arsenaloyal's Laptop Security Configurations

Windows Edition
Enterprise
User Access Control
Always notify
Real-time security
Look 'n' Stop Firewall With Enhanced Ruleset
Sandbox and Hips : Sandboxie Lifetime License
DeepFreeze Standard Lifetime With Data Igloo
Anti Executable : Appguard 3.5
Anti-Exploit : Malwarebytes Anti-Exploit Premium
Anti-Keylogger : KeyScrambler Premium
Firewall security
Periodic malware scanners
Hitman Pro, Process Lasso Pro Lifetime, Anvir Task Manager Pro
Malware sample testing
I do not participate in malware testing
Browser(s) and extensions
Opera 12.18 x86, Firefox ESR Latest, IE11,CyberFox Intel x86 Latest.
Maintenance tools
CCleaner
System recovery
Terabyte Image for Windows

arsenaloyal

Level 3
Thread author
Verified
Aug 6, 2012
354
PC Environment: Home in shared environment
Security Awareness: Basic
Exposure to Malware: High
Infection Rate: Rarely
Anti-Malware Testing: No
Operating System: Windows 7 Enterprise SP1
Architecture: 32-bit (x86)
Account Privileges: Standard
Real-time Protection : Look 'n' Stop Firewall With Enhanced Ruleset
Sandbox and Hips : Sandboxie Lifetime License
System Freeze : DeepFreeze Standard Lifetime With Data Igloo
Anti-Executable : Appguard 3.5.6
Anti-Exploit : Malwarebytes Anti-Exploit Premium
Anti-Keylogger : KeyScrambler Premium
Ad-Blocker : Adguard Premium Lifetime
On-Demand Tools: Hitman Pro, Process Lasso Pro Lifetime, Anvir Task Manager Pro
Web Browsers: Opera 12.18 x86, Firefox ESR Latest, IE11,CyberFox Intel Latest x86
Extensions and Plugins: Lastpass

System configuration and hardening:
• Operating system: Windows 7 Ultimate SP1
• Standard User account is used at all times except when installing programs.
• User Account Control: I have set UAC control on 'Always notify'. All changes to my computer need administrator approval.
• Autorun / Autoplay: This feature is disabled. Everything that needs to be run is run manually.
• Services: All unnecessary services are disabled. Some services have startup type changed from "Automatic" to "Manual" and are run on-demand.
• User Accounts: Built-in Guest account is disabled.

Network security:
• Firewall: Look 'n' Stop Firewall is enabled and blocks unsolicited inbound connections also calling home programs are blocked by outbound filter.

System and applications security:
• Sandboxie Lifetime : All browsers are forced to run Sandboxed
This is how Sandboxie is Set
- Sandboxie container folder is set in a Ramdisk
- Drop rights from Admin Users Enabled.
- Sandboxie to delete content on application close.
• Appguard 3.5 : Set to lockdown mode and all media players and pdf utilities run as guarded apps.
• Malwarebytes Anti-Exploit Premium :All browsers,media players and PDF utilities are sheilded from exploits.
• KeyScrambler Premium : KeyScrambler encrypts every key you type to protect against key logging.
• DeepFreeze : C drive is perpetually in a freeze state except for monthly updates. Data Igloo Standard is used to redirect certain folders to a different drive to persist after a shutdown/restart.

Data security:
• Terabyte IFL : System image is created once a month before windows update to another HDD.
• Online back-up : adrive and skydirve are used to back-up important but not sensitive documents online.
• Lastpass: Lastpass is used for all logins except banking.
• CCleaner: MRUs, temporary files and other junk files are deleted automatically at start-up.

Internet security and privacy:
• Adguard Premium Lifetime : automatically blocks cookies and scripts and prevents tracking on all webpages.
• No other addons are used on any of the browsers except lastpass on opera and firefox.
• Banking environment: All banking is conducted in sandboxed Opera after previous browsing session is closed, all sandboxed processes are ended and all data in sandbox is deleted.

On-demand scanning:
• Hitman Pro : Monthly Scan
• VirusTotal Uploader: Uploader is used for upload and scan of individual files on online service's site.

Updating:
• Windows Update: Windows update is used to update system manually and other software from Microsoft.

Other security related tools:
• Process Lasso Pro : It is used as replacement for Windows Task Manager and also for memory and CPU management.
• Anvir Tank Manager Pro : It is used to check reputation of certain programs.

Note : All my security apps are password protected against uninstallation or settings change.

*This desktop is exclusively used for Media activities ,watching videos on youtube,hulu,netflix and other similar websites also playing videos from USB stick or DVD's.

Here is the look at the desktop interface.






Laptop 2 Config
PC Environment: Personal
Security Awareness: Basic
Exposure to Malware: Medium
Infection Rate: Rarely
Anti-Malware Testing: Yes, including the use of a VM or junk PC
Operating System: Windows Server 2012 Datacenter
Architecture: 64-bit
Account Privileges: Standard
Real-time Protection: Outpost Firewall Pro Lifetime Custom Config
Set to block Most.
Sandbox : Sandboxie Pro Lifetime
DeepFreeze Standard Lifetime With Data Igloo
Primo Ramdisk Server Edition
Appguard 4.1.45
Adguard Premium Lifetime
On-Demand Tools: Hitman Pro, Process Lasso Pro Lifetime, Anvir Tank Manager Pro
Web Browsers: Opera 12.18 x64, Firefox ESR x64, IE11
Extensions and Plugins: Lastpass

System configuration and hardening:
• Operating system: Windows Server 2012 Datacenter
• Standard User account is used at all times except when installing programs.
• User Account Control: I have set UAC control on 'Always notify'. All changes to my computer need administrator approval.
• Autorun / Autoplay: This feature is disabled. Everything that needs to be run is run manually.
• Services: All unnecessary services are disabled. Some services have startup type changed from "Automatic" to "Manual" and are run on-demand.
• User Accounts: Built-in Guest account is disabled.

Network security:
• Firewall: Outpost Firewall is enabled and blocks unsolicited inbound connections also calling home programs are blocked by outbound filter.

System and applications security:
• Sandboxie Pro Lifetime : All browsers are forced to run in sandboxie.Sandboxie's default container is a Ramdisk.
This is how SBIE is set:
- content of sandbox is deleted when the last sandboxed program ends
- browsers are run with dropped rights
- browsers have blocked access to personal data
• Appguard 4 : Set to lockdown mode and all media players and pdf utilities run as guarded apps.
• DeepFreeze : C drive is perpetually in a freeze state except for monthly updates. Data Igloo Standard is used to redirect certain folders to a different drive to persist after a shutdown/restart.

Data security:
• Terabyte IFL : System image is created once a week to another HDD.
• Online back-up : adrive and skydirve are used to back-up important but not sensitive documents online.
• Lastpass: Lastpass is used for all logins except banking.
• CCleaner: MRUs, temporary files and other junk files are deleted automatically at start-up.

Internet security and privacy:
• Adguard Premium Lifetime : automatically blocks cookies and scripts and prevents tracking on all webpages.
• No other addons are used on any of the browsers except lastpass on opera and firefox.
• Banking environment: All banking is conducted in sandboxed Opera after previous browsing session is closed, all sandboxed processes are ended and all data in sandbox is deleted.

On-demand scanning:
• Hitman Pro : Monthly Scan
• VirusTotal Uploader: Uploader is used for upload and scan of individual files on online service's site.

Updating:
• Windows Update: Windows update is used to update system manually and other software from Microsoft.

Other security related tools:
• VMWare Workstation: VMWare Workstation is used for testing purposes.
• Process Lasso Pro : It is used as replacement for Windows Task Manager and also for memory and CPU management.
• Anvir Tank Manager Pro : It is used to check reputation of certain programs.

Note : All my security apps are password protected against uninstallation or settings change.
 
Last edited:

OneDay

Level 21
Verified
Top Poster
Well-known
Aug 22, 2014
1,027
Quite an elaborate presentation of your config here, arsenaloyal..
It was a little bit difficult to follow, but here is my only recommendation:
- add WOT and HTTPS Everywhere to your broswers (if supported).
Thanks for sharing!
 

Cats-4_Owners-2

Level 39
Verified
Honorary Member
Top Poster
Well-known
Dec 4, 2013
2,800
Very nice! Your configuration is a floating fortress with theatre seats!:p
I came away feeling I'd walked through a ship that was both watertight and bullet proof!
As a Media Center configuration, the entertainment fun factor allows me a vision of a naval communications destroyer that's been converted to a pleasure craft with it's crew members given time to sit on lounges sipping cocktails:cool: while, for the most part, the only danger in a time of peace would be a concerted surprise attack by a team of:eek: pirate hackers.;) It's a good thing you're peace loving!:D
Thanks for sharing, arsenaloyal!:)
 
Last edited:

arsenaloyal

Level 3
Thread author
Verified
Aug 6, 2012
354
Quite an elaborate presentation of your config here, arsenaloyal..
It was a little bit difficult to follow, but here is my only recommendation:
- add WOT and HTTPS Everywhere to your broswers (if supported).
Thanks for sharing!

Adguard already has WOT Included In It, I have not used HTTPS everywhere extensively,so I will have to test It out first.

Exposure to Malware: High
Can i ask why this is, thanks :)

Great set up though!

Exposure to Malware Is higher than normal because this Mediabox Is connected to the Internet 24/7 and a lot of unscrupulous Web sites are browsed on a daily basis.
 

arsenaloyal

Level 3
Thread author
Verified
Aug 6, 2012
354
Very nice! Your configuration is a floating fortress with theatre seats!:p
I came away feeling I'd walked through a ship that was both watertight and bullet proof!
As a Media Center configuration, the entertainment fun factor allows me a vision of a naval communications destroyer that's been converted to a pleasure craft with it's crew members given time to sit on lounges sipping cocktails:cool: while, for the most part, the only danger in a time of peace would be a concerted surprise attack by a team of:eek: pirate hackers.;) It's a good thing you're peace loving!:D
Thanks for sharing, arsenaloyal!:)

My Intention with this setup was to actually let the family do whatever they want without me having to do anything,except perhaps update windows manually once a month.
 

arsenaloyal

Level 3
Thread author
Verified
Aug 6, 2012
354
Very straight to point configuration, suggest to have McShield since you mentioned on watching movies through those storage devices. :)

I am sorry but I am not aware of that particular program.however abt I did forget to mention was that defensewall runs all external and network drives as untrusted.
 

arsenaloyal

Level 3
Thread author
Verified
Aug 6, 2012
354
Looks fairly good to me. But i am not familiar with media box.

media box Is generally a small form factor PC with TV tuner card connected to a TV which doubles as a monitor. Most famous Is perhaps the Apple Mac mini.

I have a custom media box with 4 gigs of Ram,Core I5 2,500k,Palit GeForce GTX 750ti fanless
In a small form factor Rosewill Slim MicroATX case
 
Last edited:

arsenaloyal

Level 3
Thread author
Verified
Aug 6, 2012
354
Mcshield is an USB/ Hard Drive/ other external device to scan, detect and prevent any viruses transmitted especially autorun viruses.

thanks for making me aware of the software, I will take it for a test ride soon.
 

NSG001

Level 16
Verified
Nov 21, 2011
2,192
Unscrupulous websites eh?
Why would your family be surfing there ?
Still unsure why risk to malware would be classified as high unless we're talking warez sites which if i were you i'd block at firewall level, or use something like K9.
 
  • Like
Reactions: tonibalas

arsenaloyal

Level 3
Thread author
Verified
Aug 6, 2012
354
Unscrupulous websites eh?
Why would your family be surfing there ?
Still unsure why risk to malware would be classified as high unless we're talking warez sites which if i were you i'd block at firewall level, or use something like K9.

Warez websites are hardly the only malicious websites on the Internet. More like the websites which offer live sports and television are the ones which are more likely to have adware or malicious scripts,
and obviously USB from someone might be infected.
Its better to be prepared for any eventuality.
 

arsenaloyal

Level 3
Thread author
Verified
Aug 6, 2012
354
no children using the PC. lol am too young to be married anyway! but mom and dad do have the tendency to click on links without checking.
 
S

Sr. Normal

Desk looks so pretty ...
Mine is chaotic, every day the icons change their position , some appear , others disappear ...

I had forgotten that a desk could be attractive and functional
 

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top