| Windows 7: Best free HIPS with minimal resource usage? |
04 Jan 2013
|
#11 | | Windows 7 Home Premium x64 SP1 SoCal USA |
You can right click the icon and select "White list all running processes" so you don't have to do one at a time. It also asks if you want to do this right after the install too. It is very simple to use, and a breeze to set up. After install I get maybe 5 alerts. | My System Specs |
| OS Windows 7 Home Premium x64 SP1 |
04 Jan 2013
|
#12 | | Windows 7 Home Premium 64-bit Melbourne, Australia |
Oh okay I'll be sure to give it a go!
Do you know if there is any way for malware to run, not as an exe file? | My System Specs | | Computer type PC/Desktop System Manufacturer/Model Number Self built OS Windows 7 Home Premium 64-bit CPU Core 2 Quad Q8400 Motherboard Gigabyte UD3LR Memory 4gb PC-6400 Graphics Card Geforce GTX260 216sp Sound Card ONBOARD SOUND :D Monitor(s) Displays Viewsonic VA2413wm 24" LCD (+dead pixel...) Screen Resolution 1920x1080-(the one pixel that's stuck on red)=2073599 Keyboard GENERIC MICROSOFT KB FTW Mouse GENERIC MICROSOFT MOUSE FTW PSU TR2 550w? Case Thermaltake WingRS100 Cooling STOCK COOLERS :D Hard Drives 500gb Seagate 7200.12 Internet Speed REALLY FAST :P Other Info Wouldn't use Windows 8 even if it were free :P |
04 Jan 2013
|
#13 | | Windows 7 Home Premium x64 SP1 SoCal USA |
Yes, there are exploits that can, but if you keep your OS, browsers, java (if installed, hopefully not!) flash ect... up to date, then that lowers the risk. That being said, I would say that most malware originates via .exe. | My System Specs | | OS Windows 7 Home Premium x64 SP1 |
04 Jan 2013
|
#14 | | Windows 7 Home Premium 64-bit Melbourne, Australia |
Slightly off topic - but do you happen to know anywhere I can find live malware exploit links, I'm trying to test a program called "Exploit Shield" in a virtual PC but none of the exploit links I find work...
(funny how you can get viruses when you don't want them, and when you do want them you can't get them)
Edit: Just tried Exe Radar, it seems kinda inconsistent - some programs are allowed to run without my confirmation (and they weren't in the Program Files folder)
Also, is there any way to change the default action to Whitelist or blacklist? | My System Specs | | Computer type PC/Desktop System Manufacturer/Model Number Self built OS Windows 7 Home Premium 64-bit CPU Core 2 Quad Q8400 Motherboard Gigabyte UD3LR Memory 4gb PC-6400 Graphics Card Geforce GTX260 216sp Sound Card ONBOARD SOUND :D Monitor(s) Displays Viewsonic VA2413wm 24" LCD (+dead pixel...) Screen Resolution 1920x1080-(the one pixel that's stuck on red)=2073599 Keyboard GENERIC MICROSOFT KB FTW Mouse GENERIC MICROSOFT MOUSE FTW PSU TR2 550w? Case Thermaltake WingRS100 Cooling STOCK COOLERS :D Hard Drives 500gb Seagate 7200.12 Internet Speed REALLY FAST :P Other Info Wouldn't use Windows 8 even if it were free :P |
04 Jan 2013
|
#15 | | Win 7 Pro x64 SP1, Win 7 Ult x86 SP1 NC, USA |
Here is a site that lists several HIPS programs you can check out.
My disclaimer - I never used any of these programs and have no personal experience with them. Free Host Intrusion Prevention Systems (HIPS) and Application Firewalls (thefreecountry.com)
You can also Google for hips program or hips protection , etc. to see what else you can find... | My System Specs | | Computer type PC/Desktop System Manufacturer/Model Number home built OS Win 7 Pro x64 SP1, Win 7 Ult x86 SP1 CPU AMD Athlon II x4 620 Motherboard Gigabyte GA-MA785G-UD3H Memory 6GB GSkill DDR2 800 Graphics Card AMD 4670 GPU + AMD 4200 IGP Sound Card on board Realtek ALC889A Monitor(s) Displays RCA 40" LCD TV, Insignia 32" LCD TV, HP 15" LCD monitor Screen Resolution 1680 x 1050... Keyboard Gyration wireless, Logitech wireless, Dell USB wired Mouse Gyration wireless, Logitech wireless, V7 USB wired PSU Corsair 500 W Case Rosewill mid tower Cooling CM 90mm Tower Hard Drives OCZ Vertex 3 120GB,
Samsung F3 1TB (3),
Several others - WD, Seagate, Hitachi, ... Internet Speed Uverse - 12Mbps D / 1.5Mbps U Antivirus Avast free OR MSE. (+ MBAM Pro). Browser 1-Firefox, 2-IE. (Chrome and Opera for testing) Other Info 2 PCs: Primary: dual-boot, Test: triple-boot.
Mainly HTPC/Gen purpose (no gaming).
Trendnet USB KVM.
LG DVD burner/Blue Ray Player.
Tray system for removable SATA backup drives.
Not currently OCd, under-volted.
I use Hybrid sleep, rarely re-boot or shutdown.
Hauppauge HD-PVR, Avermedia PCIe TV Tuner, Hauppauge PCI TV Tuner. |
04 Jan 2013
|
#16 | | Windows 7 Home Premium 64-bit Melbourne, Australia |
| My System Specs | | Computer type PC/Desktop System Manufacturer/Model Number Self built OS Windows 7 Home Premium 64-bit CPU Core 2 Quad Q8400 Motherboard Gigabyte UD3LR Memory 4gb PC-6400 Graphics Card Geforce GTX260 216sp Sound Card ONBOARD SOUND :D Monitor(s) Displays Viewsonic VA2413wm 24" LCD (+dead pixel...) Screen Resolution 1920x1080-(the one pixel that's stuck on red)=2073599 Keyboard GENERIC MICROSOFT KB FTW Mouse GENERIC MICROSOFT MOUSE FTW PSU TR2 550w? Case Thermaltake WingRS100 Cooling STOCK COOLERS :D Hard Drives 500gb Seagate 7200.12 Internet Speed REALLY FAST :P Other Info Wouldn't use Windows 8 even if it were free :P |
04 Jan 2013
|
#17 | | Windows 7 Home Premium x64 SP1 SoCal USA |
The reason some files were able to run with EXE Radar is because the default setting is to auto allow system protected exe's to run. You can uncheck that in the settings tab if you like.
ExploitShield is a different animal, and they even tell you on their website not to try the usual malware. They have samples on their site if you sign in. It is an exploit blocker and is also just in beta, although it seems pretty stable
PrivateFirewall has bricked at least 2 Windows 7 x64 machines that I have read about. I wouldn't use it.
Have you thought about WinPatrol? | My System Specs | | OS Windows 7 Home Premium x64 SP1 |
04 Jan 2013
|
#18 | | Windows 7 Home Premium 64-bit Melbourne, Australia |
Yeah I know but they weren't system files, it was an old 16 bit application that happened to be installed directly into a folder on the root of C: drive.
The only link to exploit sites on ExploitShield's website links to a forum with malware samples whose domains have already gone down, and so they no longer work.
I've tried WinPatrol but it doesn't monitor anything; I even strolled into the hosts file and edited it with impunity, and WinPatrol didn't even raise the alarm.
Is Comodo's solution any good? I used it a long time ago and it wasn't really spectacular, but I don't know, things might've changed. | My System Specs | | Computer type PC/Desktop System Manufacturer/Model Number Self built OS Windows 7 Home Premium 64-bit CPU Core 2 Quad Q8400 Motherboard Gigabyte UD3LR Memory 4gb PC-6400 Graphics Card Geforce GTX260 216sp Sound Card ONBOARD SOUND :D Monitor(s) Displays Viewsonic VA2413wm 24" LCD (+dead pixel...) Screen Resolution 1920x1080-(the one pixel that's stuck on red)=2073599 Keyboard GENERIC MICROSOFT KB FTW Mouse GENERIC MICROSOFT MOUSE FTW PSU TR2 550w? Case Thermaltake WingRS100 Cooling STOCK COOLERS :D Hard Drives 500gb Seagate 7200.12 Internet Speed REALLY FAST :P Other Info Wouldn't use Windows 8 even if it were free :P |
04 Jan 2013
|
#19 | | Windows 7 Home Premium x64 SP1 SoCal USA |
Yea, I like Comodo's firewall/D+. If I were looking for that kind of software, it would be #1 on my list with Emsisoft Online Armor Free a close second. | My System Specs | | OS Windows 7 Home Premium x64 SP1 Best free HIPS with minimal resource usage? problems? All times are GMT -5. The time now is 07:23 PM. | |