Windows set system permissions to prevent some of the experience of virus intrusion

  
 

1, a hundred poisons do not invade, permissions are set such
We know that malicious programs such as viruses often hide themselves in the windows (anti-enhancement settings) system directory, if you set his permissions, you can prevent Most of the viruses.
First, make sure that your system directory does not have any viruses; right click on c:windows-attribute-security, delete all user groups except administrators and system, and then remove the administrators and system<all control”“ Modify “write ” these three check, OK. Set the c:windowssystem32 directory in the same way.
This way when a virus writes to the system, it will not be able to write because there is not enough permission. Of course, this will not be successfully installed when installing some programs, you need to manually give the full control permissions of administrators and system to be able to achieve again, after the installation is complete, you can change the permissions back.
We will first do an experiment, and take the rookie's favorite gray pigeon to experiment. Now you can go online, let's take a look at the system under the above configuration to see if it can go online. Everyone saw it and could not go online.
2, to prevent virus bundles commonly used programs
set all user permissions of explorer.exe and svchost.exe in the system directory to "read" & read "run & rdquo; but install system patches When the permissions are changed back, the installation can be successfully completed (anti-health setting permissions)
The QQ and other commonly used game main programs are set according to the above method to prevent the QQ hacking Trojan from renaming the source file after invading the system, replacing it with itself. QQ.exe (anti-health setting permissions)
According to this setting, it is very difficult for malicious programs to hack, and all game accounts can do this.
3, refuse IE hijacking
Do not want to open a web page to pop up a lot of web pages, then look down. Change the following two registry branches to "Read", read
HKEY_LOCAL_MACHINESOFTWAREMicrosoftInternet Explorer (Reflexive Settings Permissions)
HKEY_CURRENT_USERSoftwareMicrosoftInternet Explorer (Reflexive Settings Permissions)
This is just the tip of the iceberg of windows permissions, I am also At the beginning of contact, what is wrong, I hope everyone will correct, and hope to make progress together.

Copyright © Windows knowledge All Rights Reserved