View Full Version : How to make a *certain* Threatfire rule?
bellgamin
December 9th, 2009, 01:03 AM
Is there a way to define a custom rule whereby I can get Threatfire to block a specific file from loading/executing?
For example, say I want to block wuauclt.exe from executing. Is it possible to set a custom rule whereby TF will accomplish this blockage? If so, please walk me through the setting of such a rule.
Kees1958
December 9th, 2009, 04:00 AM
-{ Quote: "Is there a way to define a custom rule whereby I can get Threatfire to block a specific file from loading/executing?
For example, say I want to block wuauclt.exe from executing. Is it possible to set a custom rule whereby TF will accomplish this blockage? If so, please walk me through the setting of such a rule." }-
When any process
tries to access | execute a file (only choose execute from the pop-up menu)
named wuauclt.exe
except when (deselect all choices)
etc
Save, shut down ThreatFire, wait 30 secs, enable TF
Use explorer to double click wuauclt.exe and make the correct choices for TF to deal with
Since wuauclt.exe is a systrem process, you may want to eneable this in the except when options to prevent lock out
HAN
December 9th, 2009, 08:59 AM
Bellgamin: Related to Windows Update (but not TF...)
If you want to manually control Windows Update, you might take a look at OZO's Windows Update batch file. It also controls BITS too.
http://www.dslreports.com/forum/r21031221-OZOs-WU6bat-file-for-controlling-Microsoft-Update-BITS
jmonge
December 9th, 2009, 10:30 AM
or from msconfig and disable the service manually:)
inka
December 9th, 2009, 01:37 PM
or just move to Hawaii ;) and switch to using Linux???
(Folks, he typed -=FOR EXAMPLE=- )
bellgamin
December 9th, 2009, 03:15 PM
10Q Kees-san. I was hoping you would reply. :thumb:
@jmonge - Shazam! I hadn't realized there was a service doing this. I found it & switched it from auto start to manual.
@inka - Yeah, I said it was an example -- but I was being coy. :lurking: Sooo... INKA dinka (http://www.youtube.com/watch?v=ktMt1n3Mwmc) -- DOO! (http://www.youtube.com/watch?v=faOt3kicwy4) ;D :) ;) :D :P
vBulletin® Copyright ©2000-2012, Jelsoft Enterprises Ltd.
Copyright ©2002 - 2012, Wilders Security Forums