UACLauncher - launch adminprogs at startup without messages from UAC


Recommended Posts

Well, this program(combo) enables you to keep UAC on (not quit mode, COMPLETELY ON), and still be able to launch program that requires administrator access on startup without UACs prompts :D

It uses a program from ASUS SmartDoctor (ASDR.exe) that launches the program that I made with administrator access (without any UAC prompts)

Then, my program launches the program the user specified in the "Start.txt" :)

I dont know how ASDR works, it just does, would be fun to know....

I modified it a little using a HEX editor to read a different registry value than its original one, new one being:

HKLM\Software\UACLauncher\Path

How the other stuff works:

1. Start my prog

2. Two programs are extracted in the same folder, ASDR.exe and instsrv.exe (from microsoft, installs ASDR as a service, name UACLauncher)

3.1 Choose to install: ASDR is installed as a service

3.2 Choose to uninstall: ASDR service is uninstalled

4. See Start.txt for info

Click to download

But it's a very vulnerable attack vector for privilege escalation, which is why Vista comes with nothing to allow this.
Scheduled tasks allows the administrator to set up jobs to start, at logon, with administrative credentials - but this is really quite similar, in that services are doing the launching, and also requires administrative creds to set up.

I've used this on my machine to get SpeedFan and BOINC, two programs that require administrative privileges to run properly (no "the programs are defective, get new ones" nonsense, ok?) at logon.

Scheduled tasks allows the administrator to set up jobs to start, at logon, with administrative credentials - but this is really quite similar, in that services are doing the launching, and also requires administrative creds to set up.

I've used this on my machine to get SpeedFan and BOINC, two programs that require administrative privileges to run properly (no "the programs are defective, get new ones" nonsense, ok?) at logon.

Scheduling those tasks requires the Admin password to be entered. If at any point, something executing has your password, security is already shot to hell.

This will never be a target for exploitation, because it's just a little tool that probably won't be widely enough used to gain attention.

I was just explaining why Vista didn't come with anything to do this out of the box: Because it would be a very widely exploited feature.

Edited by MioTheGreat
Well, this program(combo) enables you to keep UAC on (not quit mode, COMPLETELY ON), and still be able to launch program that requires administrator access on startup without UACs prompts :D

Sweet! I just installed this so I can get Speedfan to start up by itself when I need to reboot. Very nice!!! Yes, yes, I realize that this creates a small security bypass vector. But the risk is damn small.

Thanks again!

Gary

P.S. When you said "ASDR is installed as a service" I looked for ASDR in the list of services but could not find it. I did find UACLauncher though! You might want to edit your first message to reflect that.

Edited by scuderiaconchiglia
  • 4 months later...
So all a hacker has to do is add their program name to start.txt... ?

Well, it's not quite that simple since you can easily store start.txt in a location that requires admin privileges to access.

It's more worrisome that if you put an executable on that list that isn't in a protected location, somebody could replace that executable (or a library that it loads) with a malicious binary.

I find it amusing that yo uactually think UAC is protecting your computer.

UAC is by far one of the worst security ideas Microsoft has implemented, imo.

The only UAC doesn't do well is protecting the user from his/her own stupidity. Otherwise, its pretty okay. If you think its invasive, you should see how Linux does it (hint: in the same way).

Scheduled tasks allows the administrator to set up jobs to start, at logon, with administrative credentials - but this is really quite similar, in that services are doing the launching, and also requires administrative creds to set up.

I've used this on my machine to get SpeedFan and BOINC, two programs that require administrative privileges to run properly (no "the programs are defective, get new ones" nonsense, ok?) at logon.

Scheduled Tasks is one way I got RivaTuner to boot without a UAC prompt. View instructions here. In the current version of RivaTuner it normally spawns a process that?prompts?the?user?for?elevation.?

It's quite unfortunate the ones who make the best hardware monitoring and control tools do it for free and have little to shell out to have their drivers signed.

This topic is now closed to further replies.
  • Recently Browsing   0 members

    • No registered users viewing this page.
  • Posts

    • Threads scales past half a billion users, brings deeper community and feed controls by Fiza Ali Meta has announced Threads crossing a major milestone of 500 million monthly active users. And, at the heart of this growth sits something simple: communities. From books to basketball, parenting to music, Threads says its rise has been powered by people clustering around shared interests and, in turn, giving the platform its identity. In response, the platform is expanding its Communities feature beyond beta and introducing a set of new tools designed to make participation easier and more engaging. A redesigned Communities Hub will now appear in the main navigation menu, allowing users to jump between groups without leaving their feed. Each community will also receive a distinct Community Icon, giving them clearer visual identity and making them easier to recognise across the platform. Then there’s Community Progress, which is a kind of live gauge showing how close a topic is to becoming a full-fledged community, alongside guidance on how users can contribute to its development. In addition, Meta is also expanding its Community Champions programme, recognising more users who actively contribute to community engagement. And then things go more local; Local Communities is already available in 100 countries, including North America, South America, Asia, and Europe but are now rolling out with native-language tags starting in Japan, South Korea, and Taiwan. The platform is also expanding Live Chats to more communities in the coming weeks, adding features such as co-hosting and the ability to quote moments directly into users’ feeds. Beyond communities, Meta is tightening the loop between users and their feeds. Earlier this year came "Dear Algo," a feature that lets people tell Threads what they want more or less of. Now it’s being paired with a new tool, "Your Algo." It allows people to adjust how frequently certain topics appear, with options lasting one, three, or seven days. Meta says these preferences remain private and can be managed alongside “Dear Algo” in a unified settings hub. The rollout begins in the US, Canada, UK, Australia, and New Zealand. Finally, the company says these changes are part of an ongoing effort to refine Threads based on user feedback and that further updates will continue as the platform evolves.
    • You pay just $100 per TB with this rare 4TB PCIe Gen4 NVMe SSD deal by Sayan Sen SSDs and GPUs are incredibly hard to get nowadays due to high pricing. Discounts are quite rare which is why we report on them as soon as we spot a good deal. For example AMD's new 9070 GRE was finally up for sale at a very good price of just $500 thanks to a special coupon. Sadly that deal is gone but if you happen to be looking for a 4TB NVMe SSD and can spend around $400 there is a really good offer on sale that you should not miss out on as TeamGroup's 4TB G50 model is on sale for that that price which means you are only paying $100 per TB, a very good deal in the current market (purchase link under the specs table down below). The TeamGroup T-FORCE G50 NVMe SSD is a PCIe Gen4 drive and as such it promises to deliver sequential read speeds of up to 5,000 MB/s, helping accelerate game loading, file transfers, and everyday computing tasks. Since this is a 4TB drive you can use it for a gaming library to take advantage of things like DirectStorage. The SSD features an InnoGrit controller and SLC caching technology to support consistent performance. An ultra-thin, patented graphene heatsink is included to aid in heat dissipation. Get it at the link below: Team Group T-FORCE G50 4TB Internal SSD (TM8FFE004T0C129): $449.99 + $50 off w/ promo code SSF69668, limited offer => $39.99 (Sold and Shipped by Newegg US) Good to know This Amazon deal is U.S. specific, and not available in other regions unless specified. We only use first-party seller links (at the time of article publishing); ensure that you purchase from a first-party seller link only. Check out Today's Deals on Amazon | or our recent tech deals. Become a Prime member (for Students or SNAP) via Neowin Get Prime Access - Prime for half price (for qualifying Medicaid, EBT, SNAP) Subscribe to Prime Video, Audible Plus, Music Unlimited or Kindle Unlimited via Neowin As an Amazon Associate, we earn from qualifying purchases.
    • I agree. I also think Phil stayed too long. They should definitely fire whoever thought all a console platform needed was Call of Duty, Elder Scrolls, and Fallout to survive. Asha and crew are still saying they need more Elder Scrolls and Fallout games. They simply don't get it.
  • Recent Achievements

    • One Year In
      Console General earned a badge
      One Year In
    • One Year In
      Twozo Technologies earned a badge
      One Year In
    • One Month Later
      Twozo Technologies earned a badge
      One Month Later
    • Week One Done
      Twozo Technologies earned a badge
      Week One Done
    • Veteran
      branfont went up a rank
      Veteran
  • Popular Contributors

    1. 1
      +primortal
      522
    2. 2
      +Edouard
      198
    3. 3
      PsYcHoKiLLa
      110
    4. 4
      Steven P.
      89
    5. 5
      Nick H.
      71
  • Tell a friend

    Love Neowin? Tell a friend!