right-click C:\WINDOWS shows little UAC? shield - security?

JimLewandowski

New member
Guru
Local time
4:31 AM
Messages
450
Location
Raleigh, NC
I have another thread that talked about an XP transplanted internal HD that right-clicking on any folder or file had little UAC? shield icon next to DELETE and RENAME in right-click context menu. When I would delete a file/folder, it would NOT give me a delete confirmation.

I happened to right-click C:\Windows and every other folder in C: (except ones I created) have the UAC shield next to delete. They ARE owned by TrustedInstaller but I just like having the protection in case I accidentally delete them.

Can anyone on their W7 machine, right-click various system folders in C: and report if you have the UAC icon? As well, check your security -> Owner to see if it's TrustedInstaller?

Worrisome. But, I've never done a thing to any C:\ folder re: security or anything. Ever.
 

My Computer My Computer

At a glance

Windows 7AMD Phenom II X2 (dual-core)4Gintegrated ATI HD 4200
Computer type
PC/Desktop
Computer Manufacturer/Model Number
Custom
OS
Windows 7
CPU
AMD Phenom II X2 (dual-core)
Motherboard
GA-MA785GM-US2H
Memory
4G
Graphics Card(s)
integrated ATI HD 4200
Sound Card
integrated
Monitor(s) Displays
Samsung 24"
Screen Resolution
1920x1080
Hard Drives
1 SSD - Samsung 840 - 500 GB - OS and DATA partitions
1 SSD - Intel 320 - 120 GB (used for backups) - Misc/BACKUP
1 SATA HD - WD, 500 GB - BACKUP
PSU
Ultra X4 500W
Case
Ultra X-blaster
Keyboard
Microsoft Digital Media Pro
Mouse
Logitech WIRED!
Internet Speed
15 Mbps FIOS
Do you mean you see the UAC shield directly next to Deelete in the context menu? I do not see that, but currently have UAC turned off on this computer. What level of UAC are you using?

Regards,
Golden
 

My Computer My Computer

At a glance

Windows 10 Pro x64 ; Xubuntu x64Intel i7 860 @ 2.80 GHz O/C'ed to 4.0GHz16GB Corsair Vengance DDR3 @ 661 MHz Dual Cha...EVGA NVidia GTX 560 1024MB
Computer type
PC/Desktop
Computer Manufacturer/Model Number
Golden Mk. I.4
OS
Windows 10 Pro x64 ; Xubuntu x64
CPU
Intel i7 860 @ 2.80 GHz O/C'ed to 4.0GHz
Motherboard
Gigabyte P55A-UD3R Rev.1. Award BIOS F13
Memory
16GB Corsair Vengance DDR3 @ 661 MHz Dual Channel (9-9-9-24)
Graphics Card(s)
EVGA NVidia GTX 560 1024MB
Sound Card
Realtek Integrated
Monitor(s) Displays
Dual Samsung SyncMaster 2494HS
Screen Resolution
1920*1080 and 1920*1080
Hard Drives
1*Samsung 840 EVO 120GB SSD;
1*OCZ Vertex 2 60GB SSD;
2*Samsung F3 SpinPoint 1TB in RAID0;
1*Samsung F1 SpinPoint 1TB;
2*Western Digital 1TB External USB 3.0
1*Western Digital 500GB External USB 3.0
1*Seagate 500GB External USB 2.0
PSU
Thermaltake ToughPower QFan 750W
Case
Thermaltake Element S VK60001W2Z
Cooling
Corsair H60 Water Cooling, 2*230mm and 2*80mm case fans
Keyboard
Logitech G110
Mouse
Logitech MX518
I have another thread that talked about an XP transplanted internal HD that right-clicking on any folder or file had little UAC? shield icon next to DELETE and RENAME in right-click context menu. When I would delete a file/folder, it would NOT give me a delete confirmation.

I happened to right-click C:\Windows and every other folder in C: (except ones I created) have the UAC shield next to delete. They ARE owned by TrustedInstaller but I just like having the protection in case I accidentally delete them.

Can anyone on their W7 machine, right-click various system folders in C: and report if you have the UAC icon? As well, check your security -> Owner to see if it's TrustedInstaller?

Worrisome. But, I've never done a thing to any C:\ folder re: security or anything. Ever.

I have the UAC shield in the places you describe, and the owner is set to TrustedInstaller.
 

My Computer My Computer

At a glance

Windows 7 Home Premium 64 BitIntel(R) Core(TM)2 Quad CPU Q9550 @ 2.83GHz6.00 GB Hundai HMT125U6BFR8C-H9ATI Radeon HD 4850
Computer Manufacturer/Model Number
HP Pavilion e9110t
OS
Windows 7 Home Premium 64 Bit
CPU
Intel(R) Core(TM)2 Quad CPU Q9550 @ 2.83GHz
Motherboard
Pegatron IPIEL-LA3
Memory
6.00 GB Hundai HMT125U6BFR8C-H9
Graphics Card(s)
ATI Radeon HD 4850
Sound Card
Realtek High Definition Audio/ATI High Definition Audio
Monitor(s) Displays
Acer AL2216W
Screen Resolution
1680x1050
Hard Drives
Hitachi HDP725050GLA360 ATA Device 500 GB
PSU
Unknown/installed by HP
Case
HP generic case
Cooling
Intel Stock Cooling
Keyboard
HP Keyboard
Mouse
HP Mouse
Internet Speed
Download: 19.15 Mbps Upload: 1.67 Mbps
Other Info
Network Adapter Realtek RTL8168D/8111D Family PCI-E Gigabit Ethernet NIC (NDIS 6.20)
Network Adapter 802.11n Wireless PCI Express Card LAN Adapter
I have the UAC shield in the places you describe, and the owner is set to TrustedInstaller.

Doesn't that imply if you accidentally tried to delete them, you would not get confirmation?

I got my UAC shield to disappear from my transplanted XP drive by adding AUTHENTICATED USERS to the volume and folders/files.

I have UAC on and Jim is the only user (I'm also admin) and am automatically signed on by W7. My level is "default" (3rd tick mark on slider).

I've dug heavily into Win. security lately, but still don't quite understand all the nuances.

For example, if you have a folder like WindowsImageBackup which you do NOT normally have access to, you can click CONTINUE when the UAC prompt appears to be able to view it. What is really happening there (is Jim/Users being added as read/execute to that folder?)? Also, is it possible for me to make WindowsImageBackup go BACK to the way it was prior to my UAC'ing my way in? Would I just delete Jim/Users from the security for the primary folder?
 

My Computer My Computer

At a glance

Windows 7AMD Phenom II X2 (dual-core)4Gintegrated ATI HD 4200
Computer type
PC/Desktop
Computer Manufacturer/Model Number
Custom
OS
Windows 7
CPU
AMD Phenom II X2 (dual-core)
Motherboard
GA-MA785GM-US2H
Memory
4G
Graphics Card(s)
integrated ATI HD 4200
Sound Card
integrated
Monitor(s) Displays
Samsung 24"
Screen Resolution
1920x1080
Hard Drives
1 SSD - Samsung 840 - 500 GB - OS and DATA partitions
1 SSD - Intel 320 - 120 GB (used for backups) - Misc/BACKUP
1 SATA HD - WD, 500 GB - BACKUP
PSU
Ultra X4 500W
Case
Ultra X-blaster
Keyboard
Microsoft Digital Media Pro
Mouse
Logitech WIRED!
Internet Speed
15 Mbps FIOS
I have the UAC shield in the places you describe, and the owner is set to TrustedInstaller.

Doesn't that imply if you accidentally tried to delete them, you would not get confirmation?

I got my UAC shield to disappear from my transplanted XP drive by adding AUTHENTICATED USERS to the volume and folders/files.

I have UAC on and Jim is the only user (I'm also admin) and am automatically signed on by W7. My level is "default" (3rd tick mark on slider).

I've dug heavily into Win. security lately, but still don't quite understand all the nuances.

For example, if you have a folder like WindowsImageBackup which you do NOT normally have access to, you can click CONTINUE when the UAC prompt appears to be able to view it. What is really happening there (is Jim/Users being added as read/execute to that folder?)? Also, is it possible for me to make WindowsImageBackup go BACK to the way it was prior to my UAC'ing my way in? Would I just delete Jim/Users from the security for the primary folder?

I do not think you can delete them if UAC is turned on. I get an "Acces is Denied" message if I try. I inadvertantly answered your question about a folder going back to its prior state. You can make a folder go back to its prior state of the owner being TrustedInstaller if you have a restore point and revert to that restore point. Otherwise, there is no method I know of to change the owner back to TrustedInstaller.
I accidentally changed winsxs to have my adminstrative user as the owner tonight, and I had to revert to a restore point to undo that change (as I wasn't sure how that would affect any programs or installers that needed that folder to run and were looking for the TrustedInstaller owner).

Edit: Also, if it does add a user with read permissions, you could revert the folder back to its prior state (if that is all that was done) by removing those users with the remove button through the Edit (Permissions) button.
 

My Computer My Computer

At a glance

Windows 7 Home Premium 64 BitIntel(R) Core(TM)2 Quad CPU Q9550 @ 2.83GHz6.00 GB Hundai HMT125U6BFR8C-H9ATI Radeon HD 4850
Computer Manufacturer/Model Number
HP Pavilion e9110t
OS
Windows 7 Home Premium 64 Bit
CPU
Intel(R) Core(TM)2 Quad CPU Q9550 @ 2.83GHz
Motherboard
Pegatron IPIEL-LA3
Memory
6.00 GB Hundai HMT125U6BFR8C-H9
Graphics Card(s)
ATI Radeon HD 4850
Sound Card
Realtek High Definition Audio/ATI High Definition Audio
Monitor(s) Displays
Acer AL2216W
Screen Resolution
1680x1050
Hard Drives
Hitachi HDP725050GLA360 ATA Device 500 GB
PSU
Unknown/installed by HP
Case
HP generic case
Cooling
Intel Stock Cooling
Keyboard
HP Keyboard
Mouse
HP Mouse
Internet Speed
Download: 19.15 Mbps Upload: 1.67 Mbps
Other Info
Network Adapter Realtek RTL8168D/8111D Family PCI-E Gigabit Ethernet NIC (NDIS 6.20)
Network Adapter 802.11n Wireless PCI Express Card LAN Adapter
I do not think you can delete them if UAC is turned on. I get an "Acces is Denied" message if I try. I inadvertantly answered your question about a folder going back to its prior state. You can make a folder go back to its prior state of the owner being TrustedInstaller if you have a restore point and revert to that restore point. Otherwise, there is no method I know of to change the owner back to TrustedInstaller.
I accidentally changed winsxs to have my adminstrative user as the owner tonight, and I had to revert to a restore point to undo that change (as I wasn't sure how that would affect any programs or installers that needed that folder to run and were looking for the TrustedInstaller owner).

Edit: Also, if it does add a user with read permissions, you could revert the folder back to its prior state (if that is all that was done) by removing those users with the remove button through the Edit (Permissions) button.

OK. I think I understand. When I double-click (UAC prompts) to get access to WindowsImageBackup, for example, Jim/User is simply being added as read/execute access but the owner stays the same. If I wrestle ownership away from TrustedInstaller, there's no way for me to return the ownership should Jim/user force ownership (properties -> security -> advanced -> owner). However, if I WERE the owner, can't I delete myself from the users lists (primary security panel, click on Delete/Remove)? I'd think NTFS would assign some other SID as the owner as there has to be some owner for each file/folder/drive.

Thanks for the great/info and being the guinea pig on this.

Edit: But wait, if I have "special" permissions, doesn't that give me the right to assign the ownership of said file/folder to any other group/person/SID?
 

My Computer My Computer

At a glance

Windows 7AMD Phenom II X2 (dual-core)4Gintegrated ATI HD 4200
Computer type
PC/Desktop
Computer Manufacturer/Model Number
Custom
OS
Windows 7
CPU
AMD Phenom II X2 (dual-core)
Motherboard
GA-MA785GM-US2H
Memory
4G
Graphics Card(s)
integrated ATI HD 4200
Sound Card
integrated
Monitor(s) Displays
Samsung 24"
Screen Resolution
1920x1080
Hard Drives
1 SSD - Samsung 840 - 500 GB - OS and DATA partitions
1 SSD - Intel 320 - 120 GB (used for backups) - Misc/BACKUP
1 SATA HD - WD, 500 GB - BACKUP
PSU
Ultra X4 500W
Case
Ultra X-blaster
Keyboard
Microsoft Digital Media Pro
Mouse
Logitech WIRED!
Internet Speed
15 Mbps FIOS
I do not think you can delete them if UAC is turned on. I get an "Acces is Denied" message if I try. I inadvertantly answered your question about a folder going back to its prior state. You can make a folder go back to its prior state of the owner being TrustedInstaller if you have a restore point and revert to that restore point. Otherwise, there is no method I know of to change the owner back to TrustedInstaller.
I accidentally changed winsxs to have my adminstrative user as the owner tonight, and I had to revert to a restore point to undo that change (as I wasn't sure how that would affect any programs or installers that needed that folder to run and were looking for the TrustedInstaller owner).

Edit: Also, if it does add a user with read permissions, you could revert the folder back to its prior state (if that is all that was done) by removing those users with the remove button through the Edit (Permissions) button.

OK. I think I understand. When I double-click (UAC prompts) to get access to WindowsImageBackup, for example, Jim/User is simply being added as read/execute access but the owner stays the same. If I wrestle ownership away from TrustedInstaller, there's no way for me to return the ownership should Jim/user force ownership (properties -> security -> advanced -> owner). However, if I WERE the owner, can't I delete myself from the users lists (primary security panel, click on Delete/Remove)? I'd think NTFS would assign some other SID as the owner as there has to be some owner for each file/folder/drive.

Thanks for the great/info and being the guinea pig on this.

Edit: But wait, if I have "special" permissions, doesn't that give me the right to assign the ownership of said file/folder to any other group/person/SID?

I have deleted myself from the list before, but I was still considered the owner. The owner is the user with permissions to edit who gets control of what, so even deleting the user does not revoke the owner's rights to change permissions. This makes sense because if you deleted the main user from permissions, who would have the ability to edit what permissions other users get?
 

My Computer My Computer

At a glance

Windows 7 Home Premium 64 BitIntel(R) Core(TM)2 Quad CPU Q9550 @ 2.83GHz6.00 GB Hundai HMT125U6BFR8C-H9ATI Radeon HD 4850
Computer Manufacturer/Model Number
HP Pavilion e9110t
OS
Windows 7 Home Premium 64 Bit
CPU
Intel(R) Core(TM)2 Quad CPU Q9550 @ 2.83GHz
Motherboard
Pegatron IPIEL-LA3
Memory
6.00 GB Hundai HMT125U6BFR8C-H9
Graphics Card(s)
ATI Radeon HD 4850
Sound Card
Realtek High Definition Audio/ATI High Definition Audio
Monitor(s) Displays
Acer AL2216W
Screen Resolution
1680x1050
Hard Drives
Hitachi HDP725050GLA360 ATA Device 500 GB
PSU
Unknown/installed by HP
Case
HP generic case
Cooling
Intel Stock Cooling
Keyboard
HP Keyboard
Mouse
HP Mouse
Internet Speed
Download: 19.15 Mbps Upload: 1.67 Mbps
Other Info
Network Adapter Realtek RTL8168D/8111D Family PCI-E Gigabit Ethernet NIC (NDIS 6.20)
Network Adapter 802.11n Wireless PCI Express Card LAN Adapter
Also consider that you're not just a user on your own, but part of one or more groups as well - most importantly, the Administrators group. You may have separate access rights for yourself personally and for your groups as a whole - the effective permissions will then be a combination of these.
 

My Computer My Computer

At a glance

Windows 7 Professional SP1 32-bitIntel Core 2 Duo E6600 2.4GHz4GB DDR2-667 (4x1GB in dual-channel config)nVidia GeForce 9800 GT
Computer type
PC/Desktop
Computer Manufacturer/Model Number
Custom-built
OS
Windows 7 Professional SP1 32-bit
CPU
Intel Core 2 Duo E6600 2.4GHz
Motherboard
Asus PL5D2
Memory
4GB DDR2-667 (4x1GB in dual-channel config)
Graphics Card(s)
nVidia GeForce 9800 GT
Sound Card
Creative X-Fi XtremeMusic
Monitor(s) Displays
Acer P236H
Screen Resolution
1920x1200 (DVI)
Hard Drives
OCZ SSD Vertex Plus 60GB SATA (Firmware 3.55), 64MB cache
Hitachi HD321KJ SATA, 320GB, 7200rpm, 16MB cache
PSU
Antec TruePower 2.0
Case
Cooler Master Centurion
Cooling
Too many fans
Keyboard
Standard
Mouse
Microsoft wireless optical mouse
Internet Speed
AT&T U-verse (18mbit/sec)
Antivirus
Microsoft Security Essentials
Browser
Firefox
Other Info
Other devices:
Compaq CQ-60 laptop
Google Nexus 7 (2012) tablet
Nvidia SHIELD tablet (US/LTE)
Hardkernel ODROID-XU single-board computer (Samsung Exynos 5420)
Also consider that you're not just a user on your own, but part of one or more groups as well - most importantly, the Administrators group. You may have separate access rights for yourself personally and for your groups as a whole - the effective permissions will then be a combination of these.

I just learned a new one this weekend. I did my first "backup" (vs. system image which I've done before). There's a Backup Operators group that I'm now in.
 

My Computer My Computer

At a glance

Windows 7AMD Phenom II X2 (dual-core)4Gintegrated ATI HD 4200
Computer type
PC/Desktop
Computer Manufacturer/Model Number
Custom
OS
Windows 7
CPU
AMD Phenom II X2 (dual-core)
Motherboard
GA-MA785GM-US2H
Memory
4G
Graphics Card(s)
integrated ATI HD 4200
Sound Card
integrated
Monitor(s) Displays
Samsung 24"
Screen Resolution
1920x1080
Hard Drives
1 SSD - Samsung 840 - 500 GB - OS and DATA partitions
1 SSD - Intel 320 - 120 GB (used for backups) - Misc/BACKUP
1 SATA HD - WD, 500 GB - BACKUP
PSU
Ultra X4 500W
Case
Ultra X-blaster
Keyboard
Microsoft Digital Media Pro
Mouse
Logitech WIRED!
Internet Speed
15 Mbps FIOS
I have deleted myself from the list before, but I was still considered the owner. The owner is the user with permissions to edit who gets control of what, so even deleting the user does not revoke the owner's rights to change permissions. This makes sense because if you deleted the main user from permissions, who would have the ability to edit what permissions other users get?

If you deleted yourself from ACCESS to a file/folder, does that mean you get the security denied popup when you now try to access it? Or since you're the owner, does W7 let you in by default?
 

My Computer My Computer

At a glance

Windows 7AMD Phenom II X2 (dual-core)4Gintegrated ATI HD 4200
Computer type
PC/Desktop
Computer Manufacturer/Model Number
Custom
OS
Windows 7
CPU
AMD Phenom II X2 (dual-core)
Motherboard
GA-MA785GM-US2H
Memory
4G
Graphics Card(s)
integrated ATI HD 4200
Sound Card
integrated
Monitor(s) Displays
Samsung 24"
Screen Resolution
1920x1080
Hard Drives
1 SSD - Samsung 840 - 500 GB - OS and DATA partitions
1 SSD - Intel 320 - 120 GB (used for backups) - Misc/BACKUP
1 SATA HD - WD, 500 GB - BACKUP
PSU
Ultra X4 500W
Case
Ultra X-blaster
Keyboard
Microsoft Digital Media Pro
Mouse
Logitech WIRED!
Internet Speed
15 Mbps FIOS
If you deleted yourself from ACCESS to a file/folder, does that mean you get the security denied popup when you now try to access it? Or since you're the owner, does W7 let you in by default?
The owner will get an access is denied popup until the owner's username is added to the permissions by the owner.
 

My Computer My Computer

At a glance

Windows 7 Home Premium 64 BitIntel(R) Core(TM)2 Quad CPU Q9550 @ 2.83GHz6.00 GB Hundai HMT125U6BFR8C-H9ATI Radeon HD 4850
Computer Manufacturer/Model Number
HP Pavilion e9110t
OS
Windows 7 Home Premium 64 Bit
CPU
Intel(R) Core(TM)2 Quad CPU Q9550 @ 2.83GHz
Motherboard
Pegatron IPIEL-LA3
Memory
6.00 GB Hundai HMT125U6BFR8C-H9
Graphics Card(s)
ATI Radeon HD 4850
Sound Card
Realtek High Definition Audio/ATI High Definition Audio
Monitor(s) Displays
Acer AL2216W
Screen Resolution
1680x1050
Hard Drives
Hitachi HDP725050GLA360 ATA Device 500 GB
PSU
Unknown/installed by HP
Case
HP generic case
Cooling
Intel Stock Cooling
Keyboard
HP Keyboard
Mouse
HP Mouse
Internet Speed
Download: 19.15 Mbps Upload: 1.67 Mbps
Other Info
Network Adapter Realtek RTL8168D/8111D Family PCI-E Gigabit Ethernet NIC (NDIS 6.20)
Network Adapter 802.11n Wireless PCI Express Card LAN Adapter
Back
Top