Advanced Plus Security Mystic's laptop security config 2022

Last updated
Sep 9, 2022
How it's used?
For home and private use
Operating system
Windows 10
On-device encryption
Log-in security
Security updates
Allow security updates and latest features
User Access Control
Always notify
Smart App Control
Network firewall
Real-time security
Emsisoft Anti-Malware
Firewall security
Microsoft Defender Firewall
About custom security
None.
Periodic malware scanners
NPE
Malware sample testing
I do not participate in malware testing
Browser(s) and extensions
Firefox [Multi-account containers + Emsisoft + Dashlane + IDM]
Secure DNS
Adguard
Desktop VPN
Hotspot Shield
Password manager
Dashlane
Maintenance tools
Kerish Doctor
File and Photo backup
Koofr 100GB Lifetime with Cyptomator
System recovery
AOMEI Backupper Pro
Risk factors
    • Working from home
    • Browsing to popular websites
    • Browsing to unknown / untrusted / shady sites
    • Opening email attachments
    • Buying from online stores, entering banks card details
    • Logging into my bank account
    • Streaming audio/video content from trusted sites or paid subscriptions
What I'm looking for?

Looking for maximum feedback.

Mystic

Level 4
Thread author
Verified
Well-known
Aug 25, 2022
141
My laptop is was released in 2017 and Acer stopped releasing drivers long time ago. Windows 10 1803 worked perfectly and 1809 too. But newer releases especially 21H2 gave me sound issues and my drivers did not work correctly.

To avoid that, I ran Windows 10 Enterprise, for it is supported for a much longer time than Home and Pro edition. Unfortunately, neither 1803 nor 1909 are supported now. I have been looking for alternatives for a very long time and I have stumbled on Windows 10 Enterprise 2019 LTSC which is basically Windows 10 1809 and it is still supported till 2024 and with extended support till 2029.

Now the issue is the availability of this version of Windows and activation. I do not want to run a hacked or cracked version of Windows no matter what. I downloaded the ISO from Microsoft Evaluation Centre and that gave me 90 days trial. After research, there is a command that you run in CMD that repeats the 90 days trials up to 3 time. That is almost a year. I hope I figure it out in this time.

My device does not support W11. Though it was supposed to fully support Win10, that was not the case. It seems that OEM manufacturers only release updates for a fixed period of time, and after that they no longer release updates. What I do not understand is it is Win10 after all. Why would a driver released for RedStone 4 not work on 21H2?
 
  • Like
Reactions: Nevi and oldschool

Mystic

Level 4
Thread author
Verified
Well-known
Aug 25, 2022
141
Removed Opera browser.

Installed Waterfox with Multi-account containers extension.

Changed to Qwant search engine.

The reason I started using Qwant is not because it does not track its users, but because it does not use cookies in the first place. It does show ads, but those ads are the same for all users and are not targeted ads.
 

Mystic

Level 4
Thread author
Verified
Well-known
Aug 25, 2022
141
Removed Kaspersky Internet Security due to the fact that I don't want to use any security product which scan https. I know I can disable that behaviour, but there are alternatives that don't do that.

Installed CatchPuls (got a 4-year license using my .edu email). Ran the first scan, changed protection mode to Interactive and set the option to trust files only if their certificate and thumbprint is in the trusted certificate list. I also disabled auto-promote Trust level.

Removed Adguard DNS as NextDNS gave me lower latency.

I'm not using any Chromium-based browsers.
 
G

Guilhermesene

Since you liked Kaspersky's "Application Control" module and used it, you can try using NVT's OSarmor which does something similar with respect to valid digital certificates from software vendors.

At this moment I am not using it, but NextDNS in my region is also better.
 
  • Like
  • Thanks
Reactions: Shadowra and Mystic

Jan Willy

Level 13
Verified
Top Poster
Well-known
Jul 5, 2019
605
I'll be testing Ctachpulse.
Maybe not the best choice.
See:
 
Last edited:

Mystic

Level 4
Thread author
Verified
Well-known
Aug 25, 2022
141
Maybe not the best choise.
See:
Thank you very much. I watched the test a few days ago, but I have my reservations.

I have been playing with the product for some hours now, and I believe that the product should not be tested the way other traditional antivirus products are tested.

When you run a setup file or an unknown file, one should take a look at more details and there is an option to have a second opinion, which shows VT results on the specific file. There is also an option to disable Trust over certificates, but unfortunately this is only available in Pro edition not Essentials.

One more thing, if a user does not know how to deal with constant prompts, they should not go with the Interactive protection mode.

Anyway, I'll keep testing the product for a few more days and post my feedback here on MT. I'm not a malware tester, so the feedback will focus on performance and usability.
 
  • Like
Reactions: Kongo and Jan Willy

Mystic

Level 4
Thread author
Verified
Well-known
Aug 25, 2022
141
Managed to get a license for Windows 10 LTSC 2019. Will do a clean install of Windows.

Catchpulse caused several BSODs. Thus, I'll be installing MB lifetime with Binisoft WFC. Malwarebytes Browser Guard is very effective and lightweight. I'll also install NextDNS Windows client for system-wide filtering.

Kerish Doctor has fixed all the issues related to my outdated drivers. My laptop is running better than ever. Their driver updater is decent.

Will update my config here once I finish configuring my laptop.
 

Mystic

Level 4
Thread author
Verified
Well-known
Aug 25, 2022
141
MB is one of the most underrated security solutions. It is bloat-free, privacy-respecting to some extent, and it asks you about everything during installation.
 
  • Like
Reactions: Shadowra

ScandinavianFish

Level 7
Verified
Dec 12, 2021
317
MB is one of the most underrated security solutions. It is bloat-free, privacy-respecting to some extent, and it asks you about everything during installation.
Its underrated for an reason: sub-par protection against malware. It also has non-existant protection against scripts (other than the web protection). Its nagging is worse than Avast
 
  • Like
Reactions: Mystic

Mystic

Level 4
Thread author
Verified
Well-known
Aug 25, 2022
141
Its underrated for an reason: sub-par protection against malware. It alsl has non-existant protection against scripts (other than the web protection). Its nagging is worse than Avast
I see your point. But seriously why would I need the best protection when I know what I am doing online? In my opinion, a good adblocker nowadays is more important than antivirus. Regarding script protection, how would this kind of malware end up in my device? Please send me links of possible attck vectors. Sub-par protection? I have my servations over the tests conducted online. How would 3000 sample end up on my desktop? In the case of MB and Eset, both deliver excellent network protection that would stop almost everything before reaching the device. Malwarebytes browser guard is very effective, too.
 

ScandinavianFish

Level 7
Verified
Dec 12, 2021
317
I see your point. But seriously why would I need the best protection when I know what I am doing online? In my opinion, a good adblocker nowadays is more important than antivirus. Regarding script protection, how would this kind of malware end up in my device? Please send me links of possible attck vectors. Sub-par protection? I have my servations over the tests conducted online. How would 3000 sample end up on my desktop? In the case of MB and Eset, both deliver excellent network protection that would stop almost everything before reaching the device. Malwarebytes browser guard is very effective, too.
I regurlarly test antivirus products against brand new malware samples, often the same products an few weeks or months apart, and Malwarebytes has always caused an compromised system, the only protection it has against maliciou sscripts is its web protection, altough its hard to say if anything was able to connect to their C&C servers or to get their payloads, its still leaves tons of active malware samples, one system was so badly infected it caused all Malwarebytes real time protection modules to stop working,


Is it an realistic scenario to have all these samples just sitting on the desktop? No. but if anything would get trough its web protection or exploit protection there is absolutely nothing to stop malicious scripts from wreaking havoc, even Windows Defender performs an better job, which has so far only let an RAT trough from the many dozens of malware samples I have tested against it, (excluding Magniber and BBYstealer, both of which are extremely difficult for AV's to detect anyways).
 
  • Like
Reactions: Mystic

Mystic

Level 4
Thread author
Verified
Well-known
Aug 25, 2022
141
I regurlarly test antivirus products against brand new malware samples, often the same products an few weeks or months apart, and Malwarebytes has always caused an compromised system, the only protection it has against maliciou sscripts is its web protection, altough its hard to say if anything was able to connect to their C&C servers or to get their payloads, its still leaves tons of active malware samples, one system was so badly infected it caused all Malwarebytes real time protection modules to stop working,


Is it an realistic scenario to have all these samples just sitting on the desktop? No. but if anything would get trough its web protection or exploit protection there is absolutely nothing to stop malicious scripts from wreaking havoc, even Windows Defender performs an better job, which has so far only let an RAT trough from the many dozens of malware samples I have tested against it, (excluding Magniber and BBYstealer, both of which are extremely difficult for AV's to detect anyways).
First, thanks for the video. I will try to watch it this weekend. I'm well aware of MB shortcomings, but for my use, it is more than enough. Paranoia has no place in my devices. It truly saddens me when I see members of MT overflood their devices with layers of protection they don't need. Devices are for us to do our work, study etc, not to look them down rendering them useless.

As I mentioned before, MB browser guard and MB network protection are superior and are sufficient for most users. I never claimed MB is he best out there, but it is working fine on my devices, and more importantly, it does not cause me any issues. Above all, it does not scan encrypted connection breaking their security like most products do.
 

oldschool

Level 85
Verified
Top Poster
Well-known
Mar 29, 2018
7,600
The reason I started using Qwant is not because it does not track its users, but because it does not use cookies in the first place. It does show ads, but those ads are the same for all users and are not targeted ads.
Have you considered Gibiru? Excellent search results. No cookies, no tracking, no logging and no ads. They make their $$$ with affiliation links when you buy products. Its results page looks like the original Google before they went to the dark side. :cool:
 
  • Like
  • Thanks
Reactions: Kongo and Mystic

Mystic

Level 4
Thread author
Verified
Well-known
Aug 25, 2022
141
Have you considered Gibiru? Excellent search results. No cookies, no tracking, no logging and no ads. They make their $$$ with affiliation links when you buy products. Its results page looks like the original Google before they went to the dark side. :cool:
I'll give it a try and see. Thanks for the recommendation.
 
  • Like
Reactions: oldschool and Kongo

Mystic

Level 4
Thread author
Verified
Well-known
Aug 25, 2022
141
Cancelled Microsoft 365 Home subscription. Purchased Microsoft Office Home and Student 2019.

Removed my Microsoft account and now I am using a local user with Admin privillages.

Migrated my password from Dashane to KeePassXC. My KeePassXC vault is synced to my Koofr account. I did not enabled browser integration in KeePassXC. Installed KeePass2Android on my Android device to sync my KeePassXC.

Now using Koofr to backup my photos and files instead of OneDrive. Everything is encrypted using Cryptomator.
 

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top