There is a user Dad with admin privileges on a Windows machine this is me There are other users kid and kid with no admin privileges my kids - I want to let kid and kid access the contents of a directory in my userspace C Users Dad In fact it's not users wants a directory share to non-admin Admin with at the top level let's say it's C Users Admin wants to share a directory with non-admin users Dad ownCloud photos because it is I want Admin wants to share a directory with non-admin users to let kid have read write access and kid read only access I navigated my way to C Users Dad ownCloud and then right-clicked on photos clicked on properties clicked on the sharing tab and did what looked like the sensible thing gave the kids the required access I then logged in as kid and attempted to find my way to C Users Dad ownCloud photos I got there -- but on the way I saw far too much -- kid can see a complete list of the names of all files and directories in D Users Dad not ideal and also names of all files and directories in C Users Dad ownCloud which is not acceptable because that is my entire life in the cloud Is this expected behaviour when sharing directories in Windows If not what did I do wrong If so then this is no good and I guess I need a workaround The problem is that I am not at all sure that I can move the directory because it part of a cloud storage service like Dropbox but a different company and as far as I know that directory ownCloud photos the one I want to share with my kids must be a subdirectory of ownCloud the one that I really don't want my kids to be able to view the contents of Also not a viable solution is re-organizing the directory structure of ownCloud i e putting photos at the top and everything else in another directory called quot not for kids quot or whatever -- the problem with that solution is that this directory ownCloud is shared by me on many machines and if I start changing things around then various scripts running on other machines would immediately fail -- the directory structure cannot be messed with I think I need to have most directory names in C Users Dad ownCloud not visible but the entire directory C Users Dad ownCloud photos visible I'm not worried whether the kids can access the directory directly or via some network share or anything -- I just don't want them to see the names of all files and directories in C Users Dad ownCloud In unix this would be easy to do because one has very fine control on who can see what one could remove read access from C Users Dad but still allow read access to subdirectories How does one do that in Windows PS Lol quot I'm having trouble sharing quot a clickable option on the Share window That sometimes applies to my kids -- nice to see that it applies to me today
I recommend downloading and running Reimage. It's a computer repair tool that has been proven to identify and fix many Windows problems with a high level of success.
I've used it in the past to identify and fix everything from blue screens (BSOD's), ActiveX errors, corrupt files and processes, dll/exe/sys errors, recover lost memory, Windows update problems, defragging, malware removal etc.
You can download it direct from this link http://downloadreimage.com/directdownload.php. (This link will automatically start a download of Reimage that you can save to your computer.)
NTFS Folder Permissions
I'm thinking if you create a symbolic link in C:\Users\Public you may be able to let the kids go directly to the shared folder. Perhaps then you can deny Traverse permission to block the parent folder. But I haven't done it myself.
Stoik Joker,who has the NTFS permissions page in the above link, is also a regular poster on DonationCoder.com. You may be able to ask for clarifications there. And of course someone with SysAdmin type experience may chime in here.
If you succeed using external info please post the solution.
I was trying to figure out a way to block admin share access over windows domain network.
These are my requirements:
Desktop Support Engineers should have administrator privileges on all domain joined windows workstation machines. Domain Users should not have administrator privileges on their workstations.Desktop support engineers should not be able to access admin share over the network.Domain Admin must have full access on Admin Share.
So I have added NT AUTHORITY\INTERACTIVE as a member of Buit-In administrators group and I have added Desktop Support Group as a member of NT AUTHORITY\INTERACTIVE.
Which actually blocked admin share access over network for Desktop support engineers. however I was not able to control Domain Users getting Administrative privileges on domain joined PCs from above settings.
How can I control this admin share access?
Thanks in advance.
I want to be able to share Administrator documents and files with user acoounts on the same computer without having access to the internet I only have one computer But I have different user accounts on that one computer I want each of my users to have access to the Administrators documents files and folders etc I admin documents need users share computer, one to 7 accounts went to Administrator Documents then I Right clicked on a folder then I clicked on Share With gt specific people gt I click on the user account and then I get a box saying my folder was succcessfully shared and now I need to email a link to the specific one computer, 7 users accounts need to share admin documents user account I do all this one computer, 7 users accounts need to share admin documents and then switch user I go to the users email and try to click on the link and it wont click I try to copy and paste into the users documents but it will not copy and paste I go to the user's Documents and try to see if there is a link there but nothing is there What am I doing wrong thanks Granny
I looked thru HELP, but I have only a single computer. I am not trying to interact with other computers, so I cant belong to a domain, workgroup or homegroup, because all these seem to involve multiple computers.http://www.sevenforums.com/network-sharing/169735-one-computer-7-users-accounts-need-share-admin-documents.html
I have been looking for this answer for 2 days and can not find anyone who has had similair problem.
THere are 2 accounts Administrator and Kenmystro/administrator. I have the password for both and can access both. win 7 Ultimate Hp8510.
I have already selected all user permissions and taken ownership in every box I could find for Kenmystro/admin. the UAC is at minimum and the security centre is off. Run as admin on right click does not help.
It does not matter which of the 2 accounts I log into when I try install certain HP software(Maintenance
& some drivers) it says I do not have admin privileges.
This is driving me nuts can anyone help??
I hope someone can help me Just this morning i booted up as normal and the always annoying UAC stopped when account admin admin Admin checked! is even being notifications kept Admin account stopped being admin even when admin is checked! popping up I was sure i had disabled these Then i went to use my music software and it said that this account Admin account stopped being admin even when admin is checked! didn't have admin privileges I checked my user account and the check box states that is is an admin account and that UAC is turnd off i only have one account anyways Ive looked on google extensively Tried making new profiles and copy the old one over but that only worked to a certain point - lots of programs didn't work lost mail settings etc Not really workable Tried system restore to no avail Tried using the vista admin account and changing my account - rebooting - etc No change My guess is that something has got Admin account stopped being admin even when admin is checked! corrupt in my user profile and windows is not remembering that i should be an admin I can't use my software and i have a deadline Any one who can help will win a magical prize or something Jen
Should be easy, create a New Administrator account and give it permissions to use the software.
User Account - Create
Procedure for Seven is the Same as For Vista.
What is the best way to share execution priviledges between limited users, power users, and administrators?
Say an application has already been installed by a higher priviledged user type, and a limited user cannot execute it - e.g. an ISP login software, or Spy Sweeper. Note: ISP login software lacks profile, so I suppose I could just create that, however, Spy Sweeper is a head scratcher.
Should the application be uninstalled and reinstall under All Users? How do you install an application to allow All Users to use it?
I have already tried to use the "Run As" right-click Properties w/Shift key approach and that does not work.
Is there an approach with regard to local security policy that would do what I want to do? How is that done? Or, is Access Control List the way to go?
Server Enterprise R SP fully updated I ve done as much research as my eyes can handle and I ve got my server set up Now when I create a user account everything seems to work fine But when I set up a user with Admin rights the user cannot write to the shares on the server despite setting permissions accordingly Even after I ve just said quot hell with it quot and added the user to every group in the system No writing Reading is fine though While I was logged in to the server as local Administrator - Active issue Directory Share Users On step Active Directory Users - Share issue two where I had blithely added my UserId to every group in the system I then went to each quot root quot folder that was shared and added myself to the users of the folder then granted myself Full Control Under Security tab my name UserID is listed with all check boxes filled in for full control I log out of local Admin and log in as me - ON the server - and still no write access I can read and copy all I want but no writing to that shared folder Then I tried by logging in to another system connected to the server same thing No writing Should I use the Sharing tab - gt Permissions button instead Or both Or is it something else that s stopping it This is the only thing holding me up really nbsphttps://forums.techguy.org/threads/active-directory-users-share-issue.955283/
I'm trying to use PsTools to remotely send messages to clients (using the 'msg' program) regarding the network (e.g. a server is going to reboot). When using it in command prompt, it works for some machines, but for others, it errors about not being able to use the admin$ share on the target computer. I tried accessing the share via Run..., but again, it failed. The targets are all Windows XP. How do I make sure the admin$ share is accessible by the domain controller?
Usually any share with a $ on it is a default admin share and is
limited to the local computers admin acount.
You probably need to change them to standard shares by unsharing
it and clicking apply,then share it again and apply.
That should change the share to one without the $ limitation.
Hey guys I am a networking major in college right now and this is going to sound horrible but i was wondering how you install the admin tools and Active directory on windows xp pro I know on server you have that window that comes up directory... admin tools active and installing when you first boot into the os where you can choose a server role and choose domain controller to get AD but how do you do this in xp pro installing admin tools and active directory... is it only possible to do it online is there another way to install AD in besides choosing a server role As a matter of fact could someone possibly post the options and ways of installing AD on both OS s including installing the admin tools which i think are already there when you install server on a system It has been a while and i have forgotten alot of this and was wondering about it last night and google didn t help Thanks in advance guys nbsp
I'm new to the forum but it looks like a great place.
I was wondering if anyone had found a solution to accessing the default admin shares (c$, d$, etc) on a vista machine over the network.
I've tried the solution mentioned here: Default Admin Share C$
But it didn't fix anything.
I can access other non-admin shares on the computer but can't access any of the admin shares. I'd rather not have to create more shares, but obviously that is a solution.
Thanks in advance.
Hi, 06graphite, and welcome to the forums.
I assume you went through the entire thread and tried all 2 (or 3) suggestions?
My computer started acting funny after watching videos online and getting tons of pop-ups. Some of which claimed I could have a potential virus. Now I know this came from a site and I should never read into it. but it had me wondering.
Then i noticed all of sudden some of the websites I was looking at like would stop opening and would be unavailble.
Now I have AVG Virus Protection on my computer. It is letting me know that my PC health is not good cause the administrative share is enabled and it says I should disable it.
i do not fully understand what this means and why this was an issue in the first place. What should I do? Do I enable or disable and why?
okay freshly into win now having obtained a new hdd for my comp I have been running as the admin of my computer since accounts became an unavoidable thing barring the occasional frustration-induced blunder I tend to stay Properly Paranoid in my habits to make sure I have no problems but win doesn't think that I could ever be intelligent enough to have full rights on any account other than the built-in admin account which of course I'd want to avoid using outside emergencies that render other accounts damaged somehow so I'm looking to find out how to make another user account with FULL admin rights not just the constantly have to get permission stuff that a standard snort admin account has full rights that don't involve constantly having to run as administrator yes yes I've heard people trying to get me more paranoid so that I'd endure the added hassles all it does is make me more irate with the situation so if noone's willing to provide me with instruction on this it's probably best for the thread to be left to fall off the board
I don't know what your problem is. To make another administrator account - Start - Control panel - User Account -
Manage another account - Create a new account - Give it a name - put a check mark for Administrator -
click - Create Account.
Having recently rebuilt Win 2k due to corruption because of using it as Administrator, I now intend to use it as a Standard or Restricted User; but although all of my programs run fine from the Administrator account, some of them will not run from the other account. Have given the other accounts Full Control in Security Properties but still no good. Any suggestions please.
PS I had several 'tech support chats' with MS and was given a phone number to ring which is unobtainable.
I have found the answer myself! Actually with a little help from Ansys Tech Support.
Log on as Administrator:
You need to use regedt32.exe (regedit.exe will not do) and in
HKEY_LOCAL_MACHINE\SOFTWARE click Security and Permissions AT THE TOP OF THE SCREEN! Click Add, select Everyone in the next top screen, click Add in the middle, and OK at the bottom. Back in the Security screen, Select Everyone in the top screen, and click the READ box in the lower screen to put a tick in it.
This has enabled all of my Restricted users to use any program.
I downloaded windows 10 on my husband's desktop computer. He is the one user. Somehow his stuff is separated into two users - me being the other user. It may be a problem with our google/gmail accounts that messed things up, but I didn't do anything to indicate their would be two users. My husband seems to think that what I do on my desktop PC affects him. Should I see a local specialist on this and if so, who am I looking for? I'm just an average computer user with no tech knowledge.http://www.tenforums.com/user-accounts-family-safety/65548-how-do-i-combine-two-users-into-one-admin.html
"Could not load or run 'C:\Users\admin\Temp\csrss.exe' specified in the registry. My computer has been doing this for a while, but i was ignoring it, but i need help on what to do...
Hello, looks like a broken malware file. Lets try this way firstRun TFC by OT (Temp File Cleaner)Please download TFC by Old Timer and save it to your desktop. alternate download linkSave any unsaved work. TFC will close ALL open programs including your browser! Double-click on TFC.exe to run it. If you are using Vista, right-click on the file and choose Run As Administrator. Click the Start button to begin the cleaning process and let it run uninterrupted to completion. Important! If TFC prompts you to reboot, please do so immediately. If not prompted, manually reboot the machine anyway to ensure a complete clean.http://www.bleepingcomputer.com/forums/t/410205/could-not-load-or-run-cusersadmin/
Here is EXACTLY what it says
Windows could not connect to the system event notification service service.
Please consult your system administrator.
Now I checked the system event log, and all of that stuff means nothing to me.
Talked to the system admin, he doesn't know either.
So please help me out!
i have windows7 on my pc with an admin (me) and a normal user (my brother) part, every time i install a program, win7 don't ask me nothing, and install in both parts, now i want to install some programs only in my admin section, and i want the other users can't see the program i've installed, they can't see, they can't touch, they can't do any damage XD
someone can help me?
Down load the program. Right click on icon go to properties>compatibility> change setting for users >privileges. Then select what you want.http://www.sevenforums.com/general-discussion/41130-windows7-admin-users.html
Here's what we're working with...
Windows XP Pro SP3 machines.
Workgroup environment connected to our company domain via Sonicwall VPN devices. Each workgroup computer has a WINS entry so we can resolve names to IP's.
I can ping the PC names, but when trying to access the administrative share, the PC is not found. I know i overlooked some mundane detail, and to be honest, i need a hand since my brain hurts.
Does anyone know the answer to this? I have created a workgroup, my desktop and a laptop, both using XP pro accessing using same netgear router... I have created an account on the laptop (the one i was to connect to) called luke and this has been added to the admin group.
Now I login onto my desktop as luke so i figured the laptop would let me access its admin$ share? i can access the laptops basic share folder (shareddocs)... but when i try to connect to the laptops admin$ a "connect to" screen which shows the username set to "guest" which is greyed out and cant be changed! I even added guest to the admin group and set a password to see what would happen but still no difference
My laptop has only ever had one admin user account with full access to sensitive information, but I have now added a non-admin account which needs occasional access to restricted content.
I want to give temporary access only to a personal folder.
It seems that once the non admin user opens the specific restricted folder (and I input my admin password), this gives permanent access to this folder. To deny access again, I have to log back into my admin account and click 'Stop Sharing'.
Is there a way to time-out access, or have access automatically suspended via switch user/log off?
Instead of using Explorer you can get more control with
Also in a command prompt run this for options list
net use /?
Hi there, I'm sat here at my mum's at the moment, and she really needs to me help fix a computer error for her I've googled and searched and can't seem to fix the error, if you could help me asap I would really appreciate it please
Basically, she has two user accounts on her pc - both set to admin. She uses admin B all the time and admin A rarely.
Admin A contains Microsoft Office (preinstalled on the pc), but she can't access it from Admin B - which is what she ultimately wants to do.
How can I set it so she can access it from her regular admin account (B)?
I hope this is clear enough and thank so much in advance of your kind help
Happy New Year
Hi, how can i grant local computer admin rights to the domain users on the same computer? Please help, thanks.
Today I was adding my first two Win7 client workstations to our Active Directory. We map drives via GPO to WinXP SP3 clients with no problems. Today I joined my first Win7 client with no problem. However, when I log in on the Win7 client (users with local admin priv) , I don't get any drive mappings. If I switch the users to the local users group, then the drive mappings will appear. Also, if I disable the UAC (user access control), a user with local admin rights will get their drive mappings.
I don't want to operate without the extra protection of the UAC, but is there a way to have local admin rights and get your drive mappings (with the UAC enabled)???
Thanks in advance
There is a way but I believe you need to go into the group policy editor to do so. This procedure is for Vista but it should also work for Windows 7.
To change the elevation prompt behavior for administrators Click Start, click Accessories, click Run, type secpol.msc in the Open box, and then click OK.
From the Local Security Settings console tree, click Local Policies, and then Security Options.
Scroll down to and double-click User Account Control: Behavior of the elevation prompt for administrators.
From the drop-down menu, select one of the following settings:Elevate without prompting (tasks requesting elevation will automatically run as elevated without prompting the administrator)
Prompt for credentials (this setting requires user name and password input before an application or task will run as elevated)
Prompt for consent (default setting for administrators)
Close the Local Security Settings window.
To change the elevation prompt behavior for standard users Click Start, click Accessories, click Run, type secpol.msc in the Open box, and then click OK.
From the Local Security Settings console tree, click Local Policies, and then Security Options.
Scroll down to and double-click User Account Control: Behavior of the elevation prompt for standard users.
From the drop-down menu, select one of the following settings:Automatically deny elevation requests (standard users will not be able to run programs requiring elevation, and will not be prompted)
Prompt for credentials (this setting requires user name and password input before an application or task will run as elevated, and is the default for standard users)
Close the Local Security Settings window.
I need to allow some of our users to start an application on their workstations, but UAC will only allow admin users to start this application (control software for remote security cameras). The workstations are running Windows 7, and our server architecture is Server 2003. We'd prefer the application to be installed on the local machines rather than run directly from the server. Does anyone know a way to allow a user to start such an app without A) having administrator privileges, and B) completely disabling UAC?
Hi sqlreid and welcome to Sevenforums!
There's this way: Elevated Program Shortcut - Create for Standard User
In short you use the built-in administrator account and store the password in the Credential Manager. But it's not a perfect solution, make sure you read the information in the warning boxes!
Hi all, everytime I install a new program it is available to all other users on my home pc. I am the administrator but not sure how to install for only me. Also for programs already installed how can I remove them from others users but keep them available for me to use. Thanks
Boot into Safe Mode
Right click on the installation file/Properties /Security.
Click Add /Advanced /Find Now
Select the Users you want to block
then OK again
Under ?Deny for each user? put a check at ?Full Control?
Hi, how can i grant local computer admin rights to the domain users on the same computer? Please help, thanks.
I recently have installed windows 8. It works great so far for me. Currently, I have an administrator account and a normal user account.
What i noticed here was, whenever i install a software on the administrator side (for eg: Spotify), it does not go into program files but another folder : C:\Users\JohnDoe\AppData\Roaming or LocalUser...
And on the User side, it will not show the program that I have installed in the administrator side. I tried doing the application search type on the metro, it does not show anything up at all.
Usually when I install software, some application has a setting where it says install for all users, but this time there are software that does not have that options,and I would like whatever I have on the admin end to show up on the user end. Anyway I can do that?
Any ideas how can i do that?
Some programs will do that.
I'm not sure why but Spotify does it.
There is quite a few topics asking very same question. For instance: http://community.spotify.com/t5/Desktop-Mac/Change-install-location-of-Spotify/td-p/23471
I found out that Google Chrome will do very same thing: http://productforums.google.com/forum/#!topic/chrome/umUC6G8mTkA
a works laptop has gone screwey (it mainly affects the user account) and i need to get the pop3 mail settings etc off that account.
It lets me log in as admin only, albeit very slow and haphazard. It hangs when trying to log in as the user.
Whilst logged in as admin is there any way i can access the users email and export to a .pst so i can then re-import it onto a working laptop? If i log in to the user in safe mode, then try opening outlook it comes up with an error, asking me to restart the program or reinstall.
Using Outlook 2003 on XP Pro SP2 laptop.
Thanks for any help offered
Just browse to the relevant folder in the user's Documents and Settings..
If it denies access, take ownership of the folder and subfolders.
I'm the administrator for my company but was not around when the original IT here setup the account settings and whatnot The issue I'm having is with the UAC For most users whenever they try to install a file add a printer or make and kind of setting changes the UAC pops up and prompts for a password But as I work with more employees I'm noticing that some of their accounts won't for users admin prompting not UAC login certain give UAC not prompting certain users for admin login me the option to enter my login and thus not able to make appropriate changes to their computers It doesn't seem to have a real pattern as to who it is affecting e g it's happening to newly created users as well as long time employees I feel it prudent to say that I've got no official training in this field and am self taught That isn't to say I won't be able to answer followup questions or elaborate on the issue Thanks for any help advice you can give
Is that happening on an individual machine that many people share (under their own account each) or across many computers for each one? Are they using domain accounts or locally defined users?
A few things to check beforehand would be, that UAC is really enabled where the problem happens and that the users are really standard without admin rights.
When users with admin privileges have ownership of files and folders, do those files and folders remain, or are they deleted?
This question arises from having tried to copy my primary admin profile to that of a new (backup) admin user. During that tedious and unsuccessful process, I had to change ownership and privileges of a number of folders and files, and now some of my programs are having trouble finding needed files. So rather than wading through everything and changing the settings back, I'd prefer to delete the new admin user -- as long as I won't lose the files.
Does that even make sense? (It's way past my bedtime!)
Make copys of all the files you want to keep or use an admin account and pull the files onto the account you wish to keep then delete the old one. As long as you have a copy that you have privileges to on the account you are going to keep you should be fine, just make sure to keep a copy of all the files that you can get into.http://www.bleepingcomputer.com/forums/t/118638/deleting-users-with-admin-privileges/
tonight my mother takes over my admin account and is setting parental controls so it sets a time so i can log on, i have made a user account and still want to get my files from my admin folder, but i cant... is there anyway i can go around this..
its just that i cant be bothered moving files over to the user account...the parental controls are temporary till i control myself on how long i am on my computer, because atm i am not listerning to my perants requests and i end up forgetting what they have asked me, which i get in to trouble if i don't do what i am told
any help would be ace!!!
We will not help you bypass your mother's wishes. If you want this resolved, you will need to talk to her to allow you to.
If you post anymore posts trying to circumvent your mother's Parental Control settings here, you will be permanently banned.
Windows 7 Professional 64bit
I have used the guide on how to enable and hide the in-built admin account and was successful however I found that after making the account I used to set up Windows 7 from admin to standard user and then disabling the in-built admin account the UAC setting would not correctly work, as it wanted admin privileges but it was not giving me the option to enter the admin password. The ok button would be greyed out.
Has anyone come across this before and if so what is the solution.
Never happened to me before, however, did you try going into safemode and sorting it out from there?http://www.sevenforums.com/general-discussion/303016-admin-standard-account-users.html
After the updates (kb958690, kb905866, kb960225) were installed on the morning of 3/10, sound no longer functions on users that do not have admin privileges. If I log back into an admin account everything works fine. I've rolled back the Windows Mail (kb905866) update, but it has had no effect. Given that the other two are for security updates, I left those in place.
For other reference, I run a Sony VIAO media center that was working fine before that update. And after the update, there is one of the standard application services from Sony that is not prompting for an admin password when logging into a non-admin account. Entering the correct information has no effect.
Without rolling back security updates, or opening up all users as admin, are there any ideas on how to get the sound back?
One of my users wants to use a different Office Assistant in MS Word Pain in the trying to changes settings Admin make to users I say but it s a simple change so I go to make it She can t change it logged on as herself due to access restrictions I try to map the drive as the admin but can t due to conflicting credentials or something of that nature Then I log on as admin Admin trying to make changes to users settings and make the change but of course the change isn t propagated into the users account And this brings me to my point I m new to administrating on a corporate level so bear with me We have our users locked down and that won t change So when one of them wants a change to their system that requires admin rights how do I do it and make sure the change happens to the user s account as well Is there some way I can log Admin trying to make changes to users settings on as admin in their account With the above example what s the solution Thanks Kevin nbsp
Hi everyone Here is my latest Vista woe s Dell Inspiron gbRAM gb HDD Core duo T GHz Vista Home Prem - auto update AvastHome Windows Defender AVGAntispyware RUBotted Threatfire Some background I have profiles on the machine Admin which is my original Admin account I've used it to install apps etc Basic which is my everyday non-admin profile that I use for just about everything New Admin files Admin can't App Admin - Permissions Problems / Install UAC, Public / access which is a new admin account I created for trouble shooting but it has the same problems that the original one has There are basic issues I'll use one particular instance as an example but it's not the only instance AND it's an intermittent issue - sometimes problem happens sometimes it doesn't Ten minutes after this instance I downloaded and installed an app and it ran fine In my Basic profile I downloaded Skype and saved the file to my Public Downloads folder I right-clicked quot run as administrator quot Problems - Admin Permissions / App Install / UAC, Admin can't access Public files to try and install Problems - Admin Permissions / App Install / UAC, Admin can't access Public files and got this error Windows cannot access the specified device path or file You may not have the appropriate permissions to access the item I tried just clicking it to run it without quot run as administrator quot and got the same error I did some searching on the error and found some postings elsewhere but most were very old and in WinXP instead of Vista but I tried investigating the things mentioned in those posts - I ran the AVG scan and removal tool for the Gaelicum A virus - it didn't find anything - I checked the properties of the file and it did not say anything about coming from another computer and needing to be unblocked - I logged out of my Basic profile and logged into my Admin profile and all the same problems happened - I logged into my New Admin profile and all the same things happened In my New Admin profile I copied the file from the Public Downloads folder and tried pasting it into my New Admin's own Downloads folder and got this error Destination Folder Access Denied You'll need to provide administrator permission to copy this file NOTE This happened IN MY ADMIN PROFILE Click quot Continue quot and get this message User Account Control Windows needs your permission to continue If you started this action continue File Operation Microsoft Windows AD - - - - B BDB E Click quot continue quot and the installer begins It runs a while and then I get this message the dialog box says its a message from Skype but I've gotten similar messages from other software I've tried to install Cannot write the installation package on the disk Please make sue that you have the necessary disk space available There are GB available on this disk This is not a new problem so I can't think to associate it with any particular software change and so 'restoring' to an earlier time isn't helpful because it's not tied to any particular time that I can identify I haven't changed hardware AND the associated issue at least I think it's associated is that sometimes installing apps in one profile doesn't flow thru to the other profiles and I can't find any rhyme or reason to that - I've had this happen whether I install the apps while in my Admin account while in my Basic account and using quot run as administrator quot to install or whether I'm in my Admin account and using quot run as administrator quot EVEN THOUGH I'm IN MY ADMIN account because some apps seem to require that kind of thing Then the icons for that app won't show up in different profiles' start menus I can't even search for the apps - have to sometimes dig into C xx to find an executable to create a shortcut Sometimes then trying to run the app and I'm talking about something basic like maybe a PDF viewer or something like that it says I need administrator permissions to run it I'm so tired of all this Can someone please help me I'm ... Read more
Helloooooo??? Anybody out there?
I'd really appreciate any help you can offer me.
[UPDATE] incidentally, since writing this I have been able to install a couple of other small apps (but have also run into the same problem on a couple of others).
Hi Yet again Windows is frustratingly taking up all of my time and I have tried everything google has to offer to try and fix it but it seems like no one has screwed up as much reset admin | | can't admin | Lost 5 No password error rights System as I have on whatever forum Let me explain the problem I'm trying to set my account to administrator because I can't install programs change account settings make any changes through CMD without getting the system error access denied message and I can't set the administrator account through CMD either I also don't have the permission to change anything in regedit and I can't even reset my pc because it requires an administrator password System error 5 | No admin rights | Lost admin password | can't reset which I don't have is not quot nothing quot nor is it administrator or admin or password and I can't change it through cmd either I can't even access the administrator account because it is disabled and even with an elevated System error 5 | No admin rights | Lost admin password | can't reset cmd I can't activate the quot hidden quot administrator account System error 5 | No admin rights | Lost admin password | can't reset I've ran malwarebytes and superantispyware and I am now looking for the Gandalf of all Geeks to help me solve this problem I'd immensely appreciate it
Hi. When a computer is first setup, the account created is an administrative one. What happened to this account?http://www.tenforums.com/user-accounts-family-safety/37732-system-error-5-no-admin-rights-lost-admin-password-cant-reset.html
Hello All I'm delighted No to accounts change /Cannot Admin admin user account existing Access to have found you and after a long day of trying to help myself i am now requiring your much appreciated assistance please I'm not a techy person at all and am hoping someone can help Last week my husband purchased a new hp laptop which No Admin Access /Cannot change existing user accounts to admin account came with Windows On setup i used my No Admin Access /Cannot change existing user accounts to admin account microsoft account to login with a pin the account was setup as administrator No Admin Access /Cannot change existing user accounts to admin account thinking i could change things later About days later i added a standard user account for my husband with a microsoft account login with pin I wanted to make his the administrator account but thought i had better change mine to a standard account first My mistake Now i cannot change anything i have tried to use the cmd prompt to run as administrator - it asks for administrator permission and does not allow me to enter a password or yes I have tried all suggestions to enable the hidden windows account but all ask for the same permission I have tried to go to setup recovery troubleshoot advanced option system restore - it requests an administrator password and when i entered what i thought is mine it does not work Feeling a little Does anybody know anyway i can go back in time to start again or how do i access administrator rights as i really need to add programs etc Thank you for any help givenhttp://www.tenforums.com/user-accounts-family-safety/61945-no-admin-access-cannot-change-existing-user-accounts-admin-account.html
Hello, I just purchased a new lenovo v570 laptop runing windows 7 home premium.
I scanned an image using my Epson NX 400 usb all-in-one printer. Then I tried to save it to my external USB enclosed sata drive. I haven't had any problem like this before. They said, I didn't have permission. I am running the laptop as an administrator. What other permission do I need? Antivirus and firewall software is all up and funny functional.
Ive stumbled across a problem that has been causing me grief for a few days now, every time I try to access my hard drive (C disk) it says, access is denied. Also, i cant edit permissions because I've lost admin rights. Ive tried many things including unlocking the system admin, this lets me access a few extra things like being able to use the sfc command in cmd, however, it doesn't allow me to access the C disk or change permission because it also has lost admin rights? I fear that this is a bad problem and I don't know how it happened. I have tried restoring to a previous date and that doesn't work either.
Any help and/or advice would be greatly appreciated.
Hi and welcome to TSF so you have tried win 7 hidden admin Enable the (Hidden) Administrator Account on Windows 7 or Vista
have you installed or downloaded anything in the recent past
I need to either change a guest log in (kid's access) to
adminstrator, or a way to reveal or change the password
for the Admin profile. Thanks for your help.
I tried this already: Run: cmd net user guest *
I tried to rest the guest password this way but
it didn't work - I'm thinking it is because I am not
logged on as admin in the first place. What do I do now?
you cant change an admins pw from a guest account....at all
only way to change the admin pw is to boot to safe mode and enter the sys admin account or use a hacking program iso which you can find easily but use at your own risk....
I am working on a 2012 ADDS based network and I have the following requirement.
I want to create a local administrator user account on the local domain computers (Win XP, 7 and 8) which will have full access on the PC but not the permission to edit other local administrator accounts.
Please advise how I can achieve this.
Thanks in advance,
Local admin account by definition has access to everything and even if it doesn't it can take ownership and give itself the rights. In other words i am not sure that you can achieve what you
are trying to do.
I would suggest create a single shared local admin account and give it your desktop admins, change the password every 60-90 days to keep it more secure. This is common practice in many
Basically I have two admin accounts one of which belongs to another member of family and one which belongs to me. Heres the situation:
The person who owns the other Admin account is changing my accounts password (also an admin account). Surely there is some way to make it so that I can not have my account's password changed unless it is logged on to my actual account (so my account's password can only be changed if my account is logged on?)
Is there a way?
In urgent need of help!
Here's an article (for Win2K) that may help: http://support.microsoft.com/kb/309799But, IMO, the issue here is that the other person can't be trusted. In such a situation I'd suggest making the other account into a Standard User account - that way they won't be able to mess with your stuff, and they'll be reliant upon you for anything that requires administrative privileges.http://www.bleepingcomputer.com/forums/t/153087/prevent-admin-accounts-from-changing-other-admin-account-passwords-in-xp/
The firm in which I work has a Lenovo PC with Windows 10 installed. There are two user profiles on the computer, the admin and another normal account without administration rights. We have only the password of the account without administrator rights.
The network administrator had left the company surprisingly in without giving the administrator password of the PC and we cannot contact him anymore.
Now we want to install another programme and we cannot do this without an administrator account.
I disabled secure boot and have tried to boot the PC with an Linux USB Stick, but it do not boot from the stick.
Any suggestion how I either can reset the password of the administrator account or create an new account with administrator rights.
Although there may be techniques to recover a lost password it is forum policy that we do not discuss these here - your best bet would be to visit a local security specialist and get them to recover/reset it for you - and a change to the policy for the replacement admin may be a good idea, I always wrote a list of all passwords and stored it with the Managing Director and also in a fireproof safehttp://www.tenforums.com/user-accounts-family-safety/38274-windows-10-admin-password-reset-new-account-admin-rights.html
Frustrated with admin rights - Please help me.
Just purchased new PC - HP Pavilion desktop and upgraded to Windows 10 during installation. I've downloaded Google Chrome as my default search engine with no issues. I've attempted several times to download Google Earth. Download fails: "Google Earth needs administrator privileges to install."
I am the only user on this PC and User Account type indicates that I'm the "Administrator".
Why won't Google Earth install?
Hello and welcome!
Sometimes you have to run the installation file and deliberately make it "Run as Administrator" by right clicking on the downloaded file and selecting this option. Not sure if this is the case with Google Earth but worth a try.
We have a script that installs a program (Office 2007). It then imports some registry file settings. It imports HKLM and HKCU. We have noticed that if this is installed as a local admin, the settings seem to take if we scan the box as a local admin(we are running a security scan to determine this (the security scan checks multiple gpo's supposed to be set by the program/reg imports). If we scan as a domain admin, the system doesn't seem to show they are set. We believe we see the opposite if it's installed as a domain admin. For the domain scan they are set, for the local scan they are not. Does this have to do with how you can change registry entries as a domain admin versus local admin? The registry settings are imported with reg.exe import filename.reg like commands in the .bat script. Any ideas are helpful.
I'm new to Windows 7.
I'm still trying to master the file permissions.. I need some help and I'd appreciate it if someone could help me out.
I have a folder with mp3s (created with my old Windows XP system). I've included this mp3s folder in the "my music" library and then I inspected the folder and took ownership of it together with everything it contains (following instructions I found on the Net).
Nevertheless, when I'm trying to delete or move a file I get the message that I need to provide administrator permission! But I thought I am both administrator and owner...
Also, when listen to the songs with WinAmp, it seems I cannon save any song data. I get: Cannot save metadata: Error opening file.
I suppose, it's an aspect of the very same problem.
What am I missing?
Take a look on the properties of the folder see if you have an unblock button . If you do click on it .http://www.sevenforums.com/system-security/297001-i-need-admin-permission-delete-move-file-but-im-both-admin-owner.html
Hey all I have recently installed Windows on my development machine at work primarily in order to test it and get a feel for it and all the little things that can go wrong before the IT department I work for roll it out to all the other employees at the company They're still on XP SP Unfortunately I'm experiencing several crippling issues caused by admin super and the Domain users account the stricter administration Domain users and the super admin account model used in Windows and Vista for that matter compared to Windows XP We have programs crashing or refusing to install or run because they were designed for XP and require admin rights So when they're unable to acquire them from Windows the programs throw exceptions An example of this is Trend Micro OfficeScan a popular antivirus program used in many companies This program is caused to install by start-up scripts that are run when you log on to your computer using your domain username and credentials but the installer crashes because the domain user is not a local super admin And that's the core of this question I want my domain user to have full administrative privileges I've done a lot of research on this particular problem and I realize it's possible to activate a special super admin-account that has full access to everything on the computer but that workaround doesn't cut it for me because the only thing that accomplishes is to make the super admin account available for login but the super admin account is not a domain user at my company's network it is a local user It doesn't have access to the company's network resources and therefore it is useless to me What I want is for my domain user and credentials to have super admin privileges Is that possible in Windows I am essentially looking for a way to elevate any user of a system to have the same privileges as the super admin account I realize this is a potential security risk because everybody and everything has access to installing everything on the system but frankly the amount of software that Windows 's security model causes to malfunction due to too strict security features is too high a price to pay In many cases it corresponds to pulling the network cable out of the wall Sure you won't get attacked by malware but you won't get any work done either Any and all help appreciated
Due to the Dual token design of the security model in use you will have issues with applications designed for the older model.
The solution to this need not be an all or nothing one however, It should be possible to give the required installer rights to the user group(s) concerned, directly.
This may be done universally to the complete program files folder(s) or more usefully to individual folders for the older problem apps.
I have seen situations where a non working older program can be made to work/Install by the granting a standard user full access rights to a single settings file or to the installation folder.
Depending on what you desire as a company you can make some groups allowed to install some software or not just by the application of the correct rights, In a domain environment this is of course a lot easier than a peer to peer set up.
Unfortunately due to the developers taking the easy way out with regards to administrative rights with XP there will be some re-thinking required by those tasked with moving to a more secure modern OS. This is quite possible though there will be a learning curve.
The main issue with application installation is not the need for a "super" admin but the "trusted user" used by UAC to protect the Program store. by taking ownership of the role of this "User" most if not all issues may be resolved.
Full information on the Trusted Installer scenario is available from Microsoft on technet - or of course by many independents
If xp is setup in admin how do I give users access to the internet, outlook, and browsing. Thanks
As the subject indicates, I've installed 3Com ADSL software on a W2K machine as the administrator. When logged on as the admin I have internet access. However, when I log on as a user I receive an error as soon as I log on refering to the modem software. The error reads 'Cannot read registry'. It seems obvious enough that I have a permissions issue but I haven't the slightest how to work it out.
You can use regedt32 to set registry permissions.
Go to start - run and type in regedt32.
Find the key that ADSL is installed to, probably in the hkey_local_machine\software.
Click on the registry entry that you need and then on the menu go into security -- permissions. They are almost like setting file permissions.
"Could not load or run 'C:\Users\admin\Temp\csrss.exe' specified in the registry. Make sure the file exists on you computer or remove the reference to it in the registry." At first, I ignored it, but Internet Explorer only opens Https://www.facebook.com and Https://encrypted.google.com (right now I am using my laptop not my computer). What should I do?
Welcome aboard You're surely infected.Download Security Check from HERE, and save it to your Desktop. * Double-click SecurityCheck.exe * Follow the onscreen instructions inside of the black box. * A Notepad document should open automatically called checkup.txt; please post the contents of that document.=============================================================================Please download MiniToolBox and run it.Checkmark following boxes:Report IE Proxy SettingsList content of HostsList IP configurationList last 10 Event Viewer logList Users, Partitions and Memory sizeClick Go and post the result.=============================================================================Download Malwarebytes' Anti-Malware (aka MBAM): http://www.malwarebytes.org/products/malwarebytes_free to your desktop. * Double-click mbam-setup.exe and follow the prompts to install the program. * At the end, be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish. * If an update is found, it will download and install the latest version. * Once the program has loaded, select Perform quick scan, then click Scan. * When the scan is complete, click OK, then Show Results to view the results. * Be sure that everything is checked, and click Remove Selected. * When completed, a log will open in Notepad. * Post the log back here.Be sure to restart the computer.The log can also be found here:C:\Documents and Settings\Username\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\Logs\log-date.txtOr at C:\Program Files\Malwarebytes' Anti-Malware\Logs\log-date.txt=============================================================================Please download GMER from one of the following locations and save it to your desktop:Main Mirror
This version will download a randomly named file (Recommended)Zipped Mirror
This version will download a zip file you will need to extract first. If you use this mirror, please extract the zip file to your desktop.Disconnect from the Internet and close all running programs.Temporarily disable any real-time active protection so your security programs will not conflict with gmer's driver.Double-click on the randomly named GMER file (i.e. n7gmo46c.exe) and allow the gmer.sys driver to load if asked.Note: If you downloaded the zipped version, extract the file to its own folder such as C:\gmer and then double-click on gmer.exe.
GMER will open to the Rootkit/Malware tab and perform an automatic quick scan when first run. (do not use the computer while the scan is in progress)If you receive a WARNING!!! about rootkit activity and are asked to fully scan your system...click NO.Now click the Scan button. If you see a rootkit warning window, click OK.When the scan is finished, click the Save... button to save the scan results to your Desktop. Save the file as gmer.log.Click the Copy button and paste the results into your next reply.Exit GMER and be sure to re-enable your anti-virus, Firewall and any other security programs you had disabled.IMPORTANT! If for some reason GMER refuses to run, try again.If it still fails, try to UN-check "Devices" in right pane.If still no joy, try to run it from Safe Mode.
Hi guys, i have a problem, i'm not sure if this issue has been raised or what but here is my problem.My environment:2003 Domain controllerFile and Print server WSUS ServerSQL ServerWindows XP wks2 new Windows 7 wksWhat happens is that when i try to logon to the domain on the win7 machine as a std user i get error"You cannot log on because the logon method you are using is not allowed on this computer"If i logon with the domain admin account i'm able to logon and also if i make users members of domain admins they are able to logon to the domain. I realy do not believe that this is the way to go because it compromises my network security. Any help will be gladly appreciated.Thanks
Symptom: When trying to logon a computer using non administrator ID, you may receive this message: "You cannot log on because the logon method you are using is not allowed on this computer. Please see you network administrator for more details."
Case 1: Group Policy' "Allow log on locally" was not setup to allow users or domain users. To setup allow users or domain users to logon the computer or domain, you need to add the users or domain users to the "Allow log on locally". Please follow these steps to add the users.
1. Run gpedit.msc.2. Expand Windows Settings\Security Settings\Local Policies3. Click on User Rights Assignment4. Ensure that "Allow log on locally" includes Administrators, BackupOperators, Domain Users or Users.
Case 2: Group Policy' "Deny log on locally" was setup to deny users or domain users. To setup allow users or domain users to logon the computer or domain locally, "Deny log on locally" should be empty or no users or domain users in the list. Please follow these steps to remove the users or domain users from the "Deny log on locally".
1. Run gpedit.msc.2. Expand Windows Settings\Security Settings\Local Policies3. Click on User Rights Assignment4. Ensure that "Deny log on locally" is empty.
Case 3: The local group policy allow user to logon. However, domain group policy which overrides local policy doesn't allow users to logon locally. The resolution is modify the domain policy to allow users to logon locally.
Case 4: The domain policy allows domain users to logon locally, but the local policy doesn't and the domain policy doesn't apply to the computer. The fix is running gpupdate to force to update the domain policy.
Case 5: Norton Firewall blocks the communication between the client and domain controller. The solution is disabling Norton firewall or re-configuring it to allow to access the domain controller.MCSE, MCSA, MCDST
[If this post helps to resolve your issue, please click the "Mark as Answer" or "Helpful" button at the top of this message. By marking a post as Answered, or Helpful you help others find the answer faster.]
I've been on the bleepingcomputer site for some time but finally created an account
Because of the nature of the software we use at work all workstation users have to be a member of the Administrator group to use it. As a result, the guys in the back have a nack for downloading bad stuff and removing the sunshine from my day
Anyone have any suggestions on how I can limit what they can do (prevent malware, spyware, downloading of bs...ect) while they have the Admin rights?
The workstations are all custom built with Windows XP Pro SP2
There is the main Admin account and they log in with a user account thats part of the Admin group.
Hi jr, so are they admins on there own PCs or admins on the Domain? What is the software that requires a admin account?http://www.bleepingcomputer.com/forums/t/127697/any-suggestions-for-securing-users-with-admin-rights/
I have a win2k term server running with about 25 users. I've noticed that most users have administrator rights even though the administrator group is not in their properties. What causes this? Nothing shows up in adaware or AVG antivirus.
I just want to delete my User account "David". When I initially installed Windows I provided the name David so I was the main and only User account.
Now is it possible to delete that account, leaving me back at a user account screen to create a new main and only account?
Note: I do not wan't to just create a new Admin account (like you can in control panel) as I tried that (and then deleted the "David" account) but it left behind Users/David and the machine was still called David-PC. I want the new account to have No access to my old account.
Windows 7 Professional 32bit
Thanks for reading!
Well 1st you need to Add your new account then after that you need to delete inc all content of the account then goto "My Computer" and change name in the Advanced propertys.http://www.sevenforums.com/general-discussion/221753-advice-about-admin-users-if-i-can-delete-account-not.html
A work computer presented i.e. access tools, to folder users No and admin this message when trying to open Internet Explorer or more parts of this message could not be displayed there was an error opening this message there is not enough memory file download do you want to save this file google com htm Google was no help I put flash drives into the computer to No access to admin tools, users folder and i.e. access some info and later took them home and put one of them in my home computer Now both computers are infected and maybe more at work I am unable to open most of the administrative tools I cannot access the users folder and internet explorer will not open Both computers are running Windows XP I would greatly appreciate any suggestions Urge I see that dds exe has found a rootkit I want to run it but I No access to admin tools, users folder and i.e. will wait for someone to show up DDS Ver - - - NTFS x Internet Explorer BrowserJavaVersion Run by Urge at on - - Microsoft No access to admin tools, users folder and i.e. Windows XP Professional GMT - AV avast Antivirus Enabled Updated DB - F - A -B - A FD D FW avast Antivirus Enabled Running Processes C WINDOWS system Ati evxx exe D Program Files Alwil Software Avast AvastSvc exe C WINDOWS system Ati evxx exe C WINDOWS Explorer EXE D Program Files Alwil Software Avast afwServ exe C WINDOWS system spoolsv exe C WINDOWS system mmm exe D Program Files Acronis TrueImageHome TrueImageMonitor exe C Program Files Common Files Acronis Schedule schedhlp exe C Program Files Olympus ib olycamdetect exe C WINDOWS system rundll exe D Program Files Alwil Software Avast AvastUI exe D Program Files D-Tools daemon exe C Program Files Microsoft Xbox Accessories XboxStat exe C WINDOWS RTHDCPL EXE C Program Files TightVNC tvnserver exe C Program Files VistaSwitcher vswitch exe D Program Files Utilities HDD Health HDDHealth exe D Program Files Utilities Core Temp Core Temp exe C WINDOWS system ctfmon exe D Program Files SUPERAntiSpyware exe D Program Files SASCORE EXE D Program Files Innovative Solutions Advanced Uninstaller PRO - Version monitor exe D Program Files WIDCOMM Bluetooth Software BTTray exe C Program Files Common Files Acronis Schedule schedul exe C Users All Users Application Data Freemake FreemakeUtilsService FreemakeUtilsService exe C Program Files Microsoft SQL Server Tools Binn sqlmangr exe C Program Files Microsoft SQL Server MSSQL Binn sqlservr exe D Program Files Utilities T-Clock build T-Clock build X - Release to DC Win Clock exe C WINDOWS system wbem wmiprvse exe D Program Files Nitro PDF Reader NitroPDFReaderDriverService exe C Program Files Raxco PerfectDisk PDAgent exe C Program Files Savevid SavevidService exe C Program Files Secunia PSI sua exe C Program Files Savevid SavevidWSServer exe C Program Files NeoSmart Technologies ToolTipFixer ToolTipFixer exe C Program Files Savevid SavevidPluginCore exe C Program Files TightVNC tvnserver exe D Program Files Unchecky bin unchecky svc exe D Program Files WIDCOMM Bluetooth Software bin btwdins exe D Program Files Unchecky bin unchecky bg exe C WINDOWS System alg exe C WINDOWS system wbem unsecapp exe C WINDOWS system wbem wmiprvse exe C WINDOWS system rundll exe D Program Files Mozilla Firefox firefox exe C WINDOWS System svchost exe -k netsvcs C WINDOWS system svchost exe -k bthsvcs C WINDOWS System svchost exe -k HPZ C WINDOWS System svchost exe -k HPZ C WINDOWS system svchost exe -k imgsvc C WINDOWS System svchost exe -k HTTPFilter Pseudo HJT Report uStart Page hxxp www google com uSearch Bar hxxp www google com ie mSearchAssistant hxxp www google com ie mWinlogon SFCDisable dword - BHO Java Plug-In SSV Helper BB-D F - C-B EB-D DAF D D - BHO avast Online Security E E -AD D- bf-AC D-D F D - BHO Java Plug-In SSV Helper DBC -A - b-BC - C C C A - uRun VistaSwitcher c program files vistaswitcher vswitch exe startup uRun HDDHealth d program files utilities hdd health HDDHealth exe -wl uRun Core Temp d program files utilities cor... Read more
Hello and welcome to Bleeping Computer! I am HelpBot: an automated program designed to help the Bleeping Computer Staff better assist you! This message contains very important information, so please read through all of it before doing anything.
We apologize for the delay in responding to your request for help. Here at Bleeping Computer we get overwhelmed at times, and we are trying our best to keep up. Please note that your topic was not intentionally overlooked. Our mission is to help everyone in need, but sometimes it takes just a little longer to get to every request for help. No one is ignored here.
To help Bleeping Computer better assist you please perform the following steps:
*************************************************** In order to continue receiving help at BleepingComputer.com, YOU MUST tell me if you still need help or if your issue has already been resolved on your own or through another resource! To tell me this, please click on the following link and follow the instructions there.CLICK THIS LINK >>> http://www.bleepingcomputer.com/logreply/556953 <<< CLICK THIS LINK
If you no longer need help, then all you needed to do was the previous instructions of telling me so. You can skip the rest of this post. If you do need help please continue with Step 2 below.
***************************************************If you still need help, I would like you to post a Reply to this topic (click the "Add Reply" button in the lower right hand of this page). In that reply, please include the following information:If you have not done so already, include a clear description of the problems you're having, along with any steps you may have performed so far.A new DDS log. For your convenience, you will find the instructions for generating these logs repeated at the bottom of this post.Please do this even if you have previously posted logs for us.If you were unable to produce the logs originally please try once more.If you are unable to create a log please provide detailed information about your installed Windows Operating System including the Version, Edition and if it is a 32bit or a 64bit system.If you are unsure about any of these characteristics just post what you can and we will guide you.Please tell us if you have your original Windows CD/DVD available. Upon completing the above steps and posting a reply, another staff member will review your topic and do their best to resolve your issues.
Thank you for your patience, and again sorry for the delay.
We need to see some information about what is happening in your machine. Please perform the following scan again: Download DDS by sUBs from the following link if you no longer have it available and save it to your destop.DDS.com Download LinkDouble click on the DDS icon, allow it to run. A small box will open, with an explanation about the tool. No input is needed, the scan is running. Notepad will open with the results. Follow the instructions that pop up for posting the results. Close the program window, and delete the program from your desktop.Please note: You may have to disable any script protection running if the scan fails to run. After downloading the tool, disconnect from the internet and disable all antivirus protection. Run the scan, enable your A/V and reconnect to the internet.
Information on A/V control can be found HERE.As I am just a silly little program running on the BleepingComputer.com servers, please do not send me private messages as I do not know how to read and reply to them! Thanks!
Our Windows Domain Cannot 7 Admin Update Users w/o computer network was Windows XP Pro We upgraded the computers to Windows Pro Under XP users were allowed to update without any problems With Windows it prompts for an administrator account The computers already have checked quot Allow all users to install updates on this computer quot However it does indicate on that same screen at the top quot Some settings are managed by your system Windows 7 Domain Users Cannot Update w/o Admin Administrator quot Currently Windows 7 Domain Users Cannot Update w/o Admin it's wanting to install the monthly malware tool but is unable to do so without domain admin's credentials What I'm Windows 7 Domain Users Cannot Update w/o Admin baffled with is that this worked under the WinXP systems but not Win systems Server did not change anything Win Server w active directory Might there be some group policy on the server that wouldn't allow Win computers when WinXP computers worked Or is there something beyond the quot Who can install updates quot option on the computers locally All computers on the network experience this same problem Thank you for any suggestions and taking the time to read this
There's an option switch in WU which allows standard users to install updates - it sounds as if it's not been correctly toggled. Check the GPs and see if you can find it in there somewhere.http://www.sevenforums.com/windows-updates-activation/340711-windows-7-domain-users-cannot-update-w-o-admin.html
Im new to Xp Pro, I installed a game in Admin mode, but want it to be accessable in user mode, how do i do that? How do i add it to the start menu?
I tried logging in user mode, went to my computer , then went to the folder the program was stored in and tried running it from there and I got an error. Went back to admin mode and ran it with no error.
Thanks for the help.
you need to access the all users folder (in the Documents and settings folder) and place the application shortcuts either on the desktop or in the start menu. with the shortcuts in that folder all users who log in will have access to them. You can also place different application shortcuts in each users profile so they only have access to them.
Our office is growing fast and I am having an issue with rogue users The main software we use AutoDesk Building Design Suite requires users to be admins on their machines However we are having users install software on their own including personal programs educational licensed software bootleg software etc In the process several users have installed spyware malware leading to bigger issues Without strict support from management to enforce policy but with pressure from management to stop this from happening I am looking for a way to stop user accounts from installing software I would like to keep my admin account capable of doing this of course We are running Win Pro on all users admin ability for install Remove machines I am Remove install ability for admin users not too familiar with modifying policies in Win If you can tell me where to look I have no issue doing the reading I just cannot seem to find the correct info with the searches I have done Any help would be greatly appreciated
You can use the Group Policy Editor to create a Software Restriction Policy. You can also use it to Whitelist applications. You can start with the following.
My Hp Pavilion has been a clean machine (due to your expert advise in the past),
until my adult son brought his comp to my business and logged onto the internet via my connection. Not sure where his comp. has been.
Now I have no Desktop. I cannot access any thing to try and see what has happened. I have blue fractal screen. Cannot access internet except thru. hp button on keyboard or thru another user acct.
I know you guys have the answer, and it's probably very simple.
I would like to send a HiJack This Log for you, but under circumstances not sure how.
My business (florist) is sorta shut down till I get this fixed.
Thanks a bunch!! Wow has this forum changed in just a few years!
NewGirl (but now not so new)
I have encountered a curious problem at work. All clients use limited users and in this case there's a Windows 7 on x64 on which I don't have privileged access at all. The normal behaviour, as far as I know, is that when I try to access something that needs administrator privileges, a window shows up and asks me for a privileged user's password. There are two users on the machine (a user called "Admin", the other one being the limited user) and I expect this behaviour (the password windows popping up) when trying access something that needs privileges - this is what happens at home, for instance, as I don't use a privileged user for security reasons.
Any suggestions on how to make that window pop up?
Are you the admin? Did you set up the limited user account? Just want to make sure you didn't lock yourself out.http://www.sevenforums.com/general-discussion/210303-no-admin-privileges-password-limited-users.html
Have just migrated sic quot down graded ? + PC + user need Users Single Owner why do I Admin quot from XP to Win I am on Win training wheels Single user PC why do I need Admin + Owner + Users ? and I still fall of As a single user PC the new quot Administrator quot quot Owner quot etc is driving me insane In the process Single user PC why do I need Admin + Owner + Users ? of trying to get a grasp on Win and its foibles I am getting more frstrated with Win My four other WinXp PRO machines are just a dream to use Thay are all standalone PCs -- stable and they let me quot in quot My Toshiba laptop came with Win Home preloaded Is there such a thing as a single user install If so would I have to buy a Win Disc I am seriously thinking of buying a full retail version of Win so that when if my XP machines fall over I wont have the agony of Win because hopefully I will be familiar with Win tweaks As a Autocad programmer I mostly work in VBA and scripts I think I am developing a crush on Linux and we haven't even met I would appreciate any informative help
I can appreciate your frustration, Russell. The learning curve from XP to 7 can be kinda steep. One of the issues many people first have is the increased security offered by Windows 7. As you said in your post about your XP machines, "They are all standalone PCs -- stable and they let me "in"." That was one of XP's major problems ... lots of malware was able to get in as well as the authorized user(s).
When a new 7 computer is first set up, the initial account created is an administrator account so you can make required changes to the computer (like choosing language of choice, setting computer time zone, etc.) So there always has to be at least one administrator account on a 7 machine.
But to add to the confusion, this is an "unelevated" administrator account. In other words, there are some tasks (such as running a system file checker scan [sfc /scannow] from a command prompt), that cannot be done without jumping through one more hoop. If you open a command prompt in 7 (either by typing cmd in the start menu search box or using the long way start > all programs > accessories > command prompt) you have to right-click the command prompt icon and select "Run as administrator". It's just another security feature to make it more difficult for malware to get in.
A lot of people who are the only ones using the computer leave things as is ... running with that administrator account. Nothing wrong with that if you're careful and know what sites you're visiting, what email attachments you're opening, etc. But for an extra degree of security many people operate as a standard user just because it does make it more difficult for malware to get in. This tutorial goes into more detail about the various account types.
User Account Type - Change
As far as obtaining a Windows 7 installation disk, you could check out Step 4 in this tutorial (doing a repair install of Windows 7.)
You could download the ISO file for your version of Windows 7, save it to desktop, then burn it to a DVD. If you ever did a repair install or a clean install, just use the Product Key on your Toshiba laptop to re-activate with Microsoft. Hope some of this helps and doesn't make things even more confusing.
hello there, just wondering whether anyone could tell me how i could limit a certain user's access to programs in XP Pro. i'm one of the normal admins and know the password to the real administrator account (the one that comes up when u boot in safe mode, dont know what u call it really!). To be specific i dont want this person to play certain games and run certain programs like MS VB etc.
Thanks for ur help people!
oh btw, he's an admin himself too so he can do some other things, but like i say i might be able to overwhelm him with TWO accounts in my arsenal...mwuhaha....
There's a couple of ways to do this.
1) You can set up policies to deny the application the access to run.
2) You can deny the user access to the application or its folder(s)
The policies are invisible, the app just won't run. The deny on the application is very visible, with a nice big Access Denied flag being waved. The deny will override his administrator access for that particular application.
Hope this helps.
Hi all I m a fairly Users for Kingdom Local Admin for My Rights My new guy to the whole My Kingdom for Local Admin Rights for My Users Active Directory thing and GPO paradigm so forgive me if the question seems droll - but I can t for the life of me figure out how to grant Local Admin rights to users on their laptops while logging into the domain I ve looked evrywhere - books forums websites - but there s not much information on the topic I usually hear the typcal security arguments IE - quot you re inviting malware quot and quot That s a bad idea quot Well when the bossguy can t get AOL to intall he s kinda pissy at having to call me over Ditto for every other software installation update etc I know one solution is to have the user log onto the local machine and have quot local admin rights quot but that requires that he log on intall log off log onto domain etc Too much too complicated The long and short of it is I m looking for a way to grant admin rights for their local machine while logged onto the domain Would I do this through groups GPO or a combanation Thanks so much for any information you could give me SW nbsp
The way to do it is to login to the computer with domain admin permissions (that's often the administrator account on the domain controller), manage local computer, local users and groups, administrators group, add, and choose the user that's supposed to have local admin privileges. Click OK for everything and you're good. A method I've used before is to create a group for each computer, add that group to the local administrators group, then you can add or remove a user from the groups as necessary. You can find out how to do it with group policy here --> http://www.experts-exchange.com/Operating_Systems/Q_21577234.html which is the top result in a google search for "how to grant local admin domain". I can't say I'm impressed with your searching skills unless this doesn't answer your question.
I recently installed a new webcam on our new desktop which is running Vista, it's a family PC and I'm the Administrator.My problem is that it appears that the Webcam program need admin rights to run so hence when a standard user runs this program they are prompted for an admin password by the user account control .Is it possible to give Standard Users temporary admin rights for this program ? or any other suggestions to get to a point where I do not need to enter my admin password every time a standard user runs this webcam program.
For a long time I've had much difficulty understanding the exact difference between the computer administrator and a user whose type is administrator On my system there are two administrators - one known as quot Administrator quot and another with my name Gary or Gary and Susan Each administrator has their own profile I used Windows Professional The distinction doesn't matter to system operation in general With MS Office Professional however it does When I start MS Word All Office features MS user with but work not admin Admin with Pro or MS Excel as myself for example it won't let me access the help files When I try to a message states quot There is a problem with All MS Office Pro features work with Admin but not with admin user one All MS Office Pro features work with Admin but not with admin user or more installed help files Please repair your office installation and try again quot I ran the repair program successfully but as myself I can't access the help files When I log in as user quot administrator quot I can but the access is limited I can also access all features of the program in safe mode Yet when I log in as myself I can only access the help files if I run the program as an administrator This perplexes me because my user type is administrator This problem has occurred with other programs from time to time Would someone please help me understand this and is there a workaround I can set the privilege level to administrator which will permit me unrestricted access to the help files but then a dialog box appears every time I start the program which I'd prefer to not see All MS Office Pro features work with Admin but not with admin userhttp://www.sevenforums.com/general-discussion/389269-all-ms-office-pro-features-work-admin-but-not-admin-user.html
Using Win 8.1
First off, the account I'am signed on with is listed as admin type account. It's the one I had to enter my windows account email.
Since installing the new MalwareBytes 2.0 program (which went in without any problem) it put an shortcut icon on desktop. I tried too move the icon from desktop to another folder and it said I needed admin rights to do this. Usually once I click on continue it gives me access and proceeds to carry out the command.
So I followed the tutorial to build hidden admin account. I type in: net user administrator /active:yes, it completed. I signed on to the admin account and tried the same operation and it still asked for admin rights.
What am I doing wrong?
UpDate: MalwareBytes 2.0 has a self protection ability that needs to not be enabled, otherwise everything associated with the Program including program icons located anywhere cannot be moved.
Hi from my research I saw this is the best place to ask these types of question Any help is appreciated policy Group admin. cannot admin error; as login Here is the gist of Group policy error; admin cannot login as admin. my issues Windows I had just Group policy error; admin cannot login as admin. finished downloading a file from our Google drive directory it was for some anti virus Right after the anti virus installed Windows froze up and an error popped up It stated Windows had crashed or something along those lines I had to unplug the cord Once rebooting I noticed it was taking incredibly long The screen went to yellow showing signs of loading then to black I could move my mouse here After this happened the login screen appeared Everything was very slow I tried to right click and noticed it freezing up After it finally loaded the login screen I entered in my pin but it took over minutes then went to black After other tries to boot I had very mixed signals Sometimes it made it to the login other times just a black screen On one occasion I got this error The Group Policy Client Service Failed The Sign-in The Universal Unique Identifier UUID Type Is Not Supported Sadly this is for the admin account I have no idea where to go from here and have a lot invested file and program wise and thus time wise into this set up for work Any ideas where to go I cannot access system restore or anything as it won't let me log in Any help is appreciated Edit title shouldn't say admin at the end Meaning I cannot log in to the admin or any other profilehttp://www.bleepingcomputer.com/forums/t/616132/group-policy-error;-admin-cannot-login-as-admin/
Recently I did a clean install from the windows installation tool off a CD I made. Soon after logging on and making my first account (again!) I couldn't open the C drive. I messed with the owner options and made my account the owner so I could open it. Possibly before or maybe after (I'm not sure) I realised I wasn't able to use any admin settings, (like add another account or see advanced system settings) open any applications that required admin rights (like CMD or any installation file) or do anything in the system menu. I've tried to look up the solution but can't find anything that fits the description of my problem. Any help is welcome. Thanks in advance for at least reading this.http://www.tenforums.com/user-accounts-family-safety/59249-no-admin-rights-admin-account-after-clean-install.html
Hi Guys I'm new to this forum as in this is my first post so please be gentle with Admin? Standard Account to Hidden (Admin) Transferring me if this has been answered before So anyway I have a standard account with admin privileges turned off UAC etc but it doesn't seem to be elevated all the time for example I still see the quot admin shield Transferring Standard (Admin) Account to Hidden Admin? quot icon next to some programs on my desktop Most of the time I have to right click and select quot Run as Administrator quot from the popup menu and also Windows still asks me when something needs admin mode and do I want to continue I have Transferring Standard (Admin) Account to Hidden Admin? activated the hidden true admin account on my PC and when I log into that everything is elevated and great no more prompts etc which is what I want But the problem is it looks very basic I want to be able to transfer all my settings from my standard admin account to my true admin account is this possible I've tried going to system- gt advanced system settings- gt user profiles to copy the account across but the copy button is grayed out If this is not possible is there any way to make this standard admin account the full type which is always elevated Hope someone can help me I'm getting very annoyed having to give permission for things I want to do all the time Thanks in advance -milw rm
Hello milw0rm, and welcome to Eight Forums.
You could use the tutorial below to elevate your standard administrator account to have the same elevated rights as the built-in elevated Administrator account.
Be warned though, that all Metro Store apps and the Store will not work in an elevated account.
User Account Control (UAC) - Elevate Privilege Level - Vista Forums
Hope this helps,
Hi guys when my pc gets to the first screen where you choose your account my admin account has changed from my name to 'Other user' and when I click on it it asks for a username and password. Also trying to access files from the admin account when it prompts me with a password I enter it and the dialogue box goes away as if it has accepted the password but does not let me access the files. Any help appreciated thanks.http://www.sevenforums.com/general-discussion/381483-admin-account-corrupted-cant-access-files-using-admin-p-w.html
I'm having some issues with my upgrade to win system me Programs asking passwords and for admin user admin Programs that need elevated access are now asking me for both the Sys Admin and my local admin password Of course the sys admin has no password and my local admin does So no matter what I do I get it wrong Earlier today I was trying to reset the tiles in my start menu to default I followed directions I found on the web activated the sys admin account went to the sys admin account the users app data tabletray But I kept getting the error that something quot was already in use quot and I couldn't copy all the files I went ahead Programs asking me for system admin and user admin passwords and pasted what I had in my local admin and standard user account then I disabled the sys admin account Now some programs icons I installed earlier today have disappeared I have to go to an admin account to gain access and turn them on MSI afterburner And any program that needs Programs asking me for system admin and user admin passwords admin access I'm not sure if I'm giving it access or it's just starting without admin access Seems like the next time I re-boot or log off I have to do it all over again when a program asks for elevated access it shows sys admin account AND local admin account above the password box Is that normal I could have sworn it only had my local admin account listed before If I have to re-install where do I Programs asking me for system admin and user admin passwords get the free win upgrade again are those files saved on my pchttp://www.tenforums.com/user-accounts-family-safety/58127-programs-asking-me-system-admin-user-admin-passwords.html
For a long time I've had much difficulty understanding the exact difference between the computer administrator and a user whose type is administrator On my system there are two administrators - one known as quot Administrator quot and another with my name Gary or Gary and Susan Each administrator has their own profile I used Windows Professional The distinction doesn't matter to system operation in general With MS Office Professional however it does When I start MS Word or MS Excel as myself for example it won't let me access the help files When I try to a message states quot There is a problem with one Pro work not MS user features All but admin with Admin Office with or more installed help files Please repair your office installation and try again quot I ran the repair program successfully but as myself All MS Office Pro features work with Admin but not with admin user I can't access the help files When I log in All MS Office Pro features work with Admin but not with admin user as user quot administrator quot I can but the access is limited I can also access all features of the program in safe mode Yet when I log in as myself I can only access the help files if I run the program as an administrator This perplexes me because my user type is administrator This problem has occurred with other programs from time to time Would someone please help me understand this and is there a workaround I can set the privilege level to administrator which will permit me unrestricted access to the help files but then a dialog box appears every time I start the program which I'd prefer to not seehttp://www.sevenforums.com/microsoft-office/389269-all-ms-office-pro-features-work-admin-but-not-admin-user.html
Three of four users are logged-off immediately after attempted logon The administrator user off Vista signon users except admin all logs after immediately seems to work fine Dell support suggests restoring the computer only eight months old to factory settings Bill - Logfile of Trend Micro HijackThis v Scan saved at on Platform Windows Vista SP WinNT MSIE Internet Explorer v Boot mode NormalRunning processes C Windows system Dwm exeC Windows Explorer EXEC Program Files Google Google Desktop Search GoogleDesktop exeC Program Files Creative SBAudigy Volume Panel VolPanlu exeC Windows System wpcumi exeC Program Files Trend Micro Internet Security UfSeAgnt exeC Program Files Dell Photo AIO Printer dlcxmon exeC Program Files Dell Photo AIO Vista logs all users except admin off immediately after signon Printer memcard exeC Windows Vista logs all users except admin off immediately after signon RtHDVCpl exeC Windows System rundll exeC Program Files Dell Support Center bin sprtcmd exeC Program Files Google GoogleToolbarNotifier GoogleToolbarNotifier exeC Program Files Trend Micro Internet Security TMAS OE TMAS OEMon exeC Program Files Spybot - Search amp Destroy TeaTimer exeC Program Files Digital Line Detect DLG exeC Program Files Nikon NkView NkvMon exeC Windows System rundll exeC Program Files Common Files Intuit QuickBooks QBServerUtilityMgr exeC Program Files Google Google Desktop Search GoogleDesktop exeC Windows system taskeng exeC Program Files Internet Explorer iexplore exeC Windows system SearchFilterHost exeC Program Files Trend Micro HijackThis HijackThis exeR - HKCU Software Microsoft Internet Explorer Main Window Title Internet Explorer provided by DellR - HKCU Software Microsoft Windows CurrentVersion Internet Settings ProxyOverride localR - HKCU Software Microsoft Internet Explorer Toolbar LinksFolderName F - REG system ini UserInit C Windows system userinit exe C Windows system vinrunerz exeO - Hosts localhostO - BHO Adobe PDF Reader Link Helper - E F-C D - D -B D- B D BE B - C Program Files Common Files Adobe Acrobat ActiveX AcroIEHelper dllO - BHO Spybot-S amp D IE Protection - - F - D - - D F - C Program Files Spybot - Search amp Destroy SDHelper dllO - BHO SSVHelper Class - BB-D F - C-B EB-D DAF D D - c Program Files Java jre bin ssv dllO - BHO Google Toolbar Helper - AA ED - DD- d - -CF F - c program files google googletoolbar dllO - BHO Google Toolbar Notifier BHO - AF DE - D - -B FA-CE B AD D - C Program Files Google GoogleToolbarNotifier swg dllO - BHO Browser Address Error Redirector - CA C - B - E-A -A C DB F - C Program Files Dell BAE BAE dllO - Toolbar amp Google - C B - - d - B - A CD F - c program files google googletoolbar dllO - HKLM Run Windows Defender ProgramFiles Windows Defender MSASCui exe -hideO - HKLM Run Google Desktop Search quot C Program Files Google Google Desktop Search GoogleDesktop exe quot startupO - HKLM Run PrinTray C Windows system spool DRIVERS W X printray exeO - HKLM Run VolPanel quot C Program Files Creative SBAudigy Volume Panel VolPanlu exe quot rO - HKLM Run Windows Mobile Device Center windir WindowsMobile wmdc exeO - HKLM Run WPCUMI C Windows system WpcUmi exeO - HKLM Run UfSeAgnt exe quot C Program Files Trend Micro Internet Security UfSeAgnt exe quot O - HKLM Run FaxCenterServer quot C Program Files Dell PC Fax fm exe quot sO - HKLM Run dlcxmon exe quot C Program Files Dell Photo AIO Printer dlcxmon exe quot O - HKLM Run MemoryCardManager quot C Program Files Dell Photo AIO Printer memcard exe quot O - HKLM Run DLCXCATS rundll C Windows system spool DRIVERS W X DLCXtime dll RunDLLEntry O - HKLM Run RtHDVCpl RtHDVCpl exeO - HKLM Run NvSvc RUNDLL EXE C Windows system nvsvc dll nvsvcStartO - HKLM Run NvCplDaemon RUNDLL EXE C Windows system NvCpl dll NvStartupO - HKLM Run NvMediaCenter RUNDLL EXE C Windows system NvMcTray dll NvTaskbarInitO - HKLM Run dellsupportcenter quot C Program Files Dell Support Center bin sprtcmd exe quot P dellsupportcenterO - HKCU Run swg C Program F... Read more
Hi My name is Extremeboy (or EB for short), and I will be helping you with your log.I apologize for the delay in response. We get overwhelmed with logs at times, but we are trying our best to keep up. If you have since resolved the original problem you were having, we would appreciate you letting us know. If not please perform the following so I can have a look at the current condition of your machine.If you do not make a reply in 5 days, we will need to close your topic.You may want to keep the link to this topic in your favourites. Alternatively, you can click the button at the top bar of this topic and Track this Topic. The topics you are tracking can be found here.Please take note of some guidelines for this fix:Refrain from making any changes to your computer including installing/uninstall programs, deleting files, modifying the registry, and running scanners or tools. Doing so could cause changes to the directions I have to give you and prolong the time required. Further more, you should not be taking any advice relating to this computer from any other source throughout the course of this fix.If you do not understand any step(s) provided, please do not hesitate to ask before continuing. I would much rather clarify instructions or explain them differently than have something important broken.Even if things appear to be better, it might not mean we are finished. Please continue to follow my instructions and reply back until I give you the "all clean". We do not want to clean you part-way, only to have the system re-infect itself. Please reply using the button in the lower right hand corner of your screen. Do not start a new topic. The logs that you post should be pasted directly into the reply. Only attach them if requested or if they do not fit into the post.Old topics are closed after 3 days with no reply, and working topics are closed after 5 days. If for any reason you cannot complete instructions within that time, that's fine, just post back here so that we know you're still here.Download and Run OTViewitPlease download OTViewIt by OldTimer.Save it to your desktop.Double click on the icon on your desktop.Click the "Scan All Users" checkbox.Push the button.Two reports will open, copy and paste them in a reply here:OTViewIt.txt <-- Will be openedExtra.txt <-- Will be minimizedRun Kaspersky Online ScannerPlease do a scan with Kaspersky Online Scanner.This scan is for Internet Explorer only.If you are using Windows Vista, open your browser by right-clicking on its icon and select Run as administrator to perform this scan.Open the Kaspersky Scanner page.Click on Accept and install any components it needs.The program will install and then begin downloading the latest definition files.After the files have been downloaded on the left side of the page in the Scan section select My ComputerThis will start the program and scan your system.The scan will take a while, so be patient and let it run.Once the scan is complete, click on View scan reportNow, click on the Save Report as button.Save the file to your desktop.Copy and paste that information in your next post.You can refer to this animation by sundavis.In your next reply please include the following:OTViewIt.txtExtra.txtKaspersky's LogImportant Note: For other users who are reading this topic,the instructions provided in this topic are for the original topic starter ONLY. Even if you have similar problems or even log entries to those given here, please do not follow the directions, especially those involving specific tools and scripts. Doing so can result in serious damage to your computer. Instead, please start your own topic and feel free to link to any relevant topics as needed.Please Do NOT follow the instructions provided for this topic.With Regards,Extremeboyhttp://www.bleepingcomputer.com/forums/t/181694/vista-logs-all-users-except-admin-off-immediately-after-signon/
I manage a windows 2003 domain, and I need regular users to have the ability to disconnect active session or open files to their local server. I have been using the command "openfiles", but you need to be an admin to query the server. I am looking for the explicit permission needed to query the server, or an alternate solution for these users to administer a share.
I am not sure what you mean by regular users? If they are authenticated on the domain you can give or limit access to anything you want.
Hey everyone First post here as we are prevent How My all to local do users I Documents Admin's the access having some issues at How do I prevent all users access to the local Admin's My Documents my job We're a small sized school district and we are in the process of currently attempting to create a universal image to roll out across the district As part of the initial process we are following a spiceworks directed tutorial to create the image and we are enabling the local administrator account After imaging there are How do I prevent all users access to the local Admin's My Documents a few other things that need to be done on each individual machine so we have a quot tech quot folder set up to allow our techs to go step by step to get the machine to where we want it to be Once a machine is imaged it is then added to our domain The issue we are having is that whether we place this How do I prevent all users access to the local Admin's My Documents 'tech' folder on the desktop the Admin's desktop or the Admin's My Documents folder any other user on the computer even non-admins are getting access to the Administrator's user folders including desktop and documents This means that any enterprising student can search hard enough and find it and then access the files in the tech folder Now it is our practice to then disable the local admin account after imaging before sending the machine out However on the off chance one of the techs forgets or has a lapse in procedure this could result in a few non-critical but still important pieces of software being accessible to all users Our question is this What could be causing this lapse in policy Or are we misunderstanding the way Win operates the local Admin account Our understanding is that no users should by default have access to the Admin's files so there must be something in the way we are creating the image that is causing this issue Is there something we can do using domain GPOs or local GPOs to prevent this The image we are using is a SYSprepped generalized image of Windows professional bit Our domain is using Windows Server R We have fairly strict GPOs on our domain but are unsure where to locate this specific issue Any help would be greatly appreciated and if there is any other information needed I will be glad to provide what I can Thanks
No users have access to any other user's profile directory. "C:\Users\[username]" The only way they can get access is if they are an Administrator. The next way is if you are changing the permissions to give everyone access. But the default state for Windows is no user has access to another user's profile directory. Most likely you have done something to set it up to give users access or your method for detecting this is flawed. (I.e. you are using an Admin account to check the access of the directory, an Admin account can and will override permissions to give itself access.)http://www.sevenforums.com/general-discussion/371760-how-do-i-prevent-all-users-access-local-admins-my-documents.html
Big problem easily solved you may be thinking but All I have to work on is a normal users account with NO priviledges I cannot logon via ctrl-alt del del route as administrator as I get unable to logon becuase of an account restriction I cannot logon as administrator in safe mode I get an error which flashes too quickly to be seen I ve tried to press Pause key but no use All I can see is x This is the same for all safe modes I cannot edit any registry settings Values cannot be changed I Forgotten account users xp admin home password win cannot use control userpasswords as I am not an administrator I ve tried using XP home install CD to repair but cannot get the laptop to boot from CD ROM despite changing BIOS settings I ve also tried a few password recovery tools but again cannot boot from CD This is driving me mad and I refuse to be beaten Can anone suggest any other route I may have missed or advise how to get the laptop to boot from CD so I can at least attempt to use the recover option on the boot cd nbsp
I have a desktop on windows xp sp2 32b that has two hdd partition (C: & D:)
Is there anyway I can set permission so that only people with Admin access can access my D Drive? I tried creating more than 1 user account (Admin, Guest) which keeps the guest account out of the admin's document folder on the C drive but the guest account can still access the D Drive.
Nothing on my D Drive but personal files. I don't use my desktop anymore except as a backup PC or to backup files. I'm too cheap to buy a Flash Drive when I have a available HDD. More than 4GB of data so burning it to a DVD is out. Don't use DVD/Burner enough to buy the newer DVDs that can hold 8GB either.
Scared to just delete them cos I know I'll need it as soon as I do (That is how my luck always is)
First setup Limited User accounts for any other users other then you. Then make your files or folders Private: How to make files and folders private in Windows XP so that only you have access to themhttp://www.techsupportforum.com/forums/f10/solved-limited-access-to-d-drive-for-non-admin-users-655118.html
I am working on the task to take Admin Privileges form the development users in our company. Now there is a problem that some of the applications require the Admin privileges when they need to be installed on the system. And Development people need to install/uninstall these softwares in their daily routine. I have tested that the power user is also not able to install these applications and it requires admin privileges to install these kinds of applications.
Can anyone help me how I can specify a program/or applications to be installed without providing the admin privileges or any other solution for this problem so that I should not be giving the Admin privileges to the developers and at the same time they can install/uninstall those applications.
Plz help me in this regard.
Earlier this year I solved some permission problems with help from this forum. Now I have a new Administrator User and my own personal User setups (I don't know how to refer to User sets). Now when I get into program or network installations I'm constantly told I must be installing as a member of the Admin group. But my Admin setup is minimal with no logos or links I normally use and so I'm forced to switch back and forth which is a real bummer. How can I make my Admin setup look like my normal personal setup? I'm told often to not normally operate as the Administrator so I stay in my old normal user mode. What a mess......how do I get out of it and make life easier?
Log into the administrator account. Go to user accounts in the control panel. Elevate your standard user account (your account name) to admistrator level whist you make the changes you want to make. Once everything is as you want it. Log off, log back on as administrator and return (your account name) to standard user again.http://www.sevenforums.com/general-discussion/290663-separate-admin-personal-users-real-problem.html
When I am on a limited user and I try to set permissions of its folders I need to provide the admin password to proceed, why?
Now the problem with User Account Control.
When I click on advanced sharing, or try to do any activity that requires admin priviliges, User Account Control window pops up, you know, that window asks for the password and it somehow blocks the desktop and anything else so I cant take a picture of it.
Anyway after I provide the admin's password, the pop up closes but the process hangs/freezes does not respond for eternity.
If it is an app, it does not run.
If it is a folder, the explorer thread(is it thread?) related to that folder is not responding for eternity and it is stuck, hangs. however you want to call it.
Well 21 hours ago your post.
TWO problems; allowing a limited user access to an admin folder
Who's computer is it.
Ask the administrator for help is my suggestion.
Keep getting this and certain applications dont run properly anymore. Help please
Scan Date: 2/26/2015
Scan Time: 8:03:08 PM
Logfile: bites scan.txt
Malware Database: v2015.02.26.02
Rootkit Database: v2015.02.25.01
Malware Protection: Enabled
Malicious Website Protection: Enabled
OS: Windows 7 Service Pack 1
File System: NTFS
Scan Type: Threat Scan
Objects Scanned: 332982
Time Elapsed: 11 min, 4 sec
(No malicious items detected)
(No malicious items detected)
Registry Keys: 0
(No malicious items detected)
Registry Values: 0
(No malicious items detected)
Registry Data: 0
(No malicious items detected)
(No malicious items detected)
PUP.Optional.MySearch.A, C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qr44xpuw.default\user.js, Good: (), Bad: (user_pref("extensions.irmysearch.cd", "2XzuyEtN2Y1L1QzutAtDzzyD0AzytA0CyC0EtD0D0EyD0A0AtN0D0Tzu0SzzyCtBtN1L2XzutBtFtBtDtFzytFtBtN1L1CzutCyEtDtAtDyD1V1TtN1L1G1B1V1N2Y1L1Qzu2StDyByE0FyEyD0DtCtGyB0EtAtDtGyE0E0AyEtG0E0A0BtBtGyD0CtDtAyDzz0CyCtCtDtByB2QtN1M1F1B2Z1V1N2Y1L1Qzu2SyEtB0E0CzyzyyB0DtGtC0ByBtDtG0A0CtDyCtGtDzyyBtAtGtAzz0CyCtAtBtByEtDyD0B0B2Q"), Replaced,[fd0d68bb503a84b233f9f11d54b22ed2]
PUP.Optional.MySearch.A, C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qr44xpuw.default\user.js, Good: (), Bad: (tD0D0EyD0A0AtN0D0Tzu0SzzyCtBtN1L2XzutBtFtBtDtFzytFtB), Replaced,[c64476ad47431e18ba72ff0fbf4709f7]
PUP.Optional.MySearch.A, C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qr44xpuw.default\user.js, Good: (), Bad: (che.mtokenizing.time", 2250000);
Physical Sectors: 0
(No malicious items detected)
I created a new image using Win XP Pro bit and made my profile the default user profile on a stand alone computer My profile includes our Desktop users non-admin for doesn't show Wallpaper company logo as the desktop background My user account has full admin rights When a user with non-admin rights logs in - the logo does not appear as the Desktop Wallpaper doesn't show for non-admin users desktop background When I go to display properties and click on desktop the company logo is already selected as the background The apply button is greyed out but once I hit OK the logo appears on the desktop of the non-admin user The logo remains for the user even after logging off or rebooting the pc However if I delete the user s profile and they log back in the logo disappears once again Any user account with admin rights sees the logo those without admin rights don t Non-admins have to go to display properties and click OK for the image to appear on their desktop The logo file is a jpg and it s stored in C WINDOWS Web Wallpaper Any idea how I can get the logo to show up on the desktop for all users automatically nbsp
Hopefully this discussion may help:
Hi guys Operating system Windows Server No malware programs listed in Add Remove Programs Main symptoms of problem users are being created with Admin access for remote access user quot cool quot and quot mcy quot are usually created Recently the 'Local user and accounts' snap in was removed from 'Computer management' MMC i managed to get this back by changing the admin Remote illegally Cool$/MCY$ users : created registry policy Viruse trojans are found consistently within these user accounts Main culprit that i've found with Hijackthis is 'help exe' which is run from startup however even when this is removed it still comes back at irregular intervals Symptom of a rootkit virus perhaps I cannot see it in HijackThis but it is visible in Windows Defender in startup list Ran full AVG virus scan found tojan horse generic ceu within user mcy temporary internet files Removed Scanned again and now empty Ran Full Ad-Aware SE updated - Nothing Found Ran Full Spy Bot Search and Destroy updated - Nothing found Microsoft Update Remote admin users illegally created : Cool$/MCY$ is completely up to date Ran TrendMicro Online scan following trojans found troj dloader dsw and troj strat dx TROJ SMall cjs Spyware Remote admin users illegally created : Cool$/MCY$ trak Radmin All removed And nothing further found All the trojans that have been found by the above programs seems to be a symptom of the problem but don't actually fix the cause my guess is they're being added automatically by the virus hijacker They all seem to reside within the false user created directories cool or mcy However i don't know for sure Anyone have any idea why this keeps happening Please find below my complete HijackThis Log if you require any further information please don't hesitate to contact me HiJackThis Log Logfile of HijackThis v Scan saved at PM on Platform Windows SP WinNT MSIE Internet Explorer v SP Running processes C Documents and Settings Administrator WINDOWS System smss exe C WINDOWS system winlogon exe C WINDOWS system services exe C WINDOWS system lsass exe C WINDOWS system svchost exe C Program Files Windows Defender MsMpEng exe C WINDOWS System svchost exe C WINDOWS system spoolsv exe C PROGRA Grisoft AVG avgamsvr exe C PROGRA Grisoft AVG avgupsvc exe C PROGRA Grisoft AVG avgemc exe C WINDOWS system cisvc exe C WINDOWS System dns exe C WINDOWS System svchost exe C Program Files FolderSize FolderSizeSvc exe C WINDOWS system inetsrv inetinfo exe C WINDOWS System snmp exe C WINDOWS system spool SVCHOST EXE C Program Files Common Files System MSSearch Bin mssearch exe C WINDOWS System svchost exe C WINDOWS System svchost exe C WINDOWS System svchost exe C WINDOWS Explorer EXE C Program Files Windows Defender MSASCui exe C PROGRA Grisoft AVG avgcc exe C Program Files FileZilla Server FileZilla Server Interface exe C WINDOWS system dumprep exe C WINDOWS system rundll exe C Program Files Microsoft SQL Server Tools Binn sqlmangr exe C WINDOWS system winlogon exe C WINDOWS system rdpclip exe C WINDOWS Explorer EXE C Program Files Windows Defender MSASCui exe C PROGRA Grisoft AVG avgcc exe C Program Files Microsoft SQL Server Tools Binn sqlmangr exe C WINDOWS system cidaemon exe C WINDOWS system cidaemon exe C WINDOWS System logon scr C Program Files Server Side Solutions Paranoid PndSrv exe C Program Files FileZilla Server FileZilla Server exe C PROGRA Lavasoft AD-AWA Ad-Aware exe c windows system inetsrv w wp exe c windows system inetsrv w wp exe C Program Files ArgoSoft Mail Server mlsrvnt exe C HJT HijackThis exe R - HKCU Software Microsoft Internet Explorer Main Default Page URL res shdoclc dll hardAdmin htm R - HKCU Software Microsoft Internet Explorer Main Start Page res shdoclc dll hardAdmin htm R - HKCU Software Microsoft Internet Explorer Main Local Page C WINDOWS system blank htm R - HKCU Software Microsoft Windows CurrentVersion Internet Settings ProxyServer F - REG system ini UserInit C WINDOWS system userinit exe O - BHO Adobe PDF Reader Link Help... Read more
Hi and welcome to the Security Forum.
Apologies for any delay in replying, but we have been rather busy lately.
Since it has been a few days since you first posted, please post a fresh HijackThis Log if you still need assistance.
I have a vista ultimate computer and i want to save a document that i have created on my admin account into another normal account. I went to users and then the other account and tried to save it but it said that it was unable to save as i do not have permission and to contact the administrator. But i am the administrator
Thanks in advance
You are going to need to save it to a shared folder and then log out and into the other account, then you can move or copy the file from the shared folder to the current users Documents folder.
By the way, you are NOT "The Administrator" but a member of the Admin group.
I've been using vista premium for about 3 weeks (2 new Dell computers) and am trying to setup a maintenance schedule for both. With my XP machine I have a batch file that will go out and clean all the temp, cookies and temporary internet files of each user.
I'm trying to find the path for vista, but with vista, when I open My Computer | double-click C: the layout is different than XP...I can go into the User's folders and see all the allowed users but the temp, cookies and TIF folder's are not there.
First Q = I am one of the admin. so how do I find the path for each user?
Second Q = Do I have to use the built-in sys admin acct to gain access to these folders? If so, how do I enable it?
I quess thats three Q's....thanks for your input/reply.
The oddest thing just started happening I have limited users running on my XP SP box These users are members of the Users group only All of a sudden all of the users Effective for admin limited suddenly permissions users are now like administrators with full access to everything including the other limited users' private directories Looking Effective permissions suddenly admin for limited users at the quot Effective Permissions quot on any of these supposedly hidden Effective permissions suddenly admin for limited users directories gives ALL of Effective permissions suddenly admin for limited users the permissions The users can even write to the quot Program Files quot and quot WINDOWS quot directories obviously a catastrophic state if security is at all important I have no idea what to do about this Can this be a virus Is there something in some hidden group policy or other tweak that will restore these users back to being unable to access other directories These users can also see and write to all areas of the registry too I am worried that this is the result of some sort of bug in a Microsoft update since how else but the O S allowing this access at the NT level could this occur Any advice most gratefully accepted TIA
The only way i can think of going about it is going into the computer management console/local users and groups/groups and making sure in the admin and power user groups that none of the limited users have been added. If thats ok then its probably a good idea to scan your computer and find out if there is a virus or spyware present.
Hope this helps.
I'm running Ultimate 64bit. In my older XP installation I never used to use the admin account on a daily basis. I created a Power User for myself, and any administrative tasks I had to run I'd just use the 'Run as' function, so I almost never needed to logon as admin.
Tried it in Vista, and it didn't work (in my Power User account). I mean, I would select 'Run as Administrator', but I wasn't prompted for my admin password and didn't get the admin privs. So my question is - how do I do it?
Another question - when logged in as admin in Vista, why is there still an option to run stuff as admin? Does it mean anything?
I guess a link to some in-depth articles about Vista account management would be best for me : )
Hi this is my first post in the forum I hope this is in the right place.
My problem is that i have lots of laptop users off site and occasionally they'll need to install something.
To let them do this I've had to let them all have administrative privileges on their laptops and because of this they are downloading games and P2P software and all kinds of annoying things.
What i need is a way to be able to let them install off-site but only when i want them too, or maybe remotely doing it for them . I'm not really sure where to start at fixing this problem I'm hoping some of you have some ideas?
Hello I've got a problem I've been tasked with creating a lightweight build of Windows to run in kiosk mode here at work I've got kiosk mode running well where the only app the user has access to is Internet Explorer using a custom shell However now I'm going through and trying to lock everything down to Preventing Users Admin Account New Creating AppLocker From prevent the user from downloading and installing stuff accessing C etc I've enabled applocker and auto-generated all the rules I did this for Executables Windows Installer Files as AppLocker Preventing Admin Account From Creating New Users well as Pre-Packaged Apps however I'm running into a problem Even though I have all the rules for the pre-packaged apps set to quot allow quot for the administrators group it still won't allow me to create new users any more when using the built-in Administrator account When I go to 'Settings - gt Users - gt Create New User quot the mouse wheel spins for a little bit and a window opens and closes instantly but that's all I ended up going into System Lusrmgr and creating a new admin account that way but even after adding this new account to the admin group and signing out in rebooting etc this new admin account can't access any of the pre-packaged apps like the default Administrator account can If I am understanding AppLocker and the rules for the pre-packaged apps correctly since I have all the rules set to quot allow quot for the quot builtin-administrators quot group shouldn't my new admin account have full privileges Also why can't the default administrator account create new users from quot Settings - gt Users quot Something doesn't seem to be working right to me or I'm doing something wrong very possible Any help you can provide would be greatly appreciated Thankshttp://www.tenforums.com/user-accounts-family-safety/50707-applocker-preventing-admin-account-creating-new-users.html
I have two external drives on my PC. I have younger users that some content would not be appropriate for. Is there a way to limit what is accessible to them in My Computer? Is there a way to choose what local drives may be viewed by specific users?
You can simply remove drive access permission by editing the security properties of the drive. To do this follow the instructions.
A ) Right click on the file, folder, or drive that you want to grant a user or group permissions for, and click on Properties.
In the Security tab, and click on the Edit button. (see screenshot below)
B ) Select a user or group that you want to change the permissions for, then check Deny boxes for all items.
C ) When finished, click on OK. D ) If prompted, click on Yes. E ) Click on OK.