Advanced Plus Security Minimalist's Security Config 2022

Last updated
Sep 12, 2022
How it's used?
For home and private use
Operating system
Windows 11
On-device encryption
Log-in security
    • Biometrics (Windows Hello PIN, TouchID, Face, Iris, Fingerprint)
Security updates
Check for updates and Notify
User Access Control
Always notify
Smart App Control
Network firewall
Enabled
Real-time security
Eset Nod32 Antivirus
Firewall security
Microsoft Defender Firewall
About custom security
Macrium: Image Guardian is enabled and configured
Periodic malware scanners
HitmanPro
Norton Power Eraser
Malware sample testing
I do not participate in malware testing
Browser(s) and extensions
Firefox with uBlock Origin
Desktop VPN
Mullvad
Password manager
KeePass
Maintenance tools
CCleaner and ShutUp10
File and Photo backup
Daily backup using Macrium Reflect and weekly backup to external disk and to Icedrive
System recovery
Macrium Reflect Home
Risk factors
    • Browsing to popular websites
    • Browsing to unknown / untrusted / shady sites
    • Working from home
    • Opening email attachments
    • Buying from online stores, entering banks card details
    • Logging into my bank account
    • Downloading software and files from reputable sites
    • Sharing and receiving files and torrents
Computer specs
HP EliteDesk 800 G5 TWR
• Intel Core i7-9700 CPU @ 3.00GHz
• Intel UHD Graphics 630
• DDR4 32 GB @ 2667 MHz
• 2x 500 GB SSD + 4TB HDD
Notable changes
1.1.2022 - original post
3.2.2022 - added IceDrive for online backup
AVs used and tested during 2022: Eset, Emsisoft, Bitdefender, AVG
20.8.2022 - decided to go with Eset
What I'm looking for?

Looking for minimum feedback.

Minimalist

Level 9
Thread author
Verified
Well-known
Oct 2, 2020
439
Have you ever had to use your Macrium reflect to restore?
Yes, on two occasions.
Once it was Windows update that caused some problems. I didn't want to use workarounds so I just restored an image taken before update and waited till MS fixed a problem.
Second time it was faulting SSD. One morning it was not recognised by my motherboard any more. I replaced it with my spare SSD and restored system from last system image. Whole procedure took less than 15 minutes. Without backup image I would have to reinstall my system and apps which would probably take me a day or a two of work.
So for me system and data backup is #1 when it comes to security.
 

Minimalist

Level 9
Thread author
Verified
Well-known
Oct 2, 2020
439
Today I've reinstalled and reconfigured ESET Internet Security. Here is a list of changes I've made to default configuration.

Real-time and machine learning protection: Malware and Suspicious Application Reporting set to Aggressive.
Exclusions: detection exclusion for uTorrent was set during initial scan.
Real-time file system protection: I set up process exclusion for Macrium Reflect's binary.
Cleaning level was set to Always ask user.
Cloud based protection: I disabled Submit crash reports and diagnostics data and Submit anonymous statistics options.
Automatic submission of suspicious samples: I disabled Archives and Possible spam emails from being submitted.
HIPS was set to Smart mode. I also added rules from here. I set those rules to Ask instead of Block.
Firewall: I added rules from here. I set those rules to Ask instead of Block.
Protocol filtering: I excluded my VPN client application from protocol content filtering.
Email client protection: I disabled antispam.
Banking and payment protection: I disabled protected website redirection option.
 

Kongo

Level 36
Verified
Top Poster
Well-known
Feb 25, 2017
2,512

Minimalist

Level 9
Thread author
Verified
Well-known
Oct 2, 2020
439

Minimalist

Level 9
Thread author
Verified
Well-known
Oct 2, 2020
439
I wish your excellent config was the default. Then ESET wouldn't need all the buttons and toggles. It's ridiculous that people have to dig through all of their menus.
Yes, they offer a lot of settings that you can configure. It would be nice if we could enable all those HIPS and firewall rules just by one click instead of adding them manually. Something like enhanced ransomware protection or something similar. It could also be set off by default if they worry about FPs.
 

Minimalist

Level 9
Thread author
Verified
Well-known
Oct 2, 2020
439
I tested Bitdefender for a day. It was OK, no noticeable system impact even though memory consumption is a little higher than with other solutions. There were few problems so I decided to go back to Eset.

Problems I experienced:
1. notification about expired certificate. It reappeared many times when browsing specific website (it was not that particular site but 3rd party site from where it downloaded some resources). Only way to remove notification was AFAIK to whitelist that site but that's not what I wanted to do.
2. full system scan. Macrium Reflect Image Guardian blocked 700+ attempts to modify backup files by BD service executable. IDK why it tried to modify those files. Looking for ADS on other files that were scanned didn't reveal anything.
3. full system scan. BD detected "malware" in one of the manifest files in c:\windows\servicing\lcu. It removed it with no problems but when I tried to restore it (since it's FP) it didn't have enough rights to restore the file. So I had to restore last system image.
4. full system scan. It detected compressed installers for uTorrent. When restoring them it did not restore them as compressed but instead it created a folder named utorrent.zip and restored them there uncompressed.
5. after uninstall I had to manually remove leftovers in c:\programdata (BIN files) and [ALL PARTITIONS]:\system volume information (SDB files).

IMO it's good AV but I prefer to use ESET as it's more trouble free and less aggressive. Though if I were practising "dangerous computing" I would probably feel safer with BD.



EDIT: after some thought I decided to give BD another try. Using it for a day may not show all the picture. I added folder with installers and folders for backup files to exceptions and run custom scan instead of built-in system scan.
 
Last edited:

blackice

Level 39
Verified
Top Poster
Well-known
Apr 1, 2019
2,807
I tested Bitdefender for a day. It was OK, no noticeable system impact even though memory consumption is a little higher than with other solutions. There were few problems so I decided to go back to Eset.

Problems I experienced:
1. notification about expired certificate. It reappeared many times when browsing specific website (it was not that particular site but 3rd party site from where it downloaded some resources). Only way to remove notification was AFAIK to whitelist that site but that's not what I wanted to do.
2. full system scan. Macrium Reflect Image Guardian blocked 700+ attempts to modify backup files by BD service executable. IDK why it tried to modify those files. Looking for ADS on other files that were scanned didn't reveal anything.
3. full system scan. BD detected "malware" in one of the manifest files in c:\windows\servicing\lcu. It removed it with no problems but when I tried to restore it (since it's FP) it didn't have enough rights to restore the file. So I had to restore last system image.
4. full system scan. It detected compressed installers for uTorrent. When restoring them it did not restore them as compressed but instead it created a folder named utorrent.zip and restored them there uncompressed.
5. after uninstall I had to manually remove leftovers in c:\programdata (BIN files) and [ALL PARTITIONS]:\system volume information (SDB files).

IMO it's good AV but I prefer to use ESET as it's more trouble free and less aggressive. Though if I were practising "dangerous computing" I would probably feel safer with BD.



EDIT: after some thought I decided to give BD another try. Using it for a day may not show all the picture. I added folder with installers and folders for backup files to exceptions and run custom scan instead of built-in system scan.
I’ve noticed almost every AV will pop Image Guardian blocks. I believe even ESET showed them in the scan logs, but I could be misremembering since it’s been a while.
 

Minimalist

Level 9
Thread author
Verified
Well-known
Oct 2, 2020
439
I’ve noticed almost every AV will pop Image Guardian blocks. I believe even ESET showed them in the scan logs, but I could be misremembering since it’s been a while.
I've used ESET quite a lot and never received pop up by MRIG. I didn't check logs so am not sure if they are recorded there.
But I'm not talking about AV message here, it's IG's message that so far I only got when using BD:

1647840571915.png

Another weird thing is that I don't get right click BD options in Total Commander. They are there in Windows Explorer but not in TC. That's a first time for me also.
 
Last edited:

SpiderWeb

Level 10
Verified
Well-known
Aug 21, 2020
477
I've used ESET quite a lot and never received pop up by MRIG. I didn't check logs so am not sure if they are recorded there.
But I'm not talking about AV message here, it's IG's message that so far I only got when using BD:

View attachment 265155

Another weird thing is that I don't get right click BD options in Total Commander. They are there in Windows Explorer bur not in TC. That's a first time for me also.
Whitelist and see if it happens again
 
  • Like
Reactions: JB007 and Nevi

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top