Advanced Plus Security Gandalf_The_Grey's Security Config 2021

Last updated
Dec 21, 2021
How it's used?
For home and private use
Operating system
Windows 11
On-device encryption
Log-in security
    • Biometrics (Windows Hello PIN, TouchID, Face, Iris, Fingerprint)
Security updates
Allow security updates and latest features
User Access Control
Always notify
Smart App Control
Network firewall
Real-time security
Microsoft Defender Antivirus
HomeCare by Trend Micro on TP-Link Archer AX6000 router
Firewall security
Microsoft Defender Firewall
About custom security
Microsoft Defender Antivirus
  • ConfigureDefender 3.0.1.0: High settings
  • Simple Windows Hardening 1.0.1.0: Basic Recommended Settings and restrict SMB123
  • DocumentsAntiExploit 2.0.0.0: MS Office ON2
  • Controlled Folder Access: enabled
  • Core Isolation: Memory Integrity enabled
Windows 11 Pro
  • O&O ShutUp10++: almost all recommended settings...
  • O&O AppBuster: uninstalled apps I don't want or need
  • Samsung Magician: Full Performance Mode
  • Bitsum Process Lasso Pro: ProBalance enabled
Foxit PDF Reader
  • Protected View for all files, Safe Reading Mode enabled, JavaScript disabled
Periodic malware scanners
HitmanPro and AdwCleaner (for the kids)
Malware sample testing
I do not participate in malware testing
Browser(s) and extensions
Microsoft Edge using Google search with uBlock Origin, Bitdefender TrafficLight, Bitwarden and Microsoft Editor as extensions
Secure DNS
From ISP (Ziggo)
Desktop VPN
AdGuard VPN
Password manager
Bitwarden browser extension
Maintenance tools
Autoruns, CCleaner, Disk Cleanup, PrivaZer, PatchMyPC, SUMo and Driver Easy
File and Photo backup
Windows File History on external drive (weekly)
OneDrive with Microsoft 365 ransomware protection (always on sync)
System recovery
Windows system image
Risk factors
    • Working from home
    • Browsing to popular websites
    • Opening email attachments
    • Buying from online stores, entering banks card details
    • Logging into my bank account
    • Downloading software and files from reputable sites
    • Requesting and accepting remote access
    • Streaming audio/video content from trusted sites or paid subscriptions
Computer specs
Acer Aspire VN7-791G-576X
Intel Core i5-4210H
Intel HD Graphics 4600 / NVIDIA GeForce GTX 860M
Kingston 16GB Dual-Channel DDR3 PC3-12800 RAM
Samsung SSD 850 EVO M.2 250GB
Seagate HDD ST1000LM014-1EJ164 1TB
Realtek High Definition Audio
Notable changes
2020.12.29 Filled the new fields
2020.12.30 installed Ziggo Safe Online
2021.01.04 back to Microsoft Defender with Hard_Configurator and added SpywareBlaster
2021.01.06 removed SpywareBlaster and went with stronger H_C -setup
2021.02.01 back to simpler setup with ConfigureDefender and Simple Windows hardening. Added Process Lasso
2021.02.08 Filled the new fields, no changes to config
2021.02.12 Microsoft Defender caused problems, back to KSCF and removed Process Lasso
2021.03.03 Update Kaspersky Security Cloud Free to the latest version, removed HitmanPro and enabled Microsoft Defender periodic scanning.
2021.03.28 back to Microsoft Defender Antivirus
2021.04.25 back to Ziggo Safe Online
2021.05.03 back to Microsoft Defender Antivirus
2021.05.07 switched from the uBlock Origin to the AdGuard extension
2021.10.04 back to Ziggo Safe Online and uBlock Origin
2021.10.05 back to the AdGuard extension
2021.10.13 upgraded to Windows 11 and back to uBlock Origin
2021.10.24 back to Microsoft Defender enhanced by DefenderUI Pro
2021.10.26 back to Kaspersky Security Cloud Free and Simple Windows Hardening
2021.11.06 back to Ziggo Safe Online by F-Secure
2021.11.10 removed Simple Windows Hardening and added VoodooShield
2021.11.16 testing DefenderUI Free with the latest Voodooshield beta
2021.11.30 back to Ziggo Safe Online
2021.12.21 optimized system with Samsung Magician and Bitsum Process Lasso Pro and back to Windows built-in security
What I'm looking for?

Looking for maximum feedback.

blackice

Level 38
Verified
Top Poster
Well-known
Apr 1, 2019
2,731
Priorities! Btw, smart choice. (y)
thrive love & hip hop GIF by Robert E Blackmon
I was going to say the same thing! That’s an upgrade you won’t regret.
 

Gandalf_The_Grey

Level 76
Thread author
Verified
Honorary Member
Top Poster
Content Creator
Well-known
Apr 24, 2016
6,506
Solved my issue with black spots etc.

It turned out that I had some time ago enabled the high-performance settings for some apps and they used the NVIDIA GeForce GTX 860M card.
After turning that off all programs are now using the built-in Intel HD Graphics 4600 and no more graphical anomalies occur. (y)
All this troubleshooting also showed that the Samsung SSD 850 EVO was showing elevated temperatures.

A clean install of Windows 10, adding back the Acer Quick Access program to enable CoolBoost and enabling RAPID mode in Samsung Magician brought the temperatures down.
The Acer Coolboost application is designed to improve system cooling by increasing the fan speed during heavy use.
Found the latest Acer Quick Access especially signed for Windows 10 on the support page of a newer Acer laptop and that version will be (and is) automatically updated through the Windows store. No risk for running an outdated version anymore.

So, back once again to built-in security configured by Andy's tools.
 
Last edited:

Divine_Barakah

Level 29
Verified
Top Poster
Well-known
May 10, 2019
1,854
Found the latest Acer Quick Access especially signed for Windows 10 on the support page of a newer Acer laptop and that version will be (and is) automatically updated through the Windows store. No risk for running an outdated version anymore.
Does it work with specific Acer laptop models? If it works on all Acer laptops I would appreciate it if you share the link to download it. Thank you.
 

Gandalf_The_Grey

Level 76
Thread author
Verified
Honorary Member
Top Poster
Content Creator
Well-known
Apr 24, 2016
6,506
Does it work with specific Acer laptop models? If it works on all Acer laptops I would appreciate it if you share the link to download it. Thank you.
I think it works only with some Acer laptops like the Nitro series that are advertised with CoolBoost, but you can always try...
I went to the support page of the latest Nitro AN515-55 and downloaded the latest Quick Access Application (version 3.00.3014 ).
It is under "Application" at this page:

Acer Quick Access.png
 
Last edited:

Divine_Barakah

Level 29
Verified
Top Poster
Well-known
May 10, 2019
1,854

Gandalf_The_Grey

Level 76
Thread author
Verified
Honorary Member
Top Poster
Content Creator
Well-known
Apr 24, 2016
6,506
My mother-in-law had some problems with her laptop.
She uses KPN Veilig (a F-Secure SAFE rebrand from her ISP KPN) so I installed Ziggo Safe Online (a F-Secure SAFE rebrand from my ISP Ziggo) on my laptop to see if that could be the cause. That software change caused absolutely no problems for me, and I quite like it.

In the thread of the (now deleted?) review done by the (now deleted?) user @McMcbrad we came the conclusion that the Simple Windows Hardening tool from @Andy Ful is a great companion that adds protection especially against Java malware (by not allowing it to run).

So, for the time being this is my new combo: Ziggo Safe Online and Simple Windows Hardening.
Safe and Simple :D

The recent DNS discussions reminded me to add Quad9 DNS to my router to protect all devices in my household.
 

Kongo

Level 35
Verified
Top Poster
Well-known
Feb 25, 2017
2,481
My mother-in-law had some problems with her laptop.
She uses KPN Veilig (a F-Secure SAFE rebrand from her ISP KPN) so I installed Ziggo Safe Online (a F-Secure SAFE rebrand from my ISP Ziggo) on my laptop to see if that could be the cause. That software change caused absolutely no problems for me, and I quite like it.

In the thread of the (now deleted?) review done by the (now deleted?) user @McMcbrad we came the conclusion that the Simple Windows Hardening tool from @Andy Ful is a great companion that adds protection especially against Java malware (by not allowing it to run).

So, for the time being this is my new combo: Ziggo Safe Online and Simple Windows Hardening.
Safe and Simple :D

The recent DNS discussions reminded me to add Quad9 DNS to my router to protect all devices in my household.
I think Simple Windows Hardening is a great companion for every AV, not only F-Secure aka. Ziggo. AV + SWH is pretty much all you need imo. It doesn't intervene in the protection of the AV unlike many "compatible" Anti-Malware solutions.
 

Gandalf_The_Grey

Level 76
Thread author
Verified
Honorary Member
Top Poster
Content Creator
Well-known
Apr 24, 2016
6,506
Oh great Gandalf the Wise,

Can you compare Trend Micro HomeCare with Sophos XG home or PFSense? Or is HomeCare just offering basic functions?
IMO it just offers basic functions, but every layer helps (y)
More info:
 

Zartarra

Level 7
Verified
Well-known
May 9, 2019
312
IMO it just offers basic functions, but every layer helps (y)
More info:
Thanks for the info.
 

Gandalf_The_Grey

Level 76
Thread author
Verified
Honorary Member
Top Poster
Content Creator
Well-known
Apr 24, 2016
6,506
I just had big problems connecting to internet, maybe caused by a bad update from F-Secure... :unsure:
So, (sorry @Morro) Ziggo Safe Online is uninstalled and back (again) to Microsoft Defender Antivirus enhanced by Andy's tools.
No more connection problems (y)
 

Morro

Level 16
Verified
Top Poster
Well-known
Jul 8, 2012
792
I just had big problems connecting to internet, maybe caused by a bad update from F-Secure... :unsure:
So, (sorry @Morro) Ziggo Safe Online is uninstalled and back (again) to Microsoft Defender Antivirus enhanced by Andy's tools.
No more connection problems (y)

LoL thanks for the warning, I will keep an eye on it, if it happens to me as well I will return to KSC Free. :)
 

Gandalf_The_Grey

Level 76
Thread author
Verified
Honorary Member
Top Poster
Content Creator
Well-known
Apr 24, 2016
6,506
Google was driving me nuts with consent popups and YouTube video pauses.
ublock Origin while using AdGuard's annoyances filter didn't block/solve that.
With the AdGuard extension no more Google annoyances (y)

In the test discussed here: Q&A - Evaluate your content blocker with Ad Block Tester AdGuard (with optimized filters didn't get 100%.
Enabling the EasyPrivacy filter took care of that and in the filter logs you can clearly see it doing its work.

I have the following eight filters enabled:
AdGuard Base filter, AdGuard Tracking Protection filter, EasyPrivacy, AdGuard Social Media filter, AdGuard Annoyances filter, AdGuard Dutch filter and from Yuki2718: AdGuard Social media Plus and AdGuard Tracking Protection Plus
By using optimized filters, I have now 70106 rules.
 

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top