
nosuid,noexec to tmp
sym link from /var/tmp to /tmp
php_cli with mod_ruid2 (check the forum there is an easy how-to)
suhosin patch for php (always in this forum, search update.script)
nobodycheck (same in update.script)
clamav (as before)
proftpd with clamav mod (same update.script)

And kiss or csf firewall (i use csf but you can choose what you want/prefer).