Open MalwareTips from your Home Screen or desktop. Follow discussions, find answers and pick up where you left off.
If you cannot find an install option, update your browser or use its bookmark option to keep MalwareTips close.
After installation, open the app and sign in. Enable push notifications in Preferences if you want alerts. On iPhone and iPad, push requires a Home Screen web app and iOS or iPadOS 16.4 or later.
Sign in to manage notificationsInstallation is optional. Your notification settings stay under your control.
Thanks. I used many applications for free, so I would like to keep the H_C also free with the help of MT members.@Andy Ful
Your "devotion" to your project is admirable. The level of customer care service is at an excellent level. It's incredible that it's free. I'd be willing to pay for it.
You could ask for donation or paid support for customized tailored setup.Thanks. I used many applications for free, so I would like to keep the H_C also free with the help of MT members.![]()
I know.You could ask for donation or paid support for customized tailored setup.
This feature will block many drivers. The user cannot also use virtual machines (VirtualBox, VMware, etc.). It can be easily turn ON from the Windows Security Center (it is part of Core isolation). It requires hardware support.It would be awesome if the following Windows features can be added to your tool:
Memory integrity (HVCI) - can be configured with registry
The user cannot also use virtual machines. It can be easily turn ON from the Windows Security Center (it is part of Core isolation). It requires hardware support. There were serious issues reported.System Guard Secure Launch - can be configured with registry
It is not finished. Why doesn't Microsoft turned it ON by default? It is so important for security.enable sandboxing for Windows Defender Antivirus
This setting can break many 32-bit applications. For 64-bit applications, DEP is turned ON by default on Windows 10. It can be easily turned ON (for concrete application) from the Windows Security Center (Windows Defender Exploit Protection).enforce DEP (Data Execution Prevention) for all processes and not only for system which is default.
For example:...
Did you have any more info about the serious issues?
...
I think so. The problem is that Windows 10 security evolves too quickly. Even without these low-level security features, there are still problems with Windows Updates.I wonder if this 1year old "unpredictable and exotic bug" issue is fixed.
I do not know. If this feature is not required then it should be disabled.@Andy Ful did you plan to disable the Windows internal EFS feature do to the new ransomware?
...
Btw, I have 3rd party scripts disabled and when I load the site it doesn't show anything for about 10 seconds everytime I load the page but if I enable the script it loads instantly. Is this what google shamelessly does to amp sites when the script is disabled? I may have read somewhere a year ago about this 10 seconds delay. I can understand images not loading since the script is blocked but the 10 seconds delay is bad.It would be fine if the website could work on mobile devices too, but it is probably not a big issue because H_C does not support mobile devices. That is why no one reported such a problem until now.![]()
The browser probably does not recognize that the script is blocked and give it some time to load. I think that there is an option somewhere in the browser that allows the website to load without waiting for scripts.Btw, I have 3rd party scripts disabled and when I load the site it doesn't show anything for about 10 seconds everytime I load the page but if I enable the script it loads instantly. Is this what google shamelessly does to amp sites when the script is disabled? I may have read somewhere a year ago about this 10 seconds delay. I can understand images not loading since the script is blocked but the 10 seconds delay is bad.
Yes you're right. Just now I found another example and it only happens to sites which are dependent on cdn.ampproject.org so based on AMP of google. Some sites gives a warring like this but note on your site.The browser probably does not recognize that the script is blocked and give it some time to load.
I think that @askalan, who is the creator of the H_C website, knows the details of the blocked script.Yes you're right. Just now I found another example and it only happens to sites which are dependent on cdn.ampproject.org so based on AMP of google. Some sites gives a warring like this but note on your site.
View attachment 232802
Anyway, no problem.
This is a little late, but I think I figured out why SRP wasn't working on the wife's laptop. There is a user account on that computer that is a member of Microsoft Family. You already told me that Microsoft Family interferes with SRP.H_C in any predefined profile (except All_OFF) blocks shortcuts in UserSpace (also for USB drives), except some whitelisted locations on hard disk like Desktop, Start Menu, etc.
Shortcuts are blocked when SRP is set properly:
People who do not like default-deny setup can use the predefined profile: Windows_10_MT_Windows_Security_hardening
- <(Re)Install SRP> = Installed
- LNK extension is on <Designated File Types>
- <Default Security Level> = Disallowed
- <Enforcement> = Skip Dlls (also All Files)
- <More SRP ...> <Protect Shortcuts> = ON
which works similarly to SysHardener settings, but additionally block shortcuts, more file extensions, and some dangerous sponsors (mshta.exe, mstsc.exe, wmic.exe).
If the user needs to run unsigned applications with elevation or install/update unsigned applications, then the option <Validate Admin C.S.> must be set to OFF.
You may be sure that shortcuts are blocked by creating a shortcut on USB drive (or anywhere in the UserSpace) and trying to run it.
You can use this extension to bypass AMP sites and open the full site.Yes you're right. Just now I found another example and it only happens to sites which are dependent on cdn.ampproject.org so based on AMP of google. Some sites gives a warring like this but note on your site.
View attachment 232802
Anyway, no problem.
Yes, and SRP will not work even If you would remove this account. I tried this and the only method is refreshing the Windows.This is a little late, but I think I figured out why SRP wasn't working on the wife's laptop. There is a user account on that computer that is a member of Microsoft Family. You already told me that Microsoft Family interferes with SRP.
I use this already in Firefox but this website doesn't have a HTML version so it's not gonna work.You can use this extension to bypass AMP sites and open the full site.
![]()
Chrome Web Store
Add new features to your browser and personalize your browsing experience.chrome.google.com
Unfortunately, SRP does not have such abilities. But, HIPS rules require continuous attention because there are many possibilities to abuse something via child processes.@Andy Ful Instead of blocking sponsors for the whole process, is it possible to block child processes by Hard Configurator? Similar to some of the HIPS rules here: [KB6119] Configure HIPS rules for ESET business products to protect against ransomware
That's not always necessary. I fixed it one time just by removing the user from Microsoft family.Yes, and SRP will not work even If you would remove this account. I tried this and the only method is refreshing the Windows.
Members who viewed this thread in the last 5 minutes