Advanced Plus Security Moonhorse's Security Config 2019

Last updated
Nov 18, 2019
Windows Edition
Home
Log-in security
Security updates
Allow security updates and latest features
User Access Control
Always notify
Real-time security
Sophos home premium FREE
Comodo firewall
Firewall security
About custom security
Comodo firewall on internet security config
Periodic malware scanners
Emsisoft emergency kit
Malwarebytes adwcleaner
Malware sample testing
I do not participate in malware testing
Browser(s) and extensions
Firefox stable channel (70.0.1 currently)

Extensions:
- Ublock origin
- Bitwarden
- Bitdefender trafficlight

About:config
- network.trr.mode = 2
- media.peerconnection.enabled = false
- security.secure_connection_icon_color_gray = false
- security.identityblock.show_extended_validation = true
Maintenance tools
Geek uninstaller
File and Photo backup
External drive
System recovery
Aomei backupper Free
Risk factors
    • Gaming
    • Logging into my bank account
    • Browsing to popular websites
    • Streaming audio/video content from shady sites
Computer specs
Asus m5A97
AMD FX-6300 @ 3.8ghz
MSI GTX-970
HDD 1TB
8GT Kingston Ram, @1600Hz

Moonhorse

Level 37
Thread author
Verified
Top Poster
Content Creator
Well-known
May 29, 2018
2,606
With Comodo cloud AV it is easy to set a deny execute (block rule) on your Documents, Movies, Music and Videos folders using sandbox rules. Normally no software should execute from these folders, so it should have zero impact on useability.
Theyre protected by default, invisible from sandboxed files > and already everything will be sandboxed by main rule
 

Moonhorse

Level 37
Thread author
Verified
Top Poster
Content Creator
Well-known
May 29, 2018
2,606
Forgot to add:
- geek uninstaller

Also replaced nano adblocker +defender with ublock origin
And malwarebytes extension with bitdefender trafficlight due false positive

Mainly wanted to ask is this thread marked as moderate, because of system backup missing? @harlan4096 Or im i missing something :unsure:
 

Moonhorse

Level 37
Thread author
Verified
Top Poster
Content Creator
Well-known
May 29, 2018
2,606
I have followed above suggestions and made few changes to my current security config
- Removed comodo cloud antivirus ( i couldnt enable gpu plugin on java client i use, and the removing CCAV solved the problem.)

+ Windows defender as main antivirus
+ Hard_Configurator with recommended SRP settings and Restrictions, Default deny ENABLED

+ Aomei backupper free for the backups, as suggested above

+ Bitdefender trafficlight got removed and replaced with Emsisoft extension and Windows defender browser protection.

And anyone to comment , im asking from you guys does running windows defender in sandbox mode really matters, should i enable it? Since it have to be enabled manually
 

Andy Ful

From Hard_Configurator Tools
Verified
Honorary Member
Top Poster
Developer
Well-known
Dec 23, 2014
8,129
Do you have any problems with whitelisting?
If the computer is used also by the family members, then you can optionally consider using Defender High settings + SmartScreen set to Block (use ConfigureDefender option in H_C).
If you do not plan to use Controlled Folder Access, then you can change its setting from Audit to Block.
Using H_C is not easy in the beginning, so do not hesitate to PM about problems.(y)
 
F

ForgottenSeer 72227

WD sandbox is to protect WD from being tampered with. If you have efficient 3rd party softs, WD shouldn't be even touched.

I thought it was to protect the OS from un-patched vulnerabilities and had nothing to do with WD being turned off or something like that? Maybe I am misunderstanding, but I thought MS was also introducing a separate tamper protection to prevent WD being messed with?
 

oldschool

Level 82
Verified
Top Poster
Well-known
Mar 29, 2018
7,107
Do you have any problems with whitelisting?...
... Using H_C is not easy in the beginning, so do not hesitate to PM about problems.(y)

Even I learned to whitelist by hash, etc. If @oldschool can do it, @Moonhorse can do it. And yes, you may ask Andy anything. His customer support is most excellent! Companies should model their's after him. The latter will never happen. :LOL:
 

Andy Ful

From Hard_Configurator Tools
Verified
Honorary Member
Top Poster
Developer
Well-known
Dec 23, 2014
8,129
Windows Defender processes run with high privileges, and can be exploited (in theory) by the malware via Defender vulnerabilities. This is also true for any AV and can be very dangerous, so running those processes in the sandbox is reasonable. They still can be exploited, but the exploit is isolated from the system in the sandbox.

WD Tamper protection is another kind of self defense. It prevents other application from changing some WD settings (no exploit of WD processes). Microsoft does not say what settings will be protected, but I can guess that disabling WD or disabling WD real-time protection will be included. That is why, probably, Microsoft forced me to exclude 'disabling WD real-time protectionin' setting from ConfigureDefender.
 
Last edited:

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top