Current computer virus commonly spreading as executable (*.exe, *.scr,
*.com, *.pif) and script file (such *.vbs and *.bat), and how to make
this all file not running on Drive including USB Flashdisk so our
computer is still secure from virus attack because commonly virus use
file document or folder icon to avoid user detection.
With this technique we can block all of executable/script file on
desire drive so there is no mistake when we run a wrong program which
dim as data file. For example when we plug USB Flasdisk
that contain virus on it (assume as drive E:) there is no need to worry
virus infect our computer even we click the file for many times.
But it also has shortage, all executable/script file including non
virus on that drive is blocked so be careful do not block drive with
windows system on it.
- Open Control Panel
- Chose Administrative Tools
- Chose Local Security Policy
- Then Chose Software Restriction Policies, right click on it and Create New Policies
- The result is a number new object appear on right side
- Chose Additional Rules, right click
- Chose New Path Rules
- Put drive address we want to block (exp: C:\Documents and Settings/ANDRY/My Documents)
- For Security Level, if we chose Unrestricted it mean to unblock all file on those drive, but if we chose Disallowed it mean to block executable file except data file such doc, xls, jpg etc.
- Then Apply and OK
- To Open It
- Chose Additional Rules
- Click properties to rules you wish to open.
- Chose Unrestricted or Delete the Rules.
0 comments:
Post a Comment