topbanner_forum
  *

avatar image

Welcome, Guest. Please login or register.
Did you miss your activation email?

Login with username, password and session length
  • Friday April 19, 2024, 2:56 pm
  • Proudly celebrating 15+ years online.
  • Donate now to become a lifetime supporting member of the site and get a non-expiring license key for all of our programs.
  • donate

Author Topic: A Windows 7 "WTF?" problem - anybody know what causes this?  (Read 3940 times)

40hz

  • Supporting Member
  • Joined in 2007
  • **
  • Posts: 11,858
    • View Profile
    • Donate to Member
I've just run into this problem with the second client in about the last 4 months. I was wondering if anybody knows what might be causing this:

Symptoms:

This is an issue with permissions.

Without warning, the default user with administrative elevation rights is suddenly no longer able to install anything - or run most programs - EXCEPT using the "Run as Administrator" option under Windows 7 Pro.

Additional info:


a) The system has been checked for both malware and rootkits, and has been reported  as being 'clean' after using multiple anti-malware/spyware scanners in both normal and safe mode bootups.

b) The system has been checked and does not have the infamous KB2823324 installed

c) The user profile does not appear to be corrupted

d) The user profile is flagged as an Administrator

e) The machine is current with all Windows critical updates

f) No new apps or app updates have been recently installed

g) Completely disabling UAC is not an acceptable option

Possible smoking gun:


Both affected machines were runing AVG AntiVirus 2013 - although so is every other machine in both client offices. No other machines experienced the symptoms either of the problem machines were experiencing.

Current workaround:

Going back a restore point (or two) has fixed the problem in both cases

---------------------------------

images.jpg

That's about it. No weirdness I can spot - other than this problem - which starts happening without warning. I'm fairly certain it involves some issue with the user profile although I wasn't able to diagnose anything wrong with the profiles on either machine. Just plain weird.

So...anybody know what might be causing this?


Stoic Joker

  • Honorary Member
  • Joined in 2008
  • **
  • Posts: 6,646
    • View Profile
    • Donate to Member
Re: A Windows 7 "WTF?" problem - anybody know what causes this?
« Reply #1 on: June 07, 2013, 01:46 PM »
Is user account domain or LM admin?

Are Application Policies being used?

IIRC there is an auto elevate install option in GP but I do not recall where it is. Have you run an RSOP to see if anything (in LM policy) looked hinkey?

I've never used/recommended AVG - actually have a shoot on sight policy - and have never run across this issue (Just an observation).

Curt

  • Supporting Member
  • Joined in 2006
  • **
  • Posts: 7,566
    • View Profile
    • Donate to Member
Re: A Windows 7 "WTF?" problem - anybody know what causes this?
« Reply #2 on: June 07, 2013, 04:45 PM »
I had the same problem a couple of months ago. Not understanding why, I "solved" it by removing the last two installed programs AND updating my security program's installation files - and didn't think about it again, until now.

However, I have another "WTF" problem, which I imagine began right after an automatic update from Microsoft in the middle of May, causing unstable USB Charger and mouse performances (which is odd, because the charger is only handling the wireless keyboard, not the wired mouse). Can the beginning of your reported problem maybe be dated to an automatic update?

/64-bits Windows 7 Home Premium

« Last Edit: June 07, 2013, 05:03 PM by Curt, Reason: wires »

40hz

  • Supporting Member
  • Joined in 2007
  • **
  • Posts: 11,858
    • View Profile
    • Donate to Member
Re: A Windows 7 "WTF?" problem - anybody know what causes this?
« Reply #3 on: June 08, 2013, 07:47 AM »
Can the beginning of your reported problem maybe be dated to an automatic update?

Possible, with AVG being the most likely culprit. Will have to check that out.

Is user account domain or LM admin?

It's LM for both. These guys use an open source NAS box without a domain for filesharing.

Are Application Policies being used?

AFAIK they're using Windows policy vanilla defaults since the only person who does have enough systems knowledge to even know what a policy is said she hasn't touched anything.

IIRC there is an auto elevate install option in GP but I do not recall where it is. Have you run an RSOP to see if anything (in LM policy) looked hinkey?

Good call! Will need to try that.

I've never used/recommended AVG - actually have a shoot on sight policy - and have never run across this issue (Just an observation).

I have used AVG. And I too have a shoot on sight policy regarding it. ;D

Ditto for most of the other "all-in-one plus snazzy-interface" security suites. My experiences with them consistently rams home the message: Less is More. I still prefer the old warhorse "do one thing well" AV utilities - and I've currently standardized on Bitdefender as my AV recommendation for all my clients.
 8)

worstje

  • Honorary Member
  • Joined in 2009
  • **
  • Posts: 588
  • The Gent with the White Hat
    • View Profile
    • Donate to Member
Re: A Windows 7 "WTF?" problem - anybody know what causes this?
« Reply #4 on: June 08, 2013, 04:55 PM »
You may want to try running Process Monitor as an Administrator on one of the affected boxes, and then reproduce the issue. (Of course, that is assuming that the Event Log doesn't have a more helpful message than you have already shared with us.)