PDA

View Full Version : How to make a *certain* Threatfire rule?


bellgamin
December 9th, 2009, 01:03 AM
Is there a way to define a custom rule whereby I can get Threatfire to block a specific file from loading/executing?

For example, say I want to block wuauclt.exe from executing. Is it possible to set a custom rule whereby TF will accomplish this blockage? If so, please walk me through the setting of such a rule.

Kees1958
December 9th, 2009, 04:00 AM
-{ Quote: "Is there a way to define a custom rule whereby I can get Threatfire to block a specific file from loading/executing?

For example, say I want to block wuauclt.exe from executing. Is it possible to set a custom rule whereby TF will accomplish this blockage? If so, please walk me through the setting of such a rule." }-

When any process

tries to access | execute a file (only choose execute from the pop-up menu)

named wuauclt.exe

except when (deselect all choices)

etc


Save, shut down ThreatFire, wait 30 secs, enable TF

Use explorer to double click wuauclt.exe and make the correct choices for TF to deal with

Since wuauclt.exe is a systrem process, you may want to eneable this in the except when options to prevent lock out

HAN
December 9th, 2009, 08:59 AM
Bellgamin: Related to Windows Update (but not TF...)

If you want to manually control Windows Update, you might take a look at OZO's Windows Update batch file. It also controls BITS too.
http://www.dslreports.com/forum/r21031221-OZOs-WU6bat-file-for-controlling-Microsoft-Update-BITS

jmonge
December 9th, 2009, 10:30 AM
or from msconfig and disable the service manually:)

inka
December 9th, 2009, 01:37 PM
or just move to Hawaii ;) and switch to using Linux???
(Folks, he typed -=FOR EXAMPLE=- )

bellgamin
December 9th, 2009, 03:15 PM
10Q Kees-san. I was hoping you would reply. :thumb:

@jmonge - Shazam! I hadn't realized there was a service doing this. I found it & switched it from auto start to manual.

@inka - Yeah, I said it was an example -- but I was being coy. :lurking: Sooo... INKA dinka (http://www.youtube.com/watch?v=ktMt1n3Mwmc) -- DOO! (http://www.youtube.com/watch?v=faOt3kicwy4) ;D :) ;) :D :P