Wilders Security Forums  

Go Back   Wilders Security Forums > Archived Forums > Closed Sub-Forums > Archive of Ghost Security Forums > Ghost Security Suite (GSS)
User Name
Password
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

 
 
Thread Tools Search this Thread
  #1  
Old November 7th, 2005, 04:45 AM
paperinik3's Avatar
paperinik3 paperinik3 is offline
Regular Poster
 
Join Date: Aug 2003
Posts: 90
Default regdefend blocks it again

Sorry to bother you again, but regdefend is blocking again an allowed application (=PSTrayFactory). After Nick S had told me how to modify the rule everything seemed to go well for some time but now I'm getting again the messages : "regdefend blocked PSTray from modifying a protected ap-lication" and "Failed to set data for PSTrayFactory". The rule seems to me to be correctly written - why doesn't it work ? And why "Blocked - Auto User" ?I am attaching a screenshot. Thanks.
Attached Thumbnails
Click image for larger version

Name:	PSTray blocked.jpg
Views:	9
Size:	123.3 KB
ID:	169017  

  #2  
Old November 7th, 2005, 10:37 AM
Jason_R0's Avatar
Jason_R0 Jason_R0 is offline
Developer
 
Join Date: Feb 2005
Location: Australia
Posts: 1,038
Default Re: regdefend blocks it again

Quote:
Originally Posted by paperinik3
Sorry to bother you again, but regdefend is blocking again an allowed application (=PSTrayFactory). After Nick S had told me how to modify the rule everything seemed to go well for some time but now I'm getting again the messages : "regdefend blocked PSTray from modifying a protected ap-lication" and "Failed to set data for PSTrayFactory". The rule seems to me to be correctly written - why doesn't it work ? And why "Blocked - Auto User" ?I am attaching a screenshot. Thanks.

If you take a look at the bottom value it says "trayfactory" in your rule for the value it is "pstrayfactory" . So you'll need to modify your rule to account for this. One way to do this would be to remove the "ps" from your ALLOW rule.
  #3  
Old November 7th, 2005, 05:52 PM
redwolfe_98's Avatar
redwolfe_98 redwolfe_98 is offline
Frequent Poster
 
Join Date: Feb 2002
Location: South Carolina, USA
Posts: 518
Default Re: regdefend blocks it again

yep, i saw that too.. the value in the always-allow rule does not match..
  #4  
Old November 8th, 2005, 01:32 PM
paperinik3's Avatar
paperinik3 paperinik3 is offline
Regular Poster
 
Join Date: Aug 2003
Posts: 90
Default Re: regdefend blocks it again

Yes - so it is, but the curious thing is that if in writing the permissions I did put the correct value (PSTrayfactory) as I did and as you can see in my screenshot - then why in the regdefend alerts appears (without any intervention from me) a mismatched value (trayfactory)?
Anyway, I corrected the value as suggested by Jason and now, after 24 hours, it still works well...
  #5  
Old November 8th, 2005, 01:40 PM
Jason_R0's Avatar
Jason_R0 Jason_R0 is offline
Developer
 
Join Date: Feb 2005
Location: Australia
Posts: 1,038
Default Re: regdefend blocks it again

Quote:
Originally Posted by paperinik3
Yes - so it is, but the curious thing is that if in writing the permissions I did put the correct value (PSTrayfactory) as I did and as you can see in my screenshot - then why in the regdefend alerts appears (without any intervention from me) a mismatched value (trayfactory)?
Anyway, I corrected the value as suggested by Jason and now, after 24 hours, it still works well...

Hi paperinik3,

Possibly you might have confused yourself with what the "VALUE" should be from the original alert. Either that, or maybe PS Tray Factory uses two unique values in the registry? Did you manually add the rule, or was it an "Auto Remember" rule made by clicking "always remember" on an alert?

If it was done from an Alert, then it might suggest PS Tray Factory uses two unique values in the same key, and that you will need to add both values to remove all alerts.
  #6  
Old November 8th, 2005, 02:44 PM
paperinik3's Avatar
paperinik3 paperinik3 is offline
Regular Poster
 
Join Date: Aug 2003
Posts: 90
Default Re: regdefend blocks it again

Hi Jason,

yes, I did add manually the rule (with the correct value). What can have happened to create the mismatch?
 

Wilders Security Forums > Archived Forums > Closed Sub-Forums > Archive of Ghost Security Forums > Ghost Security Suite (GSS) « Previous Thread | Next Thread »

Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Settings
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump


All times are GMT -4. The time now is 08:16 PM.


Powered by vBulletin® Copyright ©2000 - 2013, Jelsoft Enterprises Ltd.
Copyright ©2002 - 2013, Wilders Security Forums