"The reason I ask is that I was told that if you limit users from ‘installing’ anything XP is pretty bullet proof when in user mode because you or a virus cannot install itself"
I think thats a red herring.
"I do have a hardware firewall and use an antivirus on the system" Why do you have IS at all?
|