Solved

Problems with the File blocking Feature

Posted on 2013-06-28
7
375 Views
Last Modified: 2013-07-02
We all know the 'feature' in Windows which marks files as blocked when saved from for instance an internet location to the local disk. The file is marked as blocked as noted by the message "This file came from another computer and might be blocked to help protect this computer".

There are ways of preventing this, by means of a GPO setting to force to skip this feature. This setting however works at the user level.

We came across this scenario:
Windows 2003 file server in a simple network environment, XP clients and a Windows 2003 Terminal Server. On the network a Document Scanner is attached, from which the people create PDF documents to be saved directly to a SMB path on the file server.
This PDF files are marked as blocked...

Does anyone have a solution as how to prevent this?
0
Comment
Question by:ArchiLogiQ
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 3
  • 3
7 Comments
 
LVL 81

Assisted Solution

by:David Johnson, CD, MVP
David Johnson, CD, MVP earned 167 total points
ID: 39286099
you can't prevent it but you can remove the blocking using sysinternals streams to remove the stream information
0
 
LVL 25

Assisted Solution

by:Coralon
Coralon earned 333 total points
ID: 39286165
Ve3ofa is exactly correct.  The easiest thing to do is probably set up a script that runs streams.exe against that particular directory on a regular basis.  (I would think once every 5 minutes, or even every minute).. You could even use sc.exe to turn it into a service, you could install powershell and have it check to see if the file count changes, etc.

But, to use streams it would be
streams -d -s <directorypath>

Open in new window


-d delete the alternate stream data
-s include subdirectories

Coralon
0
 

Author Comment

by:ArchiLogiQ
ID: 39289147
Thank you for the responses. I am familiar with the utils for deleting the streams.
If scheduling either of these is the only option, I will try this.
I will report back how it goes.
0
Forrester Webinar: xMatters Delivers 261% ROI

Guest speaker Dean Davison, Forrester Principal Consultant, explains how a Fortune 500 communication company using xMatters found these results: Achieved a 261% ROI, Experienced $753,280 in net present value benefits over 3 years and Reduced MTTR by 91% for tier 1 incidents.

 

Author Comment

by:ArchiLogiQ
ID: 39290157
I am having trouble getting the streams util to function properly. On several files I get a "Access is denied" message and on other "The system cannot find the path specified".
The latter is probably due to long file names, the first I cannot explain.

Any suggestions?
This is Windows Server 2003, so no option to 'Run as Administrator'.
0
 
LVL 25

Accepted Solution

by:
Coralon earned 333 total points
ID: 39292086
Just go into the directory you want to run it on, or you can substitute a drive.. especially if you have a long path..

subst j: d:\<really long path>
cd /d j:
streams -d -accepteula -s *
cd /d c:
subst j: /d

Open in new window


Coralon
0
 

Author Comment

by:ArchiLogiQ
ID: 39292330
I found out that the "Access is Denied" message is due to the Read only attribute of the particular file.
Besides using subst for shortening long file paths, I will work on a script that will encorporate both options. This should bring to a solution.

Thanks for the input.
0
 
LVL 25

Expert Comment

by:Coralon
ID: 39295375
Absolutely..

and for what it's worth.. (I have done this before)

subst j: d:\<really long path>
cd /d j:
attrib -s -h -r *
streams -d -accepteula -s *
cd /d c:
subst j: /d 

Open in new window


Coralon
0

Featured Post

Technology Partners: We Want Your Opinion!

We value your feedback.

Take our survey and automatically be enter to win anyone of the following:
Yeti Cooler, Amazon eGift Card, and Movie eGift Card!

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

by Batuhan Cetin Within the dynamic life of an IT administrator, we hold many information in our minds like user names, passwords, IDs, phone numbers, incomes, service tags, bills and the order from our wives to buy milk when coming back to home.…
I guess it is not common knowledge to most Wintel engineers/administrators: If you have an SNMP-based monitoring system in your environment (and it's common to have SNMP or Syslog) it's reasonably easy to enable monitoring of the Windows Event logs,…
Attackers love to prey on accounts that have privileges. Reducing privileged accounts and protecting privileged accounts therefore is paramount. Users, groups, and service accounts need to be protected to help protect the entire Active Directory …
Are you ready to implement Active Directory best practices without reading 300+ pages? You're in luck. In this webinar hosted by Skyport Systems, you gain insight into Microsoft's latest comprehensive guide, with tips on the best and easiest way…

738 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question