- Jan 14, 2016
- 601
NOTE: Keep in mind, ONLY security-related programs on my system are mentioned above.
This is my current desktop security config. What do you guys think? Please give your honest opinions.
Previous Security Config (2016) - shukla44's Security Configuration (Desktop)
Additional Info:
This is my current desktop security config. What do you guys think? Please give your honest opinions.
Previous Security Config (2016) - shukla44's Security Configuration (Desktop)
Vulnerable Processes on my system (Windows 7):
All process's both paths (system32 & syswow64) included.
* - Reported/Logged
** - Monitored/Prompts
*** - Blocked/Disabled
- shell32.exe*
- regsvr32.exe*
- rundll32.exe*
- cmd.exe**
- mshta.exe**
- wscript.exe***
- cscript.exe***
- powershell.exe***
- powershell_ise.exe***
All process's both paths (system32 & syswow64) included.
* - Reported/Logged
** - Monitored/Prompts
*** - Blocked/Disabled
Vulnerable Apps & Programs on my System (beside Windows 7):
*** - Internet connections (Incoming & Outgoing) are disabled in Firewall
- Browsers (Firefox 64-bit, Chrome 64-bit & IE)
- Microsoft Office***
- Thunderbird
- Foxit Reader***
- Adobe Photoshop 64-bit***
- Windows Media Player***
- uTorrent (3.3.2 Build 30586)
- VLC Media Player***
- K-Lite Mega Codec Pack With MPC-HC 64-bit***
- Microsoft .NET Framework
*** - Internet connections (Incoming & Outgoing) are disabled in Firewall
Additional Info:
- I have 2 active user accounts - 1 admin (personal use only), 1 standard (friends & family use). The standard account enjoy the strict settings of kaspersky's parental control.
- For financial/banking protection, i use kaspersky's safe money. For safe money, i use ie 64-bit only with one addon kaspersky protection & all others DISABLED, also settings in ie 64-bit is modified for max protection.
- Firefox 64-bit is my primary browser. Chrome 64-bit is only used when vpn is needed. Internet explorer is only for banking.
- For exploit protection, i use hitmanpro.alert. Safe browsing (have safe money), keystroke encryption (have kaspersky secure keyboard input), webcam notifier (no webcam), badusb (have voodooshield) protections are DISABLED in hmp.a. Kaspersky exploit protection is also DISABLED for compatibility reasons.
- I use shadow defender (on admin account only) as a sandbox for testing new settings or unknown apps. All the malware-testing is done in vmware.
- In vmware, i have a number of guest os installed (temporarily), but only win7 sp1 ultimate 64-bit is permanent. Win7 guest os has rollback rx pro installed for rollback & testing purposes.
- Adguard desktop active filters - english filter, spyware filter, social media filter, annoyances filter, fanboy's enhanced tracking, anti-adblock killer reek, i dont care about cookies, nocoin. I use custom user filters as well. Phishing & malware protection is ENABLED. Stealth mode ENABLED. https filtering ENABLED. Allow search ads & websites self-promotion is DISABLED.
- Adguard protection is DISABLED on ie 64-bit. I have https scanning ENABLED in adguard & kaspersky both, so i need a seperate browser for banking only, where no conflicts should arise.
- All the internet connections (incoming & outgoing) are DISABLED in kaspersky firewall for apps/programs that doesn't depend on Internet. FYI, became very useful during the whole ccleaner debacle.
- All the important files/documents are backed up in a password-protected winrar archive file without the .rar file extension so that it cannot be encrypted by file-cryptors. For mbr-encryptors, it is also saved on the multiple cloud storage services.
- All the important passwords are kept in a password-protected doc file within a password-protected archive within a password-protected thumb drive. For emergencies, i keep some of them on a piece of paper hidden in my room. For the rest of the passwords, i use sticky password.
Suggestions & feedback's always welcome.
If you have questions about my configuration, i'll be happy to answer as much as possible.
If you have questions about my configuration, i'll be happy to answer as much as possible.
Last edited: