Advanced Plus Security Quassar - Desktop PC

Last updated
Sep 7, 2018
Windows Edition
Pro
Security updates
Block all updates
User Access Control
Always notify
Real-time security
Prevention: SpyShelterFirewall + NetLimiter.
Izolation: Shadow Defender + Sandboxie
AV: SecureAPlus BETA (+Avira/APEX)
WEB: Adguard + K9 Web Protection
Firewall security
Periodic malware scanners
Zemana, Malwarebytes, SecureAPlus (+Avira/APEX)
Malware sample testing
I do not participate in malware testing
Browser(s) and extensions
Vivaldi: uMatrix ,Adguard, HTTPS Everywhere, Canvas Defender,
Cookie AutoDelete.
Maintenance tools
DiskPulse, Sysinternals Suite, SysTracer, WinDirStat, AIDA64, WireShark
File and Photo backup
Paragon(on external offline disk) + SpiderOak(Cloud)
System recovery
Paragon(on external offline disk)
Computer specs
https://malwaretips.com/threads/quassar-desktop-pcs.74053/

Quassar

Level 12
Thread author
Verified
Well-known
Feb 10, 2012
585
Some windows security layer are off cause i use 3rd soft which work better
and i no need double layers.


Windows 10 Configurate:
PowerShell script, CMD, java - all disabled
Deny elevation of unsigned executable.
Windows Features removed: Internet Explorer, XPS; SMB, Legacy Features, Media Features, etc...
Windows Defender deleted
Ask password for Admin Account
Enable Secure Sign in screen
Harden Windows 10 - A Security Guide. How to secure Windows 10
All traffic connection are disabled from up. Manual enabled only for few program and games.
Auto-update in most apps disabled cause i use 24/7 Shadow defender.

Security Software:
Firewall: SpyShelter Firewall + NetLimiter
HIPS: SpyShelter Firewall
Vritualization: Shadow Defender, VMware Workstation
Sandbox: Sandboxie
SRP: Sandboxie , SSFW
Keystore encryption: SpyShelter Firewall,
Antivirus: SecureAPlus Beta(+Avira/APEX)
Web protection: Adguard, K9, Web Protection

Extra scanner on demand: Zemana, Malwarebytes
Ads blocker & web filter: Adguard
Filters: facebook annoyances blocker, English Filter, Spyware filter, Social media filter, Adblock & uBlock polish filter, Adblock & uBlock polish cookies filter
Block: WebRTC, Push API, Location API, Flash and Java
Disable WFP casue conflic with MBAM web filter.

Backup System: Paragon (2 system image) on external disk which i connect only during backup.
-1st is virgin system almost after fresh install with only some system basic tweaks no 3rd software.
-2 Ready to use with all 3rd software configured

Files backup by Paragon and some important files i also yet upload encrypted to cloud solution by SpiderOak

Software Hardering/ex setup:
Sandboxie limit resource access etc. by ssj100's Security Setup
Read and/or Write access only for files for specific programs which require to work. Rest partition/folder are blocked/hiden for all rest apps.
1. Create as many separate sandboxes as is required for your internet facing applications. Try to have one separate sandbox per internet facing application.
2. In each sandbox, use the appropriate start/run and internet access restrictions and only allow your program to start/run and access internet within its sandbox. You may also need to allow other programs depending on whether the application interacts with other processes.
3. In each sandbox, block file access to any areas of your computer containing sensitive information (eg. “My Documents”).
4. In each sandbox, configure Read-Only access to C:\WINDOWS
5. In each sandbox, force the relevant application to always run in its sandbox
6. Do not use any OpenFilePath rules for any internet browsers (note there are a few exceptions here, like enabling an OpenFilePath rule to allow direct access to Firefox phishing database)
7. You will need at least 2 browsers. One browser will be used for everyday browsing and other non-critical/sensitive activity.
8. The other browser will be used for online banking and other critical/sensitive activity.
9. For the browser in step 8, configure its sandbox to automatically delete whenever the browser closes.
10. Depending on the nature of your other internet facing applications, you may choose to also configure their respective sandboxes to automatically delete on closing.
11. This step is obviously optional: have one sandbox to test applications/malware in (the DefaultBox will do) where the only configurations are to enable automatically delete and block file access to any areas of your computer containing sensitive information (eg. “My Documents”).
12. Create separate sandboxes for each USB/external drive hardware you have connected (or would connect) to your computer. Force run the relevant drive letter to run in the relevant sandbox. Other configurations/restrictions may be applied here (see above).
13. Create separate sandbox(es) for your CD/DVD drive(s). Force run the relevant drive letter to run in the relevant sandbox. Other configurations/restrictions may be applied here (see above).
14. Create a separate sandbox for your Virtual Machine program. Other configurations/restrictions may be applied here (see above).
15. Create a separate sandbox for opening newly introduced files (with a sandboxed explorer.exe) on your REAL system. For easy access, you will also need to create a shortcut to this sandbox and place this shortcut appropriately. Configure this sandbox to automatically delete on closing. Please click here for more information about this step.
16. This step is only necessary if you're using SRP to block cmd.exe (see above):
Make a copy of cmd.exe and rename it (eg. cmd1234.exe). Change the Sandboxie Delete Command accordingly in each sandbox to:
%SystemRoot%\System32\cmd1234.exe /c RMDIR /s /q "%SANDBOX%"
SpyShelterFW SRP Restricted Applications | SpyShelter Anti-Keylogger
(Auto allow - high, module 48 50 54 set to no - ssfw will always ask me even if app is trusted for allow to conect)
NetLimiter -All apps limited to 80% usage bandwidth (I can play and DL in same time with out lag)
Shadow Defender:
- All disk/partitions covered 24/7
- temp Cache in RamDisk set to 5GB
- some exclusion path folder/reg for only few other security software.

System Performance/setup:
Services setup based on Home | Black Viper | www.blackviper.com
PageFile: Disabled


Some privacy:
Telemetry: killed by OOSU10 + Windows 10 Privacy Guide - Spring Creators Update
Disks Encrypted: VeraCrypt
Mask IP: ProtonVPN and Nord VPN
2FA: Authy

Other info:
Malwarelab (On another machine): VMware Workstation Pro
Wallpaper Engine
Ashampo Snap
Mirilis Action
Notepad++
NitroPDF
Total Commander
Microsoft Office (Excel and Word)
Discord
MPC-HC
AIMP + FxSound Enhancer
Spotify
Droid4X
Duelyst
RIFT
Warhammer: Vermintide 2
Dying light
Dota 2
Paragon Hard Disk Manager
Hiren & Parted Magic
Avira Rescue CD
 
Last edited:

Quassar

Level 12
Thread author
Verified
Well-known
Feb 10, 2012
585
If you use Shadow Defender all the time then there's no need for a real time solution. However security OS updates are highly recommend.

I have all time update, i just do it manualy and offen check if it present :)

Wrong wrong.. SD meaby protect you against overwrite but not about read your data.. such like exploit or keylogers which will work temp till your reset system.
 
Last edited:

a1nn

Level 2
Verified
Jun 5, 2017
50
Hi, some of the things that I recommend that you do to boost the security of your system are:
  • Important
    • Enable OS security updates. This may not seem like a big change, but it prevents outbreaks like WannaCry from happening. I cannot recommend more that you enable it.
    • Get an extension that blocks malicious & phishing websites. (I suggest Avira Browser Safety or Kaspersky Protection)
  • Optional
    • Get HTTPS Everywhere
    • Install another second-opinion scanner (HitmanPro or Norton Power Eraser)
Thank you for sharing your configuration! (◕‿◕)
 

jamescv7

Level 85
Verified
Honorary Member
Mar 15, 2011
13,070
Good combination of the products out there.

Well here's the point, nothing wrong if you have SD and Sandboxie but better yet choose one since this will consider your isolated/testing environment.
 

Duotone

Level 10
Verified
Well-known
Mar 17, 2016
464
@Quassar
"OS Security Updates: Disabled" I assume your having problems w/ Windows Update... I've set up mine as metered connection so I do manual updates

You got a good combo I would choose SBIE for everyday use and SD when necessary, I would even consider removing MBAM and just use WD with that kind of combo.
 

Quassar

Level 12
Thread author
Verified
Well-known
Feb 10, 2012
585
@Quassar
"OS Security Updates: Disabled"
Problems between Windows Updates and VeraCrypt ?

I had some time issue but i decrypted and after update i encrypted back now work fine.
I just do manual update cause my SD work all time not only o/d because this is stupid. SD will not prevent(rollback) modification if is not working.


@Quassar
"OS Security Updates: Disabled" I assume your having problems w/ Windows Update... I've set up mine as metered connection so I do manual updates

You got a good combo I would choose SBIE for everyday use and SD when necessary, I would even consider removing Malwarebytes Anti-Malware and just use WD with that kind of combo.

SD work globaly on your disks/system. So if something bypass or you make fail by wrong allow rule by HIPS etc... you will infected system til next reboot.. If you use Sandboxie you can still limit resource access Sandboxie - Resource Access Settings to your database so in this situation SD with Sandboxie is not overall.
 
Last edited:

S3cur1ty 3nthu5145t

Level 6
Verified
May 22, 2017
251
With SD running 24/7 disabling updates and running them manually when needed makes perfect sense. Although I would like to point out that Sandboxie is not required what so ever with SD running full time, as there is literally nothing you can do with Sandboxie, that you can already do with SD. Over all, for what your doing with the system "testing", this is a good set up.
 
  • Like
Reactions: _CyberGhosT_

Quassar

Level 12
Thread author
Verified
Well-known
Feb 10, 2012
585
Added tool Disk Pulse. DiskPulse - Disk Change Monitor

Good soft to monitor changes in folders/files. It's help me get list for exlusion or commit to Shadow Defender

System fully configurated and with all apps started like a steam cost me fully just 2.2GB ram while i have yet next 30 GB free for usage :)
Imgur: The most awesome images on the Internet

-bump-
About OS Update... even if i do it manualy not mean is outdate i still keep it UPDATED !! i just do it handly :p
Imgur: The most awesome images on the Internet
 
Last edited:

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top