Multiple Users

D

Doug DeCarlo

How funny. I posted about this same issue just a few
minutes later ("MSAS cant save new settings").

Let's keep this in a single thread..
Below is what I wrote:

--------
Hi,

I'm running the latest version of MSAS in XP Prof on a
number of machines (some are part of a domain, some aren't)
with 3 or 4 regular users on each.

When non-admin users log in, the same threat warnings come
up over and over. For instance, I'm constantly asked about
whether to allow/block the MS shell browser ui library.
This is pretty darn annoying.

Oh, I did turn off 'show alert if an ignored threat...' in
the alert settings. Both blocked and allowed alerts are
enabled.

If you look at the error log file, you find many entries
like this (for several different .gcd files):
-2147467259::Method '~' of object '~' failed/C:\Program
Files\Microsoft
AntiSpyware\gcAgentsDataStoreData.gcd::gcasDtServ:modData:G
lobalSave::5/14/2005
3:07:53 AM:1.0.509

I'm guessing this means it tried to save the dismissals and
allow/block preferences but couldn't. Admin users don't
generate these errors. Granting write access to all users
for these files does fix this issue, but it's a REALLY dumb
idea. As a workaround, I just change the protections
temporarily, run MSAS, then set the protections back. This
at least clears out the backlog of current warnings, etc...
Basically, a very annoying "learning mode". :)

Is there some more reasonable solution to this? (Without
making everyone an admin user, that is...)

Also, it seems these preferences are remembered across
users on a machine. Is that right? If that's the case, it
seems like you don't want to save these preferences unless
the user knows what they're doing. But the problem is that
many of these warnings aren't ever encountered by an admin
user.. Ugh.

Any help will be appreciated.

Best,

- Doug
----------
 
J

JohnF.

Its a beta - the next beta may fix the permissions problem and allow limited
users to run the program successfully.


--
If you are under attack and MSAS does not seem to help:

*Submit suspected spyware report in the tools menu of MSAS*

PREP YOUR MACHINE FIRST!
- IF you are using Spybot S/D, UN-Immunize your computer
- IF you are using Adaware, turn off AD-Watch
- Disable all other active anti-spy applications
- Dump all temporary file locations and Internet files

1. Download:
lspfix.exe www.cexx.org/lspfix.htm
winsockxpfix.exe www.snapfiles.com/get/winsockxpfix.html
ccleaner.exe www.ccleaner.com
killbox.exe www.bleepingcomputer.com/files/killbox.php

2. Clean out all temp file locations with ccleaner.exe

3. Install and use killbox to delete stubborn files

4. Reboot into safe mode - http://tinyurl.com/pfca
5. Run MSAS at least twice in full/deep mode
6. Run a robust, updated antivirus software scan
7. Reboot into normal mode,see if problem has been corrected

8. If you think something is there but can't see it, download:
- Blacklight by F-Secure
www.europe.f-secure.com/exclude/blacklight/blbeta.exe
- RootKitRevealer by SysInternals
www.sysinternals.com/ntw2k/freeware/rootkitreveal.shtml

9. If your problem is Virus or Security patch related:
In the United States or Canada, call 1-866-PCSAFETY
MS will provide free support for those issues.

Battle Notes:
- If you have trojans (files that won't go away),
you may have to disable System Restore on XP:
http://tinyurl.com/movy

- If your Internet connectivity quits:
http://support.microsoft.com/kb/892350
http://support.microsoft.com/kb/811259
LSPFix - www.cexx.org/lspfix.htm
Winsockxpfix - www.snapfiles.com/get/winsockxpfix.html

- Install SpywareBlaster to block malware apps from
installing on your machine. Does not actively run
on your machine, you run it, it makes changes that
protect you.
http://www.javacoolsoftware.com/

- This program will not detect or remove viruses
http://www.microsoft.com/athome/security/viruses/default.mspx

*** For assistance in battling infestations***
- Get HijackThis.exe from:
http://tomcoyote.org/hjt/hjt199//HijackThis.exe
- Save it to C:\hjt (new folder)
- Open it and select "Scan and Save Log"
- Send it to Ron Kinner as an attachment
- Ron's email address is (e-mail address removed)
- Put Hijack in the subject so he knows it's not spam

Application Notes:
Registering a VB6 dll seems to fix missing agents:
1) Open up a command prompt (start -> run -> cmd)
2) Type in the following "regsvr32 msvbvm60.dll" (without the quotes).
3) Close and re-open Windows AntiSpyware
4) If that fails, install VB6 runtime files:
http://www.softwarepatch.com/windows/vbrun6download.htm

- To report false positives:
www.microsoft.com/athome/security/spyware/software/isv/fpform.aspx
- To submit disputes or requests:
www.microsoft.com/athome/security/spyware/software/isv/cdform.aspx
- To learn more about how MS analyzes suspected spyware:
www.microsoft.com/athome/security/spyware/software/isv/analysis.mspx
- To Run MSAS in passive mode:
http://support.microsoft.com/kb/892375

Alternative Anti-Spyware Applications:
- Spybot Search and Destroy
http://www.majorgeeks.com/download2471.html
- LavaSoft AdAware
http://www.majorgeeks.com/download506.html
- AdAware VX2 Cleaner Plugin
http://www.majorgeeks.com/download4283.html
- BHODemon
http://www.majorgeeks.com/download3550.html
- CWShredder (CoolWWWSearch)
http://www.majorgeeks.com/download3019.html
- PestPatrol
http://www.majorgeeks.com/download1187.html
- Webroot Spysweeper
http://www.majorgeeks.com/download3263.html
- Ewido Security Suite
http://www.ewido.net/en/
- CounterSpy (Same Giant Company Engine as MSAS)
- http://www.sunbelt-software.com

Recommended Software to help protect you:
- Windows XP Service Pack 2
http://www.microsoft.com/windowsxp/sp2/default.mspx
- SpywareBlaster
http://www.javacoolsoftware.com
- Outpost Firewall Pro
http://www.agnitum.com/products/outpost
---------------------------------------------
 
A

Andre Da Costa

From Steve Dodson:
You have a limited user account running the application looking for spyware
on all files and folders. This includes the administrator account which
limited users may not be able to access. So we have to approach this
carefully in order to remove the spyware from all locations, but also
preserve file and folder permissions and access.

In short, we are addressing this for a future release, but it involves some
major coding and testing.
 

Ask a Question

Want to reply to this thread or ask your own question?

You'll need to choose a username for the site, which only take a couple of moments. After that, you can post your question and our members will help you out.

Ask a Question

Top