Basic Security Rainspell Security Config

Last updated
Apr 13, 2018
Windows Edition
Home
Security updates
Allow security updates and latest features
User Access Control
Always notify
Real-time security
Eset IS
Firewall security
Periodic malware scanners
NPE
EEK
Cure It
Trend micro House call
Sophos malware removal tool
Malware sample testing
I do not participate in malware testing
Browser(s) and extensions
Chrome, ublock origin, trafficlightdguard
Maintenance tools
Wise cleaner, Ccleaner, Kerish doctor
File and Photo backup
EaseUs
System recovery
EaseUs

rainspell

Level 1
Thread author
Verified
Mar 18, 2018
20
Good config.

Thanks for sharing.

Hi JM security,

it wasn't a so secure config...
One month with GData and credit card hackedo_O
Only 3 or 4 online transactions on "secure" site... and hundreds of euro have gone away...
Was it a Keylogger ?

Anyway Gdata didn't detect anything, nor Hitman pro, EEK, NPE, Mbam...

So bye-bye Gdata. Confidence in that product is definitively lost...
 
  • Like
Reactions: bribon77

Dhruv2193

Level 10
Verified
Well-known
Nov 7, 2016
468
Good configuration!! If it was a keylogger it is very unlikely to go undetected by so many products
 
  • Like
Reactions: bribon77

mekelek

Level 28
Verified
Well-known
Feb 24, 2017
1,661
Hi JM security,

it wasn't a so secure config...
One month with GData and credit card hackedo_O
Only 3 or 4 online transactions on "secure" site... and hundreds of euro have gone away...
Was it a Keylogger ?

Anyway Gdata didn't detect anything, nor Hitman pro, EEK, NPE, Malwarebytes Anti-Malware...

So bye-bye Gdata. Confidence in that product is definitively lost...
your credit card info just simply been stolen from a website you entered it into.
if you think you only used it on secure websites only, do a windows reformat and use something stronger than GData.
 

rainspell

Level 1
Thread author
Verified
Mar 18, 2018
20
your credit card info just simply been stolen from a website you entered it into.
if you think you only used it on secure websites only, do a windows reformat and use something stronger than GData.

Hi mekelek,
I am sure of one thing ;) Sites were secured...
It could be related to many scan ports (6 or 7 in two days) I mentionned in another post:unsure: All were linked to microsoft services for Word (I don't use it anymore...)
2 days after this strange behavior from GData, my credit card was hacked:cry:

Is it directly linked to GData ? Probably... The credit card hacked was only used for commercial transactions on the WWW. I never used it on physical shop.
A secure site where I made transactions could have been hacked too:rolleyes: but how to know ?

But for sure, I will go with another solution, on a clean install - all has been formated...
I hesitate beetween Eset (I know well and who never disappoint me) and KIS which is probably stronger, but I found in the past a little heavy...

Best regards,
Rainspell

PS. Concerning my surfing habits, I must admit I download from times to times classical music rarities in a sort of grey zone, old archives who have never been reissued on cd, like Henkemans in Mozart Concertos:), for the last download. I allways fear to fall on a rotten and disguised file on some russians underground sites- like a 0day on 7zip file... VT is very useful in this case:)
 
Last edited:

L0ckJaw

Level 19
Verified
Content Creator
Well-known
Feb 17, 2018
870
Hi mekelek,
I am sure of one thing ;) Sites were secured...
It could be related to many scan ports (6 or 7 in two days) I mentionned in another post:unsure: All were linked to microsoft services for Word (I don't use it anymore...)
2 days after this strange behavior from GData, my credit card was hacked:cry:

Is it directly linked to GData ? Probably... The credit card hacked was only used for commercial transactions on the WWW. I never used it on physical shop.
A secure site where I made transactions could have been hacked too:rolleyes: but how to know ?

But for sure, I will go with another solution, on a clean install - all has been formated...
I hesitate beetween Eset (I know well and who never disappoint me) and KIS which is probably stronger, but I found in the past a little heavy...

Best regards,
Rainspell

PS. Concerning my surfing habits, I must admit I download from times to times classical music rarities in a sort of grey zone, old archives who have never been reissued on cd, like Henkemans in Mozart Concertos:), for the last download. I allways fear to fall on a rotten and disguised file on some russians underground sites- like a 0day on 7zip file... VT is very useful in this case:)
Creditcard hack and you blame G-Data ? Strange kind of thoughts. G-Data warned you about the portscans and you did not do anything about it ?
Looks to me your cc was hacked when using it on a " secure " site as you mention. Well good luck with ESET.
 
  • Like
Reactions: bribon77
D

Deleted Member 3a5v73x

One month with GData and credit card hackedo_O
Only 3 or 4 online transactions on "secure" site... and hundreds of euro have gone away...
Was it a Keylogger ?
Depends on which browser you used for the banking transactions, by default G Data encrypts all keystrokes in IE, Chrome and Firefox. And even if your system had keylogger on, not detected by G Data, typed keys in above mentioned browsers would still be encrypted, but not in Word for example, if you wrote there some sensitive credit card info, but then again, G Data Firewall would have warned you about unknown server application outbound connection alert if keylogger was about to send out captured info, even in G Data's Firewall default settings. You should always contact your bank first, so they can immediately lock your account, investigate the transactions made and in most cases, return you the money.
 
Last edited by a moderator:

rainspell

Level 1
Thread author
Verified
Mar 18, 2018
20
Creditcard hack and you blame G-Data ? Strange kind of thoughts. G-Data warned you about the portscans and you did not do anything about it ?
Looks to me your cc was hacked when using it on a " secure " site as you mention. Well good luck with ESET.

Hi L0ckJaw,

after ports scans occured, i have spent hours reading logs in GData Firewall, BlackFog privacy logs, Last events recorded, Tcp view... Not to mention lot of scans with Gdata, HMP, EEK, Defender, and many others...
Nothing strange was detected...
I don't know what else I could have done:unsure:

You are right, I put probably too much the blame on GData. Blame is on hack ;)
But for sure, Gdata didn't detect anything. And to be right, none of the security tools too...

A data loss on one of the commercial site I visit couldn't be excluded too... But how to know, Sites hacked didn't communicate quickly about that and often they don't communicate at all when some things happens.

It's very difficult (at least for me) to clearly understand the real scenario of an hack. How did this happen ? How many times did it last ?

I know there is not 100% bulletproff security software and of course the same hack could have been made with others soft...

@ davisd,
never writed my CC infos on a texte editor ;)
my bank has been contacted, my credit card cancelled and I am now waiting for a refund.
 
Last edited:

L0ckJaw

Level 19
Verified
Content Creator
Well-known
Feb 17, 2018
870
You are right, I put probably too much the blame on GData. Blame is on hack ;)
But for sure, Gdata didn't detect anything. And to be right, none of the security tools too...
If all those tools did not find anything on your pc then your cc was " hacked " on a online website.
And you think about going to Eset ? Well i guess it wil not find anything too ;)
 
  • Like
Reactions: bribon77

mekelek

Level 28
Verified
Well-known
Feb 24, 2017
1,661
Depends on which browser you used for the banking transactions, by default G Data encrypts all keystrokes in IE, Chrome and Firefox. And even if your system had keylogger on, not detected by G Data, typed keys in above mentioned browsers would still be encrypted, but not in Word for example, if you wrote there some sensitive credit card info, but then again, G Data Firewall would have warned you about unknown server application outbound connection alert if keylogger was about to send out captured info, even in G Data's Firewall default settings. You should always contact your bank first, so they can immediately lock your account, investigate the transactions made and in most cases, return you the money.
to be fair half the time it wasn't reporting my browser to be keylogger protected, i added custom exes, didn't work. the only browser it was consistent with was Firefox.

Hi L0ckJaw,

after ports scans occured, i have spent hours reading logs in GData Firewall, BlackFog privacy logs, Last events recorded, Tcp view... Not to mention lot of scans with Gdata, HMP, EEK, Defender, and many others...
Nothing strange was detected...
I don't know what else I could have done:unsure:

You are right, I put probably too much the blame on GData. Blame is on hack ;)
But for sure, Gdata didn't detect anything. And to be right, none of the security tools too...

A data loss on one of the commercial site I visit couldn't be excluded too... But how to know, Sites hacked didn't communicate quickly about that and often they don't communicate at all when some things happens.

It's very difficult (at least for me) to clearly understand the real scenario of an hack. How did this happen ? How many times did it last ?

I know there is not 100% bulletproff security software and of course the same hack could have been made with others soft...

@ davisd,
never writed my CC infos on a texte editor ;)
my bank has been contacted, my credit card cancelled and I am now waiting for a refund.
you can never know how your CC was stolen but its more likely it was from the vendor side and not from your side.

try Kaspersky with File AV set to on execution and heuristics on Web AV disabled , and see performance.

ESET is one of the lightest AV, but with default settings its weaker than GData, well not Firewall wise, but AV wise.
 
  • Like
Reactions: bribon77

rainspell

Level 1
Thread author
Verified
Mar 18, 2018
20
Hi mekelek and L0ckJaw,

KIS installed on higher settings, with TAM enabled.
No slow down. Works fine ;-)

I realize security is also a feeling ;-) a trust in the effectiveness of some softwares. Sadly, and perhaps for bad reasons, I can't trust Gdata at this time... Although it is a good product.

Would it be a worthy addition to go with Kaspersky secure connection or another VPN ? I allways ask me if a VPN is really needed ?
 
Last edited:
  • Like
Reactions: bribon77

mekelek

Level 28
Verified
Well-known
Feb 24, 2017
1,661
Hi mekelek and L0ckJaw,

KIS installed on higher settings, with TAM enabled.
No slow down. Works fine ;-)

I realize security is also a feeling ;-) a trust in the effectiveness of some softwares. Sadly, and perhaps for bad reasons, I can't trust Gdata at this time... Although it is a good product.

Would it be a worthy addition to go with Kaspersky secure connection or another VPN ? I allways ask me if a VPN is really needed ?
kaspersky secure connection is Hotspot shield, so uninstall it and use a better VPN. you don't necessarily need a VPN tho.
 

rainspell

Level 1
Thread author
Verified
Mar 18, 2018
20
Good overall config, so you made custom rules in OSA that you can't do with ESET's HIPS?

Hi Umbra,

I found it easier to "create" rules with OS Armor.
Andrea has made a amazing software wich covert almost everything :)

I have few rules in Eset, against ransomwares, I found here on MT :) but I encountered troubles when i wanted to register the saved files in Eset... Last build 11.1.42 drives me crazy :confused:

I downgrade to 11. 0. 159. 9 build, which is less buggy:)
 
Last edited:
  • Like
Reactions: Deleted member 178

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top