Know What You're Actually Running

Discontinued utilities from outfits like RJ Software stopped receiving security patches when development ended. That means any vulnerability discovered after end-of-life1 sits open forever. Before you launch an old installer, be honest about what the tool touches. A unit-conversion utility that never phones home and writes nothing to the network is a fundamentally different risk than an old PC-tuning tool that reaches into registry entries, startup tuning, or memory optimization — the kind of deep system access that becomes genuinely dangerous when unpatched.

The threat model matters. Legacy software that stays local, handles no personal information, and makes no network calls is low-risk in isolation. Software that historically connected to external servers — time-sync tools hitting an NTP server2, anything with automatic update checks, browser-adjacent utilities that once handled temporary internet files — carries real exposure the moment it's on a live network.

Contain It, Don't Trust It

The safest approach is also the simplest: air-gap it. Run the old utility on a machine with no internet connection, or inside a virtual machine with networking disabled. Windows' own Hyper-V (built into Pro and Enterprise editions) costs nothing and creates a clean sandbox; VirtualBox is the free alternative. Snapshot the VM before you run anything, so a one-click rollback is always available.

Snapshot the VM before you run anything — rollback beats regret.

If a full VM feels like overkill for a tiny desktop tool, at minimum: create a standard user account with no administrator rights and run the software there. Deny it firewall access via Windows Defender Firewall — just block it outbound and forget about it. Many classic utilities, including most of RJ Software's catalog, were built for an era of one-user desktops and never needed elevated privileges for their core work anyway.

Watch what the installer actually does. Tools like Sysinternals Process Monitor (free, from Microsoft) let you see every file write and registry change in real time. Run it during installation on a throwaway VM first. If you see network calls or writes to sensitive system locations, you have your answer.

The Honest Bottom Line

No isolation strategy eliminates risk entirely — it only shrinks the blast radius. If a modern replacement exists and works, use it. This archive exists to document what these tools were, not to argue you should keep running them. But if the modern alternative genuinely doesn't replicate the thing you need, a sandboxed, offline, read-only-where-possible setup is a reasonable compromise — provided you go in clear-eyed about the trade-off you're making.

NOTES.TXT — 2 ENTRIES✕
  1. end-of-life — Stage where a software product is no longer actively developed or supported. ↩ back
  2. NTP server — Network Time Protocol server that synchronizes computer clocks over the internet. ↩ back