Welcome Guest ( Log In | Register )

Outline · [ Standard ] · Linear+

 How to block all type of installation

views
     
TSpandah
post Oct 21 2024, 12:47 PM, updated 2y ago

Enthusiast
*****
Senior Member
719 posts

Joined: Jul 2011

Good afternoon everyone,

recently we experience wps office automatically installing itself,

the user is on normal acc, no admin rights, the installation doesn't require admin rights, it doesn't even need user to start installation by clicking installer, it just install itself

even if user accidentally click some link, it should have just downloaded the installer and shouldn't auto run itself.

it took over microsoft office and when we try to uninstall it, it ask for admin password.

How can i set for every installation must require admin rights? meaning i want block all such installation without admin permission.

and how can i prevent such program from acquiring admin rights, when they installed without admin right?


Thanks in advance icon_question.gif


edit: found some other similar complaints, and seems like not much answer is available
https://learn.microsoft.com/en-us/answers/q...ault-pdf-viewer
https://www.reddit.com/r/WindowsHelp/commen...s_in_my_system/
https://superuser.com/questions/1729819/how...mpany-computers

for the last one it include some web link block in eu, i would prefer to just set a group policy if possible to disable all installation without admin rights, and to protect the admin rights from being accessed by the program. it seems like a loop hole that a program can install without admin and then gain the admin access afterwards. sweat.gif

This post has been edited by pandah: Oct 21 2024, 12:58 PM
hightechgadgets8
post Oct 21 2024, 12:54 PM

\(^o^)/
*******
Senior Member
6,019 posts

Joined: Sep 2011


this is on android phone or pc or laptop?
TSpandah
post Oct 21 2024, 02:15 PM

Enthusiast
*****
Senior Member
719 posts

Joined: Jul 2011

QUOTE(hightechgadgets8 @ Oct 21 2024, 12:54 PM)
this is on android phone or pc or laptop?
*
this is pc, it happens on 1 win10 and another win11.

the program itself is quite problematic also, it not only took over ms office, it also some how corrupts itself or corrupt the files. simple words and excel can be corrupted and wps itself can't open the file, then the only way to open it is uninstall wps, download a fresh copy of it and open the file again... bangwall.gif then the file is normal again rclxub.gif


hightechgadgets8
post Oct 21 2024, 03:27 PM

\(^o^)/
*******
Senior Member
6,019 posts

Joined: Sep 2011


QUOTE(pandah @ Oct 21 2024, 02:15 PM)
this is pc, it happens on 1 win10 and another win11.

the program itself is quite problematic also, it not only took over ms office, it also some how corrupts itself or corrupt the files. simple words and excel can be corrupted and wps itself can't open the file, then the only way to open it is uninstall wps, download a fresh copy of it and open the file again... bangwall.gif then the file is normal again  rclxub.gif
*
download malwarebytes do a scan.
https://www.malwarebytes.com/

imo it is some app / software you installed that does the discreet installation of WPS, thats why it happens on WIN10 /11, go thru your liat of apps and see which 1 might be rogue
TruboXL
post Oct 21 2024, 03:35 PM

Keep on keeping on! 👍
******
Senior Member
1,050 posts

Joined: Jan 2016
From: Land of floods, Kota Tinggi


Block running WPS executable?
SUSifourtos
post Oct 21 2024, 03:39 PM

Look at all my stars!!
*******
Senior Member
2,256 posts

Joined: Feb 2012



QUOTE(pandah @ Oct 21 2024, 02:15 PM)
this is pc, it happens on 1 win10 and another win11.

the program itself is quite problematic also, it not only took over ms office, it also some how corrupts itself or corrupt the files. simple words and excel can be corrupted and wps itself can't open the file, then the only way to open it is uninstall wps, download a fresh copy of it and open the file again... bangwall.gif then the file is normal again  rclxub.gif
*
been using PC 30 years.
never see a PC so compromise like this.

1. illegal Copy of Windows 10/11
2. a super infected Thumbdrive passing around. ( my company Thumbdrive = Heroin. Who bring thumbdrive = fire on the spot )
3. Email. I dont know how u guys manage email. (read, inbox, send, auth)
netmatrix
post Oct 21 2024, 11:06 PM

The machine... it sees everything.
*******
Senior Member
6,733 posts

Joined: Jan 2003
From: Zion


QUOTE(ifourtos @ Oct 21 2024, 03:39 PM)
been using PC 30 years.
never see a PC so compromise like this.

1. illegal Copy of Windows 10/11
2. a super infected Thumbdrive passing around. ( my company Thumbdrive = Heroin. Who bring thumbdrive = fire on the spot )
3. Email. I dont know how u guys manage email. (read, inbox, send, auth)
*
I heard about it. It installs from browser. I think it is a browser exploit rather than virus. It defaults WPS office as a viewer/ editor to Office & PDF file.

Anyway if you want all the pc in the office not to allow any form of installation, you have to change the account from Administrator to User account.

The Pc will function as normal. But it would not allow installation and a window would pop up asking for administrator account and password.

This post has been edited by netmatrix: Oct 21 2024, 11:40 PM
SUSifourtos
post Oct 21 2024, 11:54 PM

Look at all my stars!!
*******
Senior Member
2,256 posts

Joined: Feb 2012



QUOTE(netmatrix @ Oct 21 2024, 11:06 PM)
I heard about it. It installs from browser. I think it is a browser exploit rather than virus. It defaults WPS office as a viewer/ editor to Office & PDF file.

Anyway if you want all the pc in the office not to allow any form of installation, you have to change the account from Administrator to User account.

The Pc will function as normal. But it would not allow installation and a window would pop up asking for administrator account and password.
*
Who trigger this exploit?
From where, and how it trigger this exploit?
and you think WPS can target all PC worldwide with this exploit?

think.

Answer is simple.

This PC and their office enviroment is totally compromised. Even buy NEW PC also same.
as long as the NEW PC enter this group of people, same thing happened.

1. Their illegal Copy of Windows.
2. They use compromised Pendrive
3. a Device in their LAN compromised. keep infected other Device in LAN.
4. Email system they use
TSpandah
post Oct 21 2024, 11:58 PM

Enthusiast
*****
Senior Member
719 posts

Joined: Jul 2011

It is a standard user, some programs doesn't need to have admin rights to install, even chrome can do so. The windows is legit and malwarebyte return nothing.

I need a way to prevent these kind of installing without admin rights behaviour.
danieln
post Nov 5 2024, 08:05 PM

Regular
******
Senior Member
1,307 posts

Joined: Feb 2008
have you tried set the account to user level?
myusernameisthis
post Nov 25 2024, 09:45 PM

New Member
*
Junior Member
19 posts

Joined: May 2022
enterprise environment kah? as in workplace?

install sophos antivirus...is a layer 7 antivirus basically. can block everything. even in home network
TSpandah
post Nov 26 2024, 03:00 PM

Enthusiast
*****
Senior Member
719 posts

Joined: Jul 2011

QUOTE(danieln @ Nov 5 2024, 08:05 PM)
have you tried set the account to user level?
*
the account is set as user level, and some program is installing at user level folder such as the appdata so it doesn't require admin password to proceed. ohmy.gif

QUOTE(myusernameisthis @ Nov 25 2024, 09:45 PM)
enterprise environment kah? as in workplace?

install sophos antivirus...is a layer 7 antivirus basically. can block everything. even in home network
*
small office environment, company is using trendmicro, i may try to ask if there is any function to do this notworthy.gif

 

Change to:
| Lo-Fi Version
0.0190sec    0.66    5 queries    GZIP Disabled
Time is now: 17th December 2025 - 09:42 AM