Welson's Config

Oxygen

Level 44
Verified
Feb 23, 2014
3,319
1. Turn on UAC
2. Get "Adblock Plus, Lastpass, and DoNotTrackMe" for firefox
3. Get something better than MSE, Avira would be another choice
4. Add Malwarebytes
 
  • Like
Reactions: Rahadian Putra

omidomi

Level 71
Verified
Honorary Member
Top Poster
Malware Hunter
Well-known
Apr 5, 2014
6,001
1. Turn on UAC
2. Get "Adblock Plus, Lastpass, and DoNotTrackMe" for firefox
3. Get something better than MSE, Avira would be another choice
4. Add Malwarebytes

I think qihoo better than avira hoom?
 

Jack

Administrator
Verified
Staff Member
Well-known
Jan 24, 2011
9,378
Just basic config with no backup software, privacy software, and browser extensions installed :D
You can recommend me what software must be installed ;)

Welcome!
Real-Time Protection:
First of all, please enable UAC as its a very important layer of security. It does not have any system impact, so there is no good reason to disable it.
Now, Microsoft Security Essentials is a good antivirus, however it's very basic. I would suggest that you replace MSE with Avast Free Antivirus, and tweak it with the following settings:

1.Enable PUP Detection:
A PUP (potentially unwanted program) is a program that may be unwanted, such as spyware, despite the possibility that users consented to download it. This usually includes: toolbars, browser hijackers or adware (ad-supported software)
  1. Open Avast, click on Settings, then on Active Protection and click on the gear next to the Files System.
  2. In the "Sensitivity", select "Scan for potentially unwanted software (PUPs)".
2-jpg.7181

Next, you will need to do the same for the Web Shield so lets do it.
Click on Settings, then on Active Protection and click on the gear next to the Web Shield. Then select Sensitivity and check "Scan for potentially unwanted software (PUPs)".

2. Enable Warn when downloading files with poor reputation.
In the Web Shield field, you can enable "Warn when downloading files with poor reputation", and it does what it says.. it will warn you when you are downloading a file with a low reputation...
To enable it, click on Settings, then on Active Protection and click on the gear next to the Files System. Then select Web Shield and check Warn when downloading files with poor reputation..
1-jpg.7180



Browser Protection:
Adblock Plus: https://addons.mozilla.org/en-US/firefox/addon/adblock-plus/
You need an adblocker becauser apart from the simple fact that most ads are annoying, some of them might even lead you to adware or potentially unwanted programs. This add-on will block all the ads from a web page, making it look very clean and neat!

WOT (Web of Trust): https://addons.mozilla.org/en-US/firefox/addon/wot-safe-browsing-tool/
To help you avoid malicious sites you can use Web of Trust (WOT) a website rating browser plugin. After you add it to your browser make sure you only visit websites rated "Green" by WOT. Here is how it works:




Virtualization
A virtualization software will allow you to browse the web or run another application in a completely safe environment. This is especially useful when visiting high-risk web sites, whether accidentally or deliberately, as the Web browser will be completely contained within the virtual environment, preventing any damage to your computer.
A sandbox can also be used to run any other applications which you think may be suspect - you can run the program inside the sandbox to determine whether or not it is safe while remaining completely protected against any malicious actions that it may try to carry out.
I strongly advise you to install Sandboxie and use it for when you're browsing the Internet or running shady or unknown programs. Sandboxie (Free/Paid) - link
Sandboxie runs your programs in an isolated space which prevents them from making permanent changes to other programs and data in your computer.



Always run suspicious of freshly downloaded files in a Sandboxie to verify that he download isn't compromised! Sandboxie will replicate perfectly your operating system so all the files should run without any problems in it.
If you learn how to properly use Sandboxie, then you really decrease your chances of gettings an infection, I'm always running my web browser sandbox just to be on the safe side.....


Welcome... That's it for now.. I'm waiting for you reply for more.. :p
 

omidomi

Level 71
Verified
Honorary Member
Top Poster
Malware Hunter
Well-known
Apr 5, 2014
6,001
Welcome!
Real-Time Protection:
First of all, please enable UAC as its a very important layer of security. It does not have any system impact, so there is no good reason to disable it.
Now, Microsoft Security Essentials is a good antivirus, however it's very basic. I would suggest that you replace MSE with Avast Free Antivirus, and tweak it with the following settings:

1.Enable PUP Detection:
A PUP (potentially unwanted program) is a program that may be unwanted, such as spyware, despite the possibility that users consented to download it. This usually includes: toolbars, browser hijackers or adware (ad-supported software)
  1. Open Avast, click on Settings, then on Active Protection and click on the gear next to the Files System.
  2. In the "Sensitivity", select "Scan for potentially unwanted software (PUPs)".
2-jpg.7181

Next, you will need to do the same for the Web Shield so lets do it.
Click on Settings, then on Active Protection and click on the gear next to the Web Shield. Then select Sensitivity and check "Scan for potentially unwanted software (PUPs)".

2. Enable Warn when downloading files with poor reputation.
In the Web Shield field, you can enable "Warn when downloading files with poor reputation", and it does what it says.. it will warn you when you are downloading a file with a low reputation...
To enable it, click on Settings, then on Active Protection and click on the gear next to the Files System. Then select Web Shield and check Warn when downloading files with poor reputation..
1-jpg.7180



Browser Protection:
Adblock Plus: https://addons.mozilla.org/en-US/firefox/addon/adblock-plus/
You need an adblocker becauser apart from the simple fact that most ads are annoying, some of them might even lead you to adware or potentially unwanted programs. This add-on will block all the ads from a web page, making it look very clean and neat!

WOT (Web of Trust): https://addons.mozilla.org/en-US/firefox/addon/wot-safe-browsing-tool/
To help you avoid malicious sites you can use Web of Trust (WOT) a website rating browser plugin. After you add it to your browser make sure you only visit websites rated "Green" by WOT. Here is how it works:




Virtualization
A virtualization software will allow you to browse the web or run another application in a completely safe environment. This is especially useful when visiting high-risk web sites, whether accidentally or deliberately, as the Web browser will be completely contained within the virtual environment, preventing any damage to your computer.
A sandbox can also be used to run any other applications which you think may be suspect - you can run the program inside the sandbox to determine whether or not it is safe while remaining completely protected against any malicious actions that it may try to carry out.
I strongly advise you to install Sandboxie and use it for when you're browsing the Internet or running shady or unknown programs. Sandboxie (Free/Paid) - link
Sandboxie runs your programs in an isolated space which prevents them from making permanent changes to other programs and data in your computer.



Always run suspicious of freshly downloaded files in a Sandboxie to verify that he download isn't compromised! Sandboxie will replicate perfectly your operating system so all the files should run without any problems in it.
If you learn how to properly use Sandboxie, then you really decrease your chances of gettings an infection, I'm always running my web browser sandbox just to be on the safe side.....


Welcome... That's it for now.. I'm waiting for you reply for more.. :p

i think he use malware bytes + qihoo
 
D

Deleted member 178

Qihoo has 5 engines while avira has ONE, so of course it would be better

all of you missed one important point; you can have 1000 engines, they will be useless against a 0-minute/day malware since the vendors must create a signature for it, High heuristics may help will but generate more FPs than real protection.

it is why most security suites incorporate what they called 0-day protections (also called proactive components) , the ability to block malware by analysis of its behavior towards your system.

So when you choose a security suite, choose the one with a proper proactive component. Comodo , Kaspersky, Avast and other vendors have those strong components so the detection ratio of their antivirus component is not a necessity but more a comfort.

in fact you can run a system without any AV but just by using those proactive component , if you know what to allow or block (need some good knowledge of your system)

Norton just said that signature based AVs will be soon dead, it is not all true but no false either. A serious and really skilled cybercriminal (not an idiot script-kiddies that are just able to use tools made by others) will just create a brand new malware unknown from the security vendors , keep it secret just for one successful attack then discard it and create a new one. Your 1000+ engines will not recognize it since no one knows it.

I run 2 systems with those proactive defenses (just using Win8 defender because it come installed with the OS) but it never do anything , all is monitored and blocked by my other proactive security softs (ERP and Appguard).

bottom line is "prevention own detection"

Personally i prefer to prevent 100% of any penetration attempts on my system than be able to detect 100% of the malware ALREADY in my system.

Thanks
 

Oxygen

Level 44
Verified
Feb 23, 2014
3,319
all of you missed one important point; you can have 1000 engines, they will be useless against a 0-minute/day malware since the vendors must create a signature for it, High heuristics may help will but generate more FPs than real protection.

it is why most security suites incorporate what they called 0-day protections (also called proactive components) , the ability to block malware by analysis of its behavior towards your system.

So when you choose a security suite, choose the one with a proper proactive component. Comodo , Kaspersky, Avast and other vendors have those strong components so the detection ratio of their antivirus component is not a necessity but more a comfort.

in fact you can run a system without any AV but just by using those proactive component , if you know what to allow or block (need some good knowledge of your system)

Norton just said that signature based AVs will be soon dead, it is not all true but no false either. A serious and really skilled cybercriminal (not an idiot script-kiddies that are just able to use tools made by others) will just create a brand new malware unknown from the security vendors , keep it secret just for one successful attack then discard it and create a new one. Your 1000+ engines will not recognize it since no one knows it.

I run 2 systems with those proactive defenses (just using Win8 defender because it come installed with the OS) but it never do anything , all is monitored and blocked by my other proactive security softs (ERP and Appguard).

bottom line is "prevention own detection"

Personally i prefer to prevent 100% of any penetration attempts on my system than be able to detect 100% of the malware ALREADY in my system.

Thanks

I learned something new today, thanks for this post it was very useful to me.
 

omidomi

Level 71
Verified
Honorary Member
Top Poster
Malware Hunter
Well-known
Apr 5, 2014
6,001
all of you missed one important point; you can have 1000 engines, they will be useless against a 0-minute/day malware since the vendors must create a signature for it, High heuristics may help will but generate more FPs than real protection.

it is why most security suites incorporate what they called 0-day protections (also called proactive components) , the ability to block malware by analysis of its behavior towards your system.

So when you choose a security suite, choose the one with a proper proactive component. Comodo , Kaspersky, Avast and other vendors have those strong components so the detection ratio of their antivirus component is not a necessity but more a comfort.

in fact you can run a system without any AV but just by using those proactive component , if you know what to allow or block (need some good knowledge of your system)

Norton just said that signature based AVs will be soon dead, it is not all true but no false either. A serious and really skilled cybercriminal (not an idiot script-kiddies that are just able to use tools made by others) will just create a brand new malware unknown from the security vendors , keep it secret just for one successful attack then discard it and create a new one. Your 1000+ engines will not recognize it since no one knows it.

I run 2 systems with those proactive defenses (just using Win8 defender because it come installed with the OS) but it never do anything , all is monitored and blocked by my other proactive security softs (ERP and Appguard).

bottom line is "prevention own detection"

Personally i prefer to prevent 100% of any penetration attempts on my system than be able to detect 100% of the malware ALREADY in my system.

Thanks
Atomic_Bomb.gif

we use deep freeze!
i think its not true.
proactive defense is only a joke!
funny joke!
no security software can detected harmful by proactive!
it may cause very veryy false positive more than 1000+ engine :D
security software must be very clever than human to detect.
but in many years(6or5 years )past i agree with you.in 2017 or 2018.
but its need to connect internet and upgraded !
if a day anti virus will increase to working like human, virus will increase to alien!
virus writers and hackers will more powerful and brilliant!
or
its may we have couple of ideas of you and me/proactive + definitions(but all antivirus is working right now!)
sorry for bad English it third language of me:(
 
D

Deleted member 178

we use deep freeze!
i think its not true.
proactive defense is only a joke!
funny joke!
no security software can detected harmful by proactive!
it may cause very veryy false positive more than 1000+ engine :D
security software must be very clever than human to detect.
but in many years(6or5 years )past i agree with you.in 2017 or 2018.
but its need to connect internet and upgraded !
if a day anti virus will increase to working like human, virus will increase to alien!
virus writers and hackers will more powerful and brilliant!
or
its may we have couple of ideas of you and me/proactive + definitions(but all antivirus is working right now!)
sorry for bad English it third language of me:(

i think you dont grasp what is proactivity.

proactivity is the ability to block a process or script to access your system and modify it, NOT to detect it . Behavior Blocker, HIPS anti-executables and other webfilters are proactive defenses.

Deep Freeze ( and Shadow Defender, Time Freeze, etc....) could be considered as Proactive defenses but they are more Virtualization tools (they don't block anything they just redirect the malware/process to a virtual environment.

my security setup is a mix of proactive softs and virtualiztion; my ultimate goal is to PREVENT any unknown file to modify my system , and for that i don't need any AV.

if i can use an analogy:

in your car , if you have to choose only one feature between:

- a real-time sensor informing you of the dangerous proximity of any vehicles or obstacle. (preventing you from a potential collision)

or

- a seatbelt (protecting you during the accident)
 

omidomi

Level 71
Verified
Honorary Member
Top Poster
Malware Hunter
Well-known
Apr 5, 2014
6,001
i think you dont grasp what is proactivity.

proactivity is the ability to block a process or script to access your system and modify it, NOT to detect it . Behavior Blocker, HIPS anti-executables and other webfilters are proactive defenses.

Deep Freeze ( and Shadow Defender, Time Freeze, etc....) could be considered as Proactive defenses but they are more Virtualization tools (they don't block anything they just redirect the malware/process to a virtual environment.

my security setup is a mix of proactive softs and virtualiztion; my ultimate goal is to PREVENT any unknown file to modify my system , and for that i don't need any AV.

if i can use an analogy:

in your car , if you have to choose only one feature between:

- a real-time sensor informing you of the dangerous proximity of any vehicles or obstacle. (preventing you from a potential collision)

or

- a seatbelt (protecting you during the accident)
oh god. True.
i am only a medium user...
:D
 

Welson

New Member
Thread author
Jun 1, 2014
11
Okay.. Thanks for all replies and suggestions. I'll going to :
-Change antivirus software
-Enable UAC
-Set a backup
-Install some extensions for firefox

But, my system just have 2 GB RAM:(. It's that enough?o_O
 

rupeshkj

Level 7
Verified
Oct 31, 2013
345
Ya 2GB is enough and not so bad.

Since I have used Windows 8 with 2GB ram so Windows 7 should not be a problem.
 

Welson

New Member
Thread author
Jun 1, 2014
11
Ya 2GB is enough and not so bad.

Since I have used Windows 8 with 2GB ram so Windows 7 should not be a problem.
thanks for the quick reply. But, is Malwarebytes must be intalled? It's can make my game laggy because it's need tu much memory (about 100mb)
 
D

Deleted member 178

just use it as On-demand scanner (disable real time protection)
 

rupeshkj

Level 7
Verified
Oct 31, 2013
345
Install light av and disable the av while playing games then re-enable it.

And as Umbra keep Malwarebytes and hitmanpro as seconday scanner.
 

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top