPDATED (11-24-12) CONFIGURATION

PC Background: Private
Computer literacy skills: Advanced
PC security risk to infections: Low
How often do you get infections: Never
Do you test Antivirus software: No
Operating System and any Service Packs: Windows XP 2002 Service Pack 3 32bit
Architecture: 32-bit
User Account Type: Administrator
Real-time protection: Threatfire AV Level 5

Second-Opinion scanners: MBAM, HitMan Pro, GMER, XueTr, MBAR
Primary Web Browser: Mozilla Firefox
Opera
ALL WITH SANDBOXIE
Add-ons & Extensions: Adblock, Better Privacy, Ghostery, Key Scrambler, BitDefender Quick Scan, Google Translator for Firefox
OTHER TOOLS: CCleaner, Wireless Network Watcher, HiJack This, Autoruns, Treesize, Killswitch, Process Hacker II

NOTE: I always use "freeware". They only time I have ever purchased security software is when I was a complete novice; I bought a PC Tools Malware Scanner about 12 years ago to remove Spy Ax. LOL


Added MBAR
 

Gnosis

Level 5
Thread author
Apr 26, 2011
2,779
RE: Gnosis's UPDATED (11-24-12) CONFIGURATION

I scrapped Malware Defender. HIPS is simpy too tedius. I am going to keep it simple with TF L5 and Sandboxie.


2-20-13 Config Update
 
P

Plexx

RE: ZOU'S UPDATED (11-24-12) CONFIGURATION

Gnosis said:
I scrapped Malware Defender. HIPS is simpy too tedius. I am going to keep it simple with TF L5 and Sandboxie.


2-20-13 Config Update

Considering you have tamed TF LV5, I do not think you need additional prevention tools.

Out of curiosity, how often this gets used?: GMER, XueT
 

Gnosis

Level 5
Thread author
Apr 26, 2011
2,779
RE: Gnosis's UPDATED (11-24-12) CONFIGURATION

GMER only once a month or so.

XueTr (PCHunter) gets used up to several times a week. I get lightning fast intel with it and it is great at exposing hidden startup items and showing all inline and ssdt hooks (Ring 0 tab) in a matter of seconds. I view kernel modules with it a lot too. PCHunter is like Ice Sword on steroids.
 

Gnosis

Level 5
Thread author
Apr 26, 2011
2,779
RE: Gnosis's UPDATED (4-3-2013) CONFIGURATION

Added Dr. Web Link Scanner.
 

McLovin

Level 78
Verified
Honorary Member
Malware Hunter
Apr 17, 2011
9,228
RE: Gnosis's UPDATED (4-3-2013) CONFIGURATION

malbky said:
Any reasons for still using Windows XP?

He likes to stick to the dark ages. :p
 
  • Like
Reactions: Gnosis

jamescv7

Level 85
Verified
Honorary Member
Mar 15, 2011
13,070
RE: Gnosis's UPDATED (4-3-2013) CONFIGURATION

I understand the way you're using Threatfire since its effectiveness is still there even though already discontinued or if you want BB you may custom installation like in Avast. ;)

Also if you are continuously using Windows XP then assume no more updates to support that OS in the nearly future.
 

Gnosis

Level 5
Thread author
Apr 26, 2011
2,779
RE: Gnosis's UPDATED (4-3-2013) CONFIGURATION

I understand the way you're using Threatfire since its effectiveness is still there even though already discontinued or if you want BB you may custom installation like in Avast.

Good point. If I do anything to alter my realtime security I will use CIS, but will keep Sandboxie if Comodo's sandbox continues to have issues.
 
Last edited:

Gnosis

Level 5
Thread author
Apr 26, 2011
2,779
PC Environment: Private
Security Awareness: Advanced
Exposure to Malware: Low
Anti-Malware Testing: No
Operating System: Windows XP 2002 Service Pack 3 32bit
Architecture: 32-bit
Real-time Protection: Comodo Internet Security Premium 6; Threatfire BB Level 5 (radically customized); Sandboxie Free Edition (drop administrator rights; delete contents of sandbox upon closing; quick recovery)
On-Demand Tools: MBAM, HitMan Pro, PCHunter, MBAR, Avast anti-rootkit (mbr fix)
Web Browser: Mozilla Firefox
Opera

Browser Addons: Adblock, Better Privacy, Ghostery, Google Translator for Firefox, Self-Destructing Cookies, Dr. Web Link Checker
OTHER TOOLS: CCleaner, Wireless Network Watcher, HiJack This, Autoruns, Treesize, Killswitch, Process Hacker II
 

Gnosis

Level 5
Thread author
Apr 26, 2011
2,779
RE: Gnosis's UPDATED (11-29-2013) CONFIGURATION

Added ESET NOD 32 AV with HIPS. I am tight now, for sure.

Did away with Slimboat browser.
 

Gnosis

Level 5
Thread author
Apr 26, 2011
2,779
RE: Gnosis's UPDATED (11-28-13) CONFIGURATION

Correction: Make it ZoneAlarm
NOD 32 was just too sluggish for me. I noticed subtle hanging at times, esp. when it is scanning.
 

Gnosis

Level 5
Thread author
Apr 26, 2011
2,779
RE: Gnosis's UPDATED (11-28-13) CONFIGURATION

I have to admit that I don't like that my boot time is up to 33 seconds, from 23 seconds. Other than that, and the fact that the FW/HIPS, or whatever it is, will not stop bugging me on some things even after I check the box that says: "remember my decision".

PCHunter shows Kaspersky line items out the arse. No surprise there.
Anyone know where this firewall came from? Those Dutch guys come up with it (or they were Danish?) or is it some other company's old news that has since been revamped?
 

Gnosis

Level 5
Thread author
Apr 26, 2011
2,779
Added Comodo Internet Security Premium 6. Set auto-sandbox to untrusted. Set Firewall and HIPS to safe mode. Set heuristics to high. Pop-ups from HIPS and BB are allowed by me, though I have only seen a couple due to Comodo's whitelist. Did not allow installation of Geek Buddy, or Dragon. Virtual Kiosk is pretty neat. I really like CIS.
 

Gnosis

Level 5
Thread author
Apr 26, 2011
2,779
PC Environment: Private
Security Awareness: Advanced
Exposure to Malware: Low
Anti-Malware Testing: No
Operating System: Windows XP 2002 Service Pack 3 32bit
Architecture: 32-bit
Real-time Protection: Comodo Internet Security Premium 6; Threatfire BB Level 5 (radically customized); Sandboxie Free Edition (drop administrator rights; delete contents of sandbox upon closing; quick recovery)
On-Demand Tools: MBAM, HitMan Pro, PCHunter, MBAR, Avast anti-rootkit (mbr fix)
Web Browser: Mozilla Firefox
Opera

Browser Addons: Adblock, Better Privacy, Ghostery, Google Translator for Firefox, Self-Destructing Cookies, Dr. Web Link Checker
OTHER TOOLS: CCleaner, Wireless Network Watcher, HiJack This, Autoruns, Treesize, Killswitch, Process Hacker II
 

Gnosis

Level 5
Thread author
Apr 26, 2011
2,779
This is the most impressive security setup that I have ever had. No doubt about it. Everything is as smooth as silk too. Boot time is up to 27 seconds, but no biggie. Think about it, Two BB's, one of 'em tweaked into oblivion, Sandboxie AND an auto-sandbox, Firewall and HIPS set pretty aggressively, and AV heuristics to high, which is never done in Comodo tests before malware testers begin bashing Comodo due only to their failure to tweak CIS a bit.
 

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top