Advanced Plus Security CyberDevil's Security Config 2024

Last updated
Nov 22, 2024
How it's used?
For home and private use
Operating system
Windows 11
Other operating system
W11 Pro, 23H2, build 22631.4460
On-device encryption
N/A
Log-in security
    • Biometrics (Windows Hello PIN, TouchID, Face, Iris, Fingerprint)
Security updates
Allow security updates
Update channels
Allow stable updates only
User Access Control
Notify me only when programs try to make changes to my computer
Smart App Control
On
Network firewall
N/A
Real-time security
- Eset Smart Security Premium
- HitmanPro.Alert
Firewall security
Other - Internet Security (3rd-party)
About custom security
+ Eset Smart Security Premium.

Firewall in interactive mode after a week of training. Also a bunch of tracking and advertising domains are stuffed into the url-filter as a basic system-level filter.
Periodic malware scanners
- Emsisoft Emergency Kit
- TrendMicro HouseCall
- Norton Power Eraser
Malware sample testing
I do not participate in malware testing
Environment for malware testing
I don't do malware tests, but I have VirtualBox where I try different antiviruses and see their settings.
Browser(s) and extensions
Opera Stable
- Bitwarden
- uBlock Origin
- TWP - Translate Web Pages
- Harmony Web Protection

Avast Browser for shopping and proxy
- Same
Secure DNS
ControlD (in System and Browsers)
Desktop VPN
- Avast VPN
Password manager
- Bitwarden Free
The number of encryption cycles increased to 600,000 from the standard 100,000, two-factor authorization for login.
- Ente Auth for 2fa
Maintenance tools
- HiBit Uninstaller
- Wise Cleaner
- Glary Utilities

to disable and delete unnecessary after installation:
+ O&O ShutUp10++
+ O&O AppBuster
File and Photo backup
- One Drive
Subscriptions
    • None
System recovery
I don't do full system backups.
Risk factors
    • Browsing to popular websites
    • Browsing to unknown / untrusted / shady sites
    • Working from home
    • Making audio/video calls
    • Opening email attachments
    • Buying from online stores, entering banks card details
    • Logging into my bank account
    • Downloading software and files from reputable sites
    • Downloading software and files from unknown / untrusted / shady sites
    • Sharing and receiving files and torrents
    • Gaming
    • Gaming with third-party mods
    • Streaming audio/video content from trusted sites or paid subscriptions
    • Streaming audio/video content from shady sites
    • Coding and development
Computer specs

MSI GE75 8SG Raider (i7-8750H, RTX 2080, 32 GB, 1TB SSD)

Notable changes
2024-11-22: Changed Norton to Eset, NextDNS to ControlD, Authy to Ente, added HitmanPro.Alert to protect Opera (Eset does not protect browsers outside the big three from exploits), Web protection in browsers relies on Harmony from ZoneAlarm.
What I'm looking for?

Looking for medium feedback.

CyberDevil

Level 9
Thread author
Verified
Well-known
Apr 4, 2021
415
It's a pretty simple config for a New Year. :) I just finished reinstalling Windows and I wanted to try something new, so I bought Norton For Gamers for a special price. From my point of view, antivirus should at least not slow down the computer, besides protection, and at most do something else useful besides background load, Norton For Gamers gives me privacy leak monitor (although F-Secure do it much better!), as well as VPN and CPU optimization for games, that is very good. NextDNS in my opinion is still one of the best ways to fight against phishing (not sure about scams).

By the way, according to my experience, because I have a relatively weak processor, but 6 cores, and in the background runs MySQL and a bunch of other student stuff, then Norton really helps my games. :)

Oh, also almost all the software is installed through WinGet - it's fantastically convenient!

P.S. I really wanted to install Avast One, but I couldn't find any special promotions for it. For mobile phone it is MUCH better than Norton because it automatically protects all browsers, at least.
 
Last edited:

CyberDevil

Level 9
Thread author
Verified
Well-known
Apr 4, 2021
415
An interesting point is that with the same set of personal data, Norton only sees 7 leaks of my data for me, while F-Secure sees 18 (!!!). It seems that Norton only monitors data in the country the license applies to + the largest international incidents. Also removal of personal data at brokers is available only in the U.S. license. =(
 

LDogg

Level 33
Verified
Top Poster
Well-known
May 4, 2018
2,261
I think you could drop 1-2 extensions quite easily. Especially the Avira one, maybe Emsisoft too, and replace with BD Trafficlight, and drop one translation extension, could bookmark a website that does the same function instead. Just ideas though, they don't need to be acted upon. Apart from that, good config, thanks.

~LDogg
 

CyberDevil

Level 9
Thread author
Verified
Well-known
Apr 4, 2021
415
Doesn't Norton For Gamers include their Norton Safe Web-browserextension ?
It only activates it for Edge and Chrome, for other browsers Norton does not provide protection, only if you install Safe Search manually from the Chrome store, but that's not what I want, I certainly don't need their search engine.

I think I could drop Emsisoft, because I don't know if their recently added protection against scam sites works in their extension, but on the other hand it doesn't bother me.

I think you could drop 1-2 extensions quite easily. Especially the Avira one, maybe Emsisoft too, and replace with BD Trafficlight, and drop one translation extension, could bookmark a website that does the same function instead.
I had an experience with a phishing site, which first added to Avira database and later to Eset after my request, since then I feel very good about Avira's web-protection, Emsisoft also adds all phishing sites to its database very operatively.

One extension for translation perfect translates pages, the second one translates single phrases better and has a nice looking interface, although I think I can really replace xTranslate with Opera's sidebar, I think I will do that.

-----

In general, the problem with extensions has become less critical thanks to the new chrome interface, which allows you to conveniently block or allow extensions to work on specific sites.
1675425715941.png

----
So,
- drop xTranslate and Emsisoft extensions
+ install YogaDNS to keep Norton from changing DNS when VPN is active

I also turned off zone detection for download files and Windows built-in reputation protection, since two Norton + Windows reputation protections are too much for me.
 
Last edited:

Kongo

Level 36
Verified
Top Poster
Well-known
Feb 25, 2017
2,597
I wouldn't necessarily say that you have too many extensions, as I also see their use case, but Avira extension is truly not necessary with Opera + uBlock Origin + NextDNS malicious site protection. And in case anything is getting through, you still have Norton that will take care of it.
 

CyberDevil

Level 9
Thread author
Verified
Well-known
Apr 4, 2021
415
Update inspired by @Vitali Ortzi config (or our tastes are the same) :)

I'm too lazy to spell out all the modifications to the system so far. Nothing particularly interesting, except that I completely disabled Spectre and Meltdown protection. I think this is dangerous only for servers, considering that my PC has all the necessary protection against intrusions from the outside, I don't see the point of lowering the system performance even by 1%.
 
Last edited:
  • Like
Reactions: oldschool

Vitali Ortzi

Level 26
Verified
Top Poster
Well-known
Dec 12, 2016
1,585
Update inspired by @Vitali Ortzi config (or our tastes are the same) :)

I'm too lazy to spell out all the modifications to the system so far. Nothing particularly interesting, except that I completely disabled Spectre and Meltdown protection. I think this is dangerous only for servers, considering that my PC has all the necessary protection against intrusions from the outside, I don't see the point of lowering the system performance even by 1%.
How's the performance of having hitmanpro.alert added


Btw you may sometimes have issues with some mods getting false positives by hitman pro alert because of the way they could operate to attach into a game and anti cheats would almost definitely get detected although to me anti cheats are malware XD

Anyway if you have issues you can either disable hitman pro alert temporarily or suppress certain processes

Btw here is a list of incompatible games with could help you understand what you need to disable in case you get false positives https://support.hitmanpro.com/hc/en...249-HMPA-Incompatible-games-applications-list
 
Last edited:

CyberDevil

Level 9
Thread author
Verified
Well-known
Apr 4, 2021
415
How's the performance of having hitmanpro.alert added


Btw you may sometimes have issues with some mods getting false positives by hitman pro alert because of the way they could operate to attach into a game and anti cheats would almost definitely get detected although to me anti cheats are malware XD
I play only League of Legends with its protection no problems ) The only thing is that Hitman is very aggressive to crackers and keygens, I have to shut it down sometimes through the task manager, I never understood how to create an exception in it properly, even when I disabled everything, it still blocked the keygen.
 
  • Like
Reactions: Vitali Ortzi

Vitali Ortzi

Level 26
Verified
Top Poster
Well-known
Dec 12, 2016
1,585
I play only League of Legends with its protection no problems ) The only thing is that Hitman is very aggressive to crackers and keygens, I have to shut it down sometimes through the task manager, I never understood how to create an exception in it properly, even when I disabled everything, it still blocked the keygen.
You are suppose to suppress the alert but if there is a specific component with too many false positives you can disable that permeantly at the cost of decreased protection
So just look at what specific component generated the alert

And the reason it's aggressive to piracy is two
One sophos antimalware is aggressive towards piracy (you can just disable the antimalware component as you have eset )
Secondly the behavior of some cracks is risky and will get detected and you should look at the alert as it might actually catch some malicious behavior

Even legitimate software gets detected if it does stuff software usually isn't supposed to do like accessing lsass, Sam that malicious software do to steal sensitive information And some software use all kinds of unnecessary syscalls that malware usually use , have anti vm / debugging or write files in a manner that a ransomware could have done

So yeah hitmanpro.alert is very aggressive and that's why it's very useful and you could probably by disabling some components even with piracy get a mostly silent experience
 
Last edited:
  • Like
Reactions: CyberDevil

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top