Morro's Security Config

Last updated
Dec 31, 1969
Windows Edition
Home
User Access Control
Never notify (disabled)
Real-time security
Avast Free 2016 combined with SpyShelter Firewall, MCShield and CryptoPrevent.
Firewall security
Microsoft Defender Firewall
Periodic malware scanners
Malwarebytes AntiMalware and Zemana AntiMalware.
Malware sample testing
I do not participate in malware testing
Browser(s) and extensions
Slimjet ( Latest version ) with these extensions...

Magic Actions for YouTube™
Web Boost
Flash Video Downloader
uBlock Origin
Lastpass Free Password Manager
Supersorter
Privacy Badger
Reddit Enhancement Suite
Image in the center
Chromium Wheel Smooth Scroller
SimpleExtManager
FlashControl
Atomic Bookmarks
Maintenance tools
CCleaner with CCEnhanced and PrivaZer.
File and Photo backup
AOMEI Backupper Professional

Morro

Level 18
Thread author
Verified
Top Poster
Well-known
Jul 8, 2012
895
System specs:
--------------------

Acer Predator Intel Core i5 4460 @ 3.20GHz
8.00GB DDR3L Memory
AMD Radeon R9 255 Graphics card
127GB SSD
1TB HDD



Utilities using on my PC
----------------------------------


* Spyware Blaster
* Spybot Anti-Beacon
 
Last edited:

Malware Maniac

Level 1
May 14, 2012
673
I would recommend Emsisoft AntiMalware for an on demand scanner. And you don't have to put a link to extensions people will be able to find it and you don't have to put hxxp:// unless if the link directs toward a malicious site which in that case goes into the malware hub.

P.S. People are going to ask what your backup solution is also.
 

Morro

Level 18
Thread author
Verified
Top Poster
Well-known
Jul 8, 2012
895
Good to know about the extension links.

As for EAM, i will take a look at it. Thanks for the tip Malware Maniac. :)

And now for a moment of "Taste the shame"...i only have a Windows 7 recovery disk. So far i never was much of a person who hat a backup. If something went horribly wrong then i either formatted the hard drive, or if i was uncertain then i brought my PC to the computer store.

But some people at work mentioned it might be a good idea to start thinking about a external hard drive.
 
  • Like
Reactions: Logethica

Malware Maniac

Level 1
May 14, 2012
673
McLovin said:
Have you got any backup solution?

I knew someone would ask that.

Malware Maniac said:
P.S. People are going to ask what your backup solution is also.

Here is what he said:
Morro said:
And now for a moment of "Taste the shame"...i only have a Windows 7 recovery disk. So far i never was much of a person who hat a backup. If something went horribly wrong then i either formatted the hard drive, or if i was uncertain then i brought my PC to the computer store.

But some people at work mentioned it might be a good idea to start thinking about a external hard drive.
 

Morro

Level 18
Thread author
Verified
Top Poster
Well-known
Jul 8, 2012
895
Thank you Malware Maniac. :)

For a second on demand scanner i installed Emisoft Emergency Kit v2.0.0.8.
 
  • Like
Reactions: Logethica

Malware Maniac

Level 1
May 14, 2012
673
Morro said:
For a second on demand scanner i installed Emisoft Emergency Kit v2.0.0.8.

Emsisoft Emergency Kit and Emsisoft Antimalware are practically the same thing except Antimalware you have to install and it is not for already infected computers. Emergency Kit is directed toward infected computers but is portable.
 
  • Like
Reactions: Logethica

Morro

Level 18
Thread author
Verified
Top Poster
Well-known
Jul 8, 2012
895
Yeah i saw that, and i just placed it on a USB stick.
 
  • Like
Reactions: Logethica

NSG001

Level 16
Verified
Nov 21, 2011
2,192
Nice configuration :)
CIS using Chiron's guide is very good protection, used this myself before.
 
  • Like
Reactions: Logethica
Z

ZeroDay

Hi Morro,

I would reccomend installing Emet

Overview

The enhanced Mitigation Experience Toolkit (EMET) is designed to help prevent hackers from gaining access to your system.

Software vulnerabilities and exploits have become an everyday part of life. Virtually every product has to deal with them and consequently, users are faced with a stream of security updates. For users who get attacked before the latest updates have been applied or who get attacked before an update is even available, the results can be devastating: malware, loss of PII, etc.
 

Morro

Level 18
Thread author
Verified
Top Poster
Well-known
Jul 8, 2012
895
Okay i just installed EMET, as recommended. But i have some questions. Would activating DEP and SEHOP have a chance of causing problems with the use of software? ( Granted, i highly doubt it but i want to be certain. )

Also which programs would be good to add to the Configure Apps list, and which settings would be good while adding programs to the list?
 
  • Like
Reactions: Logethica
Z

ZeroDay

Hi Morro,

Due to the nature of Emet it can cause problems with certain software, I've never come accross this issue my self but it is possible. As regards which programs to add under 'configure software' I would add all internet facing applications plus media players and pdf readers, just use deafult settings whilst adding them.

The ideal settings under 'configure system' are maxium - DEP = On, SEHOP = Opt out, ASLR = Application opt in. But I would reccomend leaving everything at default for now.
 
  • Like
Reactions: Logethica

Jack

Administrator
Verified
Staff Member
Well-known
Jan 24, 2011
9,378
Hey Nige,
Real-time protection
Comodo Internet Security is a solid product...so you're fine on this part.
As a general knowledge,it's important to know that most infection rely strongly on social engineering, basically you'll need to run them so that they can work.
If you practice a smart online behavior then you should really decrees your chances of getting infected. You can read some tips on how to avoid infections here: http://malwaretips.com/blogs/how-to-easily-avoid-pc-infections/

Browser protection
Your security setup really needs a site advisor.
WOT (Free) - link
To help you avoid malicious sites you can use Web of Trust (WOT) a website rating browser plugin. After you add it to your browser make sure you only visit websites rated "Green" by WOT

On demand scanners
You should always upload all your downloads on virustotal.com and perform a scan with your on-demand to be checked for malware!

VTUploader (Free) - link
To upload a file to VirusTotal, you can visit the main analysis site, click the Browse button to select a file from your hard drive, and then click the Send file button. You can make this process even easier with the free VirusTotal Uploader utility. After installing it, you can simply right-click any file under 20MB and choose "VirusTotal" from the Send To Windows menu. The scan results will display in your browser as usual.

Hitman Pro (Trial ) - link
An on-demand scanner using multiple anti-malware engines and cloud technology. It offers unlimited free scanning but once you use it to remove detected malware it switches to a 30-day trial version. I recommend using it after you've scanned your hard-drive with the other products you have installed.




Virtualization:
Even if you submitted a file to virustotal.com and it said that it's clean , you'll need to run it in virtual environment because sometimes infection can be so new that security vendors don't have signs for it.

Virtualization software will allow you to browse the web or run another application in a completely safe environment. This is especially useful when visiting high-risk web sites, whether accidentally or deliberately, as the Web browser will be completely contained within the virtual enviroment, preventing any damage to your computer.
A sandbox can also be used to run any other applications which you think may be suspect - you can run the program inside the sandbox to determine whether or not it is safe while remaining completely protected against any malicious actions that it may try to carry out.
I strongly advise you to install Sandboxie and use it for when you're browsing the Internet or running shady/unknown programs(not that you should do that but... :) ) . Alternately you can try BufferZone PRO (Free) , another great virtualization software.
Sandboxie (Free/Paid) - link
Sandboxie runs your programs in an isolated space which prevents them from making permanent changes to other programs and data in your computer.




Always run suspicious of freshly downloaded files in a Sandboxie to verify that he download isn't compromised!Sandboxie will replicate perfectly your operating system so all the files should run without any problems in it.



PS.Welcome to MalwareTips! :)
 
Last edited:

Morro

Level 18
Thread author
Verified
Top Poster
Well-known
Jul 8, 2012
895
Wow that is a lot to go through, but i will. I am getting a Error Access Denied page for the VTUploader, but i got it from their website here...

https://www.virustotal.com/documentation/desktop-applications/

I installed WOT, and downloaded Sandboxie. Thank you for all the information and links Jack. Also thank you for the welcome, glad to be here. :)
 
  • Like
Reactions: Logethica

Morro

Level 18
Thread author
Verified
Top Poster
Well-known
Jul 8, 2012
895
I updated my config to reflect the changes i have made so far by following the advice given here so far.
 
  • Like
Reactions: Logethica
P

Plexx

  • Like
Reactions: Logethica

Morro

Level 18
Thread author
Verified
Top Poster
Well-known
Jul 8, 2012
895
* Okay i downloaded Unlocker to check it out, and i already use IOBit un-installer. :)

* I will wait with downloading and installing Paragon until i have a good external hard drive. Although i have no experience with programs like that, i believe it is better to have your backup on another drive then in a secure capsule on your main hard drive.

* I might try out Toolwiz Timefreeze, i am not sure yet.

* And if i am not mistaken, sandboxie allows me to try out a program in a sandbox without influencing the rest of the computer right? And even if that is different, should i decide to install Toolwiz Timefreeze would it not do similar things as VMware Player and VirtualBox?
 
  • Like
Reactions: Logethica

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top