If you must stay with Windows 7 then make sure Windows Updates are at least enabled, the root CA would normally come through that. If this doesn't fix the issue you would need to find out which root CA each website is using and manually update the certificates.