Thanks, forgot to mention running the monthly Windows Malicious Software Removal Tool (MSRT). I prefer to roll back to a clean image when programs in UAC protected folders are infected. When AV-finds poisoned documents and deletes them, I also check my documents backup (AV-scan).
Because my girlfriend uses the same setup, all custom security settings are geared towards reducing the attack surface while maintaining full functionality and compatibility
- setting software restriction policy for dangereous file extension while allowing MSI, EXE and TMP executables
- setting software restriction policy for script processing LOLbins, while allowing them to run elevated
- adding strong exploit protection designed by Microsoft for Microsoft (no compatibility issues, no functional restrictions)
- adding ACL restrictions on sub-folders which should not host executable code
To be honest, I would have stayed on all Microsoft security setup when the IT-guy had not convinced my girlfriend that Kaspersky is the best. This setup shows I am open minded by using an US operating systemwith a Russian AV, an US browser with a Russian Ad-blocker and a Chinese Browser-VPN with a third-party content blocker of a Canadian developer.