SHvFl Configuration

Last updated
Dec 31, 1969
Windows Edition
Pro
Security updates
Allow security updates
User Access Control
Always notify
Real-time security
Rehips, Emsisoft AM, WFC
Firewall security
Microsoft Defender Firewall
Periodic malware scanners
None
Malware sample testing
I do not participate in malware testing
Browser(s) and extensions
Chrome, Firefox(as backup)
Maintenance tools
CCleaner, Openvpn
File and Photo backup
Macrium Reflect
System recovery
Macrium Reflect
D

Deleted member 178

So i tested it again today. I really don't like it and here is why
  1. Initial whitelisting takes a year and a half. We are in 2016 and have decent specs this is unacceptable and no reason for it to happen.
  2. They have a vulnerable program list which then doesn't let parent execute a child process. So i have to go there and add the application. A button to not automatically whitelist child from parent would be better
  3. Gui is terrible and confusing. No clear indication of what is happening without clicking 1000 buttons.
  4. You can't see the whitelist. You can just clear things that are no longer on the pc. I really don't understand this and i hope i just missed a button.
Protection was solid as you expect for all whitelisting software but not my kind of application.

Point 1 and 3 was enough for me to not even bother completing the installation.
 

shmu26

Level 85
Verified
Honorary Member
Top Poster
Content Creator
Well-known
Jul 3, 2015
8,153
So i tested it again today. I really don't like it and here is why
  1. Initial whitelisting takes a year and a half. We are in 2016 and have decent specs this is unacceptable and no reason for it to happen.
  2. They have a vulnerable program list which then doesn't let parent execute a child process. So i have to go there and add the application. A button to not automatically whitelist child from parent would be better
  3. Gui is terrible and confusing. No clear indication of what is happening without clicking 1000 buttons.
  4. You can't see the whitelist. You can just clear things that are no longer on the pc. I really don't understand this and i hope i just missed a button.
Protection was solid as you expect for all whitelisting software but not my kind of application.
1: yes, it is a test of our patience.
But if you ever tried Kaspersky's Trusted Applications Mode, and you let it scan your system in preparation, it also takes a long time. SAP's scan is longer, but more thorough.

4: true, you can't directly access the whitelist, but you can modify trust level for files and folders:
How to set Trust Levels for your file? – SecureAPlus Support Pages
 

SHvFl

Level 35
Thread author
Verified
Honorary Member
Top Poster
Content Creator
Well-known
Nov 19, 2014
2,350
Give Webroot SecureAnywhere AV a chanse? I'm running it alongside Voodooshield and ReHIPS. Great light config btw. :)
I tried it. Not happy with that either. Deficiencies with windows 10 and none really knows how this product actually works. I don't like trusting a program if i don't understand what it does, when and how.
 

shmu26

Level 85
Verified
Honorary Member
Top Poster
Content Creator
Well-known
Jul 3, 2015
8,153
Removed: WFC
Added: Tinywall

Tired of constant updates and today the final nail on the coffin was that a rule i was making didn't work. Probably my fault but Tinywall did the rules on it's own with Autolearn mode.
tell me, does a default-deny firewall, like you are using, stop malware better than a commercial firewall, such as Kaspersky firewall at default settings?
 

SHvFl

Level 35
Thread author
Verified
Honorary Member
Top Poster
Content Creator
Well-known
Nov 19, 2014
2,350
tell me, does a default-deny firewall, like you are using, stop malware better than a commercial firewall, such as Kaspersky firewall at default settings?
I don't know how Kaspersky Firewall works but probably you have to allow applications or application are allowed if whitelisted by them. It's the same thing just in my case i have to whitelist everything manually. I prefer it that way.
 

Evjl's Rain

Level 47
Verified
Honorary Member
Top Poster
Content Creator
Malware Hunter
Apr 18, 2016
3,684
Removed: WFC
Added: Tinywall

Tired of constant updates and today the final nail on the coffin was that a rule i was making didn't work. Probably my fault but Tinywall did the rules on it's own with Autolearn mode.
Does autolearn mode make everything default allow? I tried tiny firewall but in normal mode, it blocked almost everything unless I allowed them. In autolearn mode, yes, everything can go through but I feel like it just allows everything like Allow mode. I moved to PrivateFirewall, it was a bit better because in the default setting, it didn't block everything like tinywall did
Finally, uninstalled everything and install Kaspersky IS because firewall rules are taken from application control from KSN
 
Last edited:

SHvFl

Level 35
Thread author
Verified
Honorary Member
Top Poster
Content Creator
Well-known
Nov 19, 2014
2,350
Does autolearn mode make everything default allow? I tried tiny firewall but in normal mode, it blocked almost everything unless I allowed them. In autolearn mode, yes, everything can go through but I feel like it just allows everything like Allow mode. I moved to PrivateFirewall, it was a bit better because in the default setting, it didn't block everything like tinywall did
Finally, uninstalled everything and install Kaspersky IS because firewall rules are taken from application control from KSN
Learning mode allows everything and when you get out of learning mode to normal mode it will make rules for all applications that were allowed during the learning mode.
Tinywall is default deny and that is what i want. I want nothing to connect online if i don't make rules to allow it. Kaspersky is cool but i prefer to allow things manually and not trust rules they make that might not apply to my needs. WIndows firewall with the help of Tinywall for default deny is what i need.

Great move. :)
Thanks.
 

SHvFl

Level 35
Thread author
Verified
Honorary Member
Top Poster
Content Creator
Well-known
Nov 19, 2014
2,350
Added: Windows Firewall Control
Removed: Tinywall

The issue with boot and no internet for a few seconds was annoying me and with the constant updates for windows 10 applications i had to recreate the rule all the time and was more annoying than disabling WFC annoying constant updates.
Also managed to figure my issue with my vpn application and WFC and obviously it was me being stupid like usual and assuming stuff.
 

SHvFl

Level 35
Thread author
Verified
Honorary Member
Top Poster
Content Creator
Well-known
Nov 19, 2014
2,350
Another image testing Shadow Defender to see if i can remove Appguard. Protection wise i gain probably 0.1% but if it offers me more convenience i will be happy. Also makes more sense price wise.

Added: Shadow Defender
Removed: Appguard
 

SHvFl

Level 35
Thread author
Verified
Honorary Member
Top Poster
Content Creator
Well-known
Nov 19, 2014
2,350
Added: Nothing
Removed: Shadow Defender

Testing showed that even though it does what it has to do it also annoys me a lot. I ordered an ssd to do my backups with Macrium Reflect so restoring will be fast and that should solve my problem when testing things.
 
Last edited:
H

hjlbx

Added: Nothing
Removed: Shadow Defender

Testing showed that even though it does what it has to do it also annoys me a lot. I ordered an ssd to do my backups with Macrium Reflect so restoring will be fast and that solved my problem when testing things.

Which SSD you order ? I am always interested in comparing notes. I have - what I think is a Toshiba re-branded OZC on one - and Samsung EVO 850 on the other.
 

SHvFl

Level 35
Thread author
Verified
Honorary Member
Top Poster
Content Creator
Well-known
Nov 19, 2014
2,350
Which SSD you order ? I am always interested in comparing notes. I have - what I think is a Toshiba re-branded OZC on one - and Samsung EVO 850 on the other.
I have a Samsung Evo 850(90€) for my machine and it seems to be the best in a decent price, at least where i live, so i got that again. I could have went with the Kingston SSDNow KC400(80€) because difference for what i need it would have been small but meh price difference was 10 euro so i got the Evo which is better and has a better warranty.
 
H

hjlbx

I have a Samsung Evo 850(90€) for my machine and it seems to be the best in a decent price, at least where i live, so i got that again. I could have went with the Kingston SSDNow KC400(80€) because difference for what i need it would have been small but meh price difference was 10 euro so i got the Evo which is better and has a better warranty.

I am happy with Samsung SSDs. Price is more expensive, but not so much that it will break the bank. No statistically significant difference between EVO and EVO Pro. In that case, the price difference isn't worth it...

The Toshiba SSD is surprisingly good. I hit the lottery on that one...
 

SHvFl

Level 35
Thread author
Verified
Honorary Member
Top Poster
Content Creator
Well-known
Nov 19, 2014
2,350
I am happy with Samsung SSDs. Price is more expensive, but not so much that it will break the bank. No statistically significant difference between EVO and EVO Pro. In that case, the price difference isn't worth it...

The Toshiba SSD is surprisingly good. I hit the lottery on that one...
Yeah evo and pro differences are not visible for a home user and honestly none should pay for it except if you don't know what else to do with your money. About the toshiba as you said you either got lucky or it is an older drive when OCZ played with the big boys really well. In practice almost any ssd is better than an hdd though.
We just have to wait for prices to drop so hdd can become obsolete but in the meantime an ssd and hdd combo works for most.
 

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top