Jump to content

Recommended Posts

Posted

Oh For F*** sake...

Something similar has happened again..HELP!!!!!

 

Tosh - about 6 months old.

Created a new local account for teacher - gave him administrative rights as is done in this school...

Went to put the proxy in so that he can access the internet but ALL LAN settings are greyed out.

Logged on to the actual local administrator account..same thing

 

Logged on as network admin, proxy is in but again all LAN settings greyed out - which is what you would expect as it is being applied by a GPO

SO - it seems as if the machine is sort of crossing over its settings from a network log on to a local log on and greying out the same areas - but the proxy isnt there.

Is this a Tosh thing and what can I do about it?

I need to get the proxy in so that the teacher can access the internet when logged on locally.

Thanks

Guest TheLibrarian
Posted

Does the machine have a local policy that restricts this?

 

I can't see that it would be a Toshiba thing.

Posted

But there was a teacher log on before and it worked fine.

The only difference was that the machine had never been on the network when the original account was created, but it has been since, and now I cant get to the proxy. There has to be some sort of connection, surely?

Where would I look for something that might be restricting it?

Posted

does this help?

 

Make proxy settings per-machine (rather than per user)

Computer Configuration\Administrative Templates\Windows Components\Internet Explorer

 

Description

Applies proxy settings to all users of the same computer.

 

If you enable this policy, users cannot set user-specific proxy settings. They must use the zones created for all users of the computer.

 

If you disable this policy or do not configure it, users of the same computer can establish their own proxy settings.

 

This policy is intended to ensure that proxy settings apply uniformly to the same computer and do not vary from user to user.

Guest TheLibrarian
Posted

Open the run dialog and type "gpedit.msc", that should allow you to check local policies.

 

Off the top of my head I can't remember when the policies are stored in the registry, if you can find the key (probably HKLM\Software\policies\...) and remove them manually?

 

Might be worth checking for browser hijacks / browser hardening software (Spybot etc.).

 

Group Policy should not be hitting any local users, though a forced removal of a PC from the domain has been known to leave some settings behind. Maybe remove the PC from the domain, delete the machine account from AD, re-add the PC, move the account back to the correct OU, force update group policy (remembering the replication delays).

 

I usually force the group policy update with the following command "gpupdate /force /boot /sync".

 

 

My initial checks would be browser hardening software / browser hijack, then local policy, then the registry, finally the removal from the domain.

Posted
Alternative route of attack, if proxy settings is greyed out, can you give him a reg file to import to HKCU which will change them regardless - or a VBS file? Access to the settings in IE is just a convenient(ish) way to change them. I use a proxy on/proxy off VBS that was posted here for all our local teacher accounts so they can switch it on onsite and off when they get home...
  • 1 month later...
Posted

And once again this thread is resurrected...

This is now on a teacher's laptop - a Dell Latitude D505 - old machine.

Basically the teacher can use the machine logged on to the network at school - or he can log on locally but the proxy is in so that he can still see the internet.

However, when he logs on at home he can no longer untick the proxy box as he used to do as it is all greyed out. This is a relatively new thing - it used to work fine.

He has tried Firefox and Chrome, and even though they are both set to connect directly to the internet, they do not work either.

Anyway, I have tried all the settings as mentioned here but they have not worked, or else have worked until he has logged on to the network at school, whereupon the proxy settings appeared (even when logged on locally) - greyed out again.

I have searched for a solution but can find nothing - PLEASE can someone give me a pointer or two?

(he is an administrator on his local machine)

Posted

Please Please could SOMEONE give me a hand.

I found a reg setting which took out the actual proxy IP but the whole thing was still greyed out. But when I logged back on to the network the proxy went back in.

 

There must be SOMETHING I can do? Help????

Posted

Running processes:

C:\WINDOWS\System32\smss.exe

C:\WINDOWS\system32\winlogon.exe

C:\WINDOWS\system32\services.exe

C:\WINDOWS\system32\lsass.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\System32\svchost.exe

C:\Program Files\Intel\Wireless\Bin\EvtEng.exe

C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe

C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe

C:\WINDOWS\System32\WLTRYSVC.EXE

C:\WINDOWS\System32\bcmwltry.exe

C:\WINDOWS\system32\spoolsv.exe

C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe

C:\Program Files\Bonjour\mDNSResponder.exe

C:\Program Files\Eset\nod32krn.exe

C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe

C:\WINDOWS\system32\svchost.exe

C:\Program Files\iPod\bin\iPodService.exe

C:\WINDOWS\Explorer.EXE

C:\WINDOWS\system32\igfxsrvc.exe

C:\WINDOWS\system32\hkcmd.exe

C:\WINDOWS\system32\igfxpers.exe

C:\WINDOWS\system32\WLTRAY.exe

C:\Program Files\Eset\nod32kui.exe

C:\Program Files\Activ Software\Activdriver\ActivControl2.exe

C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe

C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe

C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe

C:\Program Files\ScanSoft\OmniPageSE4.0\OpwareSE4.exe

C:\Program Files\iTunes\iTunesHelper.exe

C:\Program Files\Common Files\Real\Update_OB\realsched.exe

C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe

C:\Program Files\Messenger\msmsgs.exe

C:\WINDOWS\system32\ctfmon.exe

C:\Program Files\Apple Computer\DVD@ccess\DVDAccess.exe

C:\Program Files\Intel\Wireless\Bin\Dot1XCfg.exe

C:\WINDOWS\system32\msiexec.exe

C:\Program Files\TrendMicro\HiJackThis\HiJackThis.exe

 

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = MSN.com

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = Bing

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = Bing

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = MSN.com

R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = 10.150.193.75:8080

O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll

O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - c:\program files\real\realplayer\rpbrowserrecordplugin.dll

O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll

O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.2.4204.1700\swg.dll

O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_B7C5AC242193BB3E.dll

O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll

O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe

O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe

O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe

O4 - HKLM\..\Run: [broadcom Wireless Manager UI] C:\WINDOWS\system32\WLTRAY.exe

O4 - HKLM\..\Run: [nod32kui] "C:\Program Files\Eset\nod32kui.exe" /WAITSERVICE

O4 - HKLM\..\Run: [ActivControl] C:\Program Files\Activ Software\Activdriver\ActivControl2.exe

O4 - HKLM\..\Run: [intelZeroConfig] "C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe"

O4 - HKLM\..\Run: [intelWireless] "C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe" /tf Intel PROSet/Wireless

O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"

O4 - HKLM\..\Run: [AppleSyncNotifier] C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe

O4 - HKLM\..\Run: [sSBkgdUpdate] "C:\Program Files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" -Embedding -boot

O4 - HKLM\..\Run: [OpwareSE4] "C:\Program Files\ScanSoft\OmniPageSE4.0\OpwareSE4.exe"

O4 - HKLM\..\Run: [scanSoft OmniPage SE 4.0-reminder] "C:\Program Files\ScanSoft\OmniPageSE4.0\Ereg\Ereg.exe" -r "C:\Documents and Settings\All Users\Application Data\ScanSoft\OmniPageSE4.0\Ereg\ereg.ini"

O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"

O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime

O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"

O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot

O4 - HKCU\..\Run: [swg] "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"

O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background

O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe

O4 - Global Startup: [email protected] = ?

O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present

O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Control Panel present

O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000

O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL

O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe

O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe

O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe

O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe

O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1227102118133

O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab

O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = uptonjun.local

O17 - HKLM\Software\..\Telephony: DomainName = uptonjun.local

O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = uptonjun.local

O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll

O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll

O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe

O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe

O23 - Service: Intel® PROSet/Wireless Event Log (EvtEng) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe

O23 - Service: Google Update Service (gupdate1c99079510f360) (gupdate1c99079510f360) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe

O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe

O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe

O23 - Service: NOD32 Kernel Service (NOD32krn) - Eset - C:\Program Files\Eset\nod32krn.exe

O23 - Service: Intel® PROSet/Wireless Registry Service (RegSrvc) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe

O23 - Service: Intel® PROSet/Wireless Service (S24EventMonitor) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe

O23 - Service: Intel® PROSet/Wireless SSO Service (WLANKEEPER) - Intel® Corporation - C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe

O23 - Service: Dell Wireless WLAN Tray Service (wltrysvc) - Unknown owner - C:\WINDOWS\System32\WLTRYSVC.EXE

 

--

End of file - 8275 bytes

Posted

It deletes the IP from the box but the whole thing remains greyed out and when I reboot the machine (on or off the network) it comes back.

Anyway, the other browsers, Chrome and Firefox, apparently have no proxy but can't connect except at school so the proxy is hidden in there somewhere!

 

Sorry, gotta go - will pick this up Mon

Posted

Could it be a service thats not running - Windows Firewall/ICS service maybe? Could be worth comparing the services list with a simlar laptop that works...?

 

I freely admit I'm guessing - I've never heard of a problem like this before!! :confused:

Guest TheLibrarian
Posted

I'd put my money on these entries:

  • O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
  • O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Control Panel present

I think this may contain your solution How do I restore security settings to the default settings?.

 

This is just my hunch, but I can't see anything else that I think is suspect in the HijackThis log.

Posted
We had this with w98, with poledit (I think that's what it was called) the w98 equilalent to group policies, an IEAK policy had been set up but was running separately, so whatever I changed on the computer reverted back at the next logon. Any chance there's a legacy from IEAK anywhere?
Posted
O4 - HKLM\..\Run: [nod32kui] "C:\Program Files\Eset\nod32kui.exe" /WAITSERVICE

 

If you have NOD32 on there, try changing the HTTP traffic filtering options. I've had some very weird effects when it comes to web browsing on my admin PC as NOD tries to decide what's a browser/web traffic and what isn't, then gives up and does neither...

Posted

I'll certainly look into those entries on Monday, thanks thelibrarian.

There shouldnt be anything left over from w98 as the server was new and the system rebuilt just over a year ago. But I suppose it could have been copied over - I remember poledit but would have to google IEAK as I would have no idea where to look anymore!

 

Ref: NOD32 - never ever had a problem with it - either here with Server 2003 or my other job with Server 2008. Why would that affect the proxy settings?

I can't see what has changed to do this as up until recently I did not have this problem. I certainly dont have it in my other job.

Thanks guys - keep the suggestions coming in!

Posted

Try using RSOP.msc to see what policies are being applied when logged on as the affected account (since it is an administrative account).

 

Might also be worth looking at the group policies in GPEdit.Msc to see who settings are applied to- I know it's not default (Domain Users would normally be default IIRC) but I imagine it is possible to set a group policy to apply to "Everyone" and have the same settings applied to local users.

Posted

Ref: NOD32 - never ever had a problem with it - either here with Server 2003 or my other job with Server 2008. Why would that affect the proxy settings?

 

The problem that I've had with it is the HTTP/HTTPS traffic scan misbehaving and preventing web pages loading - it has a list of programs to consider browsers and treats them differently to other apps when scanning. I don't know why or how it causes a problem but it was just a suggestion to investigate - on some machines here when it's thrown a wobbly disabling the HTTP scan element brings back connectivity :confused:

Posted

As an experiment, move the Computer Object into a new OU, don't create a GPO and block Policy Inheritance. Once the Computer Object is moved in AD, run gpupdate /force then reboot the machine. Are the proxy settings still greyed out at this point?

 

If they are then I'd say there is something a bit odd going on. Out of curiosity also are you using the laptop 'as supplied' or do you format and create your own generic images? I find creating generic images gives better performance and removes any of the carp many OEMs install by default.

Posted

Check the following

 

Policy\Computer Configuration\Administrative templates\Internet Explorer\Disable changing proxy settings

 

Needs to be set to disabled or Not Configured

 

 

Policy\User Configuration\Administrative templates\Internet Explorer\Disable changing proxy settings

 

Needs to be set to disabled or Not Configured

 

 

 

HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel

 

If the option is locked (greyed out) it will have the value of 1....changing the value to 0 immeadiately unlocks each setting

Posted

I think I am a bit confused

We want the proxy configured when the computer is logged on to the network - so I don't want to change anything that will affect that. So I don't want to be changing any policy settings I wouldnt have thought?

It is just when they are logged on locally, and want to access the internet.

I cannot find a setting called 'control panel under HKCU as described above

Posted (edited)
I'd put my money on these entries:

  • O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
  • O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Control Panel present

I think this may contain your solution How do I restore security settings to the default settings?.

 

This is just my hunch, but I can't see anything else that I think is suspect in the HijackThis log.

 

This didn't work I'm afraid

 

When I look at local policies there are no proxies set so it is coming from somewhere else!

Edited by witch

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...