UAC, hiding folders, creating a secure and safe Win 7 environment

CptSupermrkt

New member
Local time
7:08 AM
Messages
4
Hello there.

I've been a horrible home user of Windows for years --- my policy has consistently been to just be Administrator all day, every day, install random stuff, never uninstall anything, never question the origin of that questionable ".exe", etc...

So I formatted and am taking a new approach --- I will never log in as Administrator except to do administrative stuff like install software and upgrade drivers. I will use a Standard account for myself for everything else from playing games to organizing my music.

What I want to do, though, that I can't figure out, is basically lock my Standard user account down so it can't even possibly mistakenly do something administrative. I wish to be strict on myself, if for no other reason than to get me to stop working at 120 mph and THINK before I take an action that could potentially do more harm than good.

That being said, I basically figured out some basic functions of MMC and the idea of group policies. But I already found something that bothers me that I can't seem to fix:

As Administrator, I downloaded a program called CPU-Z to do some hardware stuff. I do not want this program to be visible to any Standard account in any way, period. Yet, when I log out, and log in as a Standard user, there it is, right in the Start Menu.

Using the group policy to specify programs that CAN'T be run, indeed I can "intercept" the attempt to run it from another account, but it shouldn't be visible from any other account, period.

Basically, I want my Standard accounts to see ABSOLUTELY NOTHING, except!!! for the programs and folders that I explicitly choose as Administrator. The other goal here is to create a completely clean and clutter free interface for myself and my average-user wife, so that when we log into our own accounts, we don't even have the chance to be confused, or accidentally click something, nothing should be visible, period, as a Standard user, unless I explicitly choose for it to be visible for that particular user.

I'm not interested in just "hiding" the folder/applications universally, or just removing them from the Start Menu universally, because I DO want everything to be visible from the Administrator account.
 

My Computer My Computer

At a glance

Windows 7 Ultimate x64
OS
Windows 7 Ultimate x64
Click the start orb and then right click on "All Programs". You should see Open and Open All Users.
"Open All Users" is the start menu everybody See's.
C:\ProgramData\Microsoft\Windows\Start Menu
"Open" is the start menu for that logged in user. For example mine is
C:\Users\Kerry\AppData\Roaming\Microsoft\Windows\Start Menu.
I do believe what is in there only shows up in the start menu when I'm logged on. You could try putting that app in C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Start Menu.
Even if you do that though anybody could still run it by finding its folder in explorer and running the exe file.
 

My Computer My Computer

At a glance

Windows 10 Education 64 bitAMD Phenom II X4 980 Black Edition Deneb 3.7GHz8GB 4GBx2 Kingston PC10600 DDR3 1333 MemoryZotac NVIDIA Geforce GT640 2 Gig DDR3 PCIe
Computer type
PC/Desktop
Computer Manufacturer/Model Number
Home Built
OS
Windows 10 Education 64 bit
CPU
AMD Phenom II X4 980 Black Edition Deneb 3.7GHz
Motherboard
Asus M4N68T-M V2 µATX Motherboard
Memory
8GB 4GBx2 Kingston PC10600 DDR3 1333 Memory
Graphics Card(s)
Zotac NVIDIA Geforce GT640 2 Gig DDR3 PCIe
Sound Card
VIA VT1708s High Definition Audio 8-channel Onboard
Monitor(s) Displays
22" LG E2242 1080p and 2 19" I-INC AG191D
Screen Resolution
1280x1024 - 1920x1080 - 1280x1024
Hard Drives
Crucial M100 256 GB SSD and 500 GB WD Blue SATA
PSU
Thermaltake TR 620
Case
Power Up Black ATX Mid-Tower Case
Cooling
Stock heatsink and fan
Keyboard
Logitech Wireless K350 Wave
Mouse
Logitech Wireless M570 Trackman Wheel
Internet Speed
80 Mbps Down 30 Mbps Up
Antivirus
Windows Defender
Browser
Internet Explorer 11
Other Info
HP DVD1040e Lightscribe - External USB2
Welcome to Seven Forums CptSupermrkt.
Many program have two install options, Install for all users, and, Only for me. Try using the latter when installing from your Admin account.
CPUz would be fine for all users, it can't change anything, it is just a monitor and hardware viewing utility.
 

My Computer My Computer

At a glance

Windows 7 Ultimate X64 SP1Intel i5-2550K, Differing ~4.4-4.8GHz No buil...16GB G.Skill Sniper 1866MHz @ 2133MHz 2x8GBASUS GTX650TIB-DC2OC-2GD5, (650TI Boost)
Computer type
PC/Desktop
Computer Manufacturer/Model Number
Home Built Desktop By DataTech
OS
Windows 7 Ultimate X64 SP1
CPU
Intel i5-2550K, Differing ~4.4-4.8GHz No built in GPU
Motherboard
ASUS P8Z68-V PRO/GEN3
Memory
16GB G.Skill Sniper 1866MHz @ 2133MHz 2x8GB
Graphics Card(s)
ASUS GTX650TIB-DC2OC-2GD5, (650TI Boost)
Sound Card
Onboard Realtek 5-1
Monitor(s) Displays
Samsung P2570HD
Screen Resolution
1920x1080
Hard Drives
Samsung 840 Pro 256GB SSD for OS, 500GB Seagate Constellation (Enterprise drive) for Data
PSU
Corsair HX650W
Case
Inwin Dragon Rider
Cooling
Hyper 212 EVO w/two Noctua fans, push-pull, @1300 RPM
Keyboard
E-Z Eyes, bright yellow keys with large characters
Mouse
steelseries SENSEI Laser Pro Gaming
Internet Speed
48-51Mbs Mbs down, 11 Mbs up Xfinity Cable
Antivirus
Norton Internet Security 2013
Browser
IE 10, Opera, Pale Moon if needed
Other Info
4 case fans, LG BluRay-RE, ASUS DVD-RW, Mr. Fusion power supply, 1.21 gigawatts.
Adjust Permissions?

As alphnumeric says, you can move the shortcuts to the Administrator's Start Menu.

You could set the "Hidden" attribute on the specific program folder (e.g. CPU-Z) to stop casual browsing.

:eek: Make a backup image before trying the options listed below. :eek:
You could also adjust the permissions (folder "Properties" window > "Security" tab) on the specific program folder (e.g. CPU-Z) so that "Administrator"/"Administrators" is the only User/Group with rights (i.e. you could remove "Authenticated Users" and "Users" from the list or restrict/remove their rights).

Do not remove "System" or "Trusted Installer" from that list.

If you are unfamiliar with adjusting permissions (this can be tricky) you could easily make a critical system-destroying error (hence the absolute necessity for a backup image).

If you have a viable backup image (two would be better) you can afford to experiment. :)

 

My Computer My Computer

At a glance

W7 Ultimate SP1, LM19.2 MATE, W10 Home 1703, ...AMD Phenom II x6 1100T, 3.3 GHz12GB DDR3 1333 G-Skill (4GB x 2), G-Skill (2G...NVIDIA GeForce GTX 660
Computer type
PC/Desktop
Computer Manufacturer/Model Number
n/a
OS
W7 Ultimate SP1, LM19.2 MATE, W10 Home 1703, W10 Pro 1703 VM, #All 64 bit
CPU
AMD Phenom II x6 1100T, 3.3 GHz
Motherboard
ASUS M4A88T-M/USB3 (AM3)
Memory
12GB DDR3 1333 G-Skill (4GB x 2), G-Skill (2GB x 2)
Graphics Card(s)
NVIDIA GeForce GTX 660
Sound Card
Realtek?
Monitor(s) Displays
Samsung S23B350
Screen Resolution
1920x1080
Hard Drives
WD Green 2TB (SATA), WD Green 3TB (SATA), WD Blue 4TB (SATA), WD Blue 6TB (SATA)
PSU
Cooler Master
Case
Antec GX300 Tower
Cooling
3x Antec TRICOOL 120mm Fans
Mouse
Wired Optical
Internet Speed
DSL
Antivirus
Avast
Browser
Pale Moon (64 bit)
Other Info
2018-12-27 Upgraded HDDs
2015-12-10 Upgraded case, graphics card, storage
2015-08-15 Upgraded motherboard & RAM
2015-07-15 Upgraded LM17.1 to LM17.2
Every user can have their own start menu..
C:\Users\[USERNAME]\AppData\Roaming\Microsoft\Windows\Start Menu

Put the things you only want your administrator account to have in its start menu folder.
However, honestly if you are running under a standard user account you cannot mistakenly do something.
 

My Computer My Computer

At a glance

Windows 10 Pro (x64)Intel Core i7-3930K (3.2GHz - 4.5GHz)4x Samsung 4GB PC3-12800 DDR3 (16GB 1600MHz)Nvidia Geforce GTX 690
Computer type
PC/Desktop
Computer Manufacturer/Model Number
Alienware Aurora ALX R4
OS
Windows 10 Pro (x64)
CPU
Intel Core i7-3930K (3.2GHz - 4.5GHz)
Motherboard
Alienware Aurora-R4 x79
Memory
4x Samsung 4GB PC3-12800 DDR3 (16GB 1600MHz)
Graphics Card(s)
Nvidia Geforce GTX 690
Sound Card
SteelSeries Siberia Elite
Monitor(s) Displays
Dell UltraSharp U3011
Screen Resolution
2560x1600
Hard Drives
Samsung 850 Pro 256 GB, Seagate 1TB Desktop Hybrid HDD, 2x Western Digital 4TB Green HDD
PSU
875W Some Dell PSU <.<
Case
Alienware Aurora ALX
Cooling
Custom Liquid Cooling (EK CPU & GPU blocks) dual EK 480RAD
Keyboard
Logitech G710+ Mechanical
Mouse
Logitech G700s
Internet Speed
Verizon Fios (50 mbps average)
Other Info
Server: Intel NUC D54250WYK: i5-4250U, 16GB, 256 GB mSATA, Windows Server 2012 R2
Back
Top