Advanced Plus Security joyous home PC Config 2020

Last updated
Jun 18, 2020
How it's used?
For home and private use
Operating system
Windows 11
Log-in security
Security updates
Allow security updates and latest features
User Access Control
Always notify
Real-time security
Symantec endpoint protection 14.3 managed by Symantec endpoint Manager. Adguard desktop. NextDNS.
Firewall security
About custom security
Custom virus and spyware protection (maxed out), proactive protection( Sonar in aggressive mode), deception policies and firewall with max security settings. installation from External devises is prevented by using device control. Exploit mitigation uses prevention of running scripts in docx files and pdf files. IPV6 traffic is blocked.Only selected application out bound traffic is allowed. Firewall is set to detect changes in application and to report for re-allowing traffic.
Periodic malware scanners
Norton power eraser. EEK, Hitman pro.
Malware sample testing
I do not participate in malware testing
Browser(s) and extensions
Firefox,Chrome, Brave, Edge chromium with adguard, malwarebytes browser guard, lastpass and adguard vpn
Maintenance tools
reg organizer. Kerish doctor.
File and Photo backup
Windows base Image backup on two external hdds, Macrium Reflect incremental backup. Important data is also on Google drive and One drive as password protected zip file with 256 bit encryption.
System recovery
Windows base Image backup on two external hdds, Macrium Reflect incremental backup
Risk factors
    • Gaming
    • Logging into my bank account
    • Browsing to popular websites
    • Streaming audio/video content from shady sites
    • Browsing to unknown / untrusted / shady sites
    • Working from home
Computer specs
AMD Ryzen 5 3600.
Asus X570 tuf gaming Mobo.
Silicon Power 256GB NVMe PCIe Gen3 M2 ssd as boot drive.
2x 2Tb Thoshiba 7200 rpm Hdd.
Corsair Vengeance LPX 32GB (16GBx2) 3200MHz DDR4.
ZOTAC GAMING GeForce GTX 1660 SUPER.
Notable changes
1. Removed Fseure safe ( it was going to expire.)
Edit:
1. User access Control changed to " always notify"
2. added "WPD" to control windows privacy settings.
3.added malwarebytes browser guard
4. Added firefox with Next Dns DOH enabled.
5. Added NextDns.
6. Updated windows to 2004 version.
7. Added one more 16GB ram stick ( now running in dual channel mode)
8.Removed yoga dns app. Now running NextDns in doh mode in Mikrotik hAP AC router.

Brahman

Level 17
Thread author
Verified
Top Poster
Well-known
Aug 22, 2013
815
Edit:
System Dns changed to NextDns. They have a Dns server in India which is as fast as cloudflare. Custom blocklists enabled in next dns, system implimentaion is done with yoga dns app and all the filters in adguard except adguard's own removed. The major filtering is done in Nextdns server and some cosmetic level filtering with adguard, hence the browsing and page loading is a bit faster i feel. Oh and the the UI of NextDns is just awesome really a "piehole" as a service.
 
Last edited:

Vitali Ortzi

Level 22
Verified
Top Poster
Well-known
Dec 12, 2016
1,148
Edit:
System Dns changed to NextDns. They have a Dns server in India which is as fast as cloudflare. Custom blocklistds enabled in next dns, system implimentaion is done with yoga dns app and all the filters in adguard except adguard's own removed. The major filtering is done in Nextdns server and some cosmetic level filtering with adguard, hence the browsing and page loading is a bit faster i feel.
Heard good things about nextDNS .
Good choice 👌.
 

Brahman

Level 17
Thread author
Verified
Top Poster
Well-known
Aug 22, 2013
815
Today I had an urge to try out Chromium and i dowloaded it from "Download Chromium" and the very next moment i have recevied evidence of Symantec download insight working:giggle::giggle:.. This can be a very good option to prevet zero day attacks. I am impressed.
Untitled-1.jpg
 

Vitali Ortzi

Level 22
Verified
Top Poster
Well-known
Dec 12, 2016
1,148
Today I had an urge to try out Chromium and i dowloaded it from "Download Chromium" and the very next moment i have recevied evidence of Symantec download insight working:giggle::giggle:.. This can be a very good option to prevet zero day attacks. I am impressed.
View attachment 242882
If you can live with such a high sensitivity it can be pretty strong against zero days .
But false positives are insane with this feature.
 

Brahman

Level 17
Thread author
Verified
Top Poster
Well-known
Aug 22, 2013
815
Made some changes to Firewall rules. Added Two new rules to block TCP and UDP traffic to block both incoming and outgoing traffic on port 53. Blocked initial netbios and dhcp traffic and enabled rule to block all traffic till firewall starts.(This is to prevent any unencrypted dns traffic from any application during system startup through port 53 and to force all dns through port 443 via Yoga DNS application.) Apart from these a few other rules are also changed to prevent UPnP discovery ( as mitigation to the newly found UPnP CVe.)
Untitled-1.jpg
 
Last edited:

Vitali Ortzi

Level 22
Verified
Top Poster
Well-known
Dec 12, 2016
1,148
Edit:
Updated to windows 2004 version.
My ciniebench score is around 40 points better than prevous test on windows 10 1909.
View attachment 242896
Stronger multi score then a 24 threaded Xeon not bad and the improvement of Zen 2 over Zen 1 is very strong dam the Zen r7 1700x 16 threaded CPU is comparable to your 12 threaded CPU on base clocks (200 MHz higher base clocks on your CPU ).
haven't seen such a IPC improvement per gen at Intel for some time .
 
  • Thanks
Reactions: Brahman

Brahman

Level 17
Thread author
Verified
Top Poster
Well-known
Aug 22, 2013
815
Added a 16GB Corsair Vengeance LPX to the mix.Now running in dual channel mode. (The first module controller was made by samsung and the new one by micron yet no issues in entering dual channel mode- i was skeptical and afraid if the controller turned out to be a different one than the first one, dual channel mode would not get activated, but it did. ).
Untitled-1.jpg
Untitled-1.jpg
Untitled-2.jpg
 
Last edited:

Vitali Ortzi

Level 22
Verified
Top Poster
Well-known
Dec 12, 2016
1,148
Added a 16GB Corsair Vengeance LPX to the mix.Now running in dual channel mode. (The first module controller was made by samsung and the new one by micron yet no issues in entering dual channel mode- i was skeptical and afraid if the controller turned out to be a different one than the first one, dual channel mode would not get activated, but it did. ).
View attachment 246064View attachment 246071View attachment 246072
Nice 👍
If the dram is mostly unused I would consider some ram caching (I use Diskeeper because it works dynamicly but won't recommend it anymore as it changed to a subscription rather then a lifetime product)
 
  • Like
Reactions: Brahman

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top