Windows Vista Tips

Windows Vista Tips > Newsgroups > Windows Vista Security > Documenting the command line that UAC attempts to launch

Reply
Thread Tools Display Modes

Documenting the command line that UAC attempts to launch

 
 
Guest
Posts: n/a

 
      05-21-2009
Is there a way to set UAC to capture or log the entire command line of a
program including all switches that is requesting elevation? I have an
unknown potentially suspicious program that is requesting elevation and I am
unable to see the entire command line or path to the binary to investigate
it. To be safe, I have declined running the program, and briefly examined
the Windows event logs but have not been able to find the details I am
looking for.
As a temporary work-around, I am going to connect via remote desktop to
take a screenshot of the UAC prompt, but this only gives me part of the
command since the display dialog cuts of the text.

 
Reply With Quote
 
 
 
 
Mark Blain
Guest
Posts: n/a

 
      05-21-2009
<> wrote in
news::

> Is there a way to set UAC to capture or log the entire command
> line of a
> program including all switches that is requesting elevation? I have
> an unknown potentially suspicious program that is requesting elevation
> and I am unable to see the entire command line or path to the binary
> to investigate it. To be safe, I have declined running the program,
> and briefly examined the Windows event logs but have not been able to
> find the details I am looking for.
> As a temporary work-around, I am going to connect via remote
> desktop to
> take a screenshot of the UAC prompt, but this only gives me part of
> the command since the display dialog cuts of the text.


Darned good question. I'm hoping someone else will explain how to add
**auditing** for UAC elevation prompts to the Vista event log.
In the meantime:

There are utilities that let you grab text from most dialog boxes.
Try SysExporter.
<http://www.raymond.cc/blog/archives/2008/05/25/how-to-copy-text-or-error-messages-from-any-dialog-boxes-in-windows/>
I don't know if it works with the UAC prompt. Hint: turn on every
option under "Filter", click an item in the list, and the associated
text is displayed underneath.
 
Reply With Quote
 
Robinson Zhang [MSFT]
Guest
Posts: n/a

 
      05-22-2009
Hi,

Based on my knowledge, we cannot set UAC to capture or log your request.
However, I hope Standard User Analyzer can help you. Standard User Analyzer
(SUA) tool enables you to test your applications to detect potential
compatibility issues due to the User Account Control (UAC) feature.

For more information, please refer to the following links:

Standard User Analyzer Technical Reference
http://technet.microsoft.com/en-us/l...48(WS.10).aspx

Microsoft Application Compatibility Toolkit 5.5
http://www.microsoft.com/downloads/d...9E9-B581-47B0-
B45E-492DD6DA2971&displaylang=en

Thanks.

Best regards,

Robinson Zhang
Microsoft Online Support

 
Reply With Quote
 
FromTheRafters
Guest
Posts: n/a

 
      05-23-2009

<> wrote in message
news:...
> Is there a way to set UAC to capture or log the entire command line
> of a program including all switches that is requesting elevation? I
> have an unknown potentially suspicious program that is requesting
> elevation and I am unable to see the entire command line or path to
> the binary to investigate it. To be safe, I have declined running the
> program, and briefly examined the Windows event logs but have not been
> able to find the details I am looking for.
> As a temporary work-around, I am going to connect via remote
> desktop to take a screenshot of the UAC prompt, but this only gives me
> part of the command since the display dialog cuts of the text.


You might look into having the prompt not displayed on the secure
desktop, and then seeing if it acts differently on the user's desktop.


 
Reply With Quote
 
Robinson Zhang [MSFT]
Guest
Posts: n/a

 
      05-25-2009
Hi,

I am currently standing by for an update from you and would like to know
how things are going. If you have any questions or concerns on the recent
information I've provided you, please don't hesitate to let me know.

Best regards,

Robinson Zhang
Microsoft Online Support


 
Reply With Quote
 
Bob
Guest
Posts: n/a

 
      05-26-2009
Thanks for asking.
Things are going well. I'm feeling much better.

Robinson Zhang [MSFT] wrote:
> Hi,
>
> I am currently standing by for an update from you and would like to know
> how things are going. If you have any questions or concerns on the recent
> information I've provided you, please don't hesitate to let me know.
>
> Best regards,
>
> Robinson Zhang
> Microsoft Online Support
>
>

 
Reply With Quote
 
Guest
Posts: n/a

 
      05-28-2009
Sorry for the delay in responding Robinson Zhang, it looks like UAC
doesn't have the logging features I need, so it looks like I'll need to use
one of the Sysinternals tools instead to try and capture the program syntax.


""Robinson Zhang [MSFT]"" <v-> wrote in message
news:...
> Hi,
>
> I am currently standing by for an update from you and would like to know
> how things are going. If you have any questions or concerns on the recent
> information I've provided you, please don't hesitate to let me know.
>
> Best regards,
>
> Robinson Zhang
> Microsoft Online Support
>
>


 
Reply With Quote
 
Robinson Zhang [MSFT]
Guest
Posts: n/a

 
      05-29-2009
Hi,

Thank you for your reply and I understand you will use Sysinternals tool as
a workaround to your problem. Regarding the UAC logging features, I will
add it as a feature request to Microsoft's database. Thank you for your
effort on the issue.

If you have any other questions or concerns, please do not hesitate to
contact us. It is always our pleasure to be of assistance.

Have a nice day.

Robinson Zhang
Microsoft Online Support

 
Reply With Quote
 
 
 
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
command line user Windows Vista General Discussion 0 02-16-2009 09:43 PM
What is the command line command for unzipping files? Jim H Windows Vista General Discussion 3 12-04-2008 03:22 AM
Command Line Ren (Rename) command broken? SixSigmaGuy Windows Vista General Discussion 5 05-20-2008 10:52 AM
XP command line Qfreed Windows Vista Networking 2 08-25-2007 02:31 PM
Vista Command Line rshol Windows Vista File Management 3 02-27-2007 08:32 PM



1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59