Virus protection strategy - does it work?

G

Guest

While I use virus protection software (both for Win XP Pro and Win XP Pro
x64) I was thinking of an additional layer of protection. I've configured
this, but the $64,000 question:

Does it offer ANY additional protection?

Here's what I've done:
1) Set up my standard "Administrator" level profile - other than the
Administrator.
2) Set up a general profile belonging only to the "Users" group.
3) Restricted write/update ability to all HDDs and folders on my system
except for Administrators and Power Users groups.

Hmmmmm.....
 
H

Holz

Hmmmmm.....

Why in the world would you go through so much trouble running XP with AV,
anti-spyware, anti everything , defrag, reboots when you can run a free of
charge Linux Ubuntu and never worry about this shit again? I mean, would
you buy a car that required so much pre-maintenance before driving it, and
every now and than required complete overhaul?
I will never figure that one out..
 
G

Guest

wrong decision, even simple users need access to write to the hd, to update
files.
pagination etc, system files .....and the answer is NO, it causes more
problems than solutions
 
R

Rock

While I use virus protection software (both for Win XP Pro and Win XP Pro
x64) I was thinking of an additional layer of protection. I've configured
this, but the $64,000 question:

Does it offer ANY additional protection?

Here's what I've done:
1) Set up my standard "Administrator" level profile - other than the
Administrator.
2) Set up a general profile belonging only to the "Users" group.
3) Restricted write/update ability to all HDDs and folders on my system
except for Administrators and Power Users groups.

Hmmmmm.....

A better approach would be to have the user accounts be limited accounts.
Don't restrict writes. need that.
 
G

Guest

Thank you Rock. I certainly understand. I was perhaps unintentionally
misleading. Writes do occur, but in the \Documents and Settings\<profileId>
folder that is established with each profile.

Since I've been running this way, primarly for internet surfing, the writes
are minimized. In fact, under the profile in use (since I have 3 HDDs
totaling 480GB) one whole drive letter (spanned disk of 320GB) that is my
primary work environment, it is locked out from any usage (other than
Administrators or Power Users.)

I was "testing" this approach to help and ensure that my work environment
was exposed as little as possible to phishers, and other nafarious "things".

However, if the approach has no value, then I'll discontinue the practice.

I appreciate your insight and help. Thank you.
 
R

Rock

Thank you Rock. I certainly understand. I was perhaps unintentionally
misleading. Writes do occur, but in the \Documents and
Settings\<profileId>
folder that is established with each profile.

Since I've been running this way, primarly for internet surfing, the
writes
are minimized. In fact, under the profile in use (since I have 3 HDDs
totaling 480GB) one whole drive letter (spanned disk of 320GB) that is my
primary work environment, it is locked out from any usage (other than
Administrators or Power Users.)

I was "testing" this approach to help and ensure that my work environment
was exposed as little as possible to phishers, and other nafarious
"things".

However, if the approach has no value, then I'll discontinue the practice.

I appreciate your insight and help. Thank you.

Yes restricting write access to separate volumes via permissions has its
value. But if you are using an admin level account, then any malware that
gets on the system under your account can do what it wants.

That's one aspect that MS tried to address in Vista with UAC, to allow users
to run as standard users, rather than admin users. It has certainly
generated it's share of controversy...lol.

You're welcome.
 

Ask a Question

Want to reply to this thread or ask your own question?

You'll need to choose a username for the site, which only take a couple of moments. After that, you can post your question and our members will help you out.

Ask a Question

Top