Advanced Plus Security Steel9's security config (updated July 2018)

Last updated
Jul 12, 2018
Windows Edition
Home
Security updates
Allow security updates and latest features
User Access Control
Always notify
Real-time security
Kaspersky Free
Firewall security
Microsoft Defender Firewall
Periodic malware scanners
- HitmanPro
- Zemana AntiMalware
- Malwarebytes
- Emsisoft Emergency Kit
Malware sample testing
I do not participate in malware testing
Browser(s) and extensions
Google Chrome:
- uBlock Origin
- 1Password
- Kaspersky Protection
- Windscribe
- Turn off the lights (for Youtube)
Maintenance tools
The built in utilities in Windows
File and Photo backup
AOMEI Backupper
System recovery
Macrium Reflect
Thanks for your config share buddy :)

Yes, Backup is the second impotant defendline in everyday using, BUT the most important is alway as you know... you (brain.exe). Consider maybe some scriptblocking addon, looks like you use chrome, so try example scriptsafe.

Also i recommended using SUA in everyday usage. & Consider also like free sandboxie and you should try put appcontainer on chrome.

Third or is that already firth...anyway, consider some outbound firewall or easy firewall controll with GUI or something like that.... WFC or Tinywall or even CFW.. its always up to you buddy.

Just try and see yourself what is more comtible for you!

Anyways stay safe dude, there MT are lot of very great threads about security combinatons as you may know, check those out and try.

Stay safe!

- BC

Edit: Oh and say greetings for Hyppönen :P,,, great dude!
 
Like others stated before switch to macrium reflect free as a system wide imager. Our aussie friend from the pond @frogboy has first hand experience with easeus when it comes to failing backups. And you certainly do not that to happen in case things go south ;) thanks for the share of your config!
 
  • Like
Reactions: hd35 and frogboy
Like others stated before switch to macrium reflect free as a system wide imager. Our aussie friend from the pond @frogboy has first hand experience with easeus when it comes to failing backups. And you certainly do not that to happen in case things go south ;) thanks for the share of your config!
It is true do not trust EaseUs it fails all the time. You get a message saying EaseUs Todo is not running and you are screwed. :(
 
Thanks for your config share buddy :)

Yes, Backup is the second impotant defendline in everyday using, BUT the most important is alway as you know... you (brain.exe). Consider maybe some scriptblocking addon, looks like you use chrome, so try example scriptsafe.

Also i recommended using SUA in everyday usage. & Consider also like free sandboxie and you should try put appcontainer on chrome.

Third or is that already firth...anyway, consider some outbound firewall or easy firewall controll with GUI or something like that.... WFC or Tinywall or even CFW.. its always up to you buddy.

Just try and see yourself what is more comtible for you!

Anyways stay safe dude, there MT are lot of very great threads about security combinatons as you may know, check those out and try.

Stay safe!

- BC

Edit: Oh and say greetings for Hyppönen :p,,, great dude!

Yep. From what I've understood, uBlock Origin also has some script blocking feature, isn't that enough? With SUA, do you mean "Subsystem for UNIX-based Applications"? Why would I need that? :p I also use Sandboxie for some things, but imo it's a bit overkill to run your everyday browser in a sandbox. And for firewall, I have considered Comodo Firewall, but I am not sure about the compatibility with my other security products yet (and I also think Windows Firewall does a pretty good job). Thank you for the tips!

/steel9
 
It is true do not trust EaseUs it fails all the time. You get a message saying EaseUs Todo is not running and you are screwed. :(
Do you mean that the system image backups fails, or all backups? I've never had a problem with EaseUS, works great for me, maybe it depends on correct settings? (I think it is required to enter the Windows credentials in the program for it to auto backup).

/steel9
 
  • Like
Reactions: frogboy
Do you mean that the system image backups fails, or all backups? I've never had a problem with EaseUS, works great for me, maybe it depends on correct settings? (I think it is required to enter the Windows credentials in the program for it to auto backup).

/steel9
I was using the paid version and I needed to restore a system image and upon reboot all I got was a message saying EaseUS Todo not running and had to do a clean install and start from scratch. ;):mad:
 
I was using the paid version and I needed to restore a system image and upon reboot all I got was a message saying EaseUS Todo not running and had to do a clean install and start from scratch. ;):mad:
Ouch, that's bad. But I'm only using EaseUS for file backup (mainly to prevent ransomware from causing any damage), and to restore files you can just open the backup files with the program and take the files out of the backup manually.

/steel9
 
  • Like
Reactions: frogboy
I would consider saving important data to an external drive also.
As has already been suggested consider a system backup solution.
Please edit your config to reflect your current on demand scanners.
Thanks for sharing your config :)
 
I would consider saving important data to an external drive also.
As has already been suggested consider a system backup solution.
Please edit your config to reflect your current on demand scanners.
Thanks for sharing your config :)
I'm making backups of all my important files to a NAS drive (with EaseUS), and the NAS-drive is inaccessible through Windows Explorer without password (but the password is saved in the backup program though), but it would be pretty hard for ransomware to encrypt my NAS-drive. I have also updated my config, thanks for the reminder.

/steel9
 
Also I'm temporarily using the real-time protection in Zemana, as I got a free 380-days license via a giveaway. But I haven't added it in my security config as it's just a temporary real-time product I use.

/steel9
 
Added: Process Blocker configured to block: wscript.exe, cscript.exe, java.exe, javaw.exe (I unblock them if I need them temporarily)
Changed: Kerish Doctor PC Protection modified to only protect:
- Hosts file
- Important system files
- Security settings
- (Check installed applications for vulnerabilities - not sure if this is necessary)