Advanced Plus Security blackice's 2021 Security Configuration

Last updated
Feb 17, 2021
How it's used?
For home and private use
Operating system
Windows 11
On-device encryption
Log-in security
    • Biometrics (Windows Hello PIN, TouchID, Face, Iris, Fingerprint)
Security updates
Allow security updates and latest features
User Access Control
Always notify
Smart App Control
Network firewall
Real-time security
Microsoft Defender
NoVirusThanks OSArmor
Firewall security
Microsoft Defender Firewall
About custom security
Configure Defender - High
OS Armor - a few additional items ticked in the settings
Periodic malware scanners
Malwarebytes, EEK, ESET online scanner, HitmanPro
Malware sample testing
I do not participate in malware testing
Browser(s) and extensions
Chrome -
AdGuard
1Password
Malwarebytes Browser Guard

Edge Chromium -
AdGuard
1Password

Firefox -
AdGuard
1Password
Malwarebytes Browser Guard
Secure DNS
ISP / Quad9
Desktop VPN
IVPN
Password manager
1Password
Maintenance tools
HWiNFO
Process Explorer
Everything
Bandizip
File and Photo backup
File History
System recovery
Macrium Reflect
Risk factors
    • Browsing to popular websites
    • Buying from online stores, entering banks card details
    • Logging into my bank account
    • Gaming
    • Streaming audio/video content from shady sites
Computer specs
Ryzen 7 5800X
ASUS TUF Gaming X570-Pro Wifi
32GB G.Skill Trident Neo 3600 cl16
RTX 3070 DUAL OC
500GB WD SN550 NVME
1TB WD SN550 NVME
500GB WD Blue SSD
1TB WD Blue HDD
Notable changes
DNS: Cloudflare->Quad9
2/17/21 - AVG Internet Security
2/20/21 - Removed Brave, updated PC Maintenance section
3/3/21 - Removed AVG
Added Microsoft Defender
3/22/21 - Keeping NextDNS so added it
Added Bitdefender Internet Security
4/15/21 - Removed Bitdefender IS
Added Microsoft Defender
4/19/21 - Added Malwarebyte Premium just kidding it’s broken, Defender still.
4/29/21 - Changed DNS to ControlD (by WIndscribe)
Removed adblockers in browsers, Added HitmanPro
5/10/21 - Back to NextDNS
6/14/21 - Currently using ISP DNS
7/9/21 - NextDNS DoT, RT-AX86U (Merlin Firmware)
10/14/21 - Windows 11
What I'm looking for?

Looking for medium feedback.

blackice

Level 38
Thread author
Verified
Top Poster
Well-known
Apr 1, 2019
2,731
Very nice Security Configuration, although I am not a big fan of Malwarebytes. (y)
I don't blame you. It's an experiment. My internet habits are bland and I got bored. It was already installed for second opinion (though I had to reinstall a couple times), and I had a license key. Honestly I like your favorite Bitdefender, but should just go with Microsoft Defender in terms of practicality. I've had the least issues with MS Defender and ESET. But so far so good once I got Malwarebytes to register.
 

blackice

Level 38
Thread author
Verified
Top Poster
Well-known
Apr 1, 2019
2,731
You can all rest easy. Malwarebytes was not registered after my last reboot, rebooted for unrelated reason. Back to Microsoft Defender or Bitdefender for now. Such a bummer I really liked it, but that’s some pretty bad unreliability. Seriously there’s always some problem with these silly apps.
 
Last edited:

SeriousHoax

Level 47
Well-known
Mar 16, 2019
3,630
You can all rest easy. Malwarebytes was not registered after my last reboot, for unrelated reason. Back to Microsoft Defender or Bitdefender for now. Such a bummer I really liked it, but that’s some pretty bad unreliability. Seriously there’s always some problem with these silly apps.
Some seems to be having problems with this Windows Security registration. ESET had this issue for some users for a few months. Kaspersky has an issue now but that's a bit different. If you uninstall Kaspersky, it doesn't remove itself from Windows Security registration. The main uninstaller and their uninstallation tool (which is worse than the default uninstaller) both don't remove it, so after uninstallation even Windows Defender doesn't start as the AV. Good for me, I know how to manually fix that. Some AV vendors really need to fix their Windows Security integration. Maybe Windows change things from time to time and this cause problems for them.
Edit: I'm on 21H1. So don't know if that has something to do with this.
 

blackice

Level 38
Thread author
Verified
Top Poster
Well-known
Apr 1, 2019
2,731
Some seems to be having problems with this Windows Security registration. ESET had this issue for some users for a few months. Kaspersky has an issue now but that's a bit different. If you uninstall Kaspersky, it doesn't remove itself from Windows Security registration. The main uninstaller and their uninstallation tool (which is worse than the default uninstaller) both don't remove it, so after uninstallation even Windows Defender doesn't start as the AV. Good for me, I know how to manually fix that. Some AV vendors really need to fix their Windows Security integration. Maybe Windows change things from time to time and this cause problems for them.
Edit: I'm on 21H1. So don't know if that has something to do with this.
I'm still on 20H2, so maybe there is something there.
 

blackice

Level 38
Thread author
Verified
Top Poster
Well-known
Apr 1, 2019
2,731
Removed adblocking in browsers as ControlD DNS (from Windscribe) seems to be very effective. I don't care about FLoC because I don’t use Chrome for much other than Google services and banking.

Added HitmanPro as second opinion scanner.
 
Last edited:

blackice

Level 38
Thread author
Verified
Top Poster
Well-known
Apr 1, 2019
2,731
Are you using the paid version?
What about ads on Youtube?
ControlD is on the 30 day trial of the paid service. Already useful as the ad blocking DNS blocks some things I need custom rules or bypasses to unlock.

Currently I am on a free trial of youtube Premium for 3 months...so that's a good question. But, I'm also torn on that, I want channels I view to get paid. I really have mixed feelings on ad blockers since basically it is breaking the web. They really screwed things up with malvertising getting out of hand and ugly ads. I don't want to pay a subscription for every site, but I want them to get paid for their content. Anyway, if it's like NextDNS it will just not work for in video ads. But I might be okay with that.
 

blackice

Level 38
Thread author
Verified
Top Poster
Well-known
Apr 1, 2019
2,731
Looks like someone wanted to see if they could kick it with Bitdefender.
Antimalware RAM use.png
 

blackice

Level 38
Thread author
Verified
Top Poster
Well-known
Apr 1, 2019
2,731
Back to NextDNS. It's faster than ControlD where I'm at. Specifically the malware filtering. I was excited about ControlD's new enhanced malware filtering, but their malware filtering DNS now takes 2X or more time to resolve anything and sometimes sees random latency spikes. For the moment NextDNS is more mature and robust for what I use it for. Also, lacks Windscribe's lowbrow marketing.

Edit: the downside to NextDNS being that I have to use a DDNS to keep my IP updated for using the standard DNS address on our router.
 
Last edited:

Brahman

Level 16
Verified
Top Poster
Well-known
Aug 22, 2013
799
Edit: the downside to NextDNS being that I have to use a DDNS to keep my IP updated for using the standard DNS address on our router.
Its safer to use DOH than the traditional dns setup. You can use YogaDns application to convert your nextdns to system wide doh. Its very easy to setup and you can have multiple configurations and change it on the fly.
 

blackice

Level 38
Thread author
Verified
Top Poster
Well-known
Apr 1, 2019
2,731
Its safer to use DOH than the traditional dns setup. You can use YogaDns application to convert your nextdns to system wide doh. Its very easy to setup and you can have multiple configurations and change it on the fly.
Yes, but not for several other devices on the network. Most devices still use traditional DNS addresses. I would say it’s rather more private than safer.
 

Brahman

Level 16
Verified
Top Poster
Well-known
Aug 22, 2013
799
Yes, but not for several other devices on the network. Most devices still use traditional DNS addresses. I would say it’s rather more private than safer.
I beg to differ slightly on that, consider this senario, A fileless malware hardcoded with "phone home" feature using google doh to download its payload will not register anything in port 53 traffic but everything will go through the encrypted port 443, which the traditional Nextdns setting will not prevent as it does not see it even if you enable " block bypass methods" under "Parental control" setting. But if you are using DoH of nextdns and if you have enabled " block bypass methods" the call to google doh will not go through and the malware will not get activated. So I feel it also has some safety feature when it comes to Doh coupled with nextdns.
Untitled-1.jpg
 
F

ForgottenSeer 85179

I beg to differ slightly on that, consider this senario, A fileless malware hardcoded with "phone home" feature using google doh to download its payload will not register anything in port 53 traffic but everything will go through the encrypted port 443, which the traditional Nextdns setting will not prevent as it does not see it even if you enable " block bypass methods" under "Parental control" setting. But if you are using DoH of nextdns and if you have enabled " block bypass methods" the call to google doh will not go through and the malware will not get activated. So I feel it also has some safety feature when it comes to Doh coupled with nextdns.
View attachment 257953
While that's true in theory, remember that malware can just use direct IP connections without using any DNS.

Nowadays malware also know about encrypted DNS and some kind of enforcement so keep that in mind too :emoji_beer:
 

blackice

Level 38
Thread author
Verified
Top Poster
Well-known
Apr 1, 2019
2,731
I’ll wait until Windows update to natively support encrypted DNS in stable release. It’s outside my scope of risk to worry about every single scenario. Also my router filters by IP, so if the IP malware is connecting to is being recognized it would be blocked when the connection is made. I am not a high risk user and I am currently the only Windows user at home.
 
Last edited:

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top