HJLBX SSD-Only Security Config

Last updated
Dec 31, 1969
Windows Edition
Home
User Access Control
Always notify
Real-time security
AppGuard - Enterprise, Business or Personal
Windows Defender
Rollback RX
Firewall security
Microsoft Defender Firewall
Periodic malware scanners
HitmanPro
Malware sample testing
I do not participate in malware testing
Browser(s) and extensions
Chrome with uBlock Origin, Websockets and LastPass
Cyberfox with LastPass
Maintenance tools
CCleaner
Macecraft jv16
File and Photo backup
Windows and Macrium Reflect
System recovery
Windows

SHvFl

Level 35
Verified
Honorary Member
Top Poster
Content Creator
Well-known
Nov 19, 2014
2,350
Why use Spyshelter FW instead of basic windows FW? You can also use windows FW control, you already are an expert so what goes in/out can be seen in notification panel.
Spyshelter FW has a lot more features than just being a firewall and also @hjlbx likes his hips module :D
 
  • Like
Reactions: Logethica
H

hjlbx

Thread author
Why use Spyshelter FW instead of basic windows FW? You can also use windows FW control, you already are an expert so what goes in/out can be seen in notification panel.

SpyShelter extremely light + very good HIPS.

Firewall module is just graphical user interface for Windows Firewall; SSF uses Windows Firewall.
 
  • Like
Reactions: Logethica

Vasudev

Level 33
Verified
Nov 8, 2014
2,247
SpyShelter extremely light + very good HIPS.

Firewall module is just graphical user interface for Windows Firewall; SSF uses Windows Firewall.
Okay, didn't know about HIPS module on SSF. Thank you. But it's paid version, right?
I used windows 10 occasionally because I use Linux, yeah FW is turned off.
 
  • Like
Reactions: Logethica

Online_Sword

Level 12
Verified
Honorary Member
Top Poster
Well-known
Mar 23, 2015
555
Firewall module is just graphical user interface for Windows Firewall

But the staffs in Emsisoft have ever mentioned that Spyshelter FW uses its WFP driver to filter network traffic. If it is just a GUI for windows firewall, why should it use its own driver to filter the traffic?
 

Vasudev

Level 33
Verified
Nov 8, 2014
2,247
But the staffs in Emsisoft have ever mentioned that Spyshelter FW uses its WFP driver to filter network traffic. If it is just a GUI for windows firewall, why should it use its own driver to filter the traffic?
Mostly all SW out there in the market more or less the same APIs to read/write or even scan the network traffic with the help of OS, so for me, using windows built-in driver + additional/better GUI solves most of the issues.
 
H

hjlbx

Thread author
But the staffs in Emsisoft have ever mentioned that Spyshelter FW uses its WFP driver to filter network traffic. If it is just a GUI for windows firewall, why should it use its own driver to filter the traffic?

Emsisoft installs its own firewall driver and Emsisoft Network Filter.

By default, EIS just applies Windows Firewall profile - Trusted, Doman, Public - to global firewall rules.

EIS does not use Windows' built-in WFP (Windows Filtering Platform) or TDI (Transport Driver Interface).

At least that is how I understood some old Fabian Wosar posts about the EIS firewall.

Whereas SpyShelter Firewall uses WFP or TDI; it uses WFP by default.

2usacr4.png


SpyShelter Firewall is implemented as a Local System service = SpyShelterSrv - just like BiniSoft's Windows Firewall Control.

This, of course, is very easy to test:
  • Create Block rule for browser in SpyShelter Firewall.
  • Disable Windows Firewall.
  • Reboot system (must restart system otherwise WFP\TDI might continue to apply existing policy).
Now, after reboot, Browser is able to freely connect to internet; SSF created and Windows Firewall (WFP\TDI) enforced the Block rule. After disabling Windows Firewall and system reboot - the Block rule for the browser is no longer being enforced by WFP\TDI.

Re-enable Windows Firewall, reboot system (sometimes not required - WFP\TDI quirk) and browser is once again Blocked.
 
Last edited by a moderator:
H

hjlbx

Thread author
Re-Added:

HitmanPro.Alert - needed for process tampering and replacement protections.
 
  • Like
Reactions: Logethica

Azure

Level 28
Verified
Top Poster
Content Creator
Oct 23, 2014
1,714
SpyShelter extremely light + very good HIPS.

Firewall module is just graphical user interface for Windows Firewall; SSF uses Windows Firewall.
Yeah, the product is very light. Though I'm basing my comment on premium since I have never tried their firewall.

I think they could benefit with adding something similar to Zemana's intelliguard.
 
  • Like
Reactions: Logethica
H

hjlbx

Thread author
Yeah, the product is very light. Though I'm basing my comment on premium since I have never tried their firewall.

I think they could benefit with adding something similar to Zemana's intelliguard.

It appears Datpol is positioning itself to focus on refinement of existing features and introduction of new features. The developers removed the skins because they caused time consuming problems for every single one of the new SSF versions.

So we will have to see what Datpol does over the next year.

SSF is very light.

The only security related softs that I have tested that are less resource intensive are AppGuard, Excubits Bouncer, NoVirusThanks Smart Object Bouncer, HitmanPro.Alert and Webroot.
 
  • Like
Reactions: Logethica
H

hjlbx

Thread author
Updated config with new thread tool.

Removed:
  • SpyShelter Firewall (won't pay $100 for lifetime license)
  • Windows Firewall Control (for me no need)
  • Sandboxie (Microsoft Windows Updates and browser updates are always breaking something in SBIE)
Waiting... waiting... waiting... for release of:
  • ReHIPS - next stable version
  • NoVirusThanks Exe Radar Pro - next stable version
  • Smart Object Blocker - next updated version
  • Comodo Internet Security 9\10
I don't image any of my systems because they are all essentially test beds for beta and malware testing; I clean install the OS when necessary.

Besides, beyond my Windows and soft license keys there's nothing of any real value on any of my systems.
 
Last edited by a moderator:
D

Deleted member 178

Thread author
Come on Bro ! No login Password , anyone managing to get access (even remote) to your system will disable all your setup :D
 
  • Like
Reactions: Logethica and mal1

Venustus

Level 59
Verified
Honorary Member
Top Poster
Content Creator
Well-known
Dec 30, 2012
4,809
Can someone please elaborate on why the prefix:ATTENTION: AT RISK!,is highlighted?
Is it anew feature??
 
  • Like
Reactions: Logethica
H

hjlbx

Thread author
Can someone please elaborate on why the prefix:ATTENTION: AT RISK!,is highlighted?
Is it anew feature??

Yes. Dependent upon what you have selected, it will return either Protected\Safe or At Risk !

I don't cheat to get the green-tag. I'm honest and get the red-tag. Take reality for what it is...
 

Venustus

Level 59
Verified
Honorary Member
Top Poster
Content Creator
Well-known
Dec 30, 2012
4,809
Yes. Dependent upon what you have selected, it will return either Protected\Safe or At Risk !
Okay, I thought a major malware infection was about to hit the community!!:D:p
 
  • Like
Reactions: Logethica

Venustus

Level 59
Verified
Honorary Member
Top Poster
Content Creator
Well-known
Dec 30, 2012
4,809
Yes. Dependent upon what you have selected, it will return either Protected\Safe or At Risk !

I don't cheat to get the green-tag. I'm honest and get the red-tag. Take reality for what it is...
I never assumed otherwise!!;):)
 
  • Like
Reactions: Logethica

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top