Re: Restore original ACL rights of ...\system32\* - how ?

From: Colin Nash [MVP] (x_at_x)
Date: 08/21/04


Date: Fri, 20 Aug 2004 18:58:03 -0400


"Tobias Alte" <nospam@you-guess-it.org> wrote in message
news:opsc0w0hmvmmdu9g@2biased...
> Hi,
>
> I know I should't have been messing around with the cacls.exe tool in this
> folder, but unfortunatly it happend.
>
> I am working in a one person/multi-user environment with a special user
> account for internet access. This account has only non-priviledged user
> rights ( using win xp home sp2 ). The thought of changing some ACL for
> this non-priviledged user came up because I am using the CA ezArmor Suite
> ( Firewall / Anti-Virus ) to add some protection to my PC. Using the
> non-priviledged internet account I was not able to use the Autodownload
> feature to update the virus definitions because of missing priviledges. So
> it came up to me to change the ACLs in the softwares folder ( ..\CA\* )
> which worked out quit nice.
>
> But now to the problem: During the operation I was using the
> non-priviledged account and so had to use the runas command to have the
> needed priviledges to run cacls.exe .
>
> At the directory above the one I was going to chang I was using this
> command:
>
> d:\programs\security\ca\>runas /profile /user:<COMPNAME>\admin "cacls * /T
> /E /G VORDEFINIERT\Benutzer:F"
>
> ( note: I am using a german windows so I guess the VORDEFINIERT\Benutzer
> would be something like PREDEFINED\User in a english version )
>
> As expected after password input a commandline window was poping-up that
> performed the requested operations, but to my surprise it was working on
> the c:\windows\system32 directory and not as the expected one (
> d:\programs\security\ca\ ). So I did CTRL-C as fast as I could to stop
> the process, but of course was not fast enough.
>
> So now I have a windows\system32 directory with Full access for
> non-priviledged users which is quite annoying from the security
> perspective I wanted to improve by using the non-priviledged account for
> internet access.
>
> So my question is:
>
> Is there a way to restore the original ACL settings for the c:\windows\
> directory without a fresh install of the system ?
>
> Or an other way ? I know cacls.exe may do the job but how do you grant
> special rights only ( like GENERIC_READ, GENERIC_EXECUTE or
> FILE_GENERIC_READ ) which had been the original rights of some folders
> ( catroot ) for the non-priviledge user ?
>
>
> Thx for advice
> Tobias Alte
>
> --

How To Reset Security Settings Back to the Defaults (Windows XP)
http://support.microsoft.com/default.aspx?scid=kb;en-us;313222



Relevant Pages

  • Re: OT: News readers for PCs?
    ... Windows 7 seems to be a pretty good OS - pretty snappy, ... That's interesting - a Mac user finding a PC satisfactory. ... Google's Chrome browser and never use Internet Explorer if you can help ... I'll simply use my giganews account so I'm ...
    (rec.food.cooking)
  • RE: Fatal error DM
    ... First, try to clean up your caches, Internet files and delete cookies ... On the IE properties windows you will see these Tabs: ... What limit/permissions assigned to this Limited account? ... Look in the right Pane/window for error message with red or Yellow ...
    (microsoft.public.windowsxp.help_and_support)
  • Re: How do TIFs (Temporary Internet Files) work?
    ... Most of the TIFs will be empty except for index.dat and desktop.ini files. ... C:\WINDOWS\Temporary Internet Files ... Account information for each user who is granted access on the ... In Windows 2000/NT, system services are launched with "Local System" ...
    (microsoft.public.windowsxp.general)
  • Re: Temporary Internet Files
    ... folder that's associated with your account is to log on with another account ... 2.On the Windows Advanced Options menu, use the ARROW keys to select Safe ... can now safely delete your Content.IE5 folder. ...
    (microsoft.public.windowsxp.general)
  • Re: Password
    ... Boot the computer in Safe Mode and use the built-in Administrator account. ... Take Ownership of a File or Folder in Windows XP ... > Explorer/Tools/Folder options/view I do not see a check ... >>In Internet Explorer go to Tools, Internet Options, ...
    (microsoft.public.windowsxp.security_admin)