The skill of using the control strategy to completely isolate the virus Trojan under the Win7 system

  
                                    

1. Open the Start menu and enter the “secpol.msc” command in the search box and press Enter to open the local security policy;

2. Open the "Local Security Policy" In the interface, expand the “Executable Rules” in the “App Control Control Policy” on the left side, and then right-click on the “Executable Rules” option to select the “Create New Rule” option.

3, in the pop-up "Create a new rule" interface, right click on the right side of the blank space to select "Create a new rule", open a new rule wizard;

4. In the pop-up interface for creating executable rules, select the “Privilege” item on the left side, and set “To reject” in the “Actions” setting, and select “"user or group" in “ Everyone”, to prevent all people and systems from running restricted viruses;

5, then click on the "conditions" option on the left, we can limit the program run by three types of conditions, They are: &l Dquo;publisher”,"path”,"file hash","publisher" is based on digital signatures, since the virus usually does not have a digital signature, so this is temporarily unavailable , but this is especially useful when limiting common software, and "path" is to directly select the virus file or folder, and "file hash" can limit the virus by hash value, even if the virus is copied. Many copies to different places can also be scrapped. Now, Xiaobian uses the “path” restriction as an example. After entering the next step, click the “Browse Files” button to select the virus file, and then click the “Create” button;

6. Due to the creation It is the first rule, so there will be a default rule creation prompt after completion, so as not to set the rules to limit the system file program, click “ is ”, allow the creation of default rules;

After the above settings, the virus restriction rules will take effect. You can try to double-click to run the virus to see if the virus has been restricted.

Tip: If it is invalid when setting the AppLocker rule, you can open &ldquo "Services", then find the "Application Identity" service project, set the startup type to "Automatic", and then press "Start" to make the rule take effect. In addition, if you choose anti-virus software, it is recommended that you choose software with more frequent updates, the latest software will be easier to kill the latest virus.

Copyright © Windows knowledge All Rights Reserved