Software Review The biggest risk with Windows: LOLBINS

Reviews reflect the reviewer's setup and methods. Check the evidence and limitations.
Thread details
Content created by
PC Security Channel
Russia is not EU.


A persistent enemy is going to find a way to get around anything, eventually - even air-gapped. You know this, but to talk about it here it just turns into the trite answers "Home users are not targeted like that." It's their systems, their money, their lives and I could care less what happens to them.


Nobody said you did anything wrong. You're entitled to believe and think as you wish, however what you believe and think is not part of global reality.

If you use Windows then you agree to its Terms of Service which put 100% of everything onto the user. This is no different than any other software publisher in the world. Everything that you do with code written by others is at your own risk and you are responsible for the overall security. If it were not otherwise, then the global software publishing industry would collapse due to liability. Nobody in their right mind would write a single line of code under any system which they are liable for what people do with their software. Period. Full stop.


This is the internet. It is social media. It is called "entertainment" and everybody loves it.
I am not disagreeing with you; it's just rare to come across perfect civility that's all. refreshing to see in today's world.
 
@bazang I like that as well. Also, in a post not to long ago, you mentioned if you were to install F-Secure on a family (friends) PC, would would make a couple of Windows security changes, to help harden the system. What changes would those be as well, if not the same as to mitigate LOLBin abuse?

Use Hard_Configurator and set everything to maximum protection. Read the Manual. Study it. Learn it.

And don't listen to Andy Ful's propaganda that "Users cannot handle it."

Microsoft's Terms of Service are that 100% of everything is on the user. Period. Full stop.
Or use SAC, which is a derivative of WDAC and a built-in security feature. This is what I do. No problem for me.
 
Or use SAC, which is a derivative of WDAC and a built-in security feature. This is what I do. No problem for me.
Which I would have to reset Windows to enable it (it's Off, went out of Evaluation mode), but, this was a recent reset, so it would be easily done to help simplify things once I set it to On. I'm all for that :)
 
Last edited:
Good if not perfect advice, everyone should try H_C then study what is blocked. It's almost impossible to get around, you can't pwn what you can't access.
Indeed, this was confirmed by @AlanOstaszewski some years ago.
https://malwaretips.com/threads/mixed-threats-20-10-05-2019.92401/post-813956
https://malwaretips.com/threads/malware-samples-23.92317/post-813383
https://malwaretips.com/threads/malware-samples-13.92281/post-812784

... and several more tests if you search the Malware & URL Samples forum.
 
Which I would have to reset Windows to enable it (it's Off, went out of Evaluation mode), but, this was a recent reset, so it would be easily done to do to simplify things once I set it to On. I'm all for that :)
Or you can wait for MS to rollout the new feature allowing to switch On/Off, the date uncertain at this time.

BTW, this is another example of the MS introducing a new security feature only to sabotage their efforts at the request of users.
 
Not using SAC/WDAC anymore, blocking the newly released installer of Media Player Classic all the time.
With Andy's tool though, you could turn off a setting if needed to allow it, correct? And have more control over issues like that, compared to no settings in my case if I were to enable using SAC, that as of now cannot be turned on and off without a reset?

@oldschool I like your post on Windows 11 forum regarding a SAC question :)
 
BTW, this is another example of the MS introducing a new security feature only to sabotage their efforts at the request of users.
Microsoft Security does not want to listen to home users, but other divisions of Microsoft do because the company earns a lot of revenue from consumers. As far as the home user's creating their own problems, well there's an entire industry that earns billions from stupid people doing stupid things. Forrest Gump's mama be, like, "I can't even come up with anything to say about people."


Which I would have to reset Windows to enable it (it's Off, went out of Evaluation mode), but, this was a recent reset, so it would be easily done to help simplify things once I set it to On. I'm all for that :)
SAC can be turned ON/OFF via a registry key; no need to clean install Windows.

Microsoft wants users to clean install Windows because then it theoretically should be a clean, known, safe system when SAC is enabled.
 
Not using SAC/WDAC anymore, blocking the newly released installer of Media Player Classic all the time.
That is a you problem and not a SAC/WDAC problem. Microsoft does not want anybody using Media Player Classic because it is not secure.


With Andy's tool though, you could turn off a setting if needed to allow it, correct? And have more control over issues like that, compared to no settings in my case if I were to enable using SAC, that as of now cannot be turned on and off without a reset?

@oldschool I like your post on Windows 11 forum regarding a SAC question :)
A user creates an allow exception or turns off a feature just for as long as they need to do something and then re-enable it - but other than that - they should be in their SUA.

It only takes a few minutes to be extremely secure. It is people being extremely lazy that makes them extremely insecure.
 
With Andy's tool though, you could turn off a setting if needed to allow it, correct? And have more control over issues like that, compared to no settings in my case if I were to enable using SAC, that as of now cannot be turned on and off without a reset?

@oldschool I like your post on Windows 11 forum regarding a SAC question :)
I know; I have used Andy's tools for long time and I love WHHL.

Just I have found I do not need default deny solution; I donwload installers from the official websites, no cracks, and OS, browser, and all apps are updated regularly.

Security configuration has to be tailored for each user according to its pattern of use.
 
Russia is not EU.


A persistent enemy is going to find a way to get around anything, eventually - even air-gapped. You know this, but to talk about it here it just turns into the trite answers "Home users are not targeted like that." It's their systems, their money, their lives and I could care less what happens to them.
Yes I do know this, and no matter what protections or defenses you put in place there is always a way or two to compromise you. It's about time and resources.

It's a numbers game, the people who target highly locked down and sophisticated systems and defenses outnumber the people defending them.

The problem is the people who who say "Home users are not targeted like that" wouldn't know if they were attacked anyway so in a way we are not losing anything trying to educate people who cannot be educated. It's like people who believed the world is flat, no amount of evidence or scientific proof made a difference. In a way this is justice because it stops the attackers wasting time and they just get pwned anyway unknown to the user.
 
A user creates an allow exception or turns off a feature just for as long as they need to do something and then re-enable it - but other than that - they should be in their SUA.

It only takes a few minutes to be extremely secure. It is people being extremely lazy that makes them extremely insecure.
First, I backed up the registry before I did anything. I did find the registry path and Value Data Options, but I think F-Secure, according to Gemini (below), may be hindering it, SAC registry edit from sticking. I'll check if disabling the Virus Protection shield will allow it. Otherwise, maybe just uninstall F-Secure to give it a try. But for me, it's not a deal breaker if it works or doesn't for the little I do online, download and run :) Edit: #3 The conflict and The result, makes sense.

It is highly likely that F-Secure is the reason the registry change isn't sticking.

Because you are using F-Secure (which, as you noted, utilizes the Avira SDK for behavior detection), it takes deep control over the system's security provider registration. When a third-party antivirus is active, it often "hooks" into Windows Security settings to prevent malware (or the user) from weakening the system's defenses.
\Here is why the registry method failed and how F-Secure fits into the picture:

1. F-Secure's "Self-Protection"​

F-Secure has a "Tamper Protection" or "Self-Protection" feature. Because Smart App Control (SAC) is a core component of the Windows integrity layer, F-Secure may be monitoring the CI\Policy registry keys. If it sees a change to VerifiedAndReputablePolicyState, it may automatically revert it to "Off" to maintain the state it recorded during installation.

2. The "Protected" Registry Key​

There is actually a second, "hidden" registry value that Microsoft uses to prevent exactly what you tried. If you only change the main policy state, Windows detects a mismatch and resets it. To truly force it, you often have to modify the "Minimum Value Seen" key, which is usually protected by SYSTEM permissions.

The path for the secondary check is: HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\CI\Protected Value: <span>VerifiedAndReputablePolicyStateMinValueSeen</span>

3. F-Secure & SAC Redundancy​

Since F-Secure is using the Avira SDK behavior detection, it is already performing a similar role to SAC. Both are looking for suspicious patterns in unsigned or low-reputation binaries.

  • The Conflict: Windows often forces SAC to "Off" if it detects a third-party security suite that doesn't explicitly support co-existence with SAC's enforcement mode.
  • The Result: Even if you force the registry to "1" (On), F-Secure might signal to Windows that it is the primary provider, causing Windows to disable SAC again on the next boot to avoid driver conflicts.
 
Last edited:
First, I backed up the registry before I did anything. I did find the registry path and Value Data Options, but I think F-Secure, according to Gemini (below), may be hindering it, SAC registry edit from sticking. I'll check if disabling the Virus Protection shield will allow it. Otherwise, maybe just uninstall F-Secure to give it a try. But for me, it's not a deal breaker if it works or doesn't for the little I do online, download and run :) Edit: #3 The conflict and The result, makes sense.
SAC only requires Intelligence Security Graph (ISG) as it is intended by design to work alongside third party security software.

If you are setting the key using either a privileged cmd, powershell, .reg/regedit - then F-Secure should not be blocking that access - but it might. Recently I have observed F-Secure behaving uncharacteristically like a shyte show.

At most, you should just have to temporarily disable F-Secure's protections and then set the key. Afterwards re-enable F-Secure protections. That should work. If it does not then it is likely not F-Secure. It is something else. F-Secure is not designed to reverse or remove such a user created and configured registry key.
 
SAC only requires Intelligence Security Graph (ISG) as it is intended by design to work alongside third party security software.

If you are setting the key using either a privileged cmd, powershell, .reg/regedit - then F-Secure should not be blocking that access - but it might. Recently I have observed F-Secure behaving uncharacteristically like a shyte show.

At most, you should just have to temporarily disable F-Secure's protections and then set the key. Afterwards re-enable F-Secure protections. That should work. If it does not then it is likely not F-Secure. It is something else. F-Secure is not designed to reverse or remove such a user created and configured registry key.
I can confirm that setting the key with F-Secure installed does not work. Could be caused by Microsoft, by Microsoft, by something else.

Deserves no further investigation.
 
I can confirm that setting the key with F-Secure installed does not work. Could be caused by Microsoft, by Microsoft, by something else.

Deserves no further investigation.
It's what I was finding out as well in my attempts. Thank you for trying, and for your posts :)
And thank you all for being patient while I asked my questions :)
 
Last edited:
Security configuration has to be tailored for each user according to its pattern of use.
Since billions of people are involved, and billions of devices, the old dinosaur thinking of "Users want to use stuff" and allowing them to do it just that imperils everyone. The new paradigm has to shift to treating people like sheep, a surveillance state, hardware and application designs along with curated software ecosystems (like the Apple model) that give people much fewer options.

Such a system would hardly be 1984 dystopia or draconian as it sounds. It is about proper vetting of software at a larger, centralized scale than leaving the vetting up to individual companies and their very different ecosystems. For example, Google could care less if you are a crypto investor with a few million Euros in Bitcoin and you lose it all because you were dumb and downloaded a malicious Chrome browser extension that Google never reviewed. Nobody is going to hold Google responsible for your actions; it is 100% on the user.

That said, it will not change because corporations, governments, and industries earn too much profit from the current system. The more insecure the digital world is, the greater the profitability.

Plus, cannot take away toys from people that want to play with software; not enough space in mental health units and psychiatric wards. Can't be mucking up the mental ward system. That would be operationally unsound.
 
Just I have found I do not need default deny solution; I download installers from the official websites, no cracks, and OS, browser, and all apps are updated regularly.
This means nothing because "official websites" can be hacked, access to the software code gained, and then malicious code embedded. It has happened multiple times. Some were reported such as CCleaner and SolarWinds, while others were not - because the companies did not want people to know. More companies have not reported than have.

Untold hackings have never been reported, not even when regulations require them to be reported. There is no universal requirement to report cybersecurity failures. Not a one.

The whole "brain.exe" and "I know how to be safe online" are effective until they are not. Professionals - highly experienced and skilled - make mistakes, are fooled, make poor decisions, get lazy out of complacency or being tired or whatever, and so on. Of course there is an element of time connected to working on a system. The longer one works on a system, the greater the probability that the person will make a mistake or error or lapse in judgment that results in compromise. For the person that logs into their PC and then spends 1 hour per day reading the latest techniques on Nicki's Homemade Crafts - Easy Crochet Patterns & Tutorials are at much lower risk. Those that game, make purchases and financial transactions online, participate on social media, avidly watch YouTube and partake in the use of software piracy, and so on are a much higher risk.

People being people is money in the bank.
 
Percentage?
More than 10%.

Key Compromise Statistics (2025–2026)​

MetricStatistic
Daily CompromisesApproximately 30,000 new websites are hacked every day.
Third-Party Risk64% of third-party apps on major sites access sensitive data without justification.
High-Risk Sectors1 in 7 (14.3%) Education websites currently show signs of active compromise.
Critical Vulnerabilities33% of all web applications contain critical or severe security holes.
Supply Chain45% of global organizations are predicted to face software supply chain attacks by the end of 2025.
 
More than 10%.

Key Compromise Statistics (2025–2026)​

MetricStatistic
Daily CompromisesApproximately 30,000 new websites are hacked every day.
Third-Party Risk64% of third-party apps on major sites access sensitive data without justification.
High-Risk Sectors1 in 7 (14.3%) Education websites currently show signs of active compromise.
Critical Vulnerabilities33% of all web applications contain critical or severe security holes.
Supply Chain45% of global organizations are predicted to face software supply chain attacks by the end of 2025.
Never got a compromised installer before; looks that stats are wrong, common with AI-generated copied text.
 

Recently browsing

Members who viewed this thread in the last 5 minutes

Back
Top