Zolomon's paranoid Windows 10 configuration

Zolomon

New Member
Thread author
Jun 21, 2016
3
For starters I want to clarify that I have no interest whatsoever in backing up everything on my computer. Everything of value such as cat pictures reside in MEGA, and all useless things such as university essays are in OneDrive. Both programs are running at all times.

My account is SUA and I'm running Simple Software Restriction Policy with access only to certain folders where I have Telegram (connected through Tor) installed along with my Chrome folder, for example. I'm mostly running SSRP for testing purposes, I rely on Sandboxie to prevent hostile files from jumping in through Chrome or Waterfox.

I run Chrome inside Sandboxie in its own box, with access to all folders of personal value being revoked.
Waterfox and Thunderbird (with TorBirdy) is in a shared box, with access to pretty much everything completely disabled. Access to Chrome profile is set as write only in this box, due to Chrome being my standard browser when I click links in ThunderBird. I chat a lot in IRC, so I end up clicking a lot of links. The IRC channel I'm connected to is encrypted with SSL, and I'm connecting through its .Onion.

I use Posteo for emails, my account is encrypted so that not even Posteo staff can read my email.
I'm always connected to AzireVPN with Viscosity to hide my IP.
I download torrents with the open source program qBittorrent.
Zemana AntiLogger Free is... Well it's running, I don't really see a use for it since I've never had a keylogging problem in my entire life.
I use ShareX to share files with friends, and every screenshot taken by ShareX is saved to my RAM disk, assuring its destruction on Windows shutdown.

I use Microsoft Edge to access Facebook (Don't give a crap about the security on there, it's a necessary evil for school) but I've considered using a separate sandbox for Facebook. Thoughts on that?
The Windows firewall is enhanced by TinyWall, but it's so restrictive and annoying I'm considering throwing it out. Some programs just can't connect, regardless of the settings in TinyWall. Allowed programs are still blocked.
I update qBittorrent, Thunderbird, SumatraPDF (I only use it for school texts) and TeamViewer (No account connected to it, I use it to help a female friend of mine. You know how women are with computers!) with Ninite.

My Android is just Moto G3, fully updated, Chrome for browsing and K-9 for email. Encrypted with pattern lock.
My Iphone 4S is collecting dust ATM.

95% of my chatting takes place on end-to-end-encrypted Signal.
 

Zolomon

New Member
Thread author
Jun 21, 2016
3
(I tried editing this in, but I keep getting an error. My apologies!)

To clarify why I don't have any real time scanning or on-demand scanning aside from Windows Defender: I just don't believe in signature-based scanning. If Sandboxie and SSRP doesn't stand a chance at blocking whatever abomination might break through their combined strength, what chance would avast! have?
 
N

Noxx

If you use sandboxie, be sure to actually put it in your config under real-time prot. If you're not a fan of signature-based antimalware, consider a cloud-based one like Zemana AntiMalware. You need to have something just in case. Thank you for sharing.
 

Zolomon

New Member
Thread author
Jun 21, 2016
3
Oh right, I'll fix that.

I previously used Panda, but the Polish popups at the bottom right corner made me flip after a while. AzireVPN seems to trick certain services into believing I'm not where I really am. I actually have ZAM installed, I just don't like it very much. I'll have to check what other options there are.

Thanks!
 

DardiM

Level 26
Verified
Honorary Member
Top Poster
Malware Hunter
Well-known
May 14, 2016
1,597
Thanks for sharing your config :)

... I actually have ZAM installed, I just don't like it very much. I'll have to check what other options there are.
Thanks!

You should try Crystal Security :)

"Anti-Malware
Crystal Security is an easy to use application that was created in order to help you quickly detect and remove malware that might affect your computer.
Cloud Based
The cloud based Crystal Security gathers data from millions of participating users systems around the world to help defend you from the very latest viruses and malware attacks.
Freeware
Cloud based malware detection, easy to use, user-friendly interface, automatic/manual updates, no installations, supports multiple languages and many other features."
 
Last edited:

shmu26

Level 85
Verified
Honorary Member
Top Poster
Content Creator
Well-known
Jul 3, 2015
8,153
you have a lot of security there.
two things you could possibly do:
1 save your windows installation from most disasters, by making a system image backup (macrium reflect is good for this). This is not for your cat pics, it's for the total system.
2 as an powerful additional layer of protection, consider an anti-executable. If you want to be paranoid, why not do it right?

you are right about the inherent drawbacks of traditional AV. But keep in mind that Avast free, especially if you custom install it, with only the file system shield, will actually make your system run faster and lighter than Windows Defender.
 

Duotone

Level 10
Verified
Well-known
Mar 17, 2016
457
As your familiar with sandboxie don't have much to add, except an anti-exe/whitelist type of software like AppGuard/VoodooShield. If you don't like ZAM just use it as on-demand. You may want to add a system image soft IMO in case of system failure or update problems.

Thanks for sharing your config!:)
 

jamescv7

Level 85
Verified
Honorary Member
Mar 15, 2011
13,070
Simple hardening the protection is indeed effective. :)

Optional: Third party programs will help you out to improve more, if you have opportunity then try Appguard or NVT Radar Pro for much lock down the protection.

Well again if you have opportunity to then have a system image backup so that you can revert any changes anytime without problems.
 

Exterminator

Community Manager
Verified
Staff Member
Well-known
Oct 23, 2012
12,527
From what i read, he doesn't need anything else. Each layer is secured.
I totally agree with this!! Thanks for sharing your config :)
I like to use a third party system image backup but I also like an occasional reinstall.
I keep the most important things in dropbox,MEGA,One Drive and an external HDD with updated ISO USB drives for all OS 7 SP1(Pro & Ultimate),8.1 (Pro) &10(Pro) 32 & 64 bit
The new Refresh Windows Tool makes it too easy :D
 

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top