What do you mean by "bomb proof"? The suggestions you've got so far aren't bad. A normal "user" account that doesn't have administrative priveledges; set your windows update to automatic so you get patches; get and install an anti-virus program (AVG is great, but set it for daily updates, and I second the brickbat for Norton); get and install a hardware firewall (NetGear is my current fav); install an anti-spyware utility (I don't like MS' product, they've been slow to denounce bad behaviour from "partner" organizations); turn off windows file sharing; uninstall any Peer-to-Peer apps like kazaa or limewire; use a mail program other than outlook express (preferably one that doesn't render active content) ...
With those precautions, you're mostly "bomb proof". If you're adventurous, have a look at Windows "onecare" -- a peek at the next-gen MS service.
For more protection, consider unplugging from the net, or installing a linux OS, or go to greater lengths (like hiring someone) to harden your Windows OS.
|