<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="http://blogs.msdn.com/utility/FeedStylesheets/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/"><channel><title>We know IE!</title><link>http://blogs.msdn.com/askie/default.aspx</link><description>This site discusses all things "Internet Explorer"</description><dc:language>en-US</dc:language><generator>CommunityServer 2.1 SP1 (Build: 61025.2)</generator><item><title>Slow performance in Internet Explorer 8 after installing the Skype v4.1 application</title><link>http://blogs.msdn.com/askie/archive/2009/07/17/slow-performance-in-internet-explorer-8-after-installing-the-skype-v4-1-application.aspx</link><pubDate>Fri, 17 Jul 2009 15:00:00 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:9837676</guid><dc:creator>Brent Goodpaster</dc:creator><slash:comments>8</slash:comments><comments>http://blogs.msdn.com/askie/comments/9837676.aspx</comments><wfw:commentRss>http://blogs.msdn.com/askie/commentrss.aspx?PostID=9837676</wfw:commentRss><wfw:comment>http://blogs.msdn.com/askie/rsscomments.aspx?PostID=9837676</wfw:comment><description>&lt;P&gt;Hi everyone!&lt;/P&gt;
&lt;P&gt;We’re seeing another emerging issue around Internet Explorer that we wanted to make you aware of…&lt;/P&gt;
&lt;P&gt;If you are seeing slow performance within Internet Explorer 8 (opening new tabs, for example), after just recently installing the latest version of the Skype application (v4.1), this could be the cause.&amp;nbsp; We believe the reason behind this performance issue is an IE add-on that gets installed by the latest revision of the &lt;EM&gt;Skype&lt;/EM&gt; software.&lt;/P&gt;
&lt;P&gt;To resolve this issue quickly, please open &lt;EM&gt;Managed Add-Ons&lt;/EM&gt; and disable the installed &lt;EM&gt;Skype&lt;/EM&gt; IE add-on:&lt;/P&gt;
&lt;P&gt;&lt;A href="http://blogs.msdn.com/blogfiles/askie/WindowsLiveWriter/SlowperformanceinInternetExplorerafter.1_A897/image_10.png" mce_href="http://blogs.msdn.com/blogfiles/askie/WindowsLiveWriter/SlowperformanceinInternetExplorerafter.1_A897/image_10.png"&gt;&lt;IMG style="BORDER-BOTTOM: 0px; BORDER-LEFT: 0px; DISPLAY: inline; BORDER-TOP: 0px; BORDER-RIGHT: 0px" title=image border=0 alt=image src="http://blogs.msdn.com/blogfiles/askie/WindowsLiveWriter/SlowperformanceinInternetExplorerafter.1_A897/image_thumb_4.png" width=410 height=211 mce_src="http://blogs.msdn.com/blogfiles/askie/WindowsLiveWriter/SlowperformanceinInternetExplorerafter.1_A897/image_thumb_4.png"&gt;&lt;/A&gt; &lt;/P&gt;
&lt;P&gt;&lt;A href="http://blogs.msdn.com/blogfiles/askie/WindowsLiveWriter/SlowperformanceinInternetExplorerafter.1_A897/image_8.png" mce_href="http://blogs.msdn.com/blogfiles/askie/WindowsLiveWriter/SlowperformanceinInternetExplorerafter.1_A897/image_8.png"&gt;&lt;IMG style="BORDER-BOTTOM: 0px; BORDER-LEFT: 0px; DISPLAY: inline; BORDER-TOP: 0px; BORDER-RIGHT: 0px" title=image border=0 alt=image src="http://blogs.msdn.com/blogfiles/askie/WindowsLiveWriter/SlowperformanceinInternetExplorerafter.1_A897/image_thumb_3.png" width=644 height=266 mce_src="http://blogs.msdn.com/blogfiles/askie/WindowsLiveWriter/SlowperformanceinInternetExplorerafter.1_A897/image_thumb_3.png"&gt;&lt;/A&gt; &lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;EM&gt;Please note:&lt;/EM&gt;&lt;/STRONG&gt;&amp;nbsp; So far, we are only seeing this issue with this specific version of &lt;EM&gt;Skype&lt;/EM&gt; in conjunction with Internet Explorer 8.&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;
&lt;P&gt;The IE Support Team&lt;/P&gt;&lt;img src="http://blogs.msdn.com/aggbug.aspx?PostID=9837676" width="1" height="1"&gt;</description><category domain="http://blogs.msdn.com/askie/archive/tags/Solutions/default.aspx">Solutions</category></item><item><title>Unexpected behaviors and failures in Internet Explorer with McAfee Host Intrusion Prevention installed</title><link>http://blogs.msdn.com/askie/archive/2009/07/16/unexpected-behaviors-and-failures-in-internet-explorer-with-mcafee-host-intrusion-prevention-installed.aspx</link><pubDate>Thu, 16 Jul 2009 19:00:00 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:9836157</guid><dc:creator>Brent Goodpaster</dc:creator><slash:comments>4</slash:comments><comments>http://blogs.msdn.com/askie/comments/9836157.aspx</comments><wfw:commentRss>http://blogs.msdn.com/askie/commentrss.aspx?PostID=9836157</wfw:commentRss><wfw:comment>http://blogs.msdn.com/askie/rsscomments.aspx?PostID=9836157</wfw:comment><description>&lt;P&gt;Hi everyone!&lt;/P&gt;
&lt;P&gt;IE Support is seeing a huge influx of issues with weird IE behaviors and failures coming in over the last two days.&amp;nbsp; We are seeing IE crashes, IE simply unloading from memory, and even script errors on web application that have been working in the past without issue.&amp;nbsp; Currently, we are only seeing these errors with Internet Explorer 7 and 8.&lt;/P&gt;
&lt;P&gt;The issue appears to be related to a recent signature update to McAfee’s Host Intrusion Prevention software that was released on July 14, 2009.&lt;/P&gt;
&lt;P&gt;If you are seeing these kinds of behaviors with Internet Explorer since in or around the July 14th, 2009, we recommend that you review the details outlined in this McAfee KB article:&lt;/P&gt;
&lt;P&gt;&lt;A title=https://kc.mcafee.com/corporate/index?page=content&amp;amp;id=KB66316 href="https://kc.mcafee.com/corporate/index?page=content&amp;amp;id=KB66316" target=_blank mce_href="https://kc.mcafee.com/corporate/index?page=content&amp;amp;id=KB66316"&gt;https://kc.mcafee.com/corporate/index?page=content&amp;amp;id=KB66316&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;Our understanding is that a signature update has already been released to resolve this issue.&amp;nbsp; However, if you need further assistance from McAfee technical support in getting the signature update, you can contact them using the information located here:&lt;/P&gt;
&lt;P&gt;&lt;A href="http://www.mcafee.com/us/about/contact/index.html" target=_blank mce_href="http://www.mcafee.com/us/about/contact/index.html"&gt;http://www.mcafee.com/us/about/contact/index.html&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;EM&gt;More information:&lt;/EM&gt;&lt;/STRONG&gt;&amp;nbsp; You can continue to browse in a limited capacity by starting Internet Explorer in No Add Ons mode by using the shortcut located under All Programs | Accessories | System Tools until you update the affected signature file:&lt;/P&gt;
&lt;P&gt;&lt;A href="http://blogs.msdn.com/blogfiles/askie/WindowsLiveWriter/UnexpectedbehaviorsandfailuresinInternet_E8F6/image_2.png" mce_href="http://blogs.msdn.com/blogfiles/askie/WindowsLiveWriter/UnexpectedbehaviorsandfailuresinInternet_E8F6/image_2.png"&gt;&lt;IMG style="BORDER-BOTTOM: 0px; BORDER-LEFT: 0px; DISPLAY: inline; BORDER-TOP: 0px; BORDER-RIGHT: 0px" title=image border=0 alt=image src="http://blogs.msdn.com/blogfiles/askie/WindowsLiveWriter/UnexpectedbehaviorsandfailuresinInternet_E8F6/image_thumb.png" width=487 height=165 mce_src="http://blogs.msdn.com/blogfiles/askie/WindowsLiveWriter/UnexpectedbehaviorsandfailuresinInternet_E8F6/image_thumb.png"&gt;&lt;/A&gt; &lt;/P&gt;
&lt;P&gt;There is also a command line option you can use as well.&amp;nbsp; From a command line window you can using the below option:&lt;/P&gt;
&lt;P&gt;&lt;A href="http://blogs.msdn.com/blogfiles/askie/WindowsLiveWriter/UnexpectedbehaviorsandfailuresinInternet_E8F6/image_4.png" mce_href="http://blogs.msdn.com/blogfiles/askie/WindowsLiveWriter/UnexpectedbehaviorsandfailuresinInternet_E8F6/image_4.png"&gt;&lt;IMG style="BORDER-BOTTOM: 0px; BORDER-LEFT: 0px; DISPLAY: inline; BORDER-TOP: 0px; BORDER-RIGHT: 0px" title=image border=0 alt=image src="http://blogs.msdn.com/blogfiles/askie/WindowsLiveWriter/UnexpectedbehaviorsandfailuresinInternet_E8F6/image_thumb_1.png" width=440 height=85 mce_src="http://blogs.msdn.com/blogfiles/askie/WindowsLiveWriter/UnexpectedbehaviorsandfailuresinInternet_E8F6/image_thumb_1.png"&gt;&lt;/A&gt; &lt;/P&gt;
&lt;P&gt;Once you hit enter, IE will load with no Add Ons within the IE process:&lt;/P&gt;
&lt;P&gt;&lt;A href="http://blogs.msdn.com/blogfiles/askie/WindowsLiveWriter/UnexpectedbehaviorsandfailuresinInternet_E8F6/image_6.png" mce_href="http://blogs.msdn.com/blogfiles/askie/WindowsLiveWriter/UnexpectedbehaviorsandfailuresinInternet_E8F6/image_6.png"&gt;&lt;IMG style="BORDER-BOTTOM: 0px; BORDER-LEFT: 0px; DISPLAY: inline; BORDER-TOP: 0px; BORDER-RIGHT: 0px" title=image border=0 alt=image src="http://blogs.msdn.com/blogfiles/askie/WindowsLiveWriter/UnexpectedbehaviorsandfailuresinInternet_E8F6/image_thumb_2.png" width=613 height=451 mce_src="http://blogs.msdn.com/blogfiles/askie/WindowsLiveWriter/UnexpectedbehaviorsandfailuresinInternet_E8F6/image_thumb_2.png"&gt;&lt;/A&gt; &lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;
&lt;P&gt;The IE Support Team&lt;/P&gt;&lt;img src="http://blogs.msdn.com/aggbug.aspx?PostID=9836157" width="1" height="1"&gt;</description><category domain="http://blogs.msdn.com/askie/archive/tags/Solutions/default.aspx">Solutions</category></item><item><title>FYI:  The patch has been released for the vulnerability outlined in KB972890, see MS09-032</title><link>http://blogs.msdn.com/askie/archive/2009/07/14/fyi-the-patch-has-been-released-for-the-vulnerability-outlined-in-kb972890-see-ms09-032.aspx</link><pubDate>Tue, 14 Jul 2009 17:00:00 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:9833441</guid><dc:creator>Brent Goodpaster</dc:creator><slash:comments>0</slash:comments><comments>http://blogs.msdn.com/askie/comments/9833441.aspx</comments><wfw:commentRss>http://blogs.msdn.com/askie/commentrss.aspx?PostID=9833441</wfw:commentRss><wfw:comment>http://blogs.msdn.com/askie/rsscomments.aspx?PostID=9833441</wfw:comment><description>&lt;P&gt;Just in!&lt;/P&gt;
&lt;P&gt;A cumulative release is now available for the vulnerability outlined in &lt;A href="http://support.microsoft.com/kb/972890" target=_blank mce_href="http://support.microsoft.com/kb/972890"&gt;KB972890&lt;/A&gt;.&amp;nbsp; Details and downloads can be found here:&lt;/P&gt;
&lt;P&gt;&lt;A title=http://www.microsoft.com/technet/security/Bulletin/MS09-032.mspx href="http://www.microsoft.com/technet/security/Bulletin/MS09-032.mspx" target=_blank mce_href="http://www.microsoft.com/technet/security/Bulletin/MS09-032.mspx"&gt;http://www.microsoft.com/technet/security/Bulletin/MS09-032.mspx&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;If you have any questions regarding what do you if you already have a workaround in place, please review the FAQ for MS09-032 using the link above.&lt;/P&gt;
&lt;P mce_keep="true"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;EM&gt;Please note:&lt;/EM&gt;&lt;/STRONG&gt;&amp;nbsp; &lt;/P&gt;
&lt;P&gt;The majority of customers have automatic updating enabled and will not need to take any action because this security update will be downloaded and installed automatically. Customers who have not enabled automatic updating need to check for updates and install this update manually. For information about specific configuration options in automatic updating, see &lt;A href="http://support.microsoft.com/kb/294871" mce_href="http://support.microsoft.com/kb/294871"&gt;Microsoft Knowledge Base Article 294871&lt;/A&gt;.&lt;/P&gt;
&lt;P mce_keep="true"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;
&lt;P&gt;The IE Support Team&lt;/P&gt;&lt;img src="http://blogs.msdn.com/aggbug.aspx?PostID=9833441" width="1" height="1"&gt;</description><category domain="http://blogs.msdn.com/askie/archive/tags/Security/default.aspx">Security</category></item><item><title>Group Policy ADM template to implement the workaround from Security advisory 973472</title><link>http://blogs.msdn.com/askie/archive/2009/07/14/group-policy-adm-template-to-implement-the-workaround-from-security-advisory-973472.aspx</link><pubDate>Tue, 14 Jul 2009 16:30:00 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:9833325</guid><dc:creator>Brent Goodpaster</dc:creator><slash:comments>2</slash:comments><comments>http://blogs.msdn.com/askie/comments/9833325.aspx</comments><wfw:commentRss>http://blogs.msdn.com/askie/commentrss.aspx?PostID=9833325</wfw:commentRss><wfw:comment>http://blogs.msdn.com/askie/rsscomments.aspx?PostID=9833325</wfw:comment><description>&lt;P&gt;Hi everyone!&lt;/P&gt;
&lt;P&gt;Axel here from the IE Team with a quick Group Policy ADM template to help implement workaround described in security advisory &lt;A href="http://www.microsoft.com/technet/security/advisory/973472.mspx" target=_blank mce_href="http://www.microsoft.com/technet/security/advisory/973472.mspx"&gt;973472&lt;/A&gt;. I am also including the .reg file and .adm templates for both x86 and x64 versions.&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;EM&gt;Please note:&lt;/EM&gt;&lt;/STRONG&gt;&amp;nbsp; This is&amp;nbsp;an “as is” template, so feel free to tweak it as needed.&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Important&lt;/STRONG&gt;: This policy requires that you disable filtering in the group policy editor. See steps below on how to set this up.&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;How to load the Custom ADM Template?&lt;/STRONG&gt;&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;To start Group Policy, click Start and then click Run. In the Open box, type GPedit.msc or GPMC.msc if from a Domain policy and then click OK. &lt;/LI&gt;
&lt;LI&gt;Select Administrative Templates from the Computer Configuration branch. &lt;/LI&gt;
&lt;LI&gt;Right-click the Administrative Templates branch, and then select All Tasks. &lt;/LI&gt;
&lt;LI&gt;Select Add/Remove Templates. &lt;/LI&gt;
&lt;LI&gt;Click Add. &lt;/LI&gt;
&lt;LI&gt;Load the ADM templates.&lt;/LI&gt;&lt;/OL&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;EM&gt;Please note:&lt;/EM&gt;&lt;/STRONG&gt; Windows 2003, Windows XP will display the policy under: Administrative Templates &amp;gt; New Policy&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Here is how you disable the Group policy filer:&lt;/STRONG&gt;&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;Right click on the Policy and select View &amp;gt; detail &amp;gt; Filtering &lt;/LI&gt;
&lt;LI&gt;Remove the check mark from the check box next to "Only show policy settings that can be fully managed" &lt;/LI&gt;
&lt;LI&gt;You should see the template now.&lt;/LI&gt;&lt;/OL&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;x86 ADM Template&lt;/STRONG&gt;&lt;/P&gt;
&lt;TABLE border=1 cellSpacing=0 cellPadding=2 width=747&gt;
&lt;TBODY&gt;
&lt;TR&gt;
&lt;TD vAlign=top width=745&gt;
&lt;P&gt;;####################### Begin x86 adm setting&amp;nbsp; ########################### &lt;/P&gt;
&lt;P&gt;CLASS MACHINE &lt;/P&gt;
&lt;P&gt;CATEGORY "Group Policy workaround for KB973472, x86" &lt;/P&gt;
&lt;P&gt;POLICY "MS 973472 Activex component {0002E541-0000-0000-C000-000000000046}" &lt;BR&gt;KEYNAME "SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{0002E541-0000-0000-C000-000000000046}" &lt;BR&gt;EXPLAIN "Group Policy to disable CLSIDs outlined in the workaround section of kb973472" &lt;BR&gt;VALUENAME "Compatibility Flags" &lt;BR&gt;VALUEON NUMERIC 1024 &lt;BR&gt;VALUEOFF NUMERIC 0 &lt;BR&gt;END POLICY &lt;/P&gt;
&lt;P&gt;POLICY "MS 973472 Activex component {0002E559-0000-0000-C000-000000000046}" &lt;BR&gt;KEYNAME "SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{0002E559-0000-0000-C000-000000000046}" &lt;BR&gt;EXPLAIN "Group Policy to disable CLSIDs outlined in the workaround section of kb973472" &lt;BR&gt;VALUENAME "Compatibility Flags" &lt;BR&gt;VALUEON NUMERIC 1024 &lt;BR&gt;VALUEOFF NUMERIC 0 &lt;BR&gt;END POLICY &lt;BR&gt;END CATEGORY &lt;/P&gt;
&lt;P&gt;[strings] &lt;BR&gt;kb973472="kb973472" &lt;BR&gt;kb973472="Microsoft Security Advisory: Vulnerability in Microsoft Video ActiveX control could allow remote code execution "&lt;/P&gt;
&lt;P&gt;;####################### End of x86 adm setting&amp;nbsp; ########################### &lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;
&lt;P&gt;&lt;STRONG&gt;x64 ADM Template&lt;/STRONG&gt;&lt;/P&gt;
&lt;TABLE border=1 cellSpacing=0 cellPadding=2 width=750&gt;
&lt;TBODY&gt;
&lt;TR&gt;
&lt;TD vAlign=top width=748&gt;
&lt;P&gt;;####################### Begin x64 adm setting&amp;nbsp; ########################### &lt;/P&gt;
&lt;P&gt;CLASS MACHINE &lt;/P&gt;
&lt;P&gt;CATEGORY "Group Policy workaround for KB973472, x64" &lt;/P&gt;
&lt;P&gt;POLICY "MS 973472 Activex component {0002E541-0000-0000-C000-000000000046}" &lt;BR&gt;KEYNAME "SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\ActiveX Compatibility\{0002E541-0000-0000-C000-000000000046}" &lt;BR&gt;EXPLAIN "Group Policy to disable CLSIDs outlined in the workaround section of kb973472" &lt;BR&gt;VALUENAME "Compatibility Flags" &lt;BR&gt;VALUEON NUMERIC 1024 &lt;BR&gt;VALUEOFF NUMERIC 0 &lt;BR&gt;END POLICY &lt;/P&gt;
&lt;P&gt;POLICY "MS 973472 Activex component {0002E559-0000-0000-C000-000000000046}" &lt;BR&gt;KEYNAME "SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\ActiveX Compatibility\{0002E559-0000-0000-C000-000000000046}" &lt;BR&gt;EXPLAIN "Group Policy to disable CLSIDs outlined in the workaround section of kb973472" &lt;BR&gt;VALUENAME "Compatibility Flags" &lt;BR&gt;VALUEON NUMERIC 1024 &lt;BR&gt;VALUEOFF NUMERIC 0 &lt;BR&gt;END POLICY &lt;BR&gt;END CATEGORY &lt;/P&gt;
&lt;P&gt;[strings] &lt;BR&gt;kb973472="kb973472" &lt;BR&gt;kb973472="Microsoft Security Advisory: Vulnerability in Microsoft Video ActiveX control could allow remote code execution " &lt;/P&gt;
&lt;P&gt;;####################### End of x64 adm setting&amp;nbsp; ########################### &lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;
&lt;P&gt;&lt;STRONG&gt;x64 Registry key&lt;/STRONG&gt;&lt;/P&gt;
&lt;TABLE border=1 cellSpacing=0 cellPadding=2 width=400&gt;
&lt;TBODY&gt;
&lt;TR&gt;
&lt;TD vAlign=top width=400&gt;
&lt;P&gt;Windows Registry Editor Version 5.00 &lt;/P&gt;
&lt;P&gt;[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\ActiveX Compatibility\{0002E541-0000-0000-C000-000000000046}] &lt;BR&gt;"Compatibility Flags"=dword:00000400 &lt;BR&gt;[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\ActiveX Compatibility\{0002E559-0000-0000-C000-000000000046}] &lt;BR&gt;"Compatibility Flags"=dword:00000400&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;
&lt;P&gt;&lt;STRONG&gt;x86 Registry key&lt;/STRONG&gt;&lt;/P&gt;
&lt;TABLE border=1 cellSpacing=0 cellPadding=2 width=477&gt;
&lt;TBODY&gt;
&lt;TR&gt;
&lt;TD vAlign=top width=475&gt;
&lt;P&gt;Windows Registry Editor Version 5.00 &lt;/P&gt;
&lt;P&gt;[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{0002E541-0000-0000-C000-000000000046}] &lt;BR&gt;"Compatibility Flags"=dword:00000400 &lt;BR&gt;[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{0002E559-0000-0000-C000-000000000046}] &lt;BR&gt;"Compatibility Flags"=dword:00000400&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;
&lt;P&gt;We also have the above samples available to download &lt;A href="http://blogs.msdn.com/askie/attachment/9833325.ashx" target=_blank mce_href="http://blogs.msdn.com/askie/attachment/9833325.ashx"&gt;here&lt;/A&gt;.&lt;/P&gt;
&lt;P mce_keep="true"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;
&lt;P&gt;The IE Support Team&lt;/P&gt;&lt;img src="http://blogs.msdn.com/aggbug.aspx?PostID=9833325" width="1" height="1"&gt;</description><enclosure url="http://blogs.msdn.com/askie/attachment/9833325.ashx" length="2775" type="application/x-zip-compressed" /><category domain="http://blogs.msdn.com/askie/archive/tags/Group+Policy/default.aspx">Group Policy</category><category domain="http://blogs.msdn.com/askie/archive/tags/Solutions/default.aspx">Solutions</category></item><item><title>IE8: VS 2005 Script debugging is broken after installing IE8 on Windows Vista</title><link>http://blogs.msdn.com/askie/archive/2009/07/14/ie8-vs-2005-script-debugging-is-broken-after-installing-ie8-on-windows-vista.aspx</link><pubDate>Tue, 14 Jul 2009 16:00:00 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:9833423</guid><dc:creator>Brent Goodpaster</dc:creator><slash:comments>1</slash:comments><comments>http://blogs.msdn.com/askie/comments/9833423.aspx</comments><wfw:commentRss>http://blogs.msdn.com/askie/commentrss.aspx?PostID=9833423</wfw:commentRss><wfw:comment>http://blogs.msdn.com/askie/rsscomments.aspx?PostID=9833423</wfw:comment><description>&lt;p&gt;Hi everyone!&lt;/p&gt;  &lt;p&gt;Veena here to discuss an issue that might affect developers using Visual Studio 2005 to perform client side script debugging.&lt;/p&gt;  &lt;p&gt;&amp;#160; &lt;/p&gt;  &lt;p&gt;After you install Internet Explorer 8, you may no longer be able to perform client side script debugging using Visual Studio 2005. This issue is discussed in &lt;a href="http://blogs.msdn.com/greggm/archive/2009/04/01/script-debugging-broken-in-vs-2005-after-installing-ie8.aspx"&gt;http://blogs.msdn.com/greggm/archive/2009/04/01/script-debugging-broken-in-vs-2005-after-installing-ie8.aspx&lt;/a&gt;.&lt;/p&gt;  &lt;p&gt;Typically, setting the registry value : TabProcGrowth to a DWORD value of 0 is sufficient to resolve this problem.&amp;#160; However, if you are using Windows Vista, you need to follow ALL of the steps below to resolve this issue:&lt;/p&gt;  &lt;p&gt;1) Install VS 2005 update for Vista from &lt;a href="http://www.microsoft.com/downloads/details.aspx?FamilyID=90e2942d-3ad1-4873-a2ee-4acc0aace5b6&amp;amp;displaylang=en"&gt;http://www.microsoft.com/downloads/details.aspx?FamilyID=90e2942d-3ad1-4873-a2ee-4acc0aace5b6&amp;amp;displaylang=en&lt;/a&gt;.&lt;/p&gt;  &lt;p&gt;2) Install Visual Web Developer express from &lt;a href="http://www.microsoft.com/express/vwd/Default.aspx"&gt;http://www.microsoft.com/express/vwd/Default.aspx&lt;/a&gt;.&amp;#160; This is to update PDM.DLL to the required version.&lt;/p&gt;  &lt;p&gt;&lt;strong&gt;&lt;em&gt;Please note:&lt;/em&gt;&lt;/strong&gt;&amp;#160; You don't need to actually use it and can remove it after it is installed. Visual Web Developer express is the free Express SKU for VS2008.&lt;/p&gt;  &lt;p&gt;3) Set the registry value : TabProcGrowth to a DWORD value of 0 under HKCU\Software\Microsoft\Internet Explorer\Main.&lt;/p&gt;  &lt;p&gt;4) Run Visual Studio 2005 with elevated permissions.&lt;/p&gt;  &lt;p&gt;&amp;#160;&lt;/p&gt;  &lt;p&gt;&lt;strong&gt;&lt;em&gt;Please note:&lt;/em&gt;&lt;/strong&gt; This is a problem in Visual Studio 2005 and doesn’t happen with Visual Studio 2008. &lt;/p&gt;  &lt;p&gt;&amp;#160;&lt;/p&gt;  &lt;p&gt;Regards,&lt;/p&gt;  &lt;p&gt;The IE Support Team&lt;/p&gt;&lt;img src="http://blogs.msdn.com/aggbug.aspx?PostID=9833423" width="1" height="1"&gt;</description><category domain="http://blogs.msdn.com/askie/archive/tags/SDK/default.aspx">SDK</category><category domain="http://blogs.msdn.com/askie/archive/tags/Solutions/default.aspx">Solutions</category></item><item><title>How to bypass the web page to save Internet Explorer 7 settings</title><link>http://blogs.msdn.com/askie/archive/2009/07/14/how-to-bypass-the-web-page-to-save-internet-explorer-7-settings.aspx</link><pubDate>Tue, 14 Jul 2009 13:00:00 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:9833293</guid><dc:creator>Brent Goodpaster</dc:creator><slash:comments>3</slash:comments><comments>http://blogs.msdn.com/askie/comments/9833293.aspx</comments><wfw:commentRss>http://blogs.msdn.com/askie/commentrss.aspx?PostID=9833293</wfw:commentRss><wfw:comment>http://blogs.msdn.com/askie/rsscomments.aspx?PostID=9833293</wfw:comment><description>&lt;p&gt;Hi everyone!&lt;/p&gt;  &lt;p&gt;&amp;#160;&lt;/p&gt;  &lt;p&gt;Here’s a quick blog to help users and administrators by-pass that initial web page asking you to save your settings after IE7 is installed…&lt;/p&gt;  &lt;p&gt;&amp;#160;&lt;/p&gt;  &lt;p&gt;After installing Internet Explorer 7 all users are supposed to save their settings, the IE automatically redirects the page to &amp;quot;&lt;a href="http://go.microsoft.com/fwlink/?LinkId=74005&amp;quot;"&gt;http://go.microsoft.com/fwlink/?LinkId=74005&amp;quot;&lt;/a&gt; which redirects to &amp;quot;&lt;a href="http://runonce.msn.com/runonce2.aspx&amp;quot;"&gt;http://runonce.msn.com/runonce2.aspx&amp;quot;&lt;/a&gt; till the user saves the settings to set their preferences such as the default search engine, whether turn on automatic Phishing Filter, language settings and so on. &lt;/p&gt;  &lt;p&gt;If the customer does not want to be auto-directed to this web page, then they need to follow the below steps.&amp;#160; Two values should be added/modified in the registry, so that IE 7 will go to the home page instead of the external link above:&lt;/p&gt;  &lt;p&gt;1. Open the regedit.exe applet.   &lt;br /&gt;2. Go to registry key:    &lt;br /&gt;[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]     &lt;br /&gt;3. Right-click this key and select New -&amp;gt; DWORD Value.    &lt;br /&gt;4. On the right pane, create the new value to RunOnceComplete.    &lt;br /&gt;5. Right-click RunOnceComplete and click “Modify” and set the value data to 1.    &lt;br /&gt;6. Repeat Step 3 to Step 5 to create/modify the value name RunOnceHasShown and set the value data to 1.    &lt;br /&gt;7. Restart the IE 7 to see if it still visits the Save settings web site.&lt;/p&gt;  &lt;p&gt;&amp;#160;&lt;/p&gt;  &lt;p&gt;If you are familiar with using .REG files, then you can use what’s below to create one and use:&lt;/p&gt;  &lt;p&gt;&amp;#160;&lt;/p&gt;  &lt;p&gt;Windows Registry Editor Version 5.00 &lt;/p&gt;  &lt;p&gt;[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]   &lt;br /&gt;&amp;quot;RunOnceComplete&amp;quot;=dword:00000001    &lt;br /&gt;&amp;quot;RunOnceHasShown&amp;quot;=dword:00000001&lt;/p&gt;  &lt;p&gt;&amp;#160;&lt;/p&gt;  &lt;p&gt;&lt;strong&gt;&lt;em&gt;Please note:&lt;/em&gt;&lt;/strong&gt; IE7 will query the two values RunOnceComplete and RunOnceHasShown every time it starts. If these values have been set as depicted above, IE will visit the home page set in the IE control panel.&lt;/p&gt;  &lt;p&gt;For terminal server, you can set a log-on script, so that these two values will be added and set automatically when users connect to the server.&lt;/p&gt;  &lt;p&gt;&amp;#160;&lt;/p&gt;  &lt;p&gt;Regards,&lt;/p&gt;  &lt;p&gt;The IE Support Team&lt;/p&gt;&lt;img src="http://blogs.msdn.com/aggbug.aspx?PostID=9833293" width="1" height="1"&gt;</description><category domain="http://blogs.msdn.com/askie/archive/tags/Solutions/default.aspx">Solutions</category></item><item><title>Custom ADM template for managing “Check for publisher's certificate revocation” in Internet Explorer</title><link>http://blogs.msdn.com/askie/archive/2009/07/09/custom-adm-template-for-managing-check-for-publisher-s-certificate-revocation-in-internet-explorer.aspx</link><pubDate>Thu, 09 Jul 2009 19:00:00 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:9827733</guid><dc:creator>Brent Goodpaster</dc:creator><slash:comments>1</slash:comments><comments>http://blogs.msdn.com/askie/comments/9827733.aspx</comments><wfw:commentRss>http://blogs.msdn.com/askie/commentrss.aspx?PostID=9827733</wfw:commentRss><wfw:comment>http://blogs.msdn.com/askie/rsscomments.aspx?PostID=9827733</wfw:comment><description>&lt;P&gt;Hi everyone!&lt;/P&gt;
&lt;P&gt;We’ve had some requests come in asking for an ADM template that would give Administrators the option to Enable or Disable the “Check for publisher's certificate revocation” Internet Explorer option.&amp;nbsp; In any event, here it is.&amp;nbsp; Simply cut/paste the content below into a file with .ADM extension and then add custom template manually:&lt;/P&gt;
&lt;P&gt;CLASS USER &lt;BR&gt;CATEGORY "Windows Components" &lt;BR&gt;CATEGORY "Internet Explorer" &lt;BR&gt;CATEGORY "Internet Control Panel" &lt;BR&gt;CATEGORY "Advanced Page" &lt;BR&gt;POLICY "Check for publisher's certificate revocation" &lt;BR&gt;KEYNAME "Software\Microsoft\Windows\CurrentVersion\WinTrust\Trust Providers\Software Publishing" &lt;BR&gt;EXPLAIN "Custom ADM template to Enable/Disable the IE advanced option, “Check for publisher's certificate revocation”" &lt;BR&gt;PART State DROPDOWNLIST REQUIRED &lt;BR&gt;VALUENAME "State" &lt;BR&gt;ITEMLIST &lt;BR&gt;NAME Enabled VALUE NUMERIC 146432 &lt;BR&gt;NAME Disabled VALUE NUMERIC 146944 &lt;BR&gt;END ITEMLIST &lt;BR&gt;END PART &lt;BR&gt;END POLICY &lt;BR&gt;END CATEGORY &lt;BR&gt;END CATEGORY &lt;BR&gt;END CATEGORY &lt;BR&gt;END CATEGORY&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;&lt;STRONG&gt;Please note:&lt;/STRONG&gt;&lt;/EM&gt;&amp;nbsp; You will need to disable the Group Policy filter option, “Only show policy settings that can be fully managed”, before the custom ADM template policy will be displayed:&lt;/P&gt;
&lt;P&gt;&lt;A href="http://blogs.msdn.com/blogfiles/askie/WindowsLiveWriter/CustomADMtemplateforCheckforpublishersce_ED66/image_4.png" mce_href="http://blogs.msdn.com/blogfiles/askie/WindowsLiveWriter/CustomADMtemplateforCheckforpublishersce_ED66/image_4.png"&gt;&lt;IMG style="BORDER-BOTTOM: 0px; BORDER-LEFT: 0px; DISPLAY: inline; BORDER-TOP: 0px; BORDER-RIGHT: 0px" title=image border=0 alt=image src="http://blogs.msdn.com/blogfiles/askie/WindowsLiveWriter/CustomADMtemplateforCheckforpublishersce_ED66/image_thumb_1.png" width=382 height=369 mce_src="http://blogs.msdn.com/blogfiles/askie/WindowsLiveWriter/CustomADMtemplateforCheckforpublishersce_ED66/image_thumb_1.png"&gt;&lt;/A&gt; &lt;/P&gt;
&lt;P&gt;Well, that’s all for now!&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;
&lt;P&gt;The IE Support Team&lt;/P&gt;&lt;img src="http://blogs.msdn.com/aggbug.aspx?PostID=9827733" width="1" height="1"&gt;</description><category domain="http://blogs.msdn.com/askie/archive/tags/Group+Policy/default.aspx">Group Policy</category><category domain="http://blogs.msdn.com/askie/archive/tags/Solutions/default.aspx">Solutions</category></item><item><title>Quick and dirty Group Policy ADM template to implement the workaround from KB972890</title><link>http://blogs.msdn.com/askie/archive/2009/07/08/quick-and-dirty-group-policy-adm-template-to-implement-the-workaround-from-kb972890.aspx</link><pubDate>Wed, 08 Jul 2009 20:30:00 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:9825065</guid><dc:creator>Brent Goodpaster</dc:creator><slash:comments>5</slash:comments><comments>http://blogs.msdn.com/askie/comments/9825065.aspx</comments><wfw:commentRss>http://blogs.msdn.com/askie/commentrss.aspx?PostID=9825065</wfw:commentRss><wfw:comment>http://blogs.msdn.com/askie/rsscomments.aspx?PostID=9825065</wfw:comment><description>&lt;P&gt;Hey folks!&lt;/P&gt;
&lt;P&gt;We’ve received many many requests asking if the workaround mentioned in &lt;A title="KB972890 Vulnerability in Microsoft Video ActiveX Control Could Allow Remote Code Execution" href="http://www.microsoft.com/technet/security/advisory/972890.mspx" target=_blank mce_href="http://www.microsoft.com/technet/security/advisory/972890.mspx"&gt;KB972890&lt;/A&gt; can be implemented via Group Policy.&amp;nbsp; To that end, we’ve put together an ADM template to help Domain Admins roll this out through Group Policy.&amp;nbsp; It’s an “as is” template, so feel free to tweak it as needed.&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Important&lt;/STRONG&gt;: This policy requires that you disable filtering in the group policy editor. See steps below on how to set this up.&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;How to load the Custom ADM Template?&lt;/STRONG&gt;&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;To start Group Policy, click Start and then click Run. In the Open box, type GPEdit.msc or GPMC.msc if from a Domain policy and then click OK. &lt;/LI&gt;
&lt;LI&gt;Select Administrative Templates from the Computer Configuration branch. &lt;/LI&gt;
&lt;LI&gt;Right-click the Administrative Templates branch, and then select All Tasks. &lt;/LI&gt;
&lt;LI&gt;Select Add/Remove Templates. &lt;/LI&gt;
&lt;LI&gt;Click Add. &lt;/LI&gt;
&lt;LI&gt;Load the ADM templates.&lt;BR&gt;&lt;/LI&gt;&lt;/OL&gt;
&lt;P&gt;&lt;STRONG&gt;NOTE:&lt;/STRONG&gt; Windows 2003, Windows XP will display the policy under: Administrative Templates &amp;gt; New Polcy&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Here is how you disable the Group policy filer:&lt;/STRONG&gt;&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;Right click on the Policy and select View &amp;gt; detail &amp;gt; Filtering&lt;/LI&gt;
&lt;LI&gt;Remove the checkmark from the checkbox next to "Only show policy settings that can be fully managed"&lt;/LI&gt;
&lt;LI&gt;You should see the template now.&lt;/LI&gt;&lt;/OL&gt;
&lt;P style="COLOR: #ff0003"&gt;&lt;BR&gt;&lt;STRONG&gt;Please see the attached file below that contains the ADM templates.&lt;/STRONG&gt;&lt;/P&gt;
&lt;P style="COLOR: #000000"&gt;&lt;STRONG&gt;&lt;U&gt;Note:&lt;/U&gt;&lt;/STRONG&gt; &lt;/P&gt;
&lt;P style="COLOR: #000000"&gt;We have updated the template base on some great feedback from our readers. When the policy is enable will set the value to hex 1024&amp;nbsp; and when disable to 0.&lt;/P&gt;
&lt;P style="COLOR: #000000"&gt;In the Zip file [&lt;A id=ctl00___ctl00___ctl01___Entry___Attachment___DownLoadLink title="Custome ADM Template to disable CLSIDs outlined in the workaround section of kb972890" href="http://blogs.msdn.com/askie/attachment/9825065.ashx" mce_href="http://blogs.msdn.com/askie/attachment/9825065.ashx" s_oidt="0" s_oid="http://blogs.msdn.com/askie/attachment/9825065.ashx"&gt;&lt;FONT color=#0000cc&gt;ADM_KB972890_v_07-09-09.zip&lt;/FONT&gt;&lt;/A&gt;], you should find:&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;The IE 32 bit custom adm version: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility]&lt;/LI&gt;
&lt;LI&gt;The IE Wow6432Node (x64) custom adm version: HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\ActiveX Compatibility&lt;/LI&gt;
&lt;LI&gt;The registry export (.reg) export for both IE 32 bit and x64 IE version.&lt;/LI&gt;
&lt;LI&gt;Readme.txt with our Registry import disclaimer.&lt;/LI&gt;&lt;/OL&gt;
&lt;P mce_keep="true"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P mce_keep="true"&gt;&lt;STRONG&gt;Related Article:&lt;/STRONG&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;
&lt;DIV mce_keep="true"&gt;&lt;A id=bp___v___r___postlist___EntryItems_ctl01_PostTitle href="http://blogs.msdn.com/askie/archive/2009/07/07/fixit-available-for-the-vulnerability-in-the-microsoft-video-activex-control-microsoft-security-advisory-972890.aspx"&gt;&lt;FONT color=#0000cc&gt;FixIT available for the vulnerability in the Microsoft Video ActiveX Control, Microsoft Security Advisory (972890)&lt;/FONT&gt;&lt;/A&gt; &lt;/DIV&gt;&lt;/LI&gt;&lt;/UL&gt;
&lt;P mce_keep="true"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;
&lt;P&gt;The IE Support Team&lt;BR&gt;&lt;/P&gt;
&lt;P mce_keep="true"&gt;&amp;nbsp;&lt;/P&gt;&lt;img src="http://blogs.msdn.com/aggbug.aspx?PostID=9825065" width="1" height="1"&gt;</description><enclosure url="http://blogs.msdn.com/askie/attachment/9825065.ashx" length="7333" type="application/x-zip-compressed" /><category domain="http://blogs.msdn.com/askie/archive/tags/Group+Policy/default.aspx">Group Policy</category><category domain="http://blogs.msdn.com/askie/archive/tags/Security/default.aspx">Security</category><category domain="http://blogs.msdn.com/askie/archive/tags/Solutions/default.aspx">Solutions</category></item><item><title>FixIT available for the vulnerability in the Microsoft Video ActiveX Control, Microsoft Security Advisory (972890)</title><link>http://blogs.msdn.com/askie/archive/2009/07/07/fixit-available-for-the-vulnerability-in-the-microsoft-video-activex-control-microsoft-security-advisory-972890.aspx</link><pubDate>Tue, 07 Jul 2009 12:00:00 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:9822710</guid><dc:creator>Brent Goodpaster</dc:creator><slash:comments>3</slash:comments><comments>http://blogs.msdn.com/askie/comments/9822710.aspx</comments><wfw:commentRss>http://blogs.msdn.com/askie/commentrss.aspx?PostID=9822710</wfw:commentRss><wfw:comment>http://blogs.msdn.com/askie/rsscomments.aspx?PostID=9822710</wfw:comment><description>&lt;P&gt;Hi Everyone!&lt;/P&gt;
&lt;P&gt;Just wanted to let everyone know that a FixIT is currently available to help users protect themselves against this latest ActiveX Control vulnerability outlined here:&amp;nbsp; &lt;A title=http://www.microsoft.com/technet/security/advisory/972890.mspx href="http://www.microsoft.com/technet/security/advisory/972890.mspx" target=_blank mce_href="http://www.microsoft.com/technet/security/advisory/972890.mspx"&gt;http://www.microsoft.com/technet/security/advisory/972890.mspx&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;The FixIT, when run, will automatically disable the Microsoft Video ActiveX Control.&amp;nbsp; More information, as well as the FixIT files themselves, can be found here:&amp;nbsp; &lt;A title=http://support.microsoft.com/kb/972890 href="http://support.microsoft.com/kb/972890" mce_href="http://support.microsoft.com/kb/972890"&gt;http://support.microsoft.com/kb/972890&lt;/A&gt;&lt;/P&gt;
&lt;P mce_keep="true"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Related Article:&lt;/STRONG&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;A id=bp___v___r___postlist___EntryItems_ctl00_PostTitle href="http://blogs.msdn.com/askie/archive/2009/07/08/quick-and-dirty-group-policy-adm-template-to-implement-the-workaround-from-kb972890.aspx"&gt;&lt;FONT color=#0000cc&gt;Quick and dirty Group Policy ADM template to implement the workaround from KB972890&lt;/FONT&gt;&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A title="How can I run a “Fix IT” silently?" href="http://blogs.msdn.com/askie/archive/2009/03/30/how-can-i-run-fix-it-with-quiet-msiexec-switch.aspx" mce_href="http://blogs.msdn.com/askie/archive/2009/03/30/how-can-i-run-fix-it-with-quiet-msiexec-switch.aspx"&gt;How can I run a “Fix IT” silently?&lt;/A&gt;&lt;/LI&gt;&lt;/UL&gt;
&lt;P mce_keep="true"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P mce_keep="true"&gt;Regards,&lt;/P&gt;
&lt;P&gt;The IE Support Team&lt;/P&gt;&lt;img src="http://blogs.msdn.com/aggbug.aspx?PostID=9822710" width="1" height="1"&gt;</description><category domain="http://blogs.msdn.com/askie/archive/tags/Security/default.aspx">Security</category><category domain="http://blogs.msdn.com/askie/archive/tags/Solutions/default.aspx">Solutions</category></item><item><title>How to disable DEP/NS Memory protection in IE 8 via policy</title><link>http://blogs.msdn.com/askie/archive/2009/07/02/how-to-disable-dep-ns-memory-protection-in-ie-8-via-policy.aspx</link><pubDate>Thu, 02 Jul 2009 20:00:00 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:9815279</guid><dc:creator>Brent Goodpaster</dc:creator><slash:comments>1</slash:comments><comments>http://blogs.msdn.com/askie/comments/9815279.aspx</comments><wfw:commentRss>http://blogs.msdn.com/askie/commentrss.aspx?PostID=9815279</wfw:commentRss><wfw:comment>http://blogs.msdn.com/askie/rsscomments.aspx?PostID=9815279</wfw:comment><description>&lt;p&gt;Hi Everyone!&lt;/p&gt;  &lt;p&gt;Axel again, from the IE Escalation team, with another Group Policy pointer. &lt;/p&gt;  &lt;p&gt;Recently, I was asked to assist in disabling DEP (Data Execution Prevention) for Internet Explorer. This can be done from Group.&amp;#160; The policy will allow you to turn off the Data Execution Prevention feature that is now on by default when you install Internet Explorer 8. There are good reasons why this is turned on by default and you should read about it &lt;a href="http://blogs.msdn.com/ie/archive/2008/04/08/ie8-security-part-I_3A00_-dep-nx-memory-protection.aspx" target="_blank"&gt;here&lt;/a&gt; before making a conscious decision to turn it off with this policy. &lt;/p&gt;  &lt;p&gt;   &lt;table border="1" cellspacing="0" cellpadding="0"&gt;&lt;tbody&gt;       &lt;tr&gt;         &lt;td valign="top" width="755"&gt;           &lt;p&gt;&lt;em&gt;&lt;strong&gt;Please note&lt;/strong&gt;:&lt;/em&gt; Please understand, that the policy should only be implemented if absolutely necessary as bypassing Memory Protection could cause serious damage to your computer and organization.&lt;/p&gt;         &lt;/td&gt;       &lt;/tr&gt;     &lt;/tbody&gt;&lt;/table&gt; &lt;/p&gt;  &lt;p&gt;&lt;strong&gt;Policy description:&amp;#160; &lt;/strong&gt;This policy setting allows you to turn off the Data Execution Prevention feature for Internet Explorer on Windows Server 2008, Windows Vista SP1 and Windows XP SP3. &lt;/p&gt;  &lt;p&gt;If you enable this policy setting, Internet Explorer will not opt-in to Data Execution Prevention on platforms that support the SetProcessDEPPolicy API. &lt;/p&gt;  &lt;p&gt;If you disable or do not configure this policy, Internet Explorer will use the SetProcessDEPPolicy API to turn on Data Execution Prevention protection on platforms that support the API. &lt;/p&gt;  &lt;p&gt;This policy has no effect if Windows has been configured to enable Data Execution Prevention.&lt;/p&gt;  &lt;p&gt;&lt;strong&gt;Location:&lt;/strong&gt; Computer Configuration &amp;gt; Internet Explorer &amp;gt; Security Features &amp;gt; Turn off Data Execution Prevention&lt;/p&gt;  &lt;p&gt;&lt;strong&gt;Screenshot of the policy:&lt;/strong&gt;&lt;/p&gt;  &lt;p&gt;&lt;a href="file:///C:\Users\axelr\AppData\Local\Temp\1\WindowsLiveWriter1286139640\supfiles51B4D526\image%5b4%5d.png"&gt;&lt;img style="border-bottom: 0px; border-left: 0px; display: inline; border-top: 0px; border-right: 0px" title="clip_image002" border="0" alt="clip_image002" src="http://blogs.msdn.com/blogfiles/askie/WindowsLiveWriter/HowtodisableDEPNSMemoryprotectioninIE8vi_FFB5/clip_image002_6eea9dce-e348-49cc-9ecc-cc7eb6c76a9e.gif" width="766" height="489" /&gt;&lt;/a&gt;&lt;/p&gt;  &lt;p&gt;&lt;strong&gt;More information:&lt;/strong&gt;&lt;/p&gt;  &lt;ol&gt;   &lt;li&gt;IE8 Security Part I: DEP/NX Memory Protection: &lt;a href="http://blogs.msdn.com/ie/archive/2008/04/08/ie8-security-part-I_3A00_-dep-nx-memory-protection.aspx"&gt;http://blogs.msdn.com/ie/archive/2008/04/08/ie8-security-part-I_3A00_-dep-nx-memory-protection.aspx&lt;/a&gt;&lt;/li&gt;    &lt;li&gt;How do I improve my website and add-ons?: &lt;a href="http://www.microsoft.com/windows/internet-explorer/readiness/developers-existing.aspx"&gt;http://www.microsoft.com/windows/internet-explorer/readiness/developers-existing.aspx&lt;/a&gt;&lt;/li&gt; &lt;/ol&gt;  &lt;p&gt;&amp;#160;&lt;/p&gt;  &lt;p&gt;Regards,&lt;/p&gt;  &lt;p&gt;The IE Support Team&lt;/p&gt;&lt;img src="http://blogs.msdn.com/aggbug.aspx?PostID=9815279" width="1" height="1"&gt;</description><category domain="http://blogs.msdn.com/askie/archive/tags/Group+Policy/default.aspx">Group Policy</category><category domain="http://blogs.msdn.com/askie/archive/tags/Solutions/default.aspx">Solutions</category></item><item><title>How to disable IE Enhanced Security on Windows 2003 Server silently?</title><link>http://blogs.msdn.com/askie/archive/2009/06/23/how-to-disable-ie-enhanced-security-on-windows-2003-server-silently.aspx</link><pubDate>Tue, 23 Jun 2009 17:00:00 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:9763393</guid><dc:creator>Brent Goodpaster</dc:creator><slash:comments>3</slash:comments><comments>http://blogs.msdn.com/askie/comments/9763393.aspx</comments><wfw:commentRss>http://blogs.msdn.com/askie/commentrss.aspx?PostID=9763393</wfw:commentRss><wfw:comment>http://blogs.msdn.com/askie/rsscomments.aspx?PostID=9763393</wfw:comment><description>&lt;P&gt;Hi Everyone! 
&lt;P&gt;Axel Rivera again from the IE Escalation team with another IE Enhanced security topic for your viewing pleasure! 
&lt;P&gt;&lt;STRONG&gt;UPDATE&lt;/STRONG&gt;: I have tested the .exe and .bat file that will disable IE Enhanced Security for both Windows 2003 and Windows 2008 TS Servers. The key is that you have to execute the files while logon with the problem user.&amp;nbsp; Basically, once your user have these setting on their profile, the only way to remove it is to either Delete the profile and let it re-create again from a fixed profile or execute the fix mention in this article. 
&lt;P&gt;In this Blog I would like to share a batch file I use to help disable IE Enhanced Security silently on Windows 2003 servers.&amp;nbsp; The challenge is that if you have multiple servers, removing it from server console is not practical and can require tremendous administrative overhead. 
&lt;P&gt;&lt;STRONG&gt;&lt;EM&gt;Please note:&lt;/EM&gt;&lt;/STRONG&gt;&amp;nbsp; This is the the same task can be achieved from the Windows Add Removed Programs User Interface. 
&lt;P&gt;Cut and paste the lines below into notepad and save&amp;nbsp;the file&amp;nbsp;as "DisableIEES.bat".&amp;nbsp; This will create a simple batch which can be used to disable IEES (IE Enhanced Security):&lt;/P&gt;
&lt;P&gt;
&lt;TABLE border=1 cellSpacing=0 cellPadding=2 width=753 unselectable="on"&gt;
&lt;TBODY&gt;
&lt;TR&gt;
&lt;TD vAlign=top width=751&gt;
&lt;P&gt;:: START 
&lt;P&gt;::Related Article 
&lt;P&gt;::933991 Standard users cannot turn off the Internet Explorer Enhanced Security feature on a Windows Server 2003-based terminal server 
&lt;P&gt;::http://support.microsoft.com/default.aspx?scid=kb;EN-US;933991 
&lt;P&gt;:: This will add the entry, as some cases we have seeing that the value is not even there, causing other problems. so, we just add it and later delete it 
&lt;P&gt;REG ADD "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{A509B1A7-37EF-4b3f-8CFC-4F3A74704073}" /v "IsInstalled" /t REG_DWORD /d 0 /f 
&lt;P&gt;REG ADD "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{A509B1A8-37EF-4b3f-8CFC-4F3A74704073}" /v "IsInstalled" /t REG_DWORD /d 0 /f 
&lt;P&gt;::Removing IE Enhanced Security from System &amp;nbsp; 
&lt;P&gt;Rundll32 iesetup.dll,IEHardenUser 
&lt;P&gt;Rundll32 iesetup.dll,IEHardenAdmin 
&lt;P&gt;Rundll32 iesetup.dll,IEHardenMachineNow 
&lt;P&gt;:: Disabling IEHarden for user 
&lt;P&gt;REG ADD "HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap" /V "IEHarden" /t REG_DWORD /d 0 /f 
&lt;P&gt;:: Removes form Add Remove Components 
&lt;P&gt;REG ADD "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Setup\OC Manager\Subcomponents" /v "iehardenadmin" /t REG_DWORD /d 0 /f 
&lt;P&gt;REG ADD "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Setup\OC Manager\Subcomponents" /v "iehardenuser" /t REG_DWORD /d 0 /f 
&lt;P&gt;::Removed the Values from the IEHarden installed components key 
&lt;P&gt;REG DELETE "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{A509B1A7-37EF-4b3f-8CFC-4F3A74704073}" /f /va 
&lt;P&gt;REG DELETE "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{A509B1A8-37EF-4b3f-8CFC-4F3A74704073}" /f /va 
&lt;P&gt;::END&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Here is where you can set the login script in a policy:&lt;/STRONG&gt; 
&lt;P&gt;&amp;gt; From Start\run type: gpedit.msc 
&lt;P&gt;&amp;gt; From User Configuration 
&lt;P&gt;&amp;nbsp;&amp;nbsp; &amp;gt; Windows Settings 
&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;gt; Scripts(logon\logoff) 
&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;gt; Select Logon 
&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;gt; Click on the Add... btn 
&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;gt; Click on the Browse... bnt 
&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;gt; Navigate to the directory where you have the file I sent you (EXE or BAT) 
&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;[You can copy the file to the default Logon script directory: %windir%\system32\grouppolicy\user\scripts\logon] 
&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;gt; Apply and OK btn to complete 
&lt;P&gt;&amp;gt; Close GPEdit.msc 
&lt;P&gt;&amp;gt; Start\run type: gpupdate /force to update the policy 
&lt;P&gt;&amp;gt; Login with a profile you know have the problem and see if this takes care of the problem. 
&lt;P&gt;&lt;STRONG&gt;More information:&lt;/STRONG&gt; 
&lt;P&gt;There&amp;nbsp;are two&amp;nbsp;parts to turning off IE Enhanced Security. 
&lt;P&gt;We need to first&amp;nbsp;identify the registry keys used to change the IE Enhanced Configuration Settings. &lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Here are the keys as a .reg export format:&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;
&lt;TABLE border=1 cellSpacing=0 cellPadding=2 width=751 unselectable="on"&gt;
&lt;TBODY&gt;
&lt;TR&gt;
&lt;TD vAlign=top width=749&gt;
&lt;P&gt;[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{A509B1A7-37EF-4b3f-8CFC-4F3A74704073}] 
&lt;P&gt;"IsInstalled"=- 
&lt;P&gt;[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{A509B1A8-37EF-4b3f-8CFC-4F3A74704073}] 
&lt;P&gt;"IsInstalled"=- 
&lt;P&gt;[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap] 
&lt;P&gt;@="" 
&lt;P&gt;"IEHarden"=dword:00000000 
&lt;P&gt;"UNCAsIntranet"=dword:00000000 
&lt;P&gt;"AutoDetect"=dword:00000001 
&lt;P&gt;[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Setup\OC Manager\Subcomponents] 
&lt;P&gt;"iehardenadmin"=dword:00000000 
&lt;P&gt;"iehardenuser"=dword:00000000 
&lt;P&gt;Then, we use the rundll32.exe command to execute the IEHarden.inf with some parameters to help turn off , the Machine "IEHardenMachineNow", Administrator "IEHardenAdminand" and User "IEHardenUser" configuration.&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;/STRONG&gt;
&lt;P&gt;&lt;STRONG&gt;Here is the command I use to&amp;nbsp;turn off IE Maintenance using the IEHarden.inf file:&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;
&lt;TABLE border=1 cellSpacing=0 cellPadding=2 width=345 unselectable="on"&gt;
&lt;TBODY&gt;
&lt;TR&gt;
&lt;TD vAlign=top width=343&gt;
&lt;P&gt;Rundll32 iesetup.dll,IEHardenUser 
&lt;P&gt;Rundll32 iesetup.dll,IEHardenAdmin 
&lt;P&gt;Rundll32 iesetup.dll,IEHardenMachineNow&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;/P&gt;
&lt;P&gt;After you execute the batch file from an existing user profile, you should consider logging out and login back in to make sure the changes take effect.&amp;nbsp; New users should now have IE Enhanced Security disabled. 
&lt;P&gt;You can &lt;A title="Download the Zip file" href="http://blogs.msdn.com/askie/attachment/9763393.ashx" mce_href="http://blogs.msdn.com/askie/attachment/9763393.ashx"&gt;download&lt;/A&gt; an executable that will perform the change for you. 
&lt;P&gt;Regards, 
&lt;P&gt;The IE Support Team&lt;/P&gt;&lt;img src="http://blogs.msdn.com/aggbug.aspx?PostID=9763393" width="1" height="1"&gt;</description><enclosure url="http://blogs.msdn.com/askie/attachment/9763393.ashx" length="29134" type="application/x-zip-compressed" /><category domain="http://blogs.msdn.com/askie/archive/tags/Miscellaneous/default.aspx">Miscellaneous</category><category domain="http://blogs.msdn.com/askie/archive/tags/Troubleshooting/default.aspx">Troubleshooting</category><category domain="http://blogs.msdn.com/askie/archive/tags/Solutions/default.aspx">Solutions</category></item><item><title>How to bypass the security warning "Unknown Publisher" with the checkbox "Always Ask Before Opening this File"</title><link>http://blogs.msdn.com/askie/archive/2009/06/19/how-to-bypass-the-security-warning-unknown-publisher-with-the-checkbox-always-ask-before-opening-this-file.aspx</link><pubDate>Fri, 19 Jun 2009 20:00:00 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:9792309</guid><dc:creator>Brent Goodpaster</dc:creator><slash:comments>1</slash:comments><comments>http://blogs.msdn.com/askie/comments/9792309.aspx</comments><wfw:commentRss>http://blogs.msdn.com/askie/commentrss.aspx?PostID=9792309</wfw:commentRss><wfw:comment>http://blogs.msdn.com/askie/rsscomments.aspx?PostID=9792309</wfw:comment><description>&lt;P&gt;Hi everyone! &lt;/P&gt;
&lt;P&gt;Axel here from the IE Escalation team with a scenario related to&amp;nbsp; Security Warning - &lt;I&gt;Unknown Publisher&lt;/I&gt; pop-up when executing a file that came from a non trusted source.&lt;/P&gt;
&lt;P&gt;
&lt;TABLE border=1 cellSpacing=0 cellPadding=2 width=605&gt;
&lt;TBODY&gt;
&lt;TR&gt;
&lt;TD vAlign=top width=603&gt;
&lt;P&gt;&lt;SPAN style="FONT-FAMILY: 'Calibri','sans-serif'; COLOR: #c00000; FONT-SIZE: 16pt; mso-fareast-font-family: Calibri; mso-fareast-theme-font: minor-latin; mso-bidi-font-family: 'Times New Roman'; mso-ansi-language: EN-US; mso-fareast-language: EN-US; mso-bidi-language: AR-SA"&gt;&lt;STRONG&gt;&lt;EM&gt;Please note:&lt;/EM&gt;&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;SPAN style="FONT-FAMILY: 'Calibri','sans-serif'; FONT-SIZE: 16pt; mso-fareast-font-family: Calibri; mso-fareast-theme-font: minor-latin; mso-bidi-font-family: 'Times New Roman'; mso-ansi-language: EN-US; mso-fareast-language: EN-US; mso-bidi-language: AR-SA"&gt;&amp;nbsp; &lt;/SPAN&gt;&lt;SPAN style="FONT-FAMILY: 'Calibri','sans-serif'; FONT-SIZE: 11pt; mso-fareast-font-family: Calibri; mso-fareast-theme-font: minor-latin; mso-bidi-font-family: 'Times New Roman'; mso-ansi-language: EN-US; mso-fareast-language: EN-US; mso-bidi-language: AR-SA"&gt;The example below sets &lt;/SPAN&gt;&lt;U&gt;&lt;SPAN style="FONT-FAMILY: 'Calibri','sans-serif'; COLOR: #c00000; FONT-SIZE: 14pt; mso-fareast-font-family: Calibri; mso-fareast-theme-font: minor-latin; mso-bidi-font-family: 'Times New Roman'; mso-ansi-language: EN-US; mso-fareast-language: EN-US; mso-bidi-language: AR-SA"&gt;&lt;STRONG&gt;&lt;EM&gt;HIGH RISK&lt;/EM&gt;&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/U&gt;&lt;SPAN style="FONT-FAMILY: 'Calibri','sans-serif'; FONT-SIZE: 14pt; mso-fareast-font-family: Calibri; mso-fareast-theme-font: minor-latin; mso-bidi-font-family: 'Times New Roman'; mso-ansi-language: EN-US; mso-fareast-language: EN-US; mso-bidi-language: AR-SA"&gt; &lt;/SPAN&gt;&lt;SPAN style="FONT-FAMILY: 'Calibri','sans-serif'; FONT-SIZE: 11pt; mso-fareast-font-family: Calibri; mso-fareast-theme-font: minor-latin; mso-bidi-font-family: 'Times New Roman'; mso-ansi-language: EN-US; mso-fareast-language: EN-US; mso-bidi-language: AR-SA"&gt;files types to &lt;/SPAN&gt;&lt;U&gt;&lt;SPAN style="FONT-FAMILY: 'Calibri','sans-serif'; COLOR: #c00000; FONT-SIZE: 14pt; mso-fareast-font-family: Calibri; mso-fareast-theme-font: minor-latin; mso-bidi-font-family: 'Times New Roman'; mso-ansi-language: EN-US; mso-fareast-language: EN-US; mso-bidi-language: AR-SA"&gt;&lt;STRONG&gt;&lt;EM&gt;LOW RISK&lt;/EM&gt;&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/U&gt;&lt;SPAN style="FONT-FAMILY: 'Calibri','sans-serif'; FONT-SIZE: 14pt; mso-fareast-font-family: Calibri; mso-fareast-theme-font: minor-latin; mso-bidi-font-family: 'Times New Roman'; mso-ansi-language: EN-US; mso-fareast-language: EN-US; mso-bidi-language: AR-SA"&gt; &lt;/SPAN&gt;&lt;SPAN style="FONT-FAMILY: 'Calibri','sans-serif'; FONT-SIZE: 11pt; mso-fareast-font-family: Calibri; mso-fareast-theme-font: minor-latin; mso-bidi-font-family: 'Times New Roman'; mso-ansi-language: EN-US; mso-fareast-language: EN-US; mso-bidi-language: AR-SA"&gt;so that they can be executed without having to honor the warning dialog.&amp;nbsp; We are creating this example because many corporate customers request this change to make their day-to-day operations easier to maintain.&amp;nbsp; With that said, setting these options in attachment manager can put your system at risk, so please fully read the external documentation available on Attachment Manager and weigh the risks involved before making the decision to allow these files types to be executed without warning the user.&lt;/SPAN&gt;&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;/P&gt;
&lt;P&gt;I am sharing this out because the immediate assumption is that by just adding the server name to the Local or Trusted Site zone will allow the file to be executed, which is not accurate. Once the file comes down from the &lt;STRONG&gt;untrusted&lt;/STRONG&gt; &lt;STRONG&gt;source&lt;/STRONG&gt; and with the Block file stream (see Fig. 1.1), until you remove the attribute you wont be able to run it without first getting the warning mentioned in this blog, see fig. 1.0.&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Fig. 1.0 [Screenshot of the Warning with the checkbox “Always ask before opening this file” option]&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="http://blogs.msdn.com/blogfiles/askie/WindowsLiveWriter/HowtobypassthesecuritywarningUnknownPubl_10B29/image_4.png" mce_href="http://blogs.msdn.com/blogfiles/askie/WindowsLiveWriter/HowtobypassthesecuritywarningUnknownPubl_10B29/image_4.png"&gt;&lt;IMG style="BORDER-RIGHT-WIDTH: 0px; DISPLAY: inline; BORDER-TOP-WIDTH: 0px; BORDER-BOTTOM-WIDTH: 0px; BORDER-LEFT-WIDTH: 0px" title=image border=0 alt=image src="http://blogs.msdn.com/blogfiles/askie/WindowsLiveWriter/HowtobypassthesecuritywarningUnknownPubl_10B29/image_thumb_1.png" width=552 height=415 mce_src="http://blogs.msdn.com/blogfiles/askie/WindowsLiveWriter/HowtobypassthesecuritywarningUnknownPubl_10B29/image_thumb_1.png"&gt;&lt;/A&gt; &lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Fig. 1.1 [Screenshot of the executable properties, showing the Security Unblock option]&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="http://blogs.msdn.com/blogfiles/askie/WindowsLiveWriter/HowtobypassthesecuritywarningUnknownPubl_10B29/image_8.png" mce_href="http://blogs.msdn.com/blogfiles/askie/WindowsLiveWriter/HowtobypassthesecuritywarningUnknownPubl_10B29/image_8.png"&gt;&lt;IMG style="BORDER-RIGHT-WIDTH: 0px; DISPLAY: inline; BORDER-TOP-WIDTH: 0px; BORDER-BOTTOM-WIDTH: 0px; BORDER-LEFT-WIDTH: 0px" title=image border=0 alt=image src="http://blogs.msdn.com/blogfiles/askie/WindowsLiveWriter/HowtobypassthesecuritywarningUnknownPubl_10B29/image_thumb_3.png" width=500 height=680 mce_src="http://blogs.msdn.com/blogfiles/askie/WindowsLiveWriter/HowtobypassthesecuritywarningUnknownPubl_10B29/image_thumb_3.png"&gt;&lt;/A&gt; &lt;/P&gt;
&lt;P&gt;Here is what it may look like once you have unchecked the option next to &lt;STRONG&gt;“Always ask before opening this file”.&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Fig. 1.2 [Here is what you will still get, even after you have removed the checkbox]&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="http://blogs.msdn.com/blogfiles/askie/WindowsLiveWriter/HowtobypassthesecuritywarningUnknownPubl_10B29/image_6.png" mce_href="http://blogs.msdn.com/blogfiles/askie/WindowsLiveWriter/HowtobypassthesecuritywarningUnknownPubl_10B29/image_6.png"&gt;&lt;IMG style="BORDER-RIGHT-WIDTH: 0px; DISPLAY: inline; BORDER-TOP-WIDTH: 0px; BORDER-BOTTOM-WIDTH: 0px; BORDER-LEFT-WIDTH: 0px" title=image border=0 alt=image src="http://blogs.msdn.com/blogfiles/askie/WindowsLiveWriter/HowtobypassthesecuritywarningUnknownPubl_10B29/image_thumb_2.png" width=571 height=403 mce_src="http://blogs.msdn.com/blogfiles/askie/WindowsLiveWriter/HowtobypassthesecuritywarningUnknownPubl_10B29/image_thumb_2.png"&gt;&lt;/A&gt; &lt;/P&gt;
&lt;P&gt;Once you add the unc path to either the Local or Trusted Sites Zone, you will no longer get the warning. &lt;/P&gt;
&lt;P&gt;In the above example, we can see that the application did not have a digital signature that verifies its publisher, so we will have to do more work to bypass the warning. You can either have the executable signed using signcode.exe or use the Build in Windows Attachment Manager Policy.&lt;/P&gt;
&lt;P&gt;The reason why you get the warning in the first place is because in Windows XP/SP2 and Windows 2003/SP1 we have introduced a new feature called &lt;A href="http://support.microsoft.com/kb/883260" mce_href="http://support.microsoft.com/kb/883260"&gt;Attachment Manager&lt;/A&gt;&lt;I&gt;&lt;/I&gt;. This feature was added to help protect your computer from unsafe file attachments. This include accessing files across your network (e.g &lt;A href="file://servername/share" mce_href="file:///%5C%5Cservername%5Cshare"&gt;\\servername\share&lt;/A&gt;), files that you might receive with an e-mail message and from unsafe files that you might save from the Internet. &lt;/P&gt;
&lt;P&gt;If the Attachment Manager identifies an attachment that might be unsafe, the Attachment Manager prevents you from opening the file, or it warns you before you open the file.&lt;/P&gt;
&lt;P&gt;Here are the steps to bypass the warning using Attachment Manager Group Policy. I am also including the registry key modified by the policy.&lt;/P&gt;
&lt;P mce_keep="true"&gt;&amp;nbsp;&lt;/P&gt;
&lt;HR align=center SIZE=2 width="100%"&gt;

&lt;P mce_keep="true"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;From Start Run type: gpedit.msc&lt;/P&gt;
&lt;P&gt;From User Configuration&amp;gt; Administrative Template&amp;gt; Windows Components&amp;gt; Attachment Manager &lt;/P&gt;
&lt;P&gt;Set the following:&lt;/P&gt;
&lt;P&gt;&lt;B&gt;Configuration Settings:&lt;/B&gt;&lt;/P&gt;
&lt;P&gt;&amp;gt; Default risk level for file attachments: Set it to Enabled and Set the default risk level to[Low Risk]&lt;/P&gt;
&lt;P&gt;&amp;gt; Inclusion list for low file types: Set it to Enabled and add the file extension [.exe;.vbs;.msi]&lt;/P&gt;
&lt;P&gt;&amp;gt; Do not preserve zone information in file attachments: Set it to Enabled.&lt;/P&gt;
&lt;P&gt;&lt;B&gt;Close Gpedit.msc and run gpupdate /force&lt;/B&gt;&lt;/P&gt;
&lt;P&gt;&lt;B&gt;Screenshot of the policy:&lt;/B&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="http://blogs.msdn.com/blogfiles/askie/WindowsLiveWriter/HowtobypassthesecuritywarningUnknownPubl_EA6D/clip_image002_2.jpg" mce_href="http://blogs.msdn.com/blogfiles/askie/WindowsLiveWriter/HowtobypassthesecuritywarningUnknownPubl_EA6D/clip_image002_2.jpg"&gt;&lt;IMG title=clip_image001 border=0 alt=clip_image001 src="http://blogs.msdn.com/blogfiles/askie/WindowsLiveWriter/HowtobypassthesecuritywarningUnknownPubl_F504/clip_image001_3df82204-ca9b-4b8c-9214-8931f048c253.jpg" width=648 height=398 mce_src="http://blogs.msdn.com/blogfiles/askie/WindowsLiveWriter/HowtobypassthesecuritywarningUnknownPubl_F504/clip_image001_3df82204-ca9b-4b8c-9214-8931f048c253.jpg"&gt;&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;B&gt;Final Step:&lt;/B&gt;&lt;/P&gt;
&lt;P&gt;&amp;gt; Add the UNC to Local Intranet or Trusted Sites &lt;/P&gt;
&lt;P&gt;&amp;gt; Log off and log back in&lt;/P&gt;
&lt;P&gt;&amp;gt; Test accessing the UNC share&lt;/P&gt;
&lt;HR align=center SIZE=2 width="100%"&gt;

&lt;P&gt;&lt;B&gt;Registry keys:&lt;/B&gt;&lt;/P&gt;
&lt;P&gt;[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies]&lt;/P&gt;
&lt;P&gt;[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Associations]&lt;/P&gt;
&lt;P&gt;"LowRiskFileTypes"=".exe;.vbs;.msi"&lt;/P&gt;
&lt;P&gt;"DefaultFileTypeRisk"=dword:00001808&lt;/P&gt;
&lt;P&gt;[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Attachments]&lt;/P&gt;
&lt;P&gt;"SaveZoneInformation"=dword:00000001&lt;/P&gt;
&lt;HR align=center SIZE=2 width="100%"&gt;

&lt;P&gt;&lt;B&gt;Article below explains everything about Attachment Management.&lt;/B&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;883260&amp;nbsp; Description of how the Attachment Manager works in Windows XP Service Pack 2&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;A href="http://support.microsoft.com/default.aspx?scid=kb;EN-US;883260" mce_href="http://support.microsoft.com/default.aspx?scid=kb;EN-US;883260"&gt;http://support.microsoft.com/default.aspx?scid=kb;EN-US;883260&lt;/A&gt; &lt;/LI&gt;
&lt;LI&gt;How would you sign your file. You could use &lt;A href="http://msdn.microsoft.com/en-us/library/9sh96ycy(VS.71).aspx" target=_blank mce_href="http://msdn.microsoft.com/en-us/library/9sh96ycy(VS.71).aspx"&gt;signcode.exe&lt;/A&gt; from Microsoft. Here is also an article: &lt;/LI&gt;
&lt;LI&gt;Steps for signing a .cab file: &lt;A href="http://support.microsoft.com/default.aspx?scid=kb;en-us;247257" mce_href="http://support.microsoft.com/default.aspx?scid=kb;en-us;247257"&gt;http://support.microsoft.com/default.aspx?scid=kb;en-us;247257&lt;/A&gt; &lt;/LI&gt;&lt;/UL&gt;
&lt;P&gt;Regards,&lt;/P&gt;
&lt;P&gt;The IE Support Team&lt;/P&gt;&lt;img src="http://blogs.msdn.com/aggbug.aspx?PostID=9792309" width="1" height="1"&gt;</description><category domain="http://blogs.msdn.com/askie/archive/tags/Security/default.aspx">Security</category><category domain="http://blogs.msdn.com/askie/archive/tags/Solutions/default.aspx">Solutions</category></item><item><title>How do I add the ‘X-UA-Compatible’ HTTP Header to a NGINX Web Server?</title><link>http://blogs.msdn.com/askie/archive/2009/06/19/how-do-i-add-the-x-ua-compatible-http-header-to-a-nginx-web-server.aspx</link><pubDate>Fri, 19 Jun 2009 17:30:00 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:9792059</guid><dc:creator>Brent Goodpaster</dc:creator><slash:comments>0</slash:comments><comments>http://blogs.msdn.com/askie/comments/9792059.aspx</comments><wfw:commentRss>http://blogs.msdn.com/askie/commentrss.aspx?PostID=9792059</wfw:commentRss><wfw:comment>http://blogs.msdn.com/askie/rsscomments.aspx?PostID=9792059</wfw:comment><description>&lt;p&gt;Hi Everyone!&lt;/p&gt;  &lt;p&gt;It’s Bac again with another solution for you…&lt;/p&gt;  &lt;p&gt;Just in case you are running &lt;a href="http://www.nginx.net/"&gt;NGINX&lt;/a&gt; Web Server and wondering how to add the &lt;a href="http://blogs.msdn.com/ie/archive/2008/06/10/introducing-ie-emulateie7.aspx"&gt;‘X-UA-Compatible’ HTTP Header&lt;/a&gt; to the web server, here are the steps:&lt;/p&gt;  &lt;p&gt;1) Open the&amp;#160; nginx.conf file in WordPad from nginx\conf folder&lt;/p&gt;  &lt;p&gt;2) Add the line in red below to the server{..} section and save&lt;/p&gt;  &lt;p&gt;…&lt;/p&gt;  &lt;p&gt;server {&lt;/p&gt;  &lt;p&gt;listen 80;&lt;/p&gt;  &lt;p&gt;server_name localhost;&lt;/p&gt;  &lt;p&gt;#charset koi8-r;&lt;/p&gt;  &lt;p&gt;&lt;b&gt;&lt;font color="#ff0000"&gt;add_header 'X-UA-Compatible' 'IE=EmulateIE7';&lt;/font&gt;&lt;/b&gt;&lt;/p&gt;  &lt;p&gt;#access_log logs/host.access.log main;&lt;/p&gt;  &lt;p&gt;location / {…&lt;/p&gt;  &lt;p&gt;3) Stop and restart NGINX server&lt;/p&gt;  &lt;p&gt;&amp;#160;&lt;/p&gt;  &lt;p&gt;&lt;strong&gt;&lt;em&gt;Please note:&lt;/em&gt;&lt;/strong&gt;&amp;#160; the above steps have been tested on version 0.6.&lt;/p&gt;  &lt;p&gt;For information on how to add this Header to IIS Server see &lt;a href="http://msdn.microsoft.com/en-us/library/cc817572.aspx"&gt;http://msdn.microsoft.com/en-us/library/cc817572.aspx&lt;/a&gt; and Apache Server see &lt;a href="http://msdn.microsoft.com/en-us/library/cc817573.aspx"&gt;http://msdn.microsoft.com/en-us/library/cc817573.aspx&lt;/a&gt;&lt;/p&gt;  &lt;p&gt;&amp;#160;&lt;/p&gt;  &lt;p&gt;Regards,&lt;/p&gt;  &lt;p&gt;The IE Support Team&lt;/p&gt;&lt;img src="http://blogs.msdn.com/aggbug.aspx?PostID=9792059" width="1" height="1"&gt;</description></item><item><title>Change in behavior with Internet Explorer 7 and later in regard to CONNECT requests</title><link>http://blogs.msdn.com/askie/archive/2009/06/18/change-in-behavior-with-internet-explorer-7-and-later-in-regard-to-connect-requests.aspx</link><pubDate>Thu, 18 Jun 2009 12:00:00 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:9776317</guid><dc:creator>Brent Goodpaster</dc:creator><slash:comments>0</slash:comments><comments>http://blogs.msdn.com/askie/comments/9776317.aspx</comments><wfw:commentRss>http://blogs.msdn.com/askie/commentrss.aspx?PostID=9776317</wfw:commentRss><wfw:comment>http://blogs.msdn.com/askie/rsscomments.aspx?PostID=9776317</wfw:comment><description>&lt;p&gt;Hi everyone!&lt;/p&gt;  &lt;p&gt;&amp;#160;&lt;/p&gt;  &lt;p&gt;Well, we’ve come across another behavior that some of you are running into so we thought it was time to do a quick write up on the behavior and why it has changed.&amp;#160; The behavior is a little complicated if you are real savvy with how IE makes connections using the HTTP protocol.&amp;#160; Hopefully, we can give you an overview of the behavior that won’t bore you to tears!&lt;/p&gt;  &lt;p&gt;:)&lt;/p&gt;  &lt;p&gt;&amp;#160;&lt;/p&gt;  &lt;p&gt;Starting with IE7, a behavior change has been made in how IE handles Server certain response codes to web browser connections that originate as a CONNECT request.&amp;#160; Specifically, if a CONNECT request is made by IE to a Web Server and it receives a Server response to that CONNECT request with something other than 200, IE could reject that response as invalid (ERROR_HTTP_INVALID_SERVER_RESPONSE).&amp;#160; &lt;/p&gt;  &lt;p&gt;Below is an example of what you might see when connecting to a secure web site with IE using an initial CONNECT with a Proxy Server in between the IE client machine and the Web Server you are connecting to:&lt;/p&gt;  &lt;p&gt;&amp;#160;&lt;/p&gt;  &lt;p&gt;CONNECT www.MyTestSSLSite.com:443 HTTP/1.0   &lt;br /&gt;User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1; .NET CLR 1.1.4322; .NET CLR 2.0.50727; .NET CLR 3.0.4506.2152; .NET CLR 3.5.30729)    &lt;br /&gt;Proxy-Connection: Keep-Alive    &lt;br /&gt;Content-Length: 0    &lt;br /&gt;Host: www.MyTestSSLSite.com    &lt;br /&gt;Pragma: no-cache&lt;/p&gt;  &lt;p&gt;HTTP/1.1 200 Connection established   &lt;br /&gt;Proxy-Connection: Keep-Alive    &lt;br /&gt;Connection: Keep-Alive    &lt;br /&gt;Via: 1.1 MyTestProxyServer&lt;/p&gt;  &lt;p&gt;This is a working example because the Server response to the &lt;em&gt;CONNECT&lt;/em&gt; request is a level &lt;em&gt;200&lt;/em&gt; response code which means the CONNECT request by the IE client has been honored.&lt;/p&gt;  &lt;p&gt;Of course, this isn’t the scenario in where IE fails to honor the Server response.&amp;#160; Failure cases we see are when a Proxy Server returns a Server response code other than the expected 200, as seen above.&amp;#160; This can happen for several reasons and is often done purposely by Proxy Server.&amp;#160; The below response, for example, will indeed be rejected by IE is connecting to a Web Server, through a proxy, where a CONNECT request would be used to make the initial secure HTTP connection:&lt;/p&gt;  &lt;p&gt;CONNECT www.MyTestSSLSite.com:443 HTTP/1.0   &lt;br /&gt;User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1; .NET CLR 1.1.4322; .NET CLR 2.0.50727; .NET CLR 3.0.4506.2152; .NET CLR 3.5.30729)    &lt;br /&gt;Proxy-Connection: Keep-Alive    &lt;br /&gt;Content-Length: 0    &lt;br /&gt;Host: www.MyTestSSLSite.com    &lt;br /&gt;Pragma: no-cache &lt;/p&gt;  &lt;p&gt;HTTP/1.1 302 Redirected   &lt;br /&gt;Date: Wed, 17 June 2009 14:21:38 GMT    &lt;br /&gt;Proxy-Connection: Keep-Alive    &lt;br /&gt;Connection: Keep-Alive    &lt;br /&gt;Location: &lt;a href="http://10.1.0.5/MyTestRedirectPage.html"&gt;http://10.1.0.5/MyTestRedirectPage.html&lt;/a&gt;&lt;/p&gt;  &lt;p&gt;As you can see in this second example above, the Server response code is now a 302 instead of the 200 expected by IE.&amp;#160; This Server response is telling the IE client to &lt;em&gt;redirect&lt;/em&gt; it’s request to a different site than it made the initial CONNECT request to.&amp;#160; Allowing this Server response to be honored by the IE client would be risky because the Proxy Server could return content that IE &lt;em&gt;would&lt;/em&gt; interpret as being from the &lt;em&gt;origin server&lt;/em&gt;, which Microsoft sees as an unsecure scenario and so honoring the 302 response in this scenario is no longer allowed. This change in behavior doesn’t mean that all Server responses which are not 200 are rejected.&amp;#160; Support for 400-level response codes are still valid and honored in the above scenario.&lt;/p&gt;  &lt;p&gt;&lt;strong&gt;&lt;em&gt;Please note:&lt;/em&gt;&lt;/strong&gt;&amp;#160; You can see HTTP protocol traffic&amp;#160; using an HTTP tracing tool such as Fiddler or a network analyzer tool such as Microsoft Network Monitor.&amp;#160; Of course the CONNECT request is setting up a secure HTTP connection and so further traffic will be encrypted.&amp;#160; A debug version of wininet.dll can allow you to view encrypted HTTP traffic via the wininet log it can generate.&lt;/p&gt;  &lt;p&gt;Well hopefully this blog was more entertaining that fingernail scratches on a chalkboard – until next time!&lt;/p&gt;  &lt;p&gt;&amp;#160;&lt;/p&gt;  &lt;p&gt;Regards,&lt;/p&gt;  &lt;p&gt;The IE Support Team&lt;/p&gt;&lt;img src="http://blogs.msdn.com/aggbug.aspx?PostID=9776317" width="1" height="1"&gt;</description><category domain="http://blogs.msdn.com/askie/archive/tags/Troubleshooting/default.aspx">Troubleshooting</category><category domain="http://blogs.msdn.com/askie/archive/tags/Solutions/default.aspx">Solutions</category></item><item><title>Printing functionality fails in Internet Explorer 7 and 8 on Windows XP</title><link>http://blogs.msdn.com/askie/archive/2009/06/16/printing-functionality-fails-in-internet-explorer-7-and-8-on-windows-xp.aspx</link><pubDate>Tue, 16 Jun 2009 18:30:00 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:9763167</guid><dc:creator>Brent Goodpaster</dc:creator><slash:comments>23</slash:comments><comments>http://blogs.msdn.com/askie/comments/9763167.aspx</comments><wfw:commentRss>http://blogs.msdn.com/askie/commentrss.aspx?PostID=9763167</wfw:commentRss><wfw:comment>http://blogs.msdn.com/askie/rsscomments.aspx?PostID=9763167</wfw:comment><description>&lt;P&gt;Hi everyone!&lt;/P&gt;
&lt;P&gt;We’ve got an emerging issue showing up in our support channels in where IE printing functionality (printing, print preview) fails on the Windows XP operating system.&amp;nbsp; This issue is specific to IE7 and IE8 and we have only reproduced the issue with service pack 3 installed, thus far, but we certainly aren't ruling out other platforms that can install and run either of these revisions of IE.&lt;/P&gt;
&lt;P&gt;The behavior is easily recognizable as you will see a blank screen within the print preview dialog instead of the page to print out.&amp;nbsp; Furthermore, if you try and actually print the page, nothing happens and the page does not print out.&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;EM&gt;Please note:&lt;/EM&gt;&lt;/STRONG&gt;&amp;nbsp; Some user have noted seeing this behavior after installing the latest IE cumulative update, &lt;A href="http://support.microsoft.com/kb/969897" target=_blank mce_href="http://support.microsoft.com/kb/969897"&gt;KB969897&lt;/A&gt;.&lt;/P&gt;
&lt;P&gt;In troubleshooting this behavior, we have found that uninstalling the &lt;A href="http://www.microsoft.com/resources/sam/msia.mspx" target=_blank mce_href="http://www.microsoft.com/resources/sam/msia.mspx"&gt;Microsoft Software Inventory Analyzer&lt;/A&gt; software, via &lt;EM&gt;Add or Remove Programs&lt;/EM&gt; option in Control panel, resolves these printing functionality issues.&amp;nbsp; This is our recommendation.&lt;/P&gt;
&lt;P&gt;Deeper troubleshooting of this issue indicates a registry key added by the Microsoft Software Inventory Analyzer, may be the root cause of the failure.&amp;nbsp; The registry key in question is seen below:&lt;/P&gt;
&lt;P&gt;&lt;A href="http://blogs.msdn.com/blogfiles/askie/WindowsLiveWriter/PrintingfunctionalityfailsinInternetExpl_BE6F/image_4.png" mce_href="http://blogs.msdn.com/blogfiles/askie/WindowsLiveWriter/PrintingfunctionalityfailsinInternetExpl_BE6F/image_4.png"&gt;&lt;IMG style="BORDER-RIGHT-WIDTH: 0px; DISPLAY: inline; BORDER-TOP-WIDTH: 0px; BORDER-BOTTOM-WIDTH: 0px; BORDER-LEFT-WIDTH: 0px" title=image border=0 alt=image src="http://blogs.msdn.com/blogfiles/askie/WindowsLiveWriter/PrintingfunctionalityfailsinInternetExpl_BE6F/image_thumb_1.png" width=490 height=95 mce_src="http://blogs.msdn.com/blogfiles/askie/WindowsLiveWriter/PrintingfunctionalityfailsinInternetExpl_BE6F/image_thumb_1.png"&gt;&lt;/A&gt; &lt;/P&gt;
&lt;P&gt;[HKEY_CLASSES_ROOT\.dlg]&lt;/P&gt;
&lt;P&gt;@="MsiaUtils" &lt;BR&gt;"Content Type"="application/msia-dlg"&lt;/P&gt;
&lt;P&gt;Removal of this registry key also seems to resolve the printing functionality issues within Internet Explorer.&amp;nbsp; However, if you are not proficient at using the registry editor tool, we do not suggest using this method but instead suggest that you simply uninstall the Microsoft Software Inventory Analyzer software.&lt;/P&gt;
&lt;P&gt;You can also remove the extension type via Explorer:&lt;/P&gt;
&lt;P&gt;1.&amp;nbsp; From the Windows desktop, double-click on &lt;EM&gt;My Computer&lt;/EM&gt;. &lt;BR&gt;2.&amp;nbsp; Click on &lt;EM&gt;Tools&lt;/EM&gt; and then &lt;EM&gt;Folder Options&lt;/EM&gt; from the menu. &lt;BR&gt;3.&amp;nbsp; Click on the &lt;EM&gt;File Types&lt;/EM&gt; tab within the &lt;EM&gt;Folder Options&lt;/EM&gt; dialog. &lt;BR&gt;4.&amp;nbsp; Within the &lt;EM&gt;Registered file types&lt;/EM&gt; listing, find the &lt;EM&gt;DLG&lt;/EM&gt; extension. &lt;BR&gt;5.&amp;nbsp; Highlight and then click the &lt;EM&gt;Delete&lt;/EM&gt; button and then choose &lt;EM&gt;Yes&lt;/EM&gt; to remove.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;A href="http://blogs.msdn.com/blogfiles/askie/WindowsLiveWriter/PrintingfunctionalityfailsinInternetExpl_BE6F/image_7.png" mce_href="http://blogs.msdn.com/blogfiles/askie/WindowsLiveWriter/PrintingfunctionalityfailsinInternetExpl_BE6F/image_7.png"&gt;&lt;IMG style="BORDER-BOTTOM: 0px; BORDER-LEFT: 0px; DISPLAY: inline; BORDER-TOP: 0px; BORDER-RIGHT: 0px" title=image border=0 alt=image src="http://blogs.msdn.com/blogfiles/askie/WindowsLiveWriter/PrintingfunctionalityfailsinInternetExpl_BE6F/image_thumb_2.png" width=384 height=258 mce_src="http://blogs.msdn.com/blogfiles/askie/WindowsLiveWriter/PrintingfunctionalityfailsinInternetExpl_BE6F/image_thumb_2.png"&gt;&lt;/A&gt; &lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;EM&gt;Please note:&lt;/EM&gt;&lt;/STRONG&gt;&amp;nbsp; This tool is not supported by Product Support Services.&lt;/P&gt;
&lt;P&gt;We have some new information coming in that the inclusion of this key seems to be effecting the rendering of text inside CSS styled textboxes.&amp;nbsp; Applications, for example WordPress, may be negatively affected as well.&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;FONT color=#ff0000&gt;&lt;EM&gt;UPDATE!&lt;/EM&gt;&lt;/FONT&gt;&lt;/STRONG&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;FONT color=#400040&gt;We’ve been working directly with the MSIA team and they have informed us that they will be making a code change to the product to help resolve this issue.&amp;nbsp; More detail on the availability of this update can be found &lt;A href="http://www.microsoft.com/resources/sam/msia.mspx" target=_blank mce_href="http://www.microsoft.com/resources/sam/msia.mspx"&gt;here&lt;/A&gt;.&amp;nbsp; The MSIA teams also suggests that instead of just removing&amp;nbsp;the above values from the registry, that users install, use, and then uninstall the MSIA tool to mitigate the app-compat issue with IE.&amp;nbsp; This is because removal of the registry information can cause certain areas of the MSIA tool to fail, such as the feedback and licensing display forms.&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;
&lt;P&gt;The IE Support Team&lt;/P&gt;&lt;img src="http://blogs.msdn.com/aggbug.aspx?PostID=9763167" width="1" height="1"&gt;</description><category domain="http://blogs.msdn.com/askie/archive/tags/Solutions/default.aspx">Solutions</category></item></channel></rss>