UACLauncher - launch adminprogs at startup without messages from UAC


Recommended Posts

Well, this program(combo) enables you to keep UAC on (not quit mode, COMPLETELY ON), and still be able to launch program that requires administrator access on startup without UACs prompts :D

It uses a program from ASUS SmartDoctor (ASDR.exe) that launches the program that I made with administrator access (without any UAC prompts)

Then, my program launches the program the user specified in the "Start.txt" :)

I dont know how ASDR works, it just does, would be fun to know....

I modified it a little using a HEX editor to read a different registry value than its original one, new one being:

HKLM\Software\UACLauncher\Path

How the other stuff works:

1. Start my prog

2. Two programs are extracted in the same folder, ASDR.exe and instsrv.exe (from microsoft, installs ASDR as a service, name UACLauncher)

3.1 Choose to install: ASDR is installed as a service

3.2 Choose to uninstall: ASDR service is uninstalled

4. See Start.txt for info

Click to download

But it's a very vulnerable attack vector for privilege escalation, which is why Vista comes with nothing to allow this.
Scheduled tasks allows the administrator to set up jobs to start, at logon, with administrative credentials - but this is really quite similar, in that services are doing the launching, and also requires administrative creds to set up.

I've used this on my machine to get SpeedFan and BOINC, two programs that require administrative privileges to run properly (no "the programs are defective, get new ones" nonsense, ok?) at logon.

Scheduled tasks allows the administrator to set up jobs to start, at logon, with administrative credentials - but this is really quite similar, in that services are doing the launching, and also requires administrative creds to set up.

I've used this on my machine to get SpeedFan and BOINC, two programs that require administrative privileges to run properly (no "the programs are defective, get new ones" nonsense, ok?) at logon.

Scheduling those tasks requires the Admin password to be entered. If at any point, something executing has your password, security is already shot to hell.

This will never be a target for exploitation, because it's just a little tool that probably won't be widely enough used to gain attention.

I was just explaining why Vista didn't come with anything to do this out of the box: Because it would be a very widely exploited feature.

Edited by MioTheGreat
Well, this program(combo) enables you to keep UAC on (not quit mode, COMPLETELY ON), and still be able to launch program that requires administrator access on startup without UACs prompts :D

Sweet! I just installed this so I can get Speedfan to start up by itself when I need to reboot. Very nice!!! Yes, yes, I realize that this creates a small security bypass vector. But the risk is damn small.

Thanks again!

Gary

P.S. When you said "ASDR is installed as a service" I looked for ASDR in the list of services but could not find it. I did find UACLauncher though! You might want to edit your first message to reflect that.

Edited by scuderiaconchiglia
  • 4 months later...
So all a hacker has to do is add their program name to start.txt... ?

Well, it's not quite that simple since you can easily store start.txt in a location that requires admin privileges to access.

It's more worrisome that if you put an executable on that list that isn't in a protected location, somebody could replace that executable (or a library that it loads) with a malicious binary.

I find it amusing that yo uactually think UAC is protecting your computer.

UAC is by far one of the worst security ideas Microsoft has implemented, imo.

The only UAC doesn't do well is protecting the user from his/her own stupidity. Otherwise, its pretty okay. If you think its invasive, you should see how Linux does it (hint: in the same way).

Scheduled tasks allows the administrator to set up jobs to start, at logon, with administrative credentials - but this is really quite similar, in that services are doing the launching, and also requires administrative creds to set up.

I've used this on my machine to get SpeedFan and BOINC, two programs that require administrative privileges to run properly (no "the programs are defective, get new ones" nonsense, ok?) at logon.

Scheduled Tasks is one way I got RivaTuner to boot without a UAC prompt. View instructions here. In the current version of RivaTuner it normally spawns a process that?prompts?the?user?for?elevation.?

It's quite unfortunate the ones who make the best hardware monitoring and control tools do it for free and have little to shell out to have their drivers signed.

This topic is now closed to further replies.
  • Recently Browsing   0 members

    • No registered users viewing this page.
  • Posts

    • That's not clickbait. Clickbait is headlines like, "You'll never guess what this person looks like now" for example. For goodness sake, take a look around the internet if you think this is clickbait. How do sites survive if people don't click through to articles? How many people in all honesty would have clicked this if it had your suggested headline? You and those upvoting your post won't be happy until the web is a couple of hundred websites all behind a paywall.
    • HopToDesk 1.46.2.0 by Razvan Serea HopToDesk aims to improve the user experience by providing a free, easy-to-use, and secure remote desktop solution for all major device types including Windows PC, Mac, Linux, Android, Chrome Books, iOS, and even Raspberry Pi devices. HopToDesk empowers you to connect, control, and collaborate with ease. Whether you're providing IT support, managing remote teams, or accessing your own devices from anywhere, HopToDesk offers a reliable and secure solution. HopToDesk does not and cannot monitor user activity as the application uses end-to-end encryption for all traffic, and does not make a distinction between personal and business use (both are allowed). Additionally, HopToDesk includes many of the main features of common remote desktop solutions such as Unattended Access, File Transfer, Live Chat, Wake-On-LAN, 2FA, Direct IP access, a Recent Session and Favorite list, and is available in over 20 languages. HopToDesk can run in portable mode or installed on desktop operating systems. Installation is optional, and will install the HopToDesk service which runs in the background and listens for incoming connections, allowing the device to be accessible at all times. Why Choose HopToDesk? Completely Free: Enjoy full access for both personal and commercial use—no hidden fees or limitations. End-to-End Encryption: All communications, including screen sharing, file transfers, and chats, are protected with robust encryption. Open Source: Contribute to and benefit from a transparent and community-driven project. No Account Required: Connect instantly without the need for sign-ups or subscriptions. Core Features Remote Control & Screen Sharing: Effortlessly access and manage remote devices. File Transfer: Securely send and receive files with drag-and-drop simplicity. Live Chat: Communicate in real-time during sessions. Multi-Monitor Support: Navigate multiple screens with ease. Clipboard Synchronization: Copy and paste seamlessly across devices. Wake-on-LAN: Power on remote systems remotely. Session Recording: Document sessions for future reference. Two-Factor Authentication: Enhance security with an additional verification layer. Custom Branding: Personalize your remote sessions with custom avatars. Unattended Access: Connect to devices without requiring user intervention. Network Customization: Adjust settings like TURN relays and signaling servers to suit your environment. Centralized Device Management Utilize the HopToDesk Dashboard to: Monitor device status in real-time. Generate invite links for easy device integration. Customize network settings and synchronize changes effortlessly. Add a personal touch with custom avatars displayed during remote sessions. Download: HopToDesk 64-bit | HopToDesk 32-bit | ~9.0 MB (Freeware) Download: HopToDesk ARM64 | 21.4 MB Link: HopToDesk Home Page | Screenshot Get alerted to all of our Software updates on Twitter at @NeowinSoftware
    • Or use Epic games and get full games for free. lol Steam and their demos. Thankfully there’s competition
    • Maybe I missed it, but does this say anywhere that the game save bug has been squashed? I haven't encountered it myself, but it would be nice to know I'm good to go. Anyway, amazingly well done game. Mostly more of the same. ...but when the same is best in class with improved graphics and features, then a win.
    • Well when your game flops, you should expect this. If I do bad at work, I would expect a layoff. Less than 1600 people played it on steam. https://steamdb.info/app/1934570/charts/
  • Recent Achievements

    • Reacting Well
      Almohandis earned a badge
      Reacting Well
    • First Post
      Cosminus earned a badge
      First Post
    • One Year In
      ThatGuyOnline earned a badge
      One Year In
    • Week One Done
      Jeroen Wilms earned a badge
      Week One Done
    • Week One Done
      rolfus earned a badge
      Week One Done
  • Popular Contributors

    1. 1
      +primortal
      482
    2. 2
      +Edouard
      181
    3. 3
      PsYcHoKiLLa
      119
    4. 4
      Steven P.
      84
    5. 5
      neufuse
      73
  • Tell a friend

    Love Neowin? Tell a friend!