| Will "locking" down local permissions to "user" level prohibit the
| installation of spyware on a destop?
No. Some types of spyware or malware will actually change
permissions.
I find that difficult to believe. I've administered networks for some fifty
people at a time, all running as limited users, without one spyware incident
in two years running.
Are you saying that spyware can change a user's access level from Limited
User to Administrator? Hm, maybe if the following conditions were met:
* The built-in Administrator account's password was left blank, and
* The machine runs XP Pro and not XP Home (where Administrator is only
available in Safe Mode)
Seems to me the easy fix to prevent that, is to start the computer in Safe
Mode and change the built-in Administrator's password. But on XP Home it
shouldn't matter since Administrator can't log on "because of a policy
restriction" outside of Safe Mode (try pressing CTRL-ALT-DEL on the Welcome
screen and logging on as "Administrator" on XP Home).
Speaking of such, IS there a way to change the built-in admin account
password from not-safe-mode? Such as from a command line, like the "setpwd"
tool available for Win2K Domain Controllers?