Opinions vary on what's best for security settings, but this is what I'd recommend for ya:
Tools>Internet Options>Security - click ""Custom Level" -
Under ".NET Framework-reliant components";
Run components not signed with Authenticode - set to "Disable" for highest security, but less functionality, "Prompt" if you think it wise to make the choices yourself
Binary and script behaviors" - set to "Prompt"
Download unsigned ActiveX controls - set to "Prompt" or "Disable"
Initialize and script ActiveX controls not marked as safe - set to "Prompt" or "Disable"
Run ActiveX controls and plugins - set to "Prompt"
Under "Miscellaneous";
Access data across domains - set to "Prompt"
Allow web pages to use restricted protocols for active content - set to "Prompt"
Display mixed content - set to "Prompt"
Software channel permissions - sit to "High" for greatest security, "Mediun" for more functionality
Submit nonencrypted form data - set to "Prompt"
Use Pop-up blocker - set to "Enable" if its not already set
Websites in less privileged web content zone can navigate into this zone - set to "Prompt"
Under "Scripting"
Active scripting - set to "Prompt"
Everything else can be left at default setting - usually "Enable", Then go to the "Advanced" tab.
Under "Browsing", uncheck both instances of "Install On Demand". Under "Security", make sure everything
EXCEPT "Allow software to run or install even if signature is invalid" and "Do not save encrypted pages to disk" is checked. Click "OK", exit to your desktop, and reboot.
If you still have Microsoft's "Virtual Machine",
Uninstall it ,
then get
Sun Java
You'll get nagged some as you browse, but you'll be aware of and hafta think about what ya allow. There's some other stuff (like addin' specific known sites to your "Trusted" zone, settin' up exceptions for the way cookies from some sites are handled, and turnin' off some 3rd party auto updates), but that's plenty for now.
I'd also recommend anyone interested in computer privacy and security take a good look around
Eric Howes' excellent website