Want to win a PS4? Go Premium and enter to win our High-Tech Treats giveaway. Enter to Win


web browsing security on stand alone computers

Posted on 2013-02-01
Medium Priority
Last Modified: 2013-02-21
Have a location that has 5 standalone computers on 5 separate Comcast Bussiness Internet connections.  Separate front desks in different buidlings.

Several different receptionists and night security folks sit at the desks during any given day/night.  They are getting infected with junk, we are sure based on browsing bad places and doing things they should not be doing . They were setup with Microsoft Security Essential by the vendor but that is not enough.

Explorer is getting corrupted among other junk

They need to get to the internet as the product they use for front desk management and work orders,  tenant tracking etc is web based.

What products can you recommend to add to this mess that we can use to effectively block most bad sites from being surfed or block all but the vendors web site for the application they need?  I have told the boss taht no matter what the prodcut there has to be some oversight and managemetn of it.
Question by:to2007
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 3
  • 2
  • 2
  • +1

Expert Comment

ID: 38844494

Let's start by describing your PCs. What OS are you running? Do users have admin-level access?

Author Comment

ID: 38844513
Windows 7 Pro 64 bit.   They have one user setup that all peopel log in as.  (that's they way they wanted it !)  They user has admin level access.

Expert Comment

ID: 38844650

Any way to convince the client to create a non-admin level user for day-to-day use?
They could have their admin user and know the password if they want, but they should refrain from using it for browsing the internet. This alone will help you protect the system and application areas from getting infected. The only piece that would get infected would be the user profile, but you could blow it and start over without having to re-install the PC.

If the above argument is not sufficient, then UAC "enabled" to as high as you can have it would also help. And, end-user education about not "clicking anything just 'because it has an OK button'" will go a long way.

Windows 7's User Access Control does a nice job at protecting even admins when it alerts a program needs elevated rights to run. At that point, if you did not mean to run "that attachment" or you did not mean to "just browse to that -nasty- site" that is trying to infect you; you can just brush it off by cancelling it at the UAC warning.

Microsoft Security Essentials and Defender, or any other respectable AV are rendered useless nowadays when people disable UAC and open/click-on undesired files/sites recklessly. After all, the user is giving it permission to run to which the AV is bypassed or overruled.

Hoe this helps!

When ransomware hits your clients, what do you do?

MSPs: Endpoint security isn’t enough to prevent ransomware.
As the impact and severity of crypto ransomware attacks has grown, Webroot has fought back, not just by building a next-gen endpoint solution capable of preventing ransomware attacks but also by being a thought leader.

LVL 27

Assisted Solution

Tolomir earned 600 total points
ID: 38844754
You can start with bitdefender


Why do they need to have admin access for reporting things by web?

Author Comment

ID: 38844800

all good info

but even if create a user that is not admin level  or if they are admin and set AC high, they can still go o sites and ignore warnings etc.  They have already been told not to use the comuter for personal browsing and still do.  We just don't have a way to trrack what person gets the computer infected and hacked etc.

I am really looking for i guess a good "parental control" prodcut to restrict web site access.  No shopping, no porno, no Facebook, no personal yahoo, msn, google email etc,    

in network environments we have used SOnicwall devices etc but that may be over kill in cost for eache of these indidivual standalaones to have their own SOnicwall device and subscription.  Heck maybe back to Nor6on 360 and parental conrols. Have never used it but assumeit can block sites.. We are i guesss wanting producto to say you can go to  www.buildinglink.com   and that is it!

Accepted Solution

xperttech earned 1400 total points
ID: 38844848
Like I said, there is no good AV that can prevent users from going to sites, or opening dangerous attachments.

As you point out, the other solution is to block sites and possibly certain attachments. This is more a policy based approach. Traditionally, you would configure a desktop firewall to block or prevent browsing, but there is a price: performance. The best way to handle this would be at the router/network level.

If you current router is not manageable or has not firewall/content-management features, then, what you need to do is insert a machine that does this for you.

The Parental Control solution is a local solution, like the desktop firewall I mentioned above. NetNanny (http://www.netnanny.com/features) is a well known one. But let me tell you. No solution is perfect without user involvement (education).

LVL 27

Expert Comment

ID: 38845017
you can give the new tool from opendns a try umbrella:


this is the feature list: http://www.umbrella.com/umbrella-security-features/

security and web filtering
LVL 83

Expert Comment

by:David Johnson, CD, MVP
ID: 38845959
opendns has a lot of options that will make it easier for you.

Featured Post

What does it mean to be "Always On"?

Is your cloud always on? With an Always On cloud you won't have to worry about downtime for maintenance or software application code updates, ensuring that your bottom line isn't affected.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

I annotated my article on ransomware somewhat extensively, but I keep adding new references and wanted to put a link to the reference library.  Despite all the reference tools I have on hand, it was not easy to find a way to do this easily. I finall…
In threads here at EE, each comment has a unique Identifier (ID). It is easy to get the full path for an ID via the right-click context menu. However, we often want to post a short link within a thread rather than the full link. This article shows a…
Google currently has a new report that is in beta and coming soon to Webmaster Tool accounts. This Micro Tutorial will highlight new features for Google Webmaster Tools.
This Micro Tutorial will demonstrate how nuggets on the Web are formatted by using Chrome Developer Tools. These tools would not only view the site's CSS but it can also modify it and save the CSS to use on your own site.
Suggested Courses

618 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question