Security for Windows 7

DIY-Computer-Repair can help!

Make your Windows 7 as secure as possible with the Windows 7 Ultimate Guide.

The Security for Windows 7 takes the same steps as other Windows Operating Systems. It just takes more time to find all the holes because MS in it's infinite wisdom has increase them by over 700 new Group Policies from XP and Vista.

As with any Operating Systems there are things you can do to keep your data safe from thieves. You primary defense against intrusion is a router with firewall capability, then a proxy server, and lastly Windows Firewall. However if you are behind a router with a firewall the Windows Firewall will interfere with you ability to communicate with the internet. If you have time and inclination you could write or enable all the rules for Windows Firewall and leave it enabled. If on the other hand you don't want to mess with the tedious task of setting up al the rules then use a router.

As always you would start with your installation of the Anit-Virus, Anti-Trojan, and Anti-Spyware. I have tested Grissoft AVG, Trojan Remover by Simply Super Software, but haven't found a spyware tool as of yet, the one I use with XP is to old for Vista or Windows 7.

Your next step would be to turn off the services that the hacker would use to gain control of your computer the main ones are -

Display Name Option
Diagnostic Policy Service Disabled
Diagnostic Policy Service Disabled
Diagnostic Service Host Disabled
Diagnostic System Host Disabled
Internet Connection Sharing (ICS) Disabled
IP Helper Disabled
Media Center Extender Service ** **** Disabled
Microsoft iSCSI Initiator Service Disabled
Net.Tcp Port Sharing Service **** Disabled
Peer Name Resolution Protocol Disabled
Peer Networking Grouping Disabled
Peer Networking Identity Manager Disabled
Portable Device Enumerator Service Disabled
Problem Reports and Solutions Control Panel Support Disabled
Program Compatibility Assistant Service Disabled
Remote Desktop Configuration ** Disabled
Remote Desktop Services Disabled
Remote Desktop Services UserMode Port Redirector Disabled
Remote Registry Disabled
Routing and Remote Access Disabled
WebClient Disabled
WinHTTP Web Proxy Auto-Discovery Service Disabled

If you think you have seen this list before you have if you have done the services page, these are listed there also.

Why go through the trouble of disabling the GPO's? The hackers are getting sophisticated in their ability to find security holes in your OS. One way to keep them from turning on a service you have disabled is to also set the corresponding GPO. If the GPO is disabled attempting to start a disabled service will result in failure, this adds another layer of security to your computer.


Would you take my survey on Windows 7?
Receive a free gift when you complete it!


Next you could turn off GPO's (Group Policy Options) as follows -

Machine Settings

Setting State
Disable remote Desktop Sharing Enabled
Offer Remote Assistance Disabled
RPC Endpoint Mapper Client Authentication Disabled
RPC Troubleshooting State Information Disabled
Turn off Autoplay Enabled
Turn off Autoplay for non-volume devices Enabled
Windows Firewall: Allow authenticated IPsec bypass Disabled
Windows Firewall: Allow ICMP exceptions Disabled
Windows Firewall: Allow ICMP exceptions Disabled
Windows Firewall: Allow inbound file and printer sharing exception Disabled
Windows Firewall: Allow inbound file and printer sharing exception Disabled
Windows Firewall: Allow inbound remote administration exception  Disabled
Windows Firewall: Allow inbound remote administration exception  Disabled
Windows Firewall: Allow inbound Remote Desktop exceptions Disabled
Windows Firewall: Allow inbound Remote Desktop exceptions Disabled
Windows Firewall: Allow inbound UPnP framework exceptions Disabled
Windows Firewall: Allow inbound UPnP framework exceptions Disabled
Windows Firewall: Allow local port exceptions Disabled
Windows Firewall: Allow local port exceptions Disabled
Windows Firewall: Allow local program exceptions Disabled
Windows Firewall: Allow local program exceptions Disabled
Windows Firewall: Allow logging Disabled
Windows Firewall: Allow logging Disabled
Windows Firewall: Define inbound port exceptions Disabled
Windows Firewall: Define inbound port exceptions Disabled
Windows Firewall: Define inbound program exceptions Disabled
Windows Firewall: Define inbound program exceptions Disabled
Windows Firewall: Do not allow exceptions Disabled
Windows Firewall: Do not allow exceptions Disabled
Windows Firewall: Prohibit notifications Disabled
Windows Firewall: Prohibit notifications Disabled
Windows Firewall: Prohibit unicast response to multicast or broadcast requests Disabled
Windows Firewall: Prohibit unicast response to multicast or broadcast requests Disabled
Windows Firewall: Protect all network connections Disabled
Windows Firewall: Protect all network connections Disabled

User Settings

Setting State
Do not allow Windows Messenger to be run Enabled
Do not automatically start Windows Messenger initially Enabled
Do not save encrypted pages to disk Enabled
Prevent CD and DVD Media Information Retrieval Enabled
Remote Access Disabled
Remote Desktop Services Configuration Disabled
Remote Desktops Disabled
Remote Installation Services Disabled
Turn off Autoplay Enabled
Turn off the Windows Messenger Customer Experience Improvement Program Enabled
Turn on Automatic Signup Disabled
Windows Firewall with Advanced Security Disabled
Windows Firewall with Advanced Security Disabled

If you think you have seen this list before you have if you have done the GPO settings page, these are listed there also.

Be aware that some GPO's will cause your OS to hang, crash, or lock you out, so use care when modifying the GPO's. Always use a reliable source for your information when researching the use of the GPO's.

(These lists came from the Windows 7 Ultimate Guide, there are over 150 different GPO's listed to increase your security)

Fix It! Your
DIY Computer Repair Newsletter!
Click here to get your copy of Fix It!

 

Are you a member?
Does your Computer need some TLC?
Want more Windows 7 help? You should see what there is in the
DIY Membership Section!



Hard Drives, Internal or External, All available at Newegg.com

Q and A

This site contains a lot of information. As with any publication not all information is available due to space, time, or subject constraints.

If you have a question that you did not find the answer on this web site  you a can ask your question here and we will endeavor to get you the most up to date answer possible!

Free Stuff!


Thank you for visiting my web site, and please come back again.

© www.diy-computer-repair.com '2008 Copyright Russell Enterprises All Rights Reserved
DiY Computer Repair contact support and sig. If you find this Web Site useful, feel free to recommend it to a friend.



Return to previous page



 
This website is not intended for children under the age of 18

Home
   Support   About owner   Site Map
Why I use SBI  Privacy Policy   Disclaimer


 

 



Return to top

From the Desert South West ~ Arizona, USA
Copyright DIY-Computer-Repair.Com 2009

powered-by-sbi


 

My Twitter! xml-rss Add to My Yahoo!
Add to My MSN Add to Google AddThis Social Bookmark Button My StumbleUpon Page Computer Blogs - BlogCatalog Blog Directory

Page copy protected against web site content infringement by Copyscape

 www.diy-computer-repair.com BBB Business Review


 
 One repair will pay for three copies of this book!
More for you! Think of the possibilities!
Now you can know what I know!

Today!