Basic Security Moonhorse's config 2018

Last updated
Dec 11, 2018
Windows Edition
Home
Security updates
Allow security updates and latest features
User Access Control
Always notify
Real-time security
Comodo Cloud Antivirus
Firewall security
Periodic malware scanners
Malwarebytes free
Malwarebytes adwcleaner
Norton power eraser
Zemana antimalware
Roguekiller antimalware
EEK
Malware sample testing
I do not participate in malware testing
Browser(s) and extensions
Chrome :
- Nano adblocker
- Nano defender
- Netcraft
- Bitwarden
Maintenance tools
Geek uninstaller
Bleachbit
Virustotal uploader 2.2
File and Photo backup
External hard drive for pictures etc.
System recovery
Usb
Computer specs
https://malwaretips.com/threads/my-microwave.86080/

Moonhorse

Level 37
Thread author
Verified
Top Poster
Content Creator
Well-known
May 29, 2018
2,608
I don't think so. It's been around for a while. But why would you?
Ransomoff doesnt have and syshardener is just to disable scripts so im missing anti-exploit right? And do windows defender really do anything there?

I can set up OSA wich have anti-exploit section, but how is syshardener even equal to that

Windows file protection, but is that an anti-exploit at all :unsure: sorry im so lost right now

Its kinda funny as it blocks process, it marks it as ransomware instead of threat or something

ransomwarelol.png


Question 2:
- is this an default deny? And if so how effective
antiexe.png
 
Last edited:
  • Like
Reactions: harlan4096

oldschool

Level 82
Verified
Top Poster
Well-known
Mar 29, 2018
7,136
First, are you using ConfigureDefender? It's the only way I would use WD to make the most of its capabilities, in which case you don't need RansomOff. Then I would consider what you are comfortable using along side WD. I prefer Hard_Configurator as it's user-friendly in Defaul-Deny setup the way Andy has it configured. Some prefer SysHardener. MBAE will give you browser and application protection. If you wish to use OSA with SysHardener then go to those threads and seek advice on how to best combine them for your needs. :)(y)
 
  • Like
Reactions: Moonhorse

Moonhorse

Level 37
Thread author
Verified
Top Poster
Content Creator
Well-known
May 29, 2018
2,608
First, are you using ConfigureDefender? It's the only way I would use WD to make the most of its capabilities, in which case you don't need RansomOff. Then I would consider what you are comfortable using along side WD. I prefer Hard_Configurator as it's user-friendly in Defaul-Deny setup the way Andy has it configured. Some prefer SysHardener. MBAE will give you browser and application protection. If you wish to use OSA with SysHardener then go to those threads and seek advice on how to best combine them for your needs. :)(y)
I dont use configuredefender.

I have disabled everything in syshardener
I have complete lockout with ransomoff
Anti-exploit from malwarebytes
Windows defender as basic antivirus

Currently it feels its me whos dominating the computer and decide what it will run or not to. Untrusted files it will automatically block so i just add everything i need to trusted files and rest are locked

For me it seems everything is perfect for now, tomorrow maybe not...welll see

Weird thing; had to manually add chrome to MBAE
 

Moonhorse

Level 37
Thread author
Verified
Top Poster
Content Creator
Well-known
May 29, 2018
2,608
Update:
- removed ransomOFF ( its too complicated, bit buggy. Even in simple mode it will block most installers and its too complicated to create those rules )
- Removed MBAE (redundant)
+ added RE:hips free back ( disabled chrome isolation) + running in learning mode

So my setup is just WD+Syshardener (max) + Re:hips from now.

+ also added brave browser, since they allow extensions from chrome webstore, its probably best chrome alternative and has decent privacy protection aswell
 

Moonhorse

Level 37
Thread author
Verified
Top Poster
Content Creator
Well-known
May 29, 2018
2,608
Actually i just updated my conf:
+ windows defender replaced with forticlient
+ brave is buggy, rather use firefox nightly as privacy browser
+ duckduckgo as searchengine

- removed malwarebytes ( false positives on finnish goverment sites)
- removed bitwarden ( realized i only sign in to MalwareTips:unsure:)
 

Moonhorse

Level 37
Thread author
Verified
Top Poster
Content Creator
Well-known
May 29, 2018
2,608
Update:
- Removed forticlient + free:hips ( probably conflicted)

Added
+Windows defender ( sandbox)
+Syshardener ( max )
+Osa (default+ some ruleblocking)

This is probably the most simple setup

Chrome as mainbrowser
- nano adblocker
- nano defender
- netcraft

Safety first > probably no need to be scared about privacy when using google services :unsure:

Only thing im wondering is adding bitdefender trafficlight

This is permanent setup for now, :coffee:

Some pictures:

sh1.png
sh12.png
pupexe.png


Only thing i really didnt disable is just hidden files + prefetch service
 
Last edited:

Nestor

Level 9
Verified
Well-known
Apr 21, 2018
397
Update:
- Removed forticlient + free:hips ( probably conflicted)

Added
+Windows defender ( sandbox)
+Syshardener ( max )
+Osa (default+ some ruleblocking)

This is probably the most simple setup

Chrome as mainbrowser
- nano adblocker
- nano defender
- netcraft

Safety first > probably no need to be scared about privacy when using google services :unsure:

Only thing im wondering is adding bitdefender trafficlight

This is permanent setup for now, :coffee:

Some pictures:

View attachment 200608View attachment 200609View attachment 200610

Only thing i really didnt disable is just hidden files + prefetch service
That's a good config but I would choose instead of WD ,KFA.I don't trust WD, even nowadays, instead KFA seems to be the safest choice.
 
  • Like
Reactions: Moonhorse

LDogg

Level 33
Verified
Top Poster
Well-known
May 4, 2018
2,261
Sensible changes. Always best to remove things or change settings that conflict.

~LDogg
 
  • Like
Reactions: Moonhorse

Moonhorse

Level 37
Thread author
Verified
Top Poster
Content Creator
Well-known
May 29, 2018
2,608
Update: Swapping Windows defender to Kaspersky free antivirus ( cloud probably has bugs fixed but kfa probably more stable choise)
That's a good config but I would choose instead of WD ,KFA.I don't trust WD, even nowadays, instead KFA seems to be the safest choice.
KFA is probably the best standalone antivirus choise, and the web filter of kaspersky will save me from installing more extensions. On malwarehub its indeed performing best so i think im gonna install it instead of WD as you request. Cruel aswell 'recommends' it

Sensible changes. Always best to remove things or change settings that conflict.

~LDogg
I think ransomOFF remnants and the uninstalling process caused many problems there aswell. Re:hips is nice, but as umbra said its only worthy over OSA with isolation feature that i dont have when im using google chrome.
 

Moonhorse

Level 37
Thread author
Verified
Top Poster
Content Creator
Well-known
May 29, 2018
2,608
Head still spinning... :eek::eek::eek:! Good luck!
Cheers and kaspersky gotremoved and replaced with windows defender

I just remember why did i uninstalled kaspersky before, because of the rootkit scanning thats running all the time
Also the threat removing of false positive took an year. And the brave fp has existed for month it seems
 

Moonhorse

Level 37
Thread author
Verified
Top Poster
Content Creator
Well-known
May 29, 2018
2,608
Wonder what the next change is going to be hehe

~LDogg
This
ccav2.png


sh222.png

Not sure would i benefit any of this or just get annoyed

Syshardener = firewall rules, script blocking, disable un-used windows services
OSA = anti-exploit , post protection
Comodo = default deny+ sandbox ^ Cruel said theres no benefit from using OSA along with cf, but CCAV only has browser protection, i dont think theres any problem running OSA with any sw
 

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top