Skip Navigation
UMass Amherst People Finder

Security Tips for Windows 2000 and XP

Operating System: Win

Download & Update Anti-Virus Software

To protect your computer against viruses and other security breaches, download anti-virus software and keep it updated. Anti-virus software for Windows computers is available at no cost to members of the UMass Amherst community.

Find out how to install and update VirusScan - the anti-virus software for Windows XP.

Update Your Operating System

Security breaches occur most often on systems that are not up-to-date. Protect your computer by keeping it updated with the latest patches, updates and drivers from the Windows Update Web site. Learn how...

Patch Internet Explorer 6 or upgrade to Internet Explorer 7

Patch IE6

Serious security issues have been identified for Microsoft Internet Explorer 6. Even if Internet Explorer 6 is not your main Web browser, but you have it installed on your computer, you must patch it immediately. To do so:

  1. Go to http://www.microsoft.com/downloads/. Find and click Internet Explorer 6 Service Pack 1.
  2. On the Download Details page, click Download (upper right corner).
  3. Click Open to run the setup, then follow the instructions on the screen.
  4. Restart your computer to complete the installation.

Download and Install IE7

  1. Go to http://www.microsoft.com/downloads/. Find and click Windows Internet Explorer 7 for Windows XP SP2 (IE 7 is included by default with Windows Vista).
  2. On the Download Details page, click Download (upper right corner).
  3. Click Open to run the setup, then follow the instructions on the screen.
  4. Restart your computer to complete the installation.

Configure User Account Security

Create a User Account

Many users log in as 'Administrators' for every computer session. While administrative privileges are necessary for software installation, viruses and trojans are most harmful when entering via an Administrator Account. We recommend that you always log in with a User Account for everyday use. To create a User Account:

  1. Go to Start > Settings > Control Panel > User Accounts.
  2. On the Users tab, click Add.
  3. In the Add New User window:
    • In the User Name field, enter a name, then click Next.
    • For the level of access, select Standard User, then click Finish.
  4. The new user name should appear under Users for this computer on the User tab.
  5. Log out of the administrator account by hitting CTRL-ALT-DEL and selecting Log Off, then log back in as the new user.

To switch to the Administrator Account, use the Run as... feature:

  1. Press Shift and simultaneously right-click on any application icon.
  2. Select Run as... from the drop-down menu.
  3. In the Run as Other User window, enter your Administrator user name and password. Click OK.

Set up a password for the Administrator Account

Most hacked computers have either a poor password or none at all on the Administrator Account. To create a password for your Administrator Account:

Windows 2000

  1. Go to Start > Settings > Control Panel > Users & Passwords.
  2. On the Users tab, under Password for Administrator, click on Set Password...
  3. Enter your password twice, then click OK.

Windows XP

  1. On the User accounts window, click Change an account.
  2. In the Pick an account to change window, click Administrator.
  3. In the What do you want to change about your account? window, click create a password.
  4. In the Create a password for your account window, in the Type a new password: field, enter the password of your choice.
  5. Re-enter the password in the Type the new password again to confirm: field.
  6. Enter a hint in the Type a word or phrase to use as a password hint: field in case you forget your password.
  7. Click Create Password.

Disable Guest Account

Intended for temporary users, Guest Accounts are an easy point of entry for hackers. We recommend that you permanently disable them.

  1. Go to Start > Settings > Control Panel > Users & Passwords.
  2. In the Users & Passwords window, select the Advanced tab.
  3. In the Advanced User Management section, click Advanced.
  4. In the Local Users & Groups window, select the Users folder (left panel). All system users will be listed in the right panel.
  5. Right-click Guest, then select Properties.
  6. In the Guest Properties window, select Account is disabled. Click Apply, then OK.

Require a user name & password for all users

Make sure everyone who uses your computer needs a user name and password to log in. To set up password requirements:

  1. Go to Start > Settings > Control Panel > Users & Passwords.
  2. In the Users & Passwords window, on the Users tab, select Users must enter a user name and password to use this computer.
  3. On the Users tab, under Users for this computer, check all accounts and make sure they all require a password.

Disable Remote Assistance (Win XP)

Remote Assistance is a Windows XP feature that allows remote access to your computer, commonly for troubleshooting purposes. To disable Remote Assistance and prevent others from taking control of your computer:

  1. Go to Start > Settings > Control Panel > System.
  2. On the System Properties window, select the Remote tab, then click Settings.
  3. Make sure Allow users to connect remotely to this computer is unselected. Click Apply, then OK.

Disable Unnecessary Applications

Disable Internet Information Services (IIS)

IIS is an application that allows your computer to become a server. Because IIS may threaten system security when you are online, we recommend that you de-activate it. To do so:

  1. Go to Start > Settings > Control Panel > Add/ Remove Programs.
  2. Click on Add/ Remove Windows Components.
  3. In the Windows Components Wizard window, make sure Internet Information Services is not selected. Click Next, then Finish.

Related Pages

Need Help?

If you encounter problems, submit an online Help Request.
- or -
Contact the OIT Help Desk at 545-9400.

Last revised December 20, 2007