<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="http://forums.eeye.com/utility/FeedStylesheets/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/"><channel><title>Tips and Tricks</title><link>http://forums.eeye.com/forums/12.aspx</link><description>A collection of shortcuts, ways to optimize Blink, new rule configurations, or any other suggestions that let you use Blink to its fullest.</description><dc:language>en</dc:language><generator>CommunityServer 2007.1 SP1 (Build: 30415.43)</generator><item><title>downloading big update</title><link>http://forums.eeye.com/forums/thread/5019.aspx</link><pubDate>Sun, 25 Oct 2009 06:51:41 GMT</pubDate><guid isPermaLink="false">a21f7e33-d546-44ed-90ca-b1df844505d6:5019</guid><dc:creator>jaiamma</dc:creator><slash:comments>3</slash:comments><comments>http://forums.eeye.com/forums/thread/5019.aspx</comments><wfw:commentRss>http://forums.eeye.com/forums/commentrss.aspx?SectionID=12&amp;PostID=5019</wfw:commentRss><description>&lt;p&gt;Hi,&lt;/p&gt;
&lt;p&gt;I&amp;#39;ve got Blink Pro 4.4.2 with a current license. I&amp;#39;m overseas and the net connection here is very slow. I try to download the 55MB update using TOOLS - CHECK FOR UPDATES but the download always fails. Any other way to download this 55MB update for Blink Pro 4.4.2?&lt;/p&gt;
&lt;p&gt;Thanks,&lt;/p&gt;
&lt;p&gt;&lt;br /&gt;Tom&lt;/p&gt;</description></item><item><title>Useful Registry Protection Rules #1 - Run Key</title><link>http://forums.eeye.com/forums/thread/3066.aspx</link><pubDate>Wed, 13 Aug 2008 19:08:28 GMT</pubDate><guid isPermaLink="false">a21f7e33-d546-44ed-90ca-b1df844505d6:3066</guid><dc:creator>Blue1978</dc:creator><slash:comments>6</slash:comments><comments>http://forums.eeye.com/forums/thread/3066.aspx</comments><wfw:commentRss>http://forums.eeye.com/forums/commentrss.aspx?SectionID=12&amp;PostID=3066</wfw:commentRss><description>&lt;p&gt;&lt;b&gt;Here are 2 rules that are useful that I have created under the &amp;quot;Registry Protection&amp;quot; tab located in the &lt;span style="text-decoration:underline;"&gt;System Protection&lt;/span&gt; section.&lt;/b&gt;&lt;/p&gt;
&lt;p&gt;NOTE:&amp;nbsp; These rules do have a few minor setbacks if you choose to use them which I will explain later.&amp;nbsp; These setbacks are easily overcome though.&lt;/p&gt;
&lt;p&gt;Most of the Malware out there will attempt to create a registry key of its own that allows it to run itself at system startup.&amp;nbsp; Here are two rules that you can use to prevent this from happening.&amp;nbsp;&lt;/p&gt;
&lt;p&gt;Create rules with the following in the fields:&amp;nbsp;&lt;/p&gt;
&lt;p&gt;1. &amp;nbsp; Registry Key Tab -&lt;/p&gt;
&lt;p&gt;&lt;span style="text-decoration:underline;"&gt;Specifiy the Registry key that this rule will protect&lt;/span&gt;:&amp;nbsp;&amp;nbsp; &lt;b&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run&lt;/b&gt;&lt;/p&gt;
&lt;p&gt;Match Type: &lt;b&gt;Partial&lt;/b&gt;&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Caller Tab -&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;span style="text-decoration:underline;"&gt;Specify the call that this rule will filter against&lt;/span&gt;:&amp;nbsp; &lt;b&gt;*&lt;/b&gt;&lt;/p&gt;
&lt;p&gt;Match Type:&lt;b&gt;&amp;nbsp; Wildcard&lt;/b&gt;&lt;/p&gt;
&lt;p&gt;&amp;nbsp;Do not use the caller MD5 is selected&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Action Tab -&lt;/p&gt;
&lt;p&gt;&amp;nbsp;Write box is checked, Deny is selected, and the Log box is checked.&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;2.&amp;nbsp; Registry Key Tab -&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;span style="text-decoration:underline;"&gt;Specifiy the Registry key that this rule will protect&lt;/span&gt;:&amp;nbsp; &lt;b&gt;HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run&lt;/b&gt;&lt;/p&gt;
&lt;p&gt;Match Type: &lt;b&gt;Partial&lt;/b&gt;&lt;/p&gt;
&lt;p&gt;&amp;nbsp;Caller Tab -&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;span style="text-decoration:underline;"&gt;Specify the call that this rule will filter against&lt;/span&gt;:&amp;nbsp; &lt;b&gt;*&lt;/b&gt;&lt;/p&gt;
&lt;p&gt;Match Type:&lt;b&gt; Wildcard&lt;/b&gt;&lt;/p&gt;
&lt;p&gt;&amp;nbsp;Do not use the caller MD5 is selected&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Action Tab -&lt;/p&gt;
&lt;p&gt;&amp;nbsp;Write box is checked, Deny is selected, and the Log box is checked.&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;Rule Results:&lt;/p&gt;
&lt;p&gt;&lt;span style="text-decoration:underline;"&gt;&lt;b&gt;The PROS&lt;/b&gt;&lt;/span&gt;:&amp;nbsp; You will be notified, it will be logged, and the attempt will be blocked, anytime a program or malware attempts to create a registry key&lt;/p&gt;
&lt;p&gt;in the two locations above.&amp;nbsp; This will keep most anything from starting itself with your system each time that you did not allow in the first place. &lt;/p&gt;
&lt;p&gt;&lt;b&gt;&lt;span style="text-decoration:underline;"&gt;The CONS&lt;/span&gt;&lt;/b&gt;:&amp;nbsp; &lt;/p&gt;
&lt;p&gt;- If you install a program that you want to start each time when your system starts, then temporarily disable these rules before you begin the installation process.&lt;/p&gt;
&lt;p&gt;- You may also want to disable these&amp;nbsp;rules too when your uninstalling a program that you want to&amp;nbsp;remove.&amp;nbsp; I have noticed instances of the program trying to remove the registry keys in placed in these locations during the&amp;nbsp;uninstall process.&lt;/p&gt;
&lt;p&gt;I have learned both of these the hard way by myself. :)&lt;/p&gt;
&lt;p&gt;- &lt;b&gt;WHEN&lt;/b&gt; your doing Microsoft Update or installing a program (that you want to start with your system each time you log on), you will need to temporarily disable these rules to accomodate these situations.&lt;/p&gt;
&lt;p&gt;&amp;nbsp;------------------------------------------------------------------------------&lt;/p&gt;</description></item><item><title>Recommended Custom IPS Signatures</title><link>http://forums.eeye.com/forums/thread/3945.aspx</link><pubDate>Thu, 05 Feb 2009 22:15:28 GMT</pubDate><guid isPermaLink="false">a21f7e33-d546-44ed-90ca-b1df844505d6:3945</guid><dc:creator>Blue1978</dc:creator><slash:comments>4</slash:comments><comments>http://forums.eeye.com/forums/thread/3945.aspx</comments><wfw:commentRss>http://forums.eeye.com/forums/commentrss.aspx?SectionID=12&amp;PostID=3945</wfw:commentRss><description>&lt;p&gt;&lt;span style="text-decoration:underline;"&gt;&lt;b&gt;I have created this forum post for anyone that wishes to post any useful Intrustion Prevention Signatures that they may have added to Blink that might benefit others.&lt;/b&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Here is one rule I have created myself (that I add to periodically) that has the purpose of blocking my system from making any contact with particular domains that are known for tracking users and for delivering flash banners ads which lead to a lot of the malware deliering sites out there.&lt;br /&gt;&lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Under the &amp;quot;Website Blocking&amp;quot; section of the IPS Signatures tab, I made a duplicate of the MySpace Web Request signature and then renamed it to &amp;quot;Additional Web Requests&amp;quot;.&amp;nbsp; I then deleted Myspace.com out from under the Search Pattern section of the rule.&amp;nbsp; I then added in the followng terms:&lt;br /&gt;&lt;br /&gt;&lt;b&gt;.doubleclick.&lt;/b&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;.fastclick.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;.yieldmanager.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;.atdmt. &lt;br /&gt;&lt;br /&gt;.ad.&lt;br /&gt;&lt;br /&gt;&lt;/strong&gt;&lt;strong&gt;.webtrends.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;.webtrendslive.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;.google-analytics.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;.googlesyndication.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;.quantserve.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;.2mdn.net&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;br /&gt;- none of the boxes at the bottom (of each of these entries) were checked.&lt;br /&gt;&lt;br /&gt;&amp;nbsp;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-size:medium;"&gt;(&lt;b&gt;LAST UPDATED&lt;/b&gt;:&amp;nbsp; 08OCT09)&lt;/span&gt;&lt;br /&gt;&lt;/p&gt;</description></item><item><title>How to Create a Memory Dump File for a Blink Kevlar Alert</title><link>http://forums.eeye.com/forums/thread/4797.aspx</link><pubDate>Sat, 05 Sep 2009 13:32:04 GMT</pubDate><guid isPermaLink="false">a21f7e33-d546-44ed-90ca-b1df844505d6:4797</guid><dc:creator>Blue1978</dc:creator><slash:comments>1</slash:comments><comments>http://forums.eeye.com/forums/thread/4797.aspx</comments><wfw:commentRss>http://forums.eeye.com/forums/commentrss.aspx?SectionID=12&amp;PostID=4797</wfw:commentRss><description>&lt;p&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Recently with the release of Blink version 4.4.1, eEye has incorporated a very useful function that creates a&amp;nbsp;memory dump file when anything sets off Blink&amp;#39;s Application Protection Engine (aka &amp;quot;Kevlar&amp;quot;).&amp;nbsp; This is useful, because these&amp;nbsp;dump files can be sent to eEye to be examined allowing them to determine if an alert was a false-positive or an actual attack that was stopped.&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; To give you an example:&lt;/p&gt;
&lt;p&gt;Recently, when I try to play a DVD movie&amp;nbsp;in Windows Media Player, Blink will halt Windows Media Player and show me the following Kevlar alert:&lt;/p&gt;
&lt;p&gt;Event ID:&amp;nbsp; BLINK-APP-100&amp;nbsp; &lt;br /&gt;&amp;nbsp;Severity:&amp;nbsp; High&amp;nbsp; &lt;br /&gt;&amp;nbsp;Description:&amp;nbsp; Blink detected a suspicious system call.&amp;nbsp; &lt;br /&gt;&amp;nbsp;Alert: Yes &lt;br /&gt;&amp;nbsp;Application: C:\Program Files (x86)\Windows Media Player\wmplayer.exe &lt;br /&gt;&amp;nbsp;Reason: KERNEL32.DLL!GetModuleHandleA &lt;br /&gt;&amp;nbsp;Action: Restart process &lt;br /&gt;&amp;nbsp;Application Arguments: &amp;quot;C:\Program Files (x86)\Windows Media Player\wmplayer.exe&amp;quot; /prefetch:1 &lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;Well, to eEye this is not enough information to determine whether or not this is something malicious, or a piece of code that when it runs (looks malcious to Blink, but is not) upon the attempt to run a video file.&amp;nbsp; I know this particular alert is not malicious.&amp;nbsp; In my attempt to troubleshoot, eEye advised me of a simple registry key that you import into your system, that forces Blink to create a memory dump anytime Kevlar alerts on something.&amp;nbsp; Once you have imported this registry key, a Kevlar alert will now show the following:&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;Event ID:&amp;nbsp; BLINK-APP-100&amp;nbsp; &lt;br /&gt;&amp;nbsp;Severity:&amp;nbsp; High&amp;nbsp; &lt;br /&gt;&amp;nbsp;Description:&amp;nbsp; Blink detected a suspicious system call.&amp;nbsp; &lt;br /&gt;&amp;nbsp;Alert: Yes &lt;br /&gt;&amp;nbsp;Application: C:\Program Files (x86)\Windows Media Player\wmplayer.exe &lt;br /&gt;&amp;nbsp;Reason: KERNEL32.DLL!GetModuleHandleA &lt;br /&gt;&amp;nbsp;Action: Restart process &lt;br /&gt;&amp;nbsp;Application Arguments: &amp;quot;C:\Program Files (x86)\Windows Media Player\wmplayer.exe&amp;quot; /prefetch:1 &lt;br /&gt;&amp;nbsp;&lt;strong&gt;Dump File: C:\Program Files (x86)\Windows Media Player\wmplayer.exe.dmp&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;NOTE&lt;/strong&gt;:&amp;nbsp; At the end of the alert, it now shows you the path where the dump file is located at so you can go and retrieve it.&lt;/p&gt;
&lt;p&gt;This particular dump file turned out to be a little over 300mbs in size.&lt;/p&gt;
&lt;p&gt;-----------------------------------------------------------------------------------------------------&lt;/p&gt;
&lt;p&gt;Now, if your interested in setting this up so your system will do the&amp;nbsp;same&amp;nbsp;(so you can submit these helpful files&amp;nbsp;to eEye) the following registry key must be imported to your system:&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;&lt;span style="text-decoration:underline;"&gt;For 32bit Operating Systems&lt;/span&gt;&lt;/strong&gt;:&lt;/p&gt;
&lt;p&gt;Windows Registry Editor Version 5.00&lt;/p&gt;
&lt;p&gt;[HKEY_LOCAL_MACHINE\SOFTWARE\eEye\Blink]&lt;br /&gt;&amp;quot;CreateDumps&amp;quot;=dword:00000001&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;&lt;span style="text-decoration:underline;"&gt;For 64bit Operating Systems&lt;/span&gt;&lt;/strong&gt;:&lt;/p&gt;
&lt;p&gt;Windows Registry Editor Version 5.00&lt;/p&gt;
&lt;p&gt;[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\eEye\Blink]&lt;br /&gt;&amp;quot;CreateDumps&amp;quot;=dword:00000001&lt;/p&gt;
&lt;p&gt;-----------------------------------------------------------------------------------------------------&lt;/p&gt;
&lt;p&gt;To create the key, copy the text above (which ever applies to your type of system) and paste it into notepad.&amp;nbsp; Finally, name it&amp;nbsp;anything you want, but change the file extension to;&amp;nbsp;&amp;nbsp; &lt;strong&gt;.reg&amp;nbsp; &lt;/strong&gt;when you go to save it.&amp;nbsp; To import it to your system, simply double left click on it as if you were attempting to run an executable (.exe) file.&amp;nbsp; It will prompt and ask if you want to add it to your system and so forth.&lt;/p&gt;
&lt;p&gt;I have also uploaded both registry keys (for both 32bit and 64bit systems) in a zip file named &amp;quot;KevlarDumps.zip&amp;quot; to this post for anyone that does not know how to complete the above process that I have explained.&amp;nbsp; They can simply download the zip file and use the one that fits your needs and you should be good!&lt;/p&gt;
&lt;p&gt;Finally, I am not sure how eEye would like these files to be sent to them (since they usually end up being too large for email),&amp;nbsp; but you can email &lt;a href="mailto:lnicula@eeye.com"&gt;lnicula@eeye.com&lt;/a&gt; OR &lt;a href="mailto:bpatten@eeye.com"&gt;bpatten@eeye.com&lt;/a&gt; and ask them for further instructions on what to do if you happen to gather some of these dump files for alerts that you feel are false-positives.&amp;nbsp; Always be sure to include information on what Operating System your using, etc when you email them.&lt;/p&gt;</description></item><item><title>eEye Auto-Update Feature</title><link>http://forums.eeye.com/forums/thread/4525.aspx</link><pubDate>Fri, 17 Jul 2009 00:14:41 GMT</pubDate><guid isPermaLink="false">a21f7e33-d546-44ed-90ca-b1df844505d6:4525</guid><dc:creator>Blue1978</dc:creator><slash:comments>1</slash:comments><comments>http://forums.eeye.com/forums/thread/4525.aspx</comments><wfw:commentRss>http://forums.eeye.com/forums/commentrss.aspx?SectionID=12&amp;PostID=4525</wfw:commentRss><description>&lt;p&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Here is an interesting feature that has existed in Blink.&amp;nbsp; For anyone that did not know, AFTER you do an manual update of Blink and it completes, you are left with the &amp;quot;Update Summary&amp;quot; window showing the final status of the updates.&amp;nbsp; If you select one of them and then click on the Details button in the lower right of the screen, you will see information regarding what the update included in it.&amp;nbsp; Not a lot is shown for the Antivirus Engine when it updates, but if you receive an update for the Blink portion, the output is quite interesting.&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; After doing an manual update on my Blink Server Edition, I noted the following bit of information for the Blink module after clicking on the Details button:&lt;/p&gt;
&lt;p&gt;--------------------------------------------------------------------------------------------------&lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;nbsp;&amp;nbsp;&amp;nbsp; RELEASE NOTES FOR APPLICATION: BlinkServer VERSION: 4.3.2 &lt;br /&gt;--------------------------------------------------------------------------------------------------&lt;br /&gt;&lt;br /&gt;SECTION: Rules&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;nbsp;&amp;nbsp;&amp;nbsp; VERSION: 1533&lt;br /&gt;&lt;br /&gt;--------------------------------------------------------------------------------------------------&lt;br /&gt;Removed a false positive.&lt;br /&gt;&lt;br /&gt;SECTION: Audits&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;nbsp;&amp;nbsp;&amp;nbsp; VERSION: 2108&lt;br /&gt;&lt;br /&gt;--------------------------------------------------------------------------------------------------&lt;br /&gt;add&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 9070 - Mozilla Firefox 3.5.0 Multiple Vulnerabilities (Zero-Day) - Windows&lt;br /&gt;add&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 9071 - Mozilla Firefox 3.5.0 Multiple Vulnerabilities (Zero-Day) - UNIX/Linux&lt;br /&gt;add&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 9072 - Mozilla Firefox 3.5.0 Multiple Vulnerabilities (Zero-Day) - Mac OS X&lt;br /&gt;add&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 9073 - Sun Java JDK/JRE XML Signature HMAC Truncation Bypass (Zero-Day) - Windows&lt;br /&gt;add&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 9074 - Sun Java JDK/JRE XML Signature HMAC Truncation Bypass (Zero-Day) - Linux&lt;br /&gt;add&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 9075 - Sun Java JDK/JRE XML Signature HMAC Truncation Bypass (Zero-Day) - Solaris&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;I have noticed a lot of times you will find out about new Zero Days (that you did not know existed) from eEye.&amp;nbsp; Pretty neat simple trick.&amp;nbsp; Keep in mind though, you must do this right after you update Blink.&amp;nbsp; If you close the window and come back in again and attempt to use the Details button, nothing will be available to look at anymore.&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;</description></item><item><title>Tips for Un-installing/Re-installing Blink Successfully</title><link>http://forums.eeye.com/forums/thread/3203.aspx</link><pubDate>Fri, 12 Sep 2008 01:30:53 GMT</pubDate><guid isPermaLink="false">a21f7e33-d546-44ed-90ca-b1df844505d6:3203</guid><dc:creator>Blue1978</dc:creator><slash:comments>2</slash:comments><comments>http://forums.eeye.com/forums/thread/3203.aspx</comments><wfw:commentRss>http://forums.eeye.com/forums/commentrss.aspx?SectionID=12&amp;PostID=3203</wfw:commentRss><description>&lt;p&gt;&lt;span style="font-size:small;"&gt;&lt;span style="text-decoration:underline;"&gt;&lt;b&gt;If you currently have Blink installed on your system and you want to remove it completely from your system and install it fresh from scratch please read below&lt;/b&gt;&lt;/span&gt;&lt;/span&gt;: &lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Blink can be picky at times and it will sometimes give you problems if you do not completely remove its old registry keys and program files folder before attempting to install it again.&amp;nbsp; Here is what I would recommend doing to avoid such difficulties to begin with.&amp;nbsp; &lt;/p&gt;
&lt;p&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; I have had problems in the past with a lot of the programs out there that claim to clean your registry.&amp;nbsp; Some either seem to corupt things when you use them or cause other problems you notice later.&amp;nbsp; I have found one program that does work and that I can vouch for that I use on a regular basis.&amp;nbsp; It is called &lt;b&gt;Ccleaner&lt;/b&gt;.&amp;nbsp; It is free program and is kept updated regularly (so check for updates from time to time).&amp;nbsp; It can be found here (I took you straight to its download link instead): &lt;/p&gt;
&lt;p&gt;&lt;a target="_blank" href="http://www.filehippo.com/download_ccleaner/" title="Ccleaner"&gt;http://www.filehippo.com/download_ccleaner/&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;Its actual website is: &lt;a target="_blank" href="http://www.ccleaner.com/" title="Ccleaner"&gt;http://www.ccleaner.com/&lt;/a&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;1. First install this program.&amp;nbsp; I will go over a basic setup of the program now with you for the heck of it.&lt;/p&gt;
&lt;p&gt;Here is what I have set in the program for my choices.&lt;/p&gt;
&lt;p&gt;On the main window of the CCleaner program you will see 2 tabs: Windows and Applications.&amp;nbsp;&amp;nbsp; Applications is the items it detects that are installed on your system and what it senses it can clean from these programs (if anything).&amp;nbsp; Under the Windows Tab I have everything checked (except the wipe free space function at the very bottom).&amp;nbsp; If you care about how things are grouped in your start menu area (where the Windows Update shortcut is) uncheck the &amp;quot;Start Menu Shortcuts&amp;quot; choice under the System Section.&amp;nbsp; If you go to the Options section (on the left side) select Settings.&amp;nbsp; I have everything unchecked under that section and at the bottom I have the NSA overwrite method for when it destroys and deletes things.&amp;nbsp; The include area of this section is where you can include extra folders and things you wanted deleted (if you wish).&amp;nbsp; Under the Advanced portion of the Options section I have only one thing checked, it is the Hide warning messages.&lt;/p&gt;
&lt;p&gt;2.&amp;nbsp; Go to the Tools section of this program.&amp;nbsp; Select the Startup option.&amp;nbsp; Select Blink&amp;#39;s startup item and delete it. (This takes Blink&amp;#39;s startup registry key and deletes it keeping Blink from starting the next time you reboot your system).&amp;nbsp; &lt;/p&gt;
&lt;p&gt;3. Set what you want in this section and then restart your system.&amp;nbsp; Blink should not restart with your system now and you should be able to uninstall it completely this way.&lt;/p&gt;
&lt;p&gt;4.&amp;nbsp; Once your system is restarted, uninstall Blink from the &amp;quot;Add or Remove Programs&amp;quot; section in Windows Control Panel.&amp;nbsp; After you un-install Blink, restart your system again.&lt;/p&gt;
&lt;p&gt;5. After your reboot (after the un-install) run Ccleaner.&amp;nbsp; First select the &amp;quot;Cleaner&amp;quot; function button on the left and then click on the &amp;quot;Run Cleaner&amp;quot; button in the lower left and it will start its process.&amp;nbsp; After it is done, it will show you what it has removed.&lt;/p&gt;
&lt;p&gt;6. Next, select the Registry button on the left of Ccleaner&amp;#39;s main window.&amp;nbsp; Select Scan for issues at the bottom.&amp;nbsp; If it finds anything, allow it to fix them.&amp;nbsp; Keep doing this until it does not show anything after you select the &amp;quot;scan for issues&amp;quot; button.&lt;/p&gt;
&lt;p&gt;7. Next go to your C:\Program Files folder (for Windows XP) or C:\Program Files (x86) (for Windows Vista) and make sure the &amp;quot;eEye Digital Security&amp;quot; folder is not there.&amp;nbsp; Also check under the C:\Program Files\Common Files and see if anything is left related to eEye or Blink.&amp;nbsp; If anything is found in any of these folders, delete it, and then rerun your Ccleaner&amp;#39;s &amp;quot;Cleaner&amp;quot; and &amp;quot;Registry&amp;quot; cleaners one more time after your done (sometimes it will find more items that are no longer needed that were associated with that file folder you just deleted).&lt;/p&gt;
&lt;p&gt;8. Download the latest version of Blink.&amp;nbsp; Before you install Blink, I would recommend going into CCleaner and then to the &amp;quot;Tools&amp;quot; section on the left side, and then to the Startup section.&amp;nbsp; Temporarily disable anything from starting with your system by selecting the item and then clicking on the Disable button at the bottom of CCleaner&amp;#39;s window.&lt;/p&gt;
&lt;p&gt;9. After you are done installing Blink, I would recommend restarting your system again (after you go back into the Startup Tab, under &amp;quot;msconfig&amp;quot; again, &amp;nbsp;and re-enable everything that was checked before.&amp;nbsp; After your system reboots itself, run CCleaner one last time to tidy up any loose ends that it may find.&lt;/p&gt;
&lt;p&gt;10.&amp;nbsp;In CCleaner, make sure you have re-enabled any programs that you wish to start with your system once again and reboot your system to ensure they start properly.&lt;/p&gt;
&lt;p&gt;To download the current version of Blink Personal Edition (free for one year) go to this page:&amp;nbsp; &lt;a target="_blank" href="http://free-antivirus.eeye.com/" title="Blink Personal Edition" class="null"&gt;http://free-antivirus.eeye.com/&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;</description></item><item><title>Blink command-line</title><link>http://forums.eeye.com/forums/thread/4514.aspx</link><pubDate>Wed, 15 Jul 2009 16:52:38 GMT</pubDate><guid isPermaLink="false">a21f7e33-d546-44ed-90ca-b1df844505d6:4514</guid><dc:creator>masvmasv</dc:creator><slash:comments>1</slash:comments><comments>http://forums.eeye.com/forums/thread/4514.aspx</comments><wfw:commentRss>http://forums.eeye.com/forums/commentrss.aspx?SectionID=12&amp;PostID=4514</wfw:commentRss><description>&lt;p&gt;Hi!&lt;/p&gt;
&lt;p&gt;I&amp;#39;m working &amp;nbsp;in a project and I want use Blink anvitirus in a command-line.&lt;/p&gt;
&lt;p&gt;Blink have command-line support ?&lt;/p&gt;
&lt;p&gt;I need scan a specific path and make .log file, like:&lt;/p&gt;
&lt;p&gt;BlinkAVScan.exe c:\windows /report:c:\blink.log&lt;/p&gt;
&lt;p&gt;Thank you&lt;/p&gt;</description></item><item><title>Which Version of Blink Should I Buy?</title><link>http://forums.eeye.com/forums/thread/4446.aspx</link><pubDate>Sat, 27 Jun 2009 03:22:32 GMT</pubDate><guid isPermaLink="false">a21f7e33-d546-44ed-90ca-b1df844505d6:4446</guid><dc:creator>Winifred</dc:creator><slash:comments>13</slash:comments><comments>http://forums.eeye.com/forums/thread/4446.aspx</comments><wfw:commentRss>http://forums.eeye.com/forums/commentrss.aspx?SectionID=12&amp;PostID=4446</wfw:commentRss><description>&lt;p&gt;Hi, all.&amp;nbsp; I am doing a bit of research before buying Blink.&amp;nbsp; I&amp;#39;ve been using the free version and my time is nearly up.&amp;nbsp; Any suggestions, anyone?&amp;nbsp; I&amp;#39;m a single user (not a business, etc.) if that matters.&amp;nbsp; Thanks!&lt;/p&gt;</description></item><item><title>"Security/Privacy" Related Programs That Work Well With Blink</title><link>http://forums.eeye.com/forums/thread/3476.aspx</link><pubDate>Thu, 30 Oct 2008 21:53:51 GMT</pubDate><guid isPermaLink="false">a21f7e33-d546-44ed-90ca-b1df844505d6:3476</guid><dc:creator>Blue1978</dc:creator><slash:comments>4</slash:comments><comments>http://forums.eeye.com/forums/thread/3476.aspx</comments><wfw:commentRss>http://forums.eeye.com/forums/commentrss.aspx?SectionID=12&amp;PostID=3476</wfw:commentRss><description>&lt;p&gt;&lt;b&gt;&lt;span style="text-decoration:underline;"&gt;After personally trying and testing numerous programs (Security or Privacy related) I have found that the following programs behave well when ran with either the&amp;nbsp;Blink Personal or&amp;nbsp;Professional Editions of Blink.&amp;nbsp; Little to no changes were required to make these programs function.&amp;nbsp; IF any changes were required to be made, I have made note of them.&amp;nbsp; &lt;/span&gt;&lt;/b&gt;&lt;/p&gt;
&lt;p&gt;&lt;b&gt;&lt;span style="text-decoration:underline;"&gt;I have used these on Windows XP Professional SP3&lt;/span&gt;&lt;/b&gt;&lt;/p&gt;
&lt;p&gt;&lt;b&gt;&lt;span style="text-decoration:underline;"&gt;&lt;/span&gt;&lt;/b&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;&lt;span style="text-decoration:underline;"&gt;Virtual Machine Related Applications Tried:&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;1.&amp;nbsp; VMWare Workstation&amp;nbsp;- &lt;a target="_blank" href="http://vmware.com/products/ws/" title="VMWare"&gt;http://vmware.com/products/ws/&lt;/a&gt;&amp;nbsp;&amp;nbsp; &lt;/p&gt;
&lt;p&gt;2.&amp;nbsp; VirtualBox - &lt;a target="_blank" href="http://www.virtualbox.org/" title="Virtualbox"&gt;http://www.virtualbox.org/&lt;/a&gt;&amp;nbsp;&amp;nbsp; (Completely Free)&lt;/p&gt;
&lt;p&gt;3.&amp;nbsp; Parallels - &lt;a target="_blank" href="http://www.parallels.com/" title="Parallels"&gt;http://www.parallels.com/&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;&lt;span style="text-decoration:underline;"&gt;Security Related Applications Tried:&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;- These items work great alongside Blink as standalone scanners (i.e. you start them up to scan your system and then shut them down when your done)&lt;/p&gt;
&lt;p&gt;1.&amp;nbsp; Prevx CSI - &lt;a target="_blank" href="http://www.prevx.com/freescan.asp" title="Prevx CSI"&gt;http://www.prevx.com/freescan.asp&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;2.&amp;nbsp; SuperAntispyware Free Edition - &lt;a target="_blank" href="http://www.superantispyware.com/download.html" title="SuperAntispyware"&gt;http://www.superantispyware.com/download.html&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;3.&amp;nbsp; ClamWin Portable - &lt;a target="_blank" href="http://portableapps.com/apps/utilities/clamwin_portable" title="ClamWin Portable"&gt;http://portableapps.com/apps/utilities/clamwin_portable&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;- This is nice because you can either run it from a USB flashdrive or you can move the single folder that it runs from somewhere else (like on another partition of your hard drive as I have done)&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;&lt;a target="_blank" href="http://www.prevx.com/freescan.asp" title="Prevx CSI"&gt;&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="text-decoration:underline;"&gt;Privacy Related &amp;quot;Cleaning&amp;quot; Applications Tried:&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;1.&amp;nbsp; CCleaner - &lt;a target="_blank" href="http://www.ccleaner.com/" title="CCleaner"&gt;http://www.ccleaner.com/&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;</description></item><item><title>How to Properly Lock Down Windows XP Professional</title><link>http://forums.eeye.com/forums/thread/4007.aspx</link><pubDate>Mon, 23 Feb 2009 20:39:57 GMT</pubDate><guid isPermaLink="false">a21f7e33-d546-44ed-90ca-b1df844505d6:4007</guid><dc:creator>Blue1978</dc:creator><slash:comments>0</slash:comments><comments>http://forums.eeye.com/forums/thread/4007.aspx</comments><wfw:commentRss>http://forums.eeye.com/forums/commentrss.aspx?SectionID=12&amp;PostID=4007</wfw:commentRss><description>&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p class="MsoNormal" style="line-height:normal;"&gt;&lt;b&gt;&lt;span style="font-size:12pt;font-family:&amp;#39;Courier New&amp;#39;;"&gt;This is a brief description of how to configure Windows XP Professional, which if completed properly, will increase your online security dramatically.&amp;nbsp; The following setup will work for about 95% of the folks out there&lt;/span&gt;&lt;/b&gt;&lt;span style="font-size:12pt;font-family:&amp;#39;Courier New&amp;#39;;"&gt;.&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal" style="line-height:normal;"&gt;&lt;span style="font-size:12pt;font-family:&amp;#39;Courier New&amp;#39;;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; IF you choose to go through with this setup and configuration, it is at your own risk.&amp;nbsp; I will however attempt to provide you with as many pointers as I can to make it go as smoothly as possible.&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal" style="line-height:normal;"&gt;&lt;span style="font-size:12pt;font-family:&amp;#39;Courier New&amp;#39;;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; First off, before you continue with all of this, I recommend you do three things.&amp;nbsp; 1.&amp;nbsp; If you don&amp;#39;t already have one, buy yourself an external hard drive (at least 100GB in size).&amp;nbsp; 2.&amp;nbsp; Find yourself an easy to use backup program that will allow you to image your system&amp;#39;s hard drive and will easily enable you to save the images you create to the external hard drive you have.&amp;nbsp; I personally use and recommend the program Acronis True Image Home 2009 for imaging my system.&amp;nbsp; You can though; use whatever works best for you.&amp;nbsp; The point of this is, once you are able to make images of your system, you will no longer have to go through all of the heartache and pain that I am about to briefly take you through ever again.&amp;nbsp; You will simply restore your system from an image you made with your backup program.&amp;nbsp; It will make it a snap to recover from a system crash and or any other security related reason you may encounter.&amp;nbsp; 3.&amp;nbsp; Make sure you have ALL of the drivers for your computer system and any other devices you wish to install before you continue!&amp;nbsp; Save ANYTHING that is important to you that currently resides on your computer system to a folder, on the external hard drive that I was speaking of earlier, so you can access it later.&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal" style="line-height:normal;"&gt;&lt;span style="font-size:12pt;font-family:&amp;#39;Courier New&amp;#39;;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Throughout this post, I will refer to clicking on a particular button or I will explain where to navigate to a location in Windows.&amp;nbsp; This will be partially explain by using &amp;quot;&amp;gt;&amp;gt;&amp;quot; between the button (and or location/link) that you need to interface with.&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal" style="line-height:normal;"&gt;&lt;span style="font-size:12pt;font-family:&amp;#39;Courier New&amp;#39;;"&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal" style="line-height:normal;"&gt;&lt;span style="text-decoration:underline;"&gt;&lt;span style="font-size:12pt;font-family:&amp;#39;Courier New&amp;#39;;"&gt;Complete the following steps&lt;/span&gt;&lt;/span&gt;&lt;span style="font-size:12pt;font-family:&amp;#39;Courier New&amp;#39;;"&gt;:&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal" style="line-height:normal;"&gt;&lt;b&gt;&lt;span style="font-size:12pt;font-family:&amp;#39;Courier New&amp;#39;;"&gt;PRE-INSTALLTION NOTE&lt;/span&gt;&lt;/b&gt;&lt;span style="font-size:12pt;font-family:&amp;#39;Courier New&amp;#39;;"&gt;:&amp;nbsp; Make sure you do not have ANY devices attached to your system before installing Windows XP (unless you need a floppy disk drive or something to install RAID drivers for example).&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal" style="line-height:normal;"&gt;&lt;span style="font-size:12pt;font-family:&amp;#39;Courier New&amp;#39;;"&gt;1.&amp;nbsp; Boot your system from your Windows XP Professional disk.&amp;nbsp; When it comes to the part about installing XP, I would first recommend DELETING the existing partition on your hard drive and creating a new one.&amp;nbsp; Me Personally, I would create a partition no smaller than about 30GB (30000 MBs) or about half of your hard drive for Windows XP.&amp;nbsp; The reason for this is it makes it easier to image your computer when it comes time and the other partition you can later on create into a separate area on your computer (as a separate drive letter) for storing things that are isolated from your main OS file system.&amp;nbsp; Either way, you choose what you want to do.&amp;nbsp; Continue on with installing Windows XP.&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal" style="line-height:normal;"&gt;&lt;span style="font-size:12pt;font-family:&amp;#39;Courier New&amp;#39;;"&gt;2.&amp;nbsp; After you have finished installing Windows XP and it boots up to your desktop for the very first time STOP.&amp;nbsp; The account that you are currently logged on with is your user account, however, you have full administrative privileges with this account.&amp;nbsp; You don&amp;#39;t want this and currently you do not want to do anything else at the moment with this account.&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal" style="line-height:normal;"&gt;&lt;span style="font-size:12pt;font-family:&amp;#39;Courier New&amp;#39;;"&gt;- Make sure your system is not connected to the internet at this point.&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal" style="line-height:normal;"&gt;&lt;span style="font-size:12pt;font-family:&amp;#39;Courier New&amp;#39;;"&gt;- Any prompts to automatically install drivers for anything that Windows XP detects on your system, ignore at this point and simply CANCEL out of the prompts.&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal" style="line-height:normal;"&gt;&lt;span style="font-size:12pt;font-family:&amp;#39;Courier New&amp;#39;;"&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal" style="line-height:normal;"&gt;&lt;span style="text-decoration:underline;"&gt;&lt;span style="font-size:12pt;font-family:&amp;#39;Courier New&amp;#39;;"&gt;Continue the following steps&lt;/span&gt;&lt;/span&gt;&lt;span style="font-size:12pt;font-family:&amp;#39;Courier New&amp;#39;;"&gt;:&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal" style="line-height:normal;"&gt;&lt;span style="font-size:12pt;font-family:&amp;#39;Courier New&amp;#39;;"&gt;1.&amp;nbsp; Right Click on Start &amp;gt;&amp;gt; Properties Select the &amp;quot;Classic Start Menu&amp;quot;, Select Apply and then OK.&amp;nbsp; You should now see some more useful common icons on your desktop.&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal" style="line-height:normal;"&gt;&lt;span style="font-size:12pt;font-family:&amp;#39;Courier New&amp;#39;;"&gt;2.&amp;nbsp; Start &amp;gt;&amp;gt; Settings &amp;gt;&amp;gt; Control Panel &amp;gt;&amp;gt; User Accounts &amp;gt;&amp;gt; &amp;quot;Change the way users log on or off&amp;quot;.&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal" style="line-height:normal;"&gt;&lt;span style="font-size:12pt;font-family:&amp;#39;Courier New&amp;#39;;"&gt;- Make sure the two options are NOT checked under this page.&amp;nbsp; Select &amp;quot;Apply Options&amp;quot;.&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal" style="line-height:normal;"&gt;&lt;span style="font-size:12pt;font-family:&amp;#39;Courier New&amp;#39;;"&gt;3.&amp;nbsp; Close the &amp;quot;User Accounts&amp;quot; window.&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal" style="line-height:normal;"&gt;&lt;span style="font-size:12pt;font-family:&amp;#39;Courier New&amp;#39;;"&gt;4.&amp;nbsp; Restart your system.&amp;nbsp; You should not be prompted with what is known as the &amp;quot;Classic&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal" style="line-height:normal;"&gt;&lt;span style="font-size:12pt;font-family:&amp;#39;Courier New&amp;#39;;"&gt;Log On&amp;quot; screen which shows only a window with a Username and Password field.&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal" style="line-height:normal;"&gt;&lt;span style="font-size:12pt;font-family:&amp;#39;Courier New&amp;#39;;"&gt;5.&amp;nbsp; Enter &amp;quot;Administrator&amp;quot; in the username field and leave the Password field blank.&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal" style="line-height:normal;"&gt;&lt;span style="font-size:12pt;font-family:&amp;#39;Courier New&amp;#39;;"&gt;- Hit Enter to log on.&amp;nbsp; This is the built in Administrator account in Windows XP Professional.&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal" style="line-height:normal;"&gt;&lt;span style="font-size:12pt;font-family:&amp;#39;Courier New&amp;#39;;"&gt;-&amp;nbsp; From this point on, the majority of the configuration changes will be made from this account.&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal" style="line-height:normal;"&gt;&lt;span style="font-size:12pt;font-family:&amp;#39;Courier New&amp;#39;;"&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal" style="line-height:normal;"&gt;&lt;span style="text-decoration:underline;"&gt;&lt;span style="font-size:12pt;font-family:&amp;#39;Courier New&amp;#39;;"&gt;Complete the following steps from the Administrator account&lt;/span&gt;&lt;/span&gt;&lt;span style="font-size:12pt;font-family:&amp;#39;Courier New&amp;#39;;"&gt;:&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal" style="line-height:normal;"&gt;&lt;span style="font-size:12pt;font-family:&amp;#39;Courier New&amp;#39;;"&gt;1.&amp;nbsp; Right Click on Start &amp;gt;&amp;gt; Properties Select the &amp;quot;Classic Start Menu&amp;quot;, Select Apply and then OK.&amp;nbsp; You should now see some more useful common icons on your desktop.&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal" style="line-height:normal;"&gt;&lt;span style="font-size:12pt;font-family:&amp;#39;Courier New&amp;#39;;"&gt;2.&amp;nbsp; Start &amp;gt;&amp;gt; Settings &amp;gt;&amp;gt; Control Panel &amp;gt;&amp;gt; Performance and Maintenance.&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal" style="line-height:normal;"&gt;&lt;span style="font-size:12pt;font-family:&amp;#39;Courier New&amp;#39;;"&gt;- Under this menu, right click on the &amp;quot;Administrative Tools&amp;quot; at the bottom and select Create Shortcut.&amp;nbsp; Allow it to place the shortcut on your desktop.&amp;nbsp; This will give you a shortcut now to one of the most accessed areas in Windows XP as an Admin (other than Group Policy) that you will be using.&amp;nbsp; At this point, when I refer to &amp;quot;Administrative Tools&amp;quot; it will be going to it via this shortcut that was created.&amp;nbsp; You can name this shortcut anything that you want to.&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal" style="line-height:normal;"&gt;&lt;span style="font-size:12pt;font-family:&amp;#39;Courier New&amp;#39;;"&gt;3.&amp;nbsp; Administrative Tools &amp;gt;&amp;gt; Computer Management &amp;gt;&amp;gt; Local Users and Groups (on the left) &amp;gt;&amp;gt; double click Users folder (on the right).&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal" style="line-height:normal;"&gt;&lt;span style="font-size:12pt;font-family:&amp;#39;Courier New&amp;#39;;"&gt;- Right click and select delete for the following users in this section.&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal" style="line-height:normal;"&gt;&lt;span style="font-size:12pt;font-family:&amp;#39;Courier New&amp;#39;;"&gt;&amp;quot;HelpAssistant&amp;quot; and &amp;quot;SUPPORT_ ...&amp;quot;&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal" style="line-height:normal;"&gt;&lt;span style="font-size:12pt;font-family:&amp;#39;Courier New&amp;#39;;"&gt;- You should only have left the Administrator, Guest, and any other account names that you created when you installed Windows XP.&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal" style="line-height:normal;"&gt;&lt;span style="font-size:12pt;font-family:&amp;#39;Courier New&amp;#39;;"&gt;4.&amp;nbsp; Groups folder (on the left) &amp;gt;&amp;gt; double left click on Administrators (on the right).&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal" style="line-height:normal;"&gt;&lt;span style="font-size:12pt;font-family:&amp;#39;Courier New&amp;#39;;"&gt;- Delete out any names that are in here EXCEPT Administrator.&amp;nbsp; Select OK when you are done.&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal" style="line-height:normal;"&gt;&lt;span style="font-size:12pt;font-family:&amp;#39;Courier New&amp;#39;;"&gt;5.&amp;nbsp; Double left click Users (on the right side).&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal" style="line-height:normal;"&gt;&lt;span style="font-size:12pt;font-family:&amp;#39;Courier New&amp;#39;;"&gt;- Select Add.&amp;nbsp; In the bottom of this window add in the name(s) of the other account(s) and select OK.&amp;nbsp; Do this for any other accounts you have created.&amp;nbsp; This places these accounts in the normal User&amp;#39;s group.&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal" style="line-height:normal;"&gt;&lt;span style="font-size:12pt;font-family:&amp;#39;Courier New&amp;#39;;"&gt;- Click OK on the Users Properties window when you are done here.&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal" style="line-height:normal;"&gt;&lt;span style="font-size:12pt;font-family:&amp;#39;Courier New&amp;#39;;"&gt;6.&amp;nbsp; Right click Start &amp;gt;&amp;gt; Explore &amp;gt;&amp;gt; Tools (at the top) &amp;gt;&amp;gt; Folder Options &amp;gt;&amp;gt; View tab.&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal" style="line-height:normal;"&gt;&lt;span style="font-size:12pt;font-family:&amp;#39;Courier New&amp;#39;;"&gt;- Under this tab make sure ALL boxes under the &amp;quot;Files and Folder&amp;quot; section at the bottom except &amp;quot;Display the contents of system folders&amp;quot; are checked.&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal" style="line-height:normal;"&gt;&lt;span style="font-size:12pt;font-family:&amp;#39;Courier New&amp;#39;;"&gt;- Under Hidden files and folders make sure the &amp;quot;Show hidden files and folders&amp;quot; is selected.&amp;nbsp; The only other boxes below this that should be checked are:&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal" style="line-height:normal;"&gt;&lt;span style="font-size:12pt;font-family:&amp;#39;Courier New&amp;#39;;"&gt;&amp;quot;Hide protected operating system files (Recommended)&amp;quot;&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal" style="line-height:normal;"&gt;&lt;span style="font-size:12pt;font-family:&amp;#39;Courier New&amp;#39;;"&gt;&amp;quot;Remember each folder&amp;#39;s view settings&amp;quot;&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal" style="line-height:normal;"&gt;&lt;span style="font-size:12pt;font-family:&amp;#39;Courier New&amp;#39;;"&gt;&amp;quot;Show encrypted or compressed NTFS files in color&amp;quot;&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal" style="line-height:normal;"&gt;&lt;span style="font-size:12pt;font-family:&amp;#39;Courier New&amp;#39;;"&gt;&amp;quot;Show pop-up description for folder and desktop items&amp;quot;&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal" style="line-height:normal;"&gt;&lt;span style="font-size:12pt;font-family:&amp;#39;Courier New&amp;#39;;"&gt;- YES, uncheck the &amp;quot;Use simple file sharing (Recommended)&amp;quot;&amp;nbsp;This is the biggest change here that must be made.&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal" style="line-height:normal;"&gt;&lt;span style="font-size:12pt;font-family:&amp;#39;Courier New&amp;#39;;"&gt;- Select Apply at the bottom right and then the &amp;quot;Apply to All Folders&amp;quot; button at the top.&amp;nbsp; Select OK to close this window.&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal" style="line-height:normal;"&gt;&lt;span style="font-size:12pt;font-family:&amp;#39;Courier New&amp;#39;;"&gt;7.&amp;nbsp; Restart your computer&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal" style="line-height:normal;"&gt;&lt;span style="font-size:12pt;font-family:&amp;#39;Courier New&amp;#39;;"&gt;- After you system has restarted, log on once again with the Administrator account.&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal" style="line-height:normal;"&gt;&lt;span style="font-size:12pt;font-family:&amp;#39;Courier New&amp;#39;;"&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal" style="line-height:normal;"&gt;&lt;span style="text-decoration:underline;"&gt;&lt;span style="font-size:12pt;font-family:&amp;#39;Courier New&amp;#39;;"&gt;Complete the following steps to properly configure permissions on your systems hard drive properly&lt;/span&gt;&lt;/span&gt;&lt;span style="font-size:12pt;font-family:&amp;#39;Courier New&amp;#39;;"&gt;.&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal" style="line-height:normal;"&gt;&lt;span style="font-size:12pt;font-family:&amp;#39;Courier New&amp;#39;;"&gt;1.&amp;nbsp; My Computer &amp;gt;&amp;gt; right click on Local Disk (C:) &amp;gt;&amp;gt; Properties.&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal" style="line-height:normal;"&gt;&lt;span style="font-size:12pt;font-family:&amp;#39;Courier New&amp;#39;;"&gt;- Uncheck the &amp;quot;Allow Indexing Service to index this disk for fast file searching.&amp;nbsp; Once you do this it will prompt you to apply the changes.&amp;nbsp; Tell it to Apply to all folders and subfolders to start the process when it asks.&amp;nbsp; Any files it stops on, simply tell it to ignore all and continue for anything it cannot complete this task on.&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal" style="line-height:normal;"&gt;&lt;span style="font-size:12pt;font-family:&amp;#39;Courier New&amp;#39;;"&gt;- This task will take a few minutes to complete.&amp;nbsp; After it is done, continue on with the next step.&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal" style="line-height:normal;"&gt;&lt;span style="font-size:12pt;font-family:&amp;#39;Courier New&amp;#39;;"&gt;2.&amp;nbsp; Security tab (at the top).&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal" style="line-height:normal;"&gt;&lt;span style="font-size:12pt;font-family:&amp;#39;Courier New&amp;#39;;"&gt;- Under this tab at the top select and remove all names that exist here EXCEPT the following:&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal" style="line-height:normal;"&gt;&lt;span style="font-size:12pt;font-family:&amp;#39;Courier New&amp;#39;;"&gt;Administrators and SYSTEM.&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal" style="line-height:normal;"&gt;&lt;span style="font-size:12pt;font-family:&amp;#39;Courier New&amp;#39;;"&gt;- Select Add and then type in &amp;quot;Users&amp;quot; and then select OK.&amp;nbsp; At the bottom right select Apply.&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal" style="line-height:normal;"&gt;&lt;span style="font-size:12pt;font-family:&amp;#39;Courier New&amp;#39;;"&gt;3.&amp;nbsp; In the same window select the Advanced button.&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal" style="line-height:normal;"&gt;&lt;span style="font-size:12pt;font-family:&amp;#39;Courier New&amp;#39;;"&gt;- Select the box that says &amp;quot;Replace permission entries on all child objects with entries shown here that apply to child objects&amp;quot;.&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal" style="line-height:normal;"&gt;&lt;span style="font-size:12pt;font-family:&amp;#39;Courier New&amp;#39;;"&gt;- Select Apply to make this official.&amp;nbsp; It may take ask you if your sure, select Yes.&amp;nbsp; A Security window will pop up and you will see the action take place.&amp;nbsp; After it is complete, select OK to close the Advanced Security Settings for Local Disk window.&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal" style="line-height:normal;"&gt;&lt;span style="font-size:12pt;font-family:&amp;#39;Courier New&amp;#39;;"&gt;- Select OK to close the Local Disk (C:) Properties window now.&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal" style="line-height:normal;"&gt;&lt;span style="font-size:12pt;font-family:&amp;#39;Courier New&amp;#39;;"&gt;At this point these permissions have been applied to your entire local disk drive.&amp;nbsp; You now need to tweak the permission on the Administrative account itself and any other user accounts you may have on your system.&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal" style="line-height:normal;"&gt;&lt;span style="font-size:12pt;font-family:&amp;#39;Courier New&amp;#39;;"&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal" style="line-height:normal;"&gt;&lt;span style="text-decoration:underline;"&gt;&lt;span style="font-size:12pt;font-family:&amp;#39;Courier New&amp;#39;;"&gt;Complete the following steps to do this&lt;/span&gt;&lt;/span&gt;&lt;span style="font-size:12pt;font-family:&amp;#39;Courier New&amp;#39;;"&gt;:&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal" style="line-height:normal;"&gt;&lt;span style="font-size:12pt;font-family:&amp;#39;Courier New&amp;#39;;"&gt;1.&amp;nbsp; My Computer &amp;gt;&amp;gt; Documents and Settings &amp;gt;&amp;gt; right click on the Administrator folder &amp;gt;&amp;gt; Properties &amp;gt;&amp;gt; Security tab (at the top).&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal" style="line-height:normal;"&gt;&lt;span style="font-size:12pt;font-family:&amp;#39;Courier New&amp;#39;;"&gt;- For this folder we only need to remove the Users (everyone else) from having access to the Administrator&amp;#39;s profile.&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal" style="line-height:normal;"&gt;&lt;span style="font-size:12pt;font-family:&amp;#39;Courier New&amp;#39;;"&gt;- Select the Advanced button at the bottom.&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal" style="line-height:normal;"&gt;&lt;span style="font-size:12pt;font-family:&amp;#39;Courier New&amp;#39;;"&gt;- Uncheck the &amp;quot;Inherit from parent the permission entries that apply ...&amp;quot; box.&amp;nbsp; When prompted, select Copy from the screen that will pop up.&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal" style="line-height:normal;"&gt;&lt;span style="font-size:12pt;font-family:&amp;#39;Courier New&amp;#39;;"&gt;- Select the box next to the &amp;quot;Replace permission entries on all child objects with entries shown here that apply to child objects&amp;quot;.&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal" style="line-height:normal;"&gt;&lt;span style="font-size:12pt;font-family:&amp;#39;Courier New&amp;#39;;"&gt;- Click Apply in the lower right to make the changes and select Yes to the prompt it asks you to confirm.&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal" style="line-height:normal;"&gt;&lt;span style="font-size:12pt;font-family:&amp;#39;Courier New&amp;#39;;"&gt;- Click OK to close this window.&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal" style="line-height:normal;"&gt;&lt;span style="font-size:12pt;font-family:&amp;#39;Courier New&amp;#39;;"&gt;- At the top, select the Users in the window and then select the Remove button.&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal" style="line-height:normal;"&gt;&lt;span style="font-size:12pt;font-family:&amp;#39;Courier New&amp;#39;;"&gt;- Select Apply at the bottom right again.&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal" style="line-height:normal;"&gt;&lt;span style="font-size:12pt;font-family:&amp;#39;Courier New&amp;#39;;"&gt;- Select the Advanced button at the bottom right again.&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal" style="line-height:normal;"&gt;&lt;span style="font-size:12pt;font-family:&amp;#39;Courier New&amp;#39;;"&gt;- Select the box next to the &amp;quot;Replace permission entries on all child objects with entries shown here that apply to child objects&amp;quot;.&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal" style="line-height:normal;"&gt;&lt;span style="font-size:12pt;font-family:&amp;#39;Courier New&amp;#39;;"&gt;- Click Apply in the lower right to make the changes and select Yes to the prompt it asks you to confirm.&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal" style="line-height:normal;"&gt;&lt;span style="font-size:12pt;font-family:&amp;#39;Courier New&amp;#39;;"&gt;- Click OK to close this window.&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal" style="line-height:normal;"&gt;&lt;span style="font-size:12pt;font-family:&amp;#39;Courier New&amp;#39;;"&gt;- Click OK again on the Administrator Properties window to close it.&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal" style="line-height:normal;"&gt;&lt;span style="font-size:12pt;font-family:&amp;#39;Courier New&amp;#39;;"&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal" style="line-height:normal;"&gt;&lt;span style="font-size:12pt;font-family:&amp;#39;Courier New&amp;#39;;"&gt;From the C:\Documents and Settings window that should still be open at this point, complete the following steps for all other users (except the &amp;quot;All Users&amp;quot; and &amp;quot;Default User&amp;quot; folders).&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal" style="line-height:normal;"&gt;&lt;span style="font-size:12pt;font-family:&amp;#39;Courier New&amp;#39;;"&gt;1.&amp;nbsp; Right click the user&amp;#39;s folder &amp;gt;&amp;gt; Properties &amp;gt;&amp;gt; Security tab (at the top).&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal" style="line-height:normal;"&gt;&lt;span style="font-size:12pt;font-family:&amp;#39;Courier New&amp;#39;;"&gt;- For this folder we only need to remove the Users (everyone else) from having access to the particular user&amp;#39;s profile.&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal" style="line-height:normal;"&gt;&lt;span style="font-size:12pt;font-family:&amp;#39;Courier New&amp;#39;;"&gt;- Select the Advanced button at the bottom.&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal" style="line-height:normal;"&gt;&lt;span style="font-size:12pt;font-family:&amp;#39;Courier New&amp;#39;;"&gt;- Uncheck the &amp;quot;Inherit from parent the permission entries that apply ...&amp;quot; box.&amp;nbsp; When prompted, select Copy from the screen that will pop up.&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal" style="line-height:normal;"&gt;&lt;span style="font-size:12pt;font-family:&amp;#39;Courier New&amp;#39;;"&gt;- Select the box next to the &amp;quot;Replace permission entries on all child objects with entries shown here that apply to child objects&amp;quot;.&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal" style="line-height:normal;"&gt;&lt;span style="font-size:12pt;font-family:&amp;#39;Courier New&amp;#39;;"&gt;- Click Apply in the lower right to make the changes and select Yes to the prompt it asks you to confirm.&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal" style="line-height:normal;"&gt;&lt;span style="font-size:12pt;font-family:&amp;#39;Courier New&amp;#39;;"&gt;- Click OK to close this window.&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal" style="line-height:normal;"&gt;&lt;span style="font-size:12pt;font-family:&amp;#39;Courier New&amp;#39;;"&gt;- At the top, select the Users in the window and then select the Remove button.&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal" style="line-height:normal;"&gt;&lt;span style="font-size:12pt;font-family:&amp;#39;Courier New&amp;#39;;"&gt;- Select Apply at the bottom right again.&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal" style="line-height:normal;"&gt;&lt;span style="font-size:12pt;font-family:&amp;#39;Courier New&amp;#39;;"&gt;- Select the Advanced button at the bottom right again.&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal" style="line-height:normal;"&gt;&lt;span style="font-size:12pt;font-family:&amp;#39;Courier New&amp;#39;;"&gt;- Select the box next to the &amp;quot;Replace permission entries on all child objects with entries shown here that apply to child objects&amp;quot;.&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal" style="line-height:normal;"&gt;&lt;span style="font-size:12pt;font-family:&amp;#39;Courier New&amp;#39;;"&gt;- Click Apply in the lower right to make the changes and select Yes to the prompt it asks you to confirm.&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal" style="line-height:normal;"&gt;&lt;span style="font-size:12pt;font-family:&amp;#39;Courier New&amp;#39;;"&gt;- Click OK to close this window.&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal" style="line-height:normal;"&gt;&lt;span style="font-size:12pt;font-family:&amp;#39;Courier New&amp;#39;;"&gt;- At the top select Add and then enter the name of this user profile.&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal" style="line-height:normal;"&gt;&lt;span style="font-size:12pt;font-family:&amp;#39;Courier New&amp;#39;;"&gt;- Select Apply at the bottom right.&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal" style="line-height:normal;"&gt;&lt;span style="font-size:12pt;font-family:&amp;#39;Courier New&amp;#39;;"&gt;- At the top select the user&amp;#39;s name you just added.&amp;nbsp; In the middle of the window, under the &amp;quot;Permissions for ...&amp;quot; make sure all of the boxes under the &amp;quot;Allow&amp;quot; column are checked, except the Full Control one at the top.&amp;nbsp; &lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal" style="line-height:normal;"&gt;&lt;span style="font-size:12pt;font-family:&amp;#39;Courier New&amp;#39;;"&gt;- Select the Apply at the bottom right.&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal" style="line-height:normal;"&gt;&lt;span style="font-size:12pt;font-family:&amp;#39;Courier New&amp;#39;;"&gt;- Select the Advanced button at the bottom right again.&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal" style="line-height:normal;"&gt;&lt;span style="font-size:12pt;font-family:&amp;#39;Courier New&amp;#39;;"&gt;- Select the box next to the &amp;quot;Replace permission entries on all child objects with entries shown here that apply to child objects&amp;quot;.&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal" style="line-height:normal;"&gt;&lt;span style="font-size:12pt;font-family:&amp;#39;Courier New&amp;#39;;"&gt;- Click Apply in the lower right to make the changes and select Yes to the prompt it asks you to confirm.&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal" style="line-height:normal;"&gt;&lt;span style="font-size:12pt;font-family:&amp;#39;Courier New&amp;#39;;"&gt;- Click OK to close this window.&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal" style="line-height:normal;"&gt;&lt;b&gt;&lt;span style="font-size:12pt;font-family:&amp;#39;Courier New&amp;#39;;"&gt;NOTE&lt;/span&gt;&lt;/b&gt;&lt;span style="font-size:12pt;font-family:&amp;#39;Courier New&amp;#39;;"&gt;:&amp;nbsp; At this point you should only see the Administrators, SYSTEM, and then the user name itself existing under each user&amp;#39;s profile.&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal" style="line-height:normal;"&gt;&lt;span style="font-size:12pt;font-family:&amp;#39;Courier New&amp;#39;;"&gt;- Click OK to close the User&amp;#39;s Properties window.&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal" style="line-height:normal;"&gt;&lt;b&gt;&lt;span style="font-size:12pt;font-family:&amp;#39;Courier New&amp;#39;;"&gt;NOTE&lt;/span&gt;&lt;/b&gt;&lt;span style="font-size:12pt;font-family:&amp;#39;Courier New&amp;#39;;"&gt;:&amp;nbsp; At this time, plug back in your connection to the internet.&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal" style="line-height:normal;"&gt;&lt;span style="font-size:12pt;font-family:&amp;#39;Courier New&amp;#39;;"&gt;2.&amp;nbsp; Restart your system again.&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal" style="line-height:normal;"&gt;&lt;span style="font-size:12pt;font-family:&amp;#39;Courier New&amp;#39;;"&gt;- After you system has restarted, log on once again with the Administrator account.&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal" style="line-height:normal;"&gt;&lt;span style="font-size:12pt;font-family:&amp;#39;Courier New&amp;#39;;"&gt;Using the Administrator account, you will now begin installing your system&amp;#39;s driver software.&amp;nbsp; Preferably, I would complete this in the following order:&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal" style="line-height:normal;"&gt;&lt;span style="font-size:12pt;font-family:&amp;#39;Courier New&amp;#39;;"&gt;1. Chipset&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal" style="line-height:normal;"&gt;&lt;span style="font-size:12pt;font-family:&amp;#39;Courier New&amp;#39;;"&gt;2. Graphics Card &lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal" style="line-height:normal;"&gt;&lt;span style="font-size:12pt;font-family:&amp;#39;Courier New&amp;#39;;"&gt;3. Sound Card&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal" style="line-height:normal;"&gt;&lt;span style="font-size:12pt;font-family:&amp;#39;Courier New&amp;#39;;"&gt;4. NIC&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal" style="line-height:normal;"&gt;&lt;span style="font-size:12pt;font-family:&amp;#39;Courier New&amp;#39;;"&gt;5. Any other base system device driver or external device driver (that does not require an internet connection to setup).&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal" style="line-height:normal;"&gt;&lt;span style="font-size:12pt;font-family:&amp;#39;Courier New&amp;#39;;"&gt;Depending on your type of driver software that you are installing, I would recommend restarting your system as it requests you to do or preferably after each one is completed.&amp;nbsp; After you have installed all of them, restart your system one last time.&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal" style="line-height:normal;"&gt;&lt;span style="font-size:12pt;font-family:&amp;#39;Courier New&amp;#39;;"&gt;- After you system has restarted, log on once again with the Administrator account.&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal" style="line-height:normal;"&gt;&lt;span style="font-size:12pt;font-family:&amp;#39;Courier New&amp;#39;;"&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal" style="line-height:normal;"&gt;&lt;span style="font-size:12pt;font-family:&amp;#39;Courier New&amp;#39;;"&gt;Begin downloading and installing your Window&amp;#39;s updates at this point.&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal" style="line-height:normal;"&gt;&lt;b&gt;&lt;span style="font-size:12pt;font-family:&amp;#39;Courier New&amp;#39;;"&gt;Use&lt;/span&gt;&lt;/b&gt;&lt;span style="font-size:12pt;font-family:&amp;#39;Courier New&amp;#39;;"&gt;:&amp;nbsp; &lt;b&gt;http://update.microsoft.com/microsoftupdate&lt;/b&gt; instead of the Windows Update.&amp;nbsp; Microsoft Update checks for all other MS products, which Windows Update does not.&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal" style="line-height:normal;"&gt;&lt;span style="font-size:12pt;font-family:&amp;#39;Courier New&amp;#39;;"&gt;When prompted, you can choose to update your system completely strictly using SP2 (unless you installed your XP originally from a disc that had SP3 on it already), or choose to install SP3 from the start when it prompts you too choose between the two.&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal" style="line-height:normal;"&gt;&lt;span style="font-size:12pt;font-family:&amp;#39;Courier New&amp;#39;;"&gt;Complete the installation of all of your Microsoft updates restarting your system as needed.&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal" style="line-height:normal;"&gt;&lt;b&gt;&lt;span style="font-size:12pt;font-family:&amp;#39;Courier New&amp;#39;;"&gt;NOTE&lt;/span&gt;&lt;/b&gt;&lt;span style="font-size:12pt;font-family:&amp;#39;Courier New&amp;#39;;"&gt;:&amp;nbsp; At this point, it is the perfect moment to now make the first image of your system using your backup software.&amp;nbsp; After you complete that, I would recommend installing your BASE programs (as I would call them).&amp;nbsp; This includes your Microsoft Office products, CCleaner, HD Defragmentation programs, zip utilities, CD Burning Software, etc.&amp;nbsp; But install the main ones only, not the programs that you normally update a lot (i.e. Acrobat, Flash Player, etc).&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal" style="line-height:normal;"&gt;&lt;span style="font-size:12pt;font-family:&amp;#39;Courier New&amp;#39;;"&gt;Run Microsoft Update again, this makes sure that you are not missing any updates for anything that you just installed that Microsoft may have available to you.&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal" style="line-height:normal;"&gt;&lt;b&gt;&lt;span style="font-size:12pt;font-family:&amp;#39;Courier New&amp;#39;;"&gt;NOTE&lt;/span&gt;&lt;/b&gt;&lt;span style="font-size:12pt;font-family:&amp;#39;Courier New&amp;#39;;"&gt;:&amp;nbsp; At this point, you should probably defragment your HD, clean up any clutter (I use CCleaner for this) and then configure your system&amp;#39;s services based on your needs.&amp;nbsp; I would recommend using http://blackviper.com for recommendations on your system&amp;#39;s services and how to set them to fit YOUR needs.&amp;nbsp; &lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal" style="line-height:normal;"&gt;&lt;span style="font-size:12pt;font-family:&amp;#39;Courier New&amp;#39;;"&gt;Before you do anything else, I would recommend setting the passwords to all of your computer&amp;#39;s accounts.&amp;nbsp;&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal" style="line-height:normal;"&gt;&lt;span style="font-size:12pt;font-family:&amp;#39;Courier New&amp;#39;;"&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal" style="line-height:normal;"&gt;&lt;span style="text-decoration:underline;"&gt;&lt;span style="font-size:12pt;font-family:&amp;#39;Courier New&amp;#39;;"&gt;Complete the following steps to do this&lt;/span&gt;&lt;/span&gt;&lt;span style="font-size:12pt;font-family:&amp;#39;Courier New&amp;#39;;"&gt;:&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal" style="line-height:normal;"&gt;&lt;span style="font-size:12pt;font-family:&amp;#39;Courier New&amp;#39;;"&gt;1. Administrative Tools &amp;gt;&amp;gt; Computer Management &amp;gt;&amp;gt; Local Users and Groups (on the left) &amp;gt;&amp;gt; double left click on Users (on the right).&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal" style="line-height:normal;"&gt;&lt;span style="font-size:12pt;font-family:&amp;#39;Courier New&amp;#39;;"&gt;- Double left click on the Administrator, uncheck &amp;quot;Password never expires&amp;quot;.&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal" style="line-height:normal;"&gt;&lt;span style="font-size:12pt;font-family:&amp;#39;Courier New&amp;#39;;"&gt;- Select Apply in the bottom right.&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal" style="line-height:normal;"&gt;&lt;span style="font-size:12pt;font-family:&amp;#39;Courier New&amp;#39;;"&gt;- Click OK to close this window.&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal" style="line-height:normal;"&gt;&lt;span style="font-size:12pt;font-family:&amp;#39;Courier New&amp;#39;;"&gt;- right click on the Administrator, select Set Password, and then the Proceed button when you&amp;rsquo;re prompted to.&amp;nbsp; Set a decent password (preferably nothing less than 8 characters).&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal" style="line-height:normal;"&gt;&lt;span style="font-size:12pt;font-family:&amp;#39;Courier New&amp;#39;;"&gt;Next, set the Guest account settings.&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal" style="line-height:normal;"&gt;&lt;span style="font-size:12pt;font-family:&amp;#39;Courier New&amp;#39;;"&gt;- Double left click on the Guest, make sure all three of the items in this window are checked in the middle.&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal" style="line-height:normal;"&gt;&lt;span style="font-size:12pt;font-family:&amp;#39;Courier New&amp;#39;;"&gt;- Select Apply in the bottom right (if you can).&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal" style="line-height:normal;"&gt;&lt;span style="font-size:12pt;font-family:&amp;#39;Courier New&amp;#39;;"&gt;- Click OK to close this window.&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal" style="line-height:normal;"&gt;&lt;span style="font-size:12pt;font-family:&amp;#39;Courier New&amp;#39;;"&gt;- right click on the Guest, select Set Password, and then the Proceed button when you&amp;rsquo;re prompted to.&amp;nbsp; Set a decent password (preferably nothing less than 8 characters and quite frankly your Administrator&amp;#39;s password should be the longest of all of them).&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal" style="line-height:normal;"&gt;&lt;b&gt;&lt;span style="font-size:12pt;font-family:&amp;#39;Courier New&amp;#39;;"&gt;NOTE&lt;/span&gt;&lt;/b&gt;&lt;span style="font-size:12pt;font-family:&amp;#39;Courier New&amp;#39;;"&gt;:&amp;nbsp; If you are on a Local Area Network and anyone attempts to connect to your system (to see if you have any files shared on the network etc), they should be prompted for a username and password in an attempt to authenticate to your system to view any resources that are available.&amp;nbsp; By default they are attempting to connect using the Guest account&amp;#39;s credentials.&amp;nbsp; Even though the account is disabled, it is wise to set a strong password on it because of this and other security related reasons.&lt;span&gt;&amp;nbsp; &lt;/span&gt;If you want to share resources that reside on your system, it is best to create a specific folder for this task (or use the Shared Documents folder under My Computer) and either set the permissions on this for sharing.&lt;span&gt;&amp;nbsp; &lt;/span&gt;Creating a separate user name and password for someone to use if they wish to connect to your computer&amp;rsquo;s shares is also a wise idea.&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal" style="line-height:normal;"&gt;&lt;span style="font-size:12pt;font-family:&amp;#39;Courier New&amp;#39;;"&gt;Next, set each User&amp;#39;s account with a basic default password, using the same steps I described above, however, I recommend that all of the boxes in the settings not be checked.&amp;nbsp; The only box I recommend that you check (before they log on for the first time) is the &amp;quot;User must change password at next logon&amp;quot;.&amp;nbsp; This will force them to change their password after they logon with the basic default password you gave them.&amp;nbsp; If they log on and they are not prompted to change their password, have them do an ALT + CTRL + DEL and then manually change it to what they want, otherwise the basic default password will still be in effect for them.&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal" style="line-height:normal;"&gt;&lt;span style="font-size:12pt;font-family:&amp;#39;Courier New&amp;#39;;"&gt;- Now Restart your system and log back in with your Administrative account and password this time to make sure it works properly.&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal" style="line-height:normal;"&gt;&lt;span style="font-size:12pt;font-family:&amp;#39;Courier New&amp;#39;;"&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal" style="line-height:normal;"&gt;&lt;span style="font-size:12pt;font-family:&amp;#39;Courier New&amp;#39;;"&gt;After all this is done, I recommend creating another image of your computer&amp;#39;s HD with your backup software.&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal" style="line-height:normal;"&gt;&lt;span style="font-size:12pt;font-family:&amp;#39;Courier New&amp;#39;;"&gt;After creating your image, log back in with the Administrative account.&amp;nbsp; Now is the time to install Blink, run Retina, and fix the audits that Blink tells you that you need to fix.&amp;nbsp; After this, I would create another image of my HD.&amp;nbsp; This image can be used to revert back to now, when you want to do fresh installs of the programs that are a pain the most to you (i.e. Adobe Acrobat, Flash Player, Sun&amp;#39;s JRE, other applications, etc).&amp;nbsp; &lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal" style="line-height:normal;"&gt;&lt;span style="font-size:12pt;font-family:&amp;#39;Courier New&amp;#39;;"&gt;The point of creating this image is, you have Blink installed and running before anything else touches your system.&amp;nbsp; This provides you with a reliable foundation to run Blink on before you begin to add things to it.&amp;nbsp; Now, you always have this image to resort too when something just does not go right.&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal" style="line-height:normal;"&gt;&lt;span style="font-size:12pt;font-family:&amp;#39;Courier New&amp;#39;;"&gt;=======================================================&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal" style="line-height:normal;"&gt;&lt;b&gt;&lt;span style="font-size:12pt;font-family:&amp;#39;Courier New&amp;#39;;"&gt;Final Notes&lt;/span&gt;&lt;/b&gt;&lt;span style="font-size:12pt;font-family:&amp;#39;Courier New&amp;#39;;"&gt;:&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal" style="line-height:normal;"&gt;&lt;span style="font-size:12pt;font-family:&amp;#39;Courier New&amp;#39;;"&gt;- DO NOT use the Administrative account to surf the internet!&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal" style="line-height:normal;"&gt;&lt;span style="font-size:12pt;font-family:&amp;#39;Courier New&amp;#39;;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; You will find that limited user accounts are NOT THAT BAD!&amp;nbsp; Some things may not work properly; therefore you would have to adjust the permissions for that one program for the user, etc via the Security tab permissions and so forth.&amp;nbsp; This is the fine tweaking aspect of Windows that everyone gets use to.&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal" style="line-height:normal;"&gt;&lt;span style="font-size:12pt;font-family:&amp;#39;Courier New&amp;#39;;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; On a final note, anyone that has kids that like to play games, unfortunately, a lot of the games nowadays are NOT happy with a limited user account and therefore will not work properly.&amp;nbsp; Unfortunately, you may end up allowing them to use the Administrative account to do this.&amp;nbsp; Quite frankly this defeats the purpose of a limited user account, therefore it may be better to have a system entirely dedicated to game playing because you are trusting that they will not fool with anything else on the system when they are using the Administrative account to play their games with.&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal" style="line-height:normal;"&gt;&lt;span style="font-size:12pt;font-family:&amp;#39;Courier New&amp;#39;;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; A lot more can be done with this guide, however, I wanted to give everyone a BASIC setup that will increase security dramatically at a low cost to usability.&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal" style="line-height:normal;"&gt;&lt;span style="font-size:12pt;font-family:&amp;#39;Courier New&amp;#39;;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; This same format and concept applies to Windows Vista and Windows 7 with the exception of different settings reside in different locations.&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal" style="line-height:normal;"&gt;&lt;span style="font-size:12pt;line-height:115%;font-family:&amp;#39;Courier New&amp;#39;;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; New to Blink, check out the post I have created for new users located here:&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal" style="line-height:normal;"&gt;&lt;span style="font-size:12pt;line-height:115%;font-family:&amp;#39;Courier New&amp;#39;;"&gt;&lt;a target="_blank" href="http://forums.eeye.com/forums/t/998.aspx?PageIndex=1"&gt;http://forums.eeye.com/forums/t/998.aspx?PageIndex=1&lt;/a&gt;&lt;/span&gt;&lt;/p&gt;</description></item><item><title>Free Audit Program to Use Alongside Retina</title><link>http://forums.eeye.com/forums/thread/3661.aspx</link><pubDate>Sun, 14 Dec 2008 15:42:22 GMT</pubDate><guid isPermaLink="false">a21f7e33-d546-44ed-90ca-b1df844505d6:3661</guid><dc:creator>Blue1978</dc:creator><slash:comments>1</slash:comments><comments>http://forums.eeye.com/forums/thread/3661.aspx</comments><wfw:commentRss>http://forums.eeye.com/forums/commentrss.aspx?SectionID=12&amp;PostID=3661</wfw:commentRss><description>&lt;p&gt;&lt;strong&gt;&lt;span style="text-decoration:underline;"&gt;Here is another awesome&amp;nbsp;free program that you can run on your system that supplements Retina&lt;/span&gt;&lt;/strong&gt;.&lt;/p&gt;
&lt;p&gt;It is called Belarc Advisor:&amp;nbsp; &lt;a href="http://www.belarc.com/free_download.html"&gt;http://www.belarc.com/free_download.html&lt;/a&gt;&lt;/p&gt;</description></item><item><title>Starting Fresh</title><link>http://forums.eeye.com/forums/thread/3625.aspx</link><pubDate>Mon, 01 Dec 2008 16:57:59 GMT</pubDate><guid isPermaLink="false">a21f7e33-d546-44ed-90ca-b1df844505d6:3625</guid><dc:creator>tomguck</dc:creator><slash:comments>1</slash:comments><comments>http://forums.eeye.com/forums/thread/3625.aspx</comments><wfw:commentRss>http://forums.eeye.com/forums/commentrss.aspx?SectionID=12&amp;PostID=3625</wfw:commentRss><description>&lt;p&gt;&amp;nbsp;How can I get rid of all my rules and start over without reinstalling?&lt;/p&gt;
&lt;p&gt;I deleted my rules but Blink does not warn me when something tries to get on the internet now.&lt;/p&gt;
&lt;p&gt;I just want to start over.&lt;/p&gt;
&lt;p&gt;Vista Home Premium&lt;/p&gt;</description></item><item><title>Useful Websites and Articles for Tightening up Your Computer's Security.</title><link>http://forums.eeye.com/forums/thread/3328.aspx</link><pubDate>Wed, 15 Oct 2008 21:23:59 GMT</pubDate><guid isPermaLink="false">a21f7e33-d546-44ed-90ca-b1df844505d6:3328</guid><dc:creator>Blue1978</dc:creator><slash:comments>2</slash:comments><comments>http://forums.eeye.com/forums/thread/3328.aspx</comments><wfw:commentRss>http://forums.eeye.com/forums/commentrss.aspx?SectionID=12&amp;PostID=3328</wfw:commentRss><description>&lt;p&gt;&lt;b&gt;&lt;span style="text-decoration:underline;"&gt;&lt;span style="font-size:small;"&gt;Here are some useful websites and articles I have come across that will assist anyone that is interested in locking down their system better&lt;/span&gt;&lt;/span&gt;&lt;/b&gt;:&lt;/p&gt;
&lt;p&gt;============================================================================================================&lt;/p&gt;
&lt;p&gt;&lt;b&gt;&lt;span style="text-decoration:underline;"&gt;I - Securing Your Web Browser(s):&lt;/span&gt;&lt;/b&gt;&lt;/p&gt;
&lt;p&gt;1.&amp;nbsp; &lt;a title="US-Cert" href="http://www.us-cert.gov/reading_room/securing_browser/#Internet_Explorer" target="_blank"&gt;http://www.us-cert.gov/reading_room/securing_browser/#Internet_Explorer&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;2.&amp;nbsp; &lt;a title="Heise" href="http://www.heise-online.co.uk/security/services/browsercheck/demos/ie/" target="_blank"&gt;http://www.heise-online.co.uk/security/services/browsercheck/demos/ie/&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&lt;b&gt;&lt;span style="text-decoration:underline;"&gt;II - Windows Services&lt;/span&gt;&lt;/b&gt;:&lt;/p&gt;
&lt;p&gt;1.&amp;nbsp; &lt;a title="BlackViper" href="http://www.blackviper.com/" target="_blank"&gt;http://www.blackviper.com/&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;2.&amp;nbsp; &lt;a title="Services" href="http://en.wikipedia.org/wiki/Windows_service" target="_blank"&gt;http://en.wikipedia.org/wiki/Windows_service&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;3.&amp;nbsp; &lt;a title="Services" href="http://beemerworld.com/tips/servicesxp.htm" target="_blank"&gt;http://beemerworld.com/tips/servicesxp.htm&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&lt;b&gt;&lt;span style="text-decoration:underline;"&gt;III - Tweak Guides&lt;/span&gt;&lt;/b&gt;:&lt;/p&gt;
&lt;p&gt;1.&amp;nbsp; &lt;a title="Tweak Guides" href="http://www.tweakguides.com/TGTC.html" target="_blank"&gt;http://www.tweakguides.com/TGTC.html&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;2.&amp;nbsp; &lt;a title="Tweak Guides" href="http://tweakhound.com/xp/xptweaks/supertweaks1.htm" target="_blank"&gt;http://tweakhound.com/xp/xptweaks/supertweaks1.htm&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&lt;b&gt;&lt;span style="text-decoration:underline;"&gt;IV - Information Straight from Microsoft&lt;/span&gt;&lt;/b&gt;:&lt;/p&gt;
&lt;p&gt;1.&amp;nbsp; &lt;a title="Technet" href="http://technet.microsoft.com/en-us/default.aspx" target="_blank"&gt;http://technet.microsoft.com/en-us/default.aspx&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;</description></item><item><title>Rule: Disables the MS-DOS command interpreter</title><link>http://forums.eeye.com/forums/thread/2568.aspx</link><pubDate>Mon, 12 May 2008 20:42:10 GMT</pubDate><guid isPermaLink="false">a21f7e33-d546-44ed-90ca-b1df844505d6:2568</guid><dc:creator>RootSpy</dc:creator><slash:comments>1</slash:comments><comments>http://forums.eeye.com/forums/thread/2568.aspx</comments><wfw:commentRss>http://forums.eeye.com/forums/commentrss.aspx?SectionID=12&amp;PostID=2568</wfw:commentRss><description>					
						MS-DOS command interpreter Disable
						Disables the MS-DOS command interpreter. Helps to mitigates command line attack vectors. Toggleunder Sytem Protection Rules, to enable when needed 
						
							C:\WINDOWS\system32\cmd.exe
							
							path
						
						
							*.*
							
							path
						
						
							
						
					



I wonder what the id field under creator represents, Blink users?</description></item><item><title>Times When Temporarily Disabling Blink's AV/Anti-Spyware Module Helps</title><link>http://forums.eeye.com/forums/thread/2295.aspx</link><pubDate>Sun, 23 Mar 2008 20:14:07 GMT</pubDate><guid isPermaLink="false">a21f7e33-d546-44ed-90ca-b1df844505d6:2295</guid><dc:creator>Blue1978</dc:creator><slash:comments>3</slash:comments><comments>http://forums.eeye.com/forums/thread/2295.aspx</comments><wfw:commentRss>http://forums.eeye.com/forums/commentrss.aspx?SectionID=12&amp;PostID=2295</wfw:commentRss><description>&lt;p&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; I have come across numerous instances when temporarily disabling Blink&amp;#39;s Antivirus/Spyware protection module greatly increases system performance when you need it most.&lt;/p&gt;
&lt;p&gt;1.&amp;nbsp; &lt;b&gt;When burning a CD or DVD&lt;/b&gt;.&amp;nbsp; &lt;/p&gt;
&lt;p&gt;-&amp;nbsp; Every file that is being burned to the CD or DVD is scanned by when it is accessed by the burning software.&amp;nbsp; This helps making your burning experience a but smoother.&lt;/p&gt;
&lt;p&gt;2.&amp;nbsp; &lt;b&gt;When transferring a large amount of data&lt;/b&gt;.&lt;/p&gt;
&lt;p&gt;-&amp;nbsp; Anytime a file is accessed Blink scans it.&amp;nbsp; I recommend you manually scan your files first before moving them, then disable Blink&amp;#39;s AV component, and then transfer them.&amp;nbsp;&lt;/p&gt;
&lt;p&gt;3.&amp;nbsp; &lt;b&gt;When using another application or system ran process to manually scan or perform a maintenance related task on a computer.&lt;/b&gt;&lt;/p&gt;
&lt;p&gt;- If you happen to be using another security software program alongside Blink then disabling Blink&amp;#39;s AV component speeds up that program&amp;#39;s scanning capabilities a bit.&amp;nbsp; The reason being is because when that program accesses any file on your system, this causes Blink to scan it too as it&amp;#39;s being accessed.&amp;nbsp; It just makes things go smoother if you scan with another program for any reason.&lt;/p&gt;
&lt;p&gt;- This applies to:&lt;/p&gt;
&lt;p&gt;Hard Drive Defragmentation programs&lt;/p&gt;
&lt;p&gt;Windows Clutter cleaning utilities (CCleaner)&lt;/p&gt;
&lt;p&gt;Disk wiping programs (Cyber Scrub)&lt;/p&gt;
&lt;p&gt;Formatting a new partition on a computer or external device&lt;/p&gt;
&lt;p&gt;Encrypting an external hardware device or large volume (TrueCypt)&amp;nbsp;&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; These are just general instances that I have experienced myself and&amp;nbsp; thought I would pass them along.&amp;nbsp; At the time when I noticed this performance loss, I was using Microsoft&amp;#39;s Process Explorer program found at:&amp;nbsp; &lt;a title="Process Explorer" href="http://technet.microsoft.com/en-us/sysinternals/bb896653.aspx" target="_blank"&gt;http://technet.microsoft.com/en-us/sysinternals/bb896653.aspx&lt;/a&gt; .&amp;nbsp; &lt;/p&gt;
&lt;p&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; I noticed Blink would take up a huge chunk of CPU usage at the same time the other program was scanning to scan things itself.&amp;nbsp; After I temporarily disabled Blink&amp;#39;s AV component I noticed a huge difference in the performance of the other program(s) I was trying to run.&amp;nbsp;&lt;/p&gt;</description></item><item><title>Any reason for locking the following post?</title><link>http://forums.eeye.com/forums/thread/2298.aspx</link><pubDate>Wed, 26 Mar 2008 04:28:31 GMT</pubDate><guid isPermaLink="false">a21f7e33-d546-44ed-90ca-b1df844505d6:2298</guid><dc:creator>Brent</dc:creator><slash:comments>1</slash:comments><comments>http://forums.eeye.com/forums/thread/2298.aspx</comments><wfw:commentRss>http://forums.eeye.com/forums/commentrss.aspx?SectionID=12&amp;PostID=2298</wfw:commentRss><description>&lt;p&gt;&amp;nbsp;Post:&lt;/p&gt;
&lt;p&gt;&amp;quot;Times When Temporarily Disabling Blink&amp;#39;s AV/Anti-Spyware Module Helps&amp;quot;&lt;/p&gt;
&lt;p&gt;Just curious - as I have found the same issue but was told there is a fix coming for the large file transfer and copy issues..&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;</description></item><item><title>Security Tip Recommendation #1 - Tightening up DNS Security in Blink.</title><link>http://forums.eeye.com/forums/thread/2103.aspx</link><pubDate>Tue, 29 Jan 2008 02:26:32 GMT</pubDate><guid isPermaLink="false">a21f7e33-d546-44ed-90ca-b1df844505d6:2103</guid><dc:creator>Blue1978</dc:creator><slash:comments>0</slash:comments><comments>http://forums.eeye.com/forums/thread/2103.aspx</comments><wfw:commentRss>http://forums.eeye.com/forums/commentrss.aspx?SectionID=12&amp;PostID=2103</wfw:commentRss><description>&lt;p&gt;&lt;span style="text-decoration:underline;"&gt;The following is purely a &lt;b&gt;recommendation&lt;/b&gt; on how to tighten up the security of DNS on your sytem by modifying a few settings in Blink, creating one firewall rule, and by disabling the &amp;quot;DNS Client&amp;quot; Service in Windows.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; The following are steps of how I have tightened up the security of DNS on my Windows XP Professional system:&amp;nbsp;&lt;/p&gt;
&lt;p&gt;1.&amp;nbsp; First go into &amp;quot;Administrative Tools&amp;quot; and then into &amp;quot;Services&amp;quot;.&amp;nbsp; (Find the &amp;quot;DNS Client&amp;quot; Service)&lt;/p&gt;
&lt;p&gt;2.&amp;nbsp; Disable this service completely.&amp;nbsp; To be sure either Stop the service first before disabling it, or disable it and then restart your system.&lt;/p&gt;
&lt;p&gt;Why do I do this? - If you disable the DNS Client service it will force any application that wants to make a DNS lookup, make it itself vice having the service &amp;quot;svchost.ext&amp;quot; do it.&amp;nbsp; &amp;quot;Svchost.exe&amp;quot; is a service that can be exploited in a few ways and taking one of the chances away from it that it may be used for malicious purposes, in my opinion, is wise.&lt;/p&gt;
&lt;p&gt;3. Go into Blink&amp;#39;s Options under the &amp;quot;Firewall&amp;quot; tab and uncheck the option Allow DNS Traffic.&lt;/p&gt;
&lt;p&gt;- This will allow you to create your own rule for Blink to control DNS by more tightly.&lt;/p&gt;
&lt;p&gt;4. Go into the&amp;nbsp; Firewall section from the &amp;quot;Blink Home Page&amp;quot; on the left.&amp;nbsp; Select View all Firewall rules. &lt;/p&gt;
&lt;p&gt;5.&amp;nbsp; Select the &amp;quot;System Wide Rules&amp;quot; section.&amp;nbsp; (by default this should be showing anyways)&lt;/p&gt;
&lt;p&gt;6. Create a new rule with the following parameters:&lt;/p&gt;
&lt;p&gt;&lt;b&gt;Action&lt;/b&gt;:&amp;nbsp; Allow&lt;/p&gt;
&lt;p&gt;&lt;b&gt;Protocol&lt;/b&gt;:&amp;nbsp; UDP&lt;/p&gt;
&lt;p&gt;&lt;b&gt;Direction&lt;/b&gt;:&amp;nbsp; Any Direction&lt;/p&gt;
&lt;p&gt;&lt;b&gt;Local Address&lt;/b&gt;:&amp;nbsp; &lt;/p&gt;
&lt;p&gt;- &amp;quot;Rule applies to all IP adresses of this computer&amp;quot; should be selected at the top&lt;/p&gt;
&lt;p&gt;-&amp;nbsp; Specify local ports section at the bottom should have 1025-65535 in it.&lt;/p&gt;
&lt;p&gt;&lt;b&gt;Remote Address&lt;/b&gt;:&amp;nbsp;&lt;/p&gt;
&lt;p&gt;- &amp;quot;Specify remote IP address for this rule&amp;quot; should be selected.&amp;nbsp; To the right of this click on the Add button and then selected the &amp;quot;Determine IP(s) at run-time&amp;quot; selection then from the drop down menu it has select &amp;quot;DNS Server&amp;quot;.&amp;nbsp; Click OK to close this window.&lt;/p&gt;
&lt;p&gt;- Specify remote ports section at the bottom should have only 53 in it.&lt;/p&gt;
&lt;p&gt;&lt;b&gt;Description&lt;/b&gt;:&amp;nbsp; &lt;/p&gt;
&lt;p&gt;- Give it a description of your choice.&amp;nbsp;&lt;/p&gt;
&lt;p&gt;7. Click &amp;quot;Save&amp;quot; at the bottom of the System Wide Firewall Rule Wizard window.&lt;/p&gt;
&lt;p&gt; (make this rule high up on your list.&amp;nbsp; It is the 2nd one on mine after the Deny all ICMP Rule I have)&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;Your done, is is that simple.&lt;/p&gt;
&lt;p&gt;NOTE:&amp;nbsp; As long as you have &amp;quot;DENY&amp;quot; selected in the drop down menu under the &amp;quot;For System Wide Traffic&amp;quot; field under the Default Actions section of the Firewall tab in Blink&amp;#39;s Options you will be good for this. &amp;nbsp;&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; This rule should now govern all DNS traffic from your system.&amp;nbsp; Any rule that you may have for DNS under the &amp;quot;Generic Host Process for Win32 Services&amp;quot; in the Application Firewall section I would say to go ahead and remove it now.&amp;nbsp; This rule simply says anything wanting to do a DNS lookup will send its request to the pre-determined location at startup that is handling DNS.&amp;nbsp; If it does not request a remote port of 53 it will drop it and if it is not a UDP request it will be dropped.&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; This rule is good for a few reasons:&lt;/p&gt;
&lt;p&gt;1 . If you still had the DNS Client service running and allowed Blink to handle all DNS traffic without a specific rule the following &amp;quot;could&amp;quot; happen.&lt;/p&gt;
&lt;p&gt;- There is a lot of Malware (DNS Trojans for one example) out there that will attempt to make its outbound connection via svchost.exe, using DNS, BUT it will not specifically ask that its request be sent to the remote Port of 53 (like a ligitament DNS request normally does).&amp;nbsp; Depending on what Blink is watching for, this type of request may make it out to its destination since there is not anything that specifically states to allow DNS traffic &lt;span style="text-decoration:underline;"&gt;only&lt;/span&gt; if it requests a DNS server IP and the correct remote port of 53.&amp;nbsp; This rule should drop anything that attempts to do this.&amp;nbsp; Keep in mind, if your gateway (router, etc) handles your LAN&amp;#39;s DNS requests it may also be wise to create a specific rule also toallow DNS to go out to the remote port of 53 of your selected DNS provider&amp;#39;s server IPs using only UDP too.&amp;nbsp; This will also ensure your gateway enforces this policy the same way as Blink does as a extra layer of protection. &lt;/p&gt;
&lt;p&gt;- Secondly, svchost.exe should nolonger be asking for DNS outbound requests like it was before.&amp;nbsp;&lt;/p&gt;
&lt;p&gt;- Finally, DNS will also use TCP if enough of its UDP requests fail out or time out shall I say...by design it will do this, but it is rare.&amp;nbsp; With this said, malware once again will attempt to use DNS, except via a TCP connection.&amp;nbsp; This rule should drop anything of this nature also by default.&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; There is only 1 downfall to my recommendation:&amp;nbsp; Sometimes it may take a few extra seconds for a webpage to load here and there.&amp;nbsp; It should not be a big impact on your surfing, but just be forwarned.&amp;nbsp; This rule is basically dropping any DNS requests that do not exactly match it.&amp;nbsp;&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; In my opinion this will tighten DNS security up some on your system, but some may disagree with me.&amp;nbsp; I look forward to any ideas or input anyone may have on this setup. &lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;</description></item><item><title>Workaround to Firefox version problem</title><link>http://forums.eeye.com/forums/thread/1106.aspx</link><pubDate>Tue, 04 Sep 2007 15:11:54 GMT</pubDate><guid isPermaLink="false">a21f7e33-d546-44ed-90ca-b1df844505d6:1106</guid><dc:creator>JayB</dc:creator><slash:comments>2</slash:comments><comments>http://forums.eeye.com/forums/thread/1106.aspx</comments><wfw:commentRss>http://forums.eeye.com/forums/commentrss.aspx?SectionID=12&amp;PostID=1106</wfw:commentRss><description>&lt;p&gt;For some reason, some of my machines  are still reporting in ARP (add remove programs) and the registry as having Firefox 2.0.0.4 rather than the 2.0.0.6 that is actually installed. Because of this Blink is reporting multiple critical vulnerabilities (which existed in 0.4) This might not be an issue but if you are maintaining records for PCI compliance or similar, it is important.  &lt;/p&gt;&lt;p&gt;You can edit these values using regedit in HKLM/software/mozilla. Just edit all the values which say 2.0.0.4 This will now allow you to run the vuln assessment and avoid the critical warnings. &lt;br /&gt;&lt;/p&gt;&lt;p&gt;Standard disclaimer:&amp;nbsp; messing about with the registry... dangerous... backup... yada yada &lt;/p&gt;&lt;p&gt;You must be logged as or using runas admin to edit these values. &lt;br /&gt;&lt;/p&gt;&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;&amp;nbsp;&lt;/p&gt;</description></item><item><title>Blink Internet Security and Anti-Virus</title><link>http://forums.eeye.com/forums/thread/1254.aspx</link><pubDate>Mon, 24 Sep 2007 14:17:03 GMT</pubDate><guid isPermaLink="false">a21f7e33-d546-44ed-90ca-b1df844505d6:1254</guid><dc:creator>Betty</dc:creator><slash:comments>2</slash:comments><comments>http://forums.eeye.com/forums/thread/1254.aspx</comments><wfw:commentRss>http://forums.eeye.com/forums/commentrss.aspx?SectionID=12&amp;PostID=1254</wfw:commentRss><description>&lt;p&gt;I have installed the Blink internet security, but it will not start up.&amp;nbsp; I get a message error code 12002.&lt;/p&gt;</description></item><item><title>This will be a great section...</title><link>http://forums.eeye.com/forums/thread/411.aspx</link><pubDate>Tue, 19 Jun 2007 04:58:50 GMT</pubDate><guid isPermaLink="false">a21f7e33-d546-44ed-90ca-b1df844505d6:411</guid><dc:creator>Brent</dc:creator><slash:comments>1</slash:comments><comments>http://forums.eeye.com/forums/thread/411.aspx</comments><wfw:commentRss>http://forums.eeye.com/forums/commentrss.aspx?SectionID=12&amp;PostID=411</wfw:commentRss><description>&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;This will be a huge help once people start posting - Hopefully Staff will post their best inside user experience knowledge here also..&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;</description></item></channel></rss>