Advanced Plus Security Durew's Security Config 2019

Last updated
May 2, 2019
Windows Edition
Pro
Security updates
Allow security updates and latest features
User Access Control
Always notify
Real-time security
Emsisoft Anti-malware (exclusions set)
Malwarebytes anti-malware (exclusions set)
OSarmor (exclusions set)
Sandboxie (custom settings)
(edit) Keepass
Firewall security
Periodic malware scanners
On-demand only:
  • Hitman pro
  • Zemana anti-malware
  • Norton power eraser
Malware sample testing
I do not participate in malware testing
Browser(s) and extensions
Firefox
  • uBlock origin
  • noScript
  • Disconnect
  • Emsisoft browser extension
Maintenance tools
hard configurator (no default deny policy)
sumo (software updater)
syshardener (no longer used)
File and Photo backup
Cobian backup (files, biweekly, I try to get it to weekly)
System recovery
Macrium reflect free (system, after large system change or after 2-3 month after last full system back-up)
Risk factors
    • Gaming
    • Logging into my bank account
    • Browsing to popular websites
    • Streaming audio/video content from shady sites
    • Working from home
Computer specs
HP Envy 15-AE046ND (laptop)
i7-5500U 2.4GHz (2 real cores, hyperthreading makes it 4 virtual cores)
12 GB RAM 1600MHz
NVIDIA GeForce GTX 950M
1 SSD, 235 GB
1 HDD, 909 GB

Durew

Level 1
Thread author
Verified
Aug 1, 2017
17
60
29
Netherlands
The security set-up of my laptop. I mainly use it for university work, mostly programming. In my time off I use it for some gaming, which don't run too fast.

For the firewall I use Window firewall control with a default deny policy.
Both EAM and MBAM have exclusion set to prevent them from clashing. As EAM was previously a companion AV and MBAM still is I am not expecting any problems with them interacting. At the moment I am considering the removal of MBAM as it's contribution on my setup seems limited.
I regularly set the firewall to block all and disable MBAM to get a bit more performance but it doesn't help as much as I'd hoped.

To my surprise, this setup passed the atelier firewall test I ran on it. Of all programs it was mostly sandboxie that was the first to intercept.

I curious to what advise the MalwareTips community may have for me.
 
Last edited:
@Durew: it seems a bit overkill:
Emsisoft Anti-malware (exclusions set)
Malwarebytes anti-malware (exclusions set)
OSarmor (exclusions set)
You may keep MWB for on demand scans...

A PassWord Manager and a VPN Service (Web Privacy) would be welcome.

Thanks for sharing :giggle:
 
You also could use fewer extensions.
NoScript and Disconnect are not needed with uBlock Origin in medium mode:
So I would suggest to only use uBlock Origin (ad, iframes and script blocking) and Emsisoft (phishing and malware blocking)
 
My advice:
- Drop MBAM to free on demand scanner
- Keep Emsisoft Anti-Malware
- You can lose NoScript & Disconnect for your browser extensions

Everything else is covered, thanks for sharing.

~LDogg