Windows Vista Forums
Vista Forums Home Join Vista Forums Windows 7 Forum Vista Tutorials Tags
Welcome to Windows Vista Forums. Our forum is dedicated to helping you find solutions with any problems, errors or issues you are experiencing with Windows Vista. The Vista forum also covers news and updates and has an extensive Windows Vista tutorial section that covers a wide range of tips and tricks.

Go Back   Vista Forums > Vista Newsgroups > Vista security

Vista - Documenting the command line that UAC attempts to launch

Reply
 
Old 05-21-2009   #1 (permalink)


 
 

Documenting the command line that UAC attempts to launch

Is there a way to set UAC to capture or log the entire command line of a
program including all switches that is requesting elevation? I have an
unknown potentially suspicious program that is requesting elevation and I am
unable to see the entire command line or path to the binary to investigate
it. To be safe, I have declined running the program, and briefly examined
the Windows event logs but have not been able to find the details I am
looking for.
As a temporary work-around, I am going to connect via remote desktop to
take a screenshot of the UAC prompt, but this only gives me part of the
command since the display dialog cuts of the text.


My System SpecsSystem Spec
Old 05-22-2009   #2 (permalink)
Robinson Zhang [MSFT]


 
 

RE: Documenting the command line that UAC attempts to launch

Hi,

Based on my knowledge, we cannot set UAC to capture or log your request.
However, I hope Standard User Analyzer can help you. Standard User Analyzer
(SUA) tool enables you to test your applications to detect potential
compatibility issues due to the User Account Control (UAC) feature.

For more information, please refer to the following links:

Standard User Analyzer Technical Reference
http://technet.microsoft.com/en-us/l...48(WS.10).aspx

Microsoft Application Compatibility Toolkit 5.5
http://www.microsoft.com/downloads/d...9E9-B581-47B0-
B45E-492DD6DA2971&displaylang=en

Thanks.

Best regards,

Robinson Zhang
Microsoft Online Support

My System SpecsSystem Spec
Old 05-22-2009   #3 (permalink)
FromTheRafters


 
 

Re: Documenting the command line that UAC attempts to launch


<Mltwwlco@xxxxxx> wrote in message
news:eAqkkzj2JHA.4412@xxxxxx
Quote:

> Is there a way to set UAC to capture or log the entire command line
> of a program including all switches that is requesting elevation? I
> have an unknown potentially suspicious program that is requesting
> elevation and I am unable to see the entire command line or path to
> the binary to investigate it. To be safe, I have declined running the
> program, and briefly examined the Windows event logs but have not been
> able to find the details I am looking for.
> As a temporary work-around, I am going to connect via remote
> desktop to take a screenshot of the UAC prompt, but this only gives me
> part of the command since the display dialog cuts of the text.
You might look into having the prompt not displayed on the secure
desktop, and then seeing if it acts differently on the user's desktop.


My System SpecsSystem Spec
Old 05-25-2009   #4 (permalink)
Robinson Zhang [MSFT]


 
 

RE: Documenting the command line that UAC attempts to launch

Hi,

I am currently standing by for an update from you and would like to know
how things are going. If you have any questions or concerns on the recent
information I've provided you, please don't hesitate to let me know.

Best regards,

Robinson Zhang
Microsoft Online Support


My System SpecsSystem Spec
Old 05-26-2009   #5 (permalink)
Bob


 
 

Re: Documenting the command line that UAC attempts to launch

Thanks for asking.
Things are going well. I'm feeling much better.

Robinson Zhang [MSFT] wrote:
Quote:

> Hi,
>
> I am currently standing by for an update from you and would like to know
> how things are going. If you have any questions or concerns on the recent
> information I've provided you, please don't hesitate to let me know.
>
> Best regards,
>
> Robinson Zhang
> Microsoft Online Support
>
>
My System SpecsSystem Spec
Old 05-28-2009   #6 (permalink)


 
 

Re: Documenting the command line that UAC attempts to launch

Sorry for the delay in responding Robinson Zhang, it looks like UAC
doesn't have the logging features I need, so it looks like I'll need to use
one of the Sysinternals tools instead to try and capture the program syntax.


""Robinson Zhang [MSFT]"" <v-robzha@xxxxxx> wrote in message
news:P3UicwQ3JHA.5720@xxxxxx
Quote:

> Hi,
>
> I am currently standing by for an update from you and would like to know
> how things are going. If you have any questions or concerns on the recent
> information I've provided you, please don't hesitate to let me know.
>
> Best regards,
>
> Robinson Zhang
> Microsoft Online Support
>
>
My System SpecsSystem Spec
Old 05-29-2009   #7 (permalink)
Robinson Zhang [MSFT]


 
 

Re: Documenting the command line that UAC attempts to launch

Hi,

Thank you for your reply and I understand you will use Sysinternals tool as
a workaround to your problem. Regarding the UAC logging features, I will
add it as a feature request to Microsoft's database. Thank you for your
effort on the issue.

If you have any other questions or concerns, please do not hesitate to
contact us. It is always our pleasure to be of assistance.

Have a nice day.

Robinson Zhang
Microsoft Online Support

My System SpecsSystem Spec
Reply

Thread Tools


Similar Threads
Thread Forum
Running a command from inside a script, command line is corrupted PowerShell
What is the command line command for unzipping files? Vista General
Command Line Ren (Rename) command broken? Vista General
XP command line Vista networking & sharing
How to launch the pretty PowerShell command line from VS? PowerShell


Vista Forums is an independent web site and has not been authorized,
sponsored, or otherwise approved by Microsoft Corporation.
"Windows Vista", the Start Orb, and related materials are trademarks of Microsoft Corp.
© Designer Media Ltd

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46