Wilders Security Forums  

Go Back   Wilders Security Forums > Security Products > other anti-malware software
User Name
Password
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

 
 
Thread Tools Search this Thread
  #1  
Old January 6th, 2008, 02:18 AM
omega5475 omega5475 is offline
Infrequent Poster
 
Join Date: Nov 2007
Posts: 34
Default GeSWall's Attack Prevention

Anyone using GeSWall having this problem?

Name:  001.png
Views: 267
Size:  29.3 KB

I checked the logs and found there are many applications that isolates explorer.exe.
  #2  
Old January 6th, 2008, 12:42 PM
aigle's Avatar
aigle aigle is offline
Incredibly Massive Poster
 
Join Date: Dec 2005
Location: Saudi Arabia/ Pakistan
Posts: 10,416
Default Re: GeSWall's Attack Prevention

Hmm........... 2.6 version of GW!
Explorer.exe isolation was an old bug that was fixed and I never saw it with 2.6 and 2.7 beta. Probably it was with 2.5 version but I am not sure.
Can u post ur log as txt?

Go to GW console, Applications> system > Exploere.exe. Right click it and check its properties.
It must be always trusted.

Thanks
Attached Images
 
__________________

Ubuntu 12.10
AX64 Time Machine, Comodo FW & Defence Plus, Sandboxie not compatible?

Last edited by aigle : January 6th, 2008 at 12:57 PM.
  #3  
Old January 6th, 2008, 06:09 PM
omega5475 omega5475 is offline
Infrequent Poster
 
Join Date: Nov 2007
Posts: 34
Default Re: GeSWall's Attack Prevention

Yup, explorer.exe is set to Always Trusted.

Name:  000.png
Views: 166
Size:  118.0 KB

From the logs:
Code:
Opera.exe ISOLATE on start from explorer.exe miranda32.exe ISOLATE on start from explorer.exe firefox.exe ISOLATE on start from explorer.exe utorrent.exe ISOLATE on start from explorer.exe

Basically, all the applications I use daily, have been isolating explorer.exe
  #4  
Old January 6th, 2008, 06:13 PM
lucas1985's Avatar
lucas1985 lucas1985 is offline
Global Moderator
 
Join Date: Nov 2006
Location: France, May 1968
Posts: 4,047
Default Re: GeSWall's Attack Prevention

You're misinterpreting the logs. They're saying that application xxx is isolated when it's launched by explorer.exe, not the other way around.
__________________
"Pouvoir à l'Imagination. Power to the imagination. La imaginación al poder".

"Perfect is the enemy of good enough". Voltaire.
  #5  
Old January 6th, 2008, 09:17 PM
omega5475 omega5475 is offline
Infrequent Poster
 
Join Date: Nov 2007
Posts: 34
Default Re: GeSWall's Attack Prevention

oops... shame on me

Any idea why these applications are starting from explorer.exe and being labelled as an attack? They are all set to auto isolation while explorer.exe is "Always Trusted".

If I understand correctly, the System folder has a higher priority than the rest. Any programs starting from a trusted process should inherit the same security level, right?
  #6  
Old January 6th, 2008, 09:19 PM
aigle's Avatar
aigle aigle is offline
Incredibly Massive Poster
 
Join Date: Dec 2005
Location: Saudi Arabia/ Pakistan
Posts: 10,416
Default Re: GeSWall's Attack Prevention

Lucas is right.
Quote:
Opera.exe ISOLATE on start from explorer.exe
It means Parent process( explorer.exe) has launched child process ( Opera.exe) and opera is isolated. It,s the normal behavior.
__________________

Ubuntu 12.10
AX64 Time Machine, Comodo FW & Defence Plus, Sandboxie not compatible?
 

Wilders Security Forums > Security Products > other anti-malware software « Previous Thread | Next Thread »

Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Settings
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump


All times are GMT -4. The time now is 11:26 PM.


Powered by vBulletin® Copyright ©2000 - 2013, Jelsoft Enterprises Ltd.
Copyright ©2002 - 2013, Wilders Security Forums