Advice Request What should a noob user do/configure/install to keep their pc some what safe?

Please provide comments and solutions that are helpful to the author of this topic.

Frogish

Level 1
Thread author
May 3, 2022
17
I have recently taken an interest in IT security and i wonder what the first steps are (except downloading an AV) to keep your pc some what safe. I dont need advice when it comes to browsing and such. More like what you need to configure and think about generally speaking. For exampel - what are the most common security flaws users neglect that can be easily fixed with a few configurations or settings?

Thanks in advance
 
Last edited:

Kongo

Level 36
Verified
Top Poster
Well-known
Feb 25, 2017
2,501
1. Using secure DNS just as NextDNS or Quad9

2. Attack surface reduction with restriction policies. A great tool for that would be:

3. Hardening Windows Firewall with tools like:
 

Back3

Level 14
Verified
Top Poster
Apr 14, 2019
660
Most of my friends are newbies. I have installed Configure Defender on their computer. Every 6 months or so, I check their device: make sure Windows Updates are current;use Sumo to check their apps updates; with Process Explorer and Autoruns, check what is running. Use a second opinion scanner to make sure Windows is clean.Check their browsers and Adguard or Ublock Origin. Make a backup of their important stuff including their passwords on an external drive.
 

pxxb1

Level 9
Verified
Well-known
Jan 17, 2018
440
I have recently taken an interest in IT security and i wonder what the first steps are (except downloading an AV) to keep your pc some what safe. I dont need advice when it comes to browsing and such. More like what you need to configure and think about generally speaking. For exampel - what are the most common security flaws users neglect that can be easily fixed with a few configurations or settings?

Thanks in advance

Since you are not saying what you do when you use your pc it is hard to say. The recommendation can be anything from make a fort out of it to, leave as is.
The usual mistakes when it comes to security is to click on anything - including mails, install programs without full attention (adware). If you do not do these "mistakes" you could have a light set up. Ms Defender tweaked with Configure Defender is enough.

As for ransomware, that ordinary people seldom get, an external backup now and then takes care of that.
 

Frogish

Level 1
Thread author
May 3, 2022
17
1. Using secure DNS just as NextDNS or Quad9

2. Attack surface reduction with restriction policies. A great tool for that would be:

3. Hardening Windows Firewall with tools like:

Hi thank you for your response. I did downlad SWH and ran it on default settings. I must admit i felt a bit dumb when i did it even though i read the manual and such because I cant find any reviews on it what so ever. My macafee webadvisor extension flagged the bete exe file as it might be harmful. I ran it anyway since you seem to be a trustworthy guy. I checked your previous posts and you genuinely seem to care about others and computer security. I also reviewed Andy fuls earlier posts and got the same impression. My question is has anyone reviewed SWH and deemed it to be safe. Like reviewed the actual code or just made a review or the software? I felt like i did something kinda stupid. I downloaded something that im not 100% sure is safe.
 

Kongo

Level 36
Verified
Top Poster
Well-known
Feb 25, 2017
2,501
Hi thank you for your response. I did downlad SWH and ran it on default settings. I must admit i felt a bit dumb when i did it even though i read the manual and such because I cant find any reviews on it what so ever. My macafee webadvisor extension flagged the bete exe file as it might be harmful. I ran it anyway since you seem to be a trustworthy guy. I checked your previous posts and you genuinely seem to care about others and computer security. I also reviewed Andy fuls earlier posts and got the same impression. My question is has anyone reviewed SWH and deemed it to be safe. Like reviewed the actual code or just made a review or the software? I felt like i did something kinda stupid. I downloaded something that im not 100% sure is safe.
Well, @Andy Ful is also the developer of ConfigureDefender which is a quite well known tool among us geeks. ;) You will find quite a few reviews about it on Google. Also, many people here on MalwareTips and also on WildersSecurity forum use his tools, and are very satisfied - me included. His tools are out there for a long time, and are even Open Source. The main idea behind his tools is to further strengthen the Windows security without the need of third-party applications that are running 24/7 on your system in real-time. That would also mean, that his tools have basically no attack surface for hackers, as they are only tools to control built in Windows functions that are not enabled by default. I hope I could take your skepticism a little... I personally use his tools for many months and never had any problems whatsoever. Just make sure that you understand what the tool actually does. If you don't, you can always PM me or ask here. And if you need more technical answers then I am sure that @Andy Ful will be happy to help you out.


A little off topic, but you can also create your own Computer Security Configuration thread, so that other people can give you recommendations and other tips how you could further improve the security of your system.
You can create it here: Computer Security Configuration
 
Last edited:

Andy Ful

From Hard_Configurator Tools
Verified
Honorary Member
Top Poster
Developer
Well-known
Dec 23, 2014
8,138
... My question is has anyone reviewed SWH and deemed it to be safe. Like reviewed the actual code or just made a review or the software? I felt like i did something kinda stupid. I downloaded something that im not 100% sure is safe.

You cannot be sure if something is safe even if someone would review the app. Generally, the application (EXE or MSI installer) can be reasonably trusted if it is not blocked by SmartScreen or another file reputation service. If the app is blocked by SmartScreen then you have to check the app in some other way. Did SmartScreen block your SWH executable after downloading it from the Internet?
 

upnorth

Moderator
Verified
Staff Member
Malware Hunter
Well-known
Jul 27, 2015
5,459
Do not use an administrator account.
Set UAC to maximum.

It's simple, but it's effective and quick to put into practice.:)
giphy-1.gif
 

Andy Ful

From Hard_Configurator Tools
Verified
Honorary Member
Top Poster
Developer
Well-known
Dec 23, 2014
8,138
Do not use an administrator account.
Set UAC to maximum.

It's simple, but it's effective and quick to put into practice.:)
The advice is recommendable for many users who use both administrator and SUA.(y):)

Some comment:
If one does not use an administrator account then there is no need to set UAC to the maximum. On SUA, any process elevation triggers the credential consent prompt. It is stronger than setting UAC to maximum on the administrator account.
 

cc207

New Member
Sep 11, 2018
6
Develop a backup strategy. Create system backups, such as with Macrium Reflect Free, so that you can quickly restore the system in case of trouble.
 
  • +Reputation
Reactions: show-Zi

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top