Needing help locking down a computer

SamuraiInBlack

Supreme [H]ardness
Joined
Oct 10, 2003
Messages
5,771
Well a friend of mine has been put in charge of locking down another friend's computer. Someone between daddy-dearest (who claims he doesn't get on the computer at all) and her sister's friends are on the web doing things they probably shouldn't be, and the computer in turn gets infected six ways to Sunday (6 viruses through AVG, about 140+ infected files as per Kaspersky online scanner)

Rather than go with a software solution such as NetNanny and what not, I decided it'd be best to just block everything at the source, that being the hosts file, so no matter what browser they use, it will simply block things out, and then we change it to read only.

Whoever is doing this only uses IE despite Firefox being on there. This machine is on dialup. (Netzero if that helps any)

I've included the hosts file from MVPS.org, Spybot S&D's host file, and also found one here:

http://www.filesharingplace.com/supertrickxg/main.htm

That I'm using to block porn sites specifically, and using their bare security hosts as well.

I'm trying to make this as secure as possible, because this computer literally gets infected beyond being able to even be used about once a month or once every other month. Obviously neither I nor my friend can stop someone from clicking a link that says "CLICK HERE! IT'S REALLY COOL!" and what not, but I figure after all that we do, the only thing that can happen is it gets infected again and hopefully we'll know who did it.


I'm thinking about having them make separate accounts, one for every member of the family, and then restricting access accordingly if that's possible, and making them use passwords. From there, it'd only be a question as to who gave what password the next time this gets infected.

The machine is an E-Machines running Windows XP Home. I'm not sure how much I have to work with, but any suggestions in making this thing as bulletproof as possible is welcome. Money unfortunately cannot be invested on our parts, but I'm sure the parents wouldn't mind paying for some extra security if it means it will end this.
 
well up until you said home, I was going to recommend that hte user accounts have very little priveldges and then set some group policy options

however, with home.. pretty sure you can't do group policy, and I am not sure what type of account security settings there is offhand

i would just lock down IE in each user profile, restricting the activex controls, and other options as needed. Look for a tutorial on google... there is also another thread in here that has some good info... http://www.hardforum.com/showthread.php?t=1030713

you could also look at removing all IE icons from the user profiles and only leave the Firefox one on there... or pull a sneak attack and make Firefox shorcuts named IE with the IE icon as wel :D
 
Back
Top