On mySimon: Caddyshack Trivia Game
BNET Business Network:
BNET
TechRepublic
ZDNet

August 25th, 2006

Windows without viruses and spyware? Yes, it's possible

Posted by Ed Bott @ 6:08 am

Categories: Security, Windows XP

Tags:

Walt Mossberg of the Wall Street Journal takes tech questions from readers each week and publishes his answers in Mossberg’s Mailbox. In this week’s column, he tackles a question I get asked all the time. How do you set up a new computer for a relative who is an enthusiastic Internet user but is naive or technically unsophisticated?

I set my parents up with a new Dell PC, and included antispyware software that I run periodically to clean up the computer. I recently discovered they had more than 200 instances of spyware on the machine. This may be because my 81-year-old father surfs porn sites ALL the time (this isn’t a joke). Is there any way to keep his computer bulletproof and safe?

OK, first of all, Dad’s probably more typical than you might think. Grandma probably doesn’t visit a lot of porn sites, but teenage boys and old men probably do (and so do a lot of guys in between those ages). Walt correctly notes that visiting these "bad" websites is a surefire way to run into the most aggressive pushers of viruses, Trojan horses, and spyware.

Walt’s answer is the same one you’ll get if you ask most reasonably experienced Windows users: "[Y]our best option is to switch to a type of antispyware program that blocks the installation and operation of spyware and adware programs as it is happening, rather than waiting until they are installed to clear them out."

Sorry, but I completely disagree with this advice. If this is the best you can do, then plan to come back once a month and clean up the mess. On the contrary, I think it’s possible to set up a Windows computer for Dad, Grandma, or Little Ricky and make it practically bulletproof. And it shouldn’t take more than about 15-20 minutes.

For the sake of these instructions, I assume you’re working with a completely clean, trustworthy installation of Windows XP with Service Pack 2, installed fresh from a clean CD or from the recovery CD that came with the computer. I also assume that Dad’s broadband connection is protected with an inexpensive hardware router. If you have even the slightest suspicion that there’s any malware installed on the computer, then stop right now. Back up any data, reformat, and reinstall Windows. Then follow these step-by-step instructions:

  1. Open Control Panel, go to User Accounts, and create two brand-new user accounts, both in the Administrators group. Let’s call them Dutiful Son and Bad Dad. For the Dutiful Son account, assign a strong, randomly generated, impossible-to-guess password. Write it down in a safe place and don’t share it with anyone else. For the Bad Dad account, use no password. (Having no password on this account actually makes the computer better able to resist external attacks.) Delete any other user accounts.
  2. Log on as Dutiful Son, visit Windows Update, and get all Critical Updates. Restart the PC, recheck Windows Update, and install any additional updates. Repeat until you see no more available updates.
  3. Configure Automatic Updates to automatically download and install updates.
  4. Log on using the Bad Dad account. Start Internet Explorer and install all mainstream, trustworthy ActiveX controls that Dad is likely to encounter in daily browsing (Flash, Acrobat, Windows Media Player, iTunes, QuickTime, and so on). Then disable the ability to download or install any additional ActiveX controls. (Step-by-step instructions are here, along with a .reg file that you can download to apply the changes automatically.)
  5. Install a good antivirus and antispyware program, download all available updates, and configure it to automatically retrieve updated definitions. This is a final line of defense only. The other changes you make here should render this protection superfluous for attacks that rely on social engineering.
  6. Open Control Panel, double-click System, click the Remote tab, and configure the Bad Dad account to allow Remote Assistance invitations to be sent. If Dad runs into trouble later, this setting will give you a fighting chance at fixing the problem without having to make a house call.
  7. Log off. Log back on to the password-protected Dutiful Son account and change the account type for the Bad Dad account to Limited.
  8. Log off and log back on to the Bad Dad account.

You’re done. Now, when Dad goes off looking for naked pictures of girls who are young enough to be his great-granddaughter, he won’t be a virus victim waiting to happen. If he uses Internet Explorer, any ActiveX prompt will be completely blocked and he’ll be unable to approve its installation no matter how convincing the pitch is. If a website or a virus-infected email offers to download an executable program, he’ll be unable to install it. In short, you’ll have protected him (and his PC) from himself.

Now go through and install any software that Dad needs. If you think he’ll be safer using Firefox, go ahead and install it, making sure to add any necessary plug-ins. If Dad has a favorite piece of software that won’t install in a Limited account and instead requires Administrator privileges, find an alternative. Whatever you do, don’t give him the password to the Administrator account.

Ed BottEd Bott is an award-winning technology writer with more than two decades' experience writing for mainstream media outlets and online publications. See his full profile and disclosure of his industry affiliations.

Email Ed Bott

Subscribe to Ed Bott's Microsoft Report via Email alerts or RSS.

  • Talkback
  • Most Recent of 74 Talkback(s)
Some handy utilities
xpy closes several windows loopholes, check all the settings to be sure they are doing what you want to do
ht... (Read the rest)
Posted by: efman Posted on: 09/03/06 You are currently: a Guest | | Terms of Use
Good avice until....  pkstephens | 08/25/06
Do you want to be safe?  Ed BottZDNet Moderator | 08/25/06
The limited accounts under xp are half baked  Hrothgar - PCLinuxOS User | 08/26/06
Not normal behavior  Ed BottZDNet Moderator | 08/26/06
Icons on my 5 year olds desk top...  Hrothgar - PCLinuxOS User | 08/26/06
Sorry, I don't follow that  Ed BottZDNet Moderator | 08/26/06
Clarification  Hrothgar - PCLinuxOS User | 08/26/06
My experience with restricted rights accounts  NonZealot | 08/25/06
My "Solution"  rickk@... | 08/28/06
yes it can be possible you use something else  Quebec-french | 08/25/06
So Ed, you don't think....  bportlock | 08/25/06
Of course I do  Ed BottZDNet Moderator | 08/25/06
Or...  30otsix | 08/25/06
Why?  Ed BottZDNet Moderator | 08/25/06
I agree, to late now.  30otsix | 08/25/06
Sunk money  Yagotta B. Kidding | 08/25/06
Dad just wants to browse the web  Ed BottZDNet Moderator | 08/25/06
Apples and Green Apples  30otsix | 08/25/06
Linux = Hammer  Ed BottZDNet Moderator | 08/25/06
Well Ed...  Linux User 147560 | 08/25/06
10 bucks says Dad wouldn't even notice.  30otsix | 08/25/06
Feel free to choose Linux if you want  Ed BottZDNet Moderator | 08/25/06
No need to get angry.  30otsix | 08/25/06
Freedom of what?  Colonel Panijk | 08/28/06
what about 3 years  funmayank@... | 08/28/06
Your right and your wrong...  Cayble | 08/28/06
Not at issue  Yagotta B. Kidding | 08/25/06
You ignore knowledge  Ed BottZDNet Moderator | 08/25/06
Far from it  Yagotta B. Kidding | 08/25/06
Is that really Knowledge...  LazLong | 08/25/06
This dutiful son  Linux User 147560 | 08/25/06
Ed, your making stuff up as you go along.  30otsix | 08/25/06
Then only that limits the number of people that  Hrothgar - PCLinuxOS User | 08/26/06
Well Ed, You give some sound advice....  LazLong | 08/25/06
Maybe reasonable fit for Linux, not perfect  Cayble | 08/28/06
This will not stop drive-by installs  BitTwiddler | 08/25/06
Not the case..  jcg_z | 08/25/06
Absolutely correct  Ed BottZDNet Moderator | 08/25/06
Say what?  Yagotta B. Kidding | 08/25/06
Not relevant here  Ed BottZDNet Moderator | 08/25/06
You are wrong  toadlife | 08/25/06
Use VirtualPC  BitTwiddler | 08/25/06
BTW....  BitTwiddler | 08/25/06
Fine for an expert  Ed BottZDNet Moderator | 08/25/06
Time Out  Yagotta B. Kidding | 08/25/06
Best post so far  brble | 08/25/06
I agree.  30otsix | 08/25/06
I don't agree that ZDNet is all Linux-heads  Ed BottZDNet Moderator | 08/25/06
Plus...  brble | 08/25/06
Ed...  30otsix | 08/25/06
Perhaps I have more time to read, or I simply comprehend what I read better  Yodaddy | 08/25/06
Ah thank you very much  Ed BottZDNet Moderator | 08/25/06
Agreed, it depends on who's willing to help  georgeou | 08/25/06
Agreed...Plus Hammer/Hammered  LazLong | 08/25/06
Good advice and a good article.  ShadeTree | 08/25/06
I wrote that part just for you  Ed BottZDNet Moderator | 08/25/06
One other tactic you forgot to mention.  Mr. Roboto | 08/25/06
just curious  rbritt | 08/27/06
Time to make it her problem  TripleII | 08/27/06
A Tip  TripleII | 08/27/06
Blank passwords  rseiler | 08/27/06
Blank passwords still secure in Vista  Ed BottZDNet Moderator | 08/27/06
Startup sound  rseiler | 08/27/06
More than Just Porn....  LazLong | 08/27/06
Why are you here?  TonyMcS | 08/27/06
90%  handydan918 | 08/28/06
Because Windows is Obsolete  slim-01 | 08/28/06
automatic update nonfunctional in limited account  Ipsenol | 08/28/06
Not supposed to be that way  Ed BottZDNet Moderator | 08/28/06
Windows without...  AmraLeo | 08/29/06
Use Linux, or tea timer  camrocks1981 | 08/29/06
Another way to harden IE against malicious Active X  Buffalo Cowboy | 08/29/06
LOOK HERE TO LEARN HOW TO PROTECT YOURSELF ON THE INTERNET  SystemArchitect | 09/01/06
Some handy utilities  efman | 09/03/06

What do you think?

SponsoredWhite Papers, Webcasts, and Downloads

Click Here
advertisement

Recent Entries

Premier Vendor Content Whitepapers, webcasts & resources from our Power Center Sponsors

Archives

ZDNet Blogs

White Papers, Webcasts, and Downloads

SmartPlanet

Click Here