I used to check windows systems with a VB script from silentrunners.org
I always disabled CD, then network, then memory stick autorun.
You could fill a page with file types executable on Windows and most of the stupidity is of MS own making. Why did they think ActiveX in a Browser was a good idea? Why did they think MS Office Macros on by default was a good idea?
So I never used Explorer if possible.
I always had macros disabled in MS Office.
Also a gazillion stupid vulnerable services on by default that most people don't need, or like uPNP shouldn't exist (and stupid firewalls that enable uPNP by default). They are clueless.
|