Wilders Security Forums  

Go Back   Wilders Security Forums > Official Returnil Support Forum > Returnil releases
User Name
Password
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

 
 
Thread Tools Search this Thread
  #1  
Old September 26th, 2010, 05:40 PM
philby's Avatar
philby philby is offline
Frequent Poster
 
Join Date: Jan 2008
Posts: 922
Default Exclude Process Explorer in VG log

Hello

I have VM set to 'Trust Programs from Real Disk Only'.

When I run PE, I get this message: 'Unable to extract x64 image. Run PE from a writeable directory'.

That's as expected.

However, if I then go to the AV log and exclude the entry for PE shown below, I still can't open it - i.e. it has not been succesfully excluded.

Name:  Capture.PNG
Views: 292
Size:  115.3 KB

How can I exclude PE correctly so it can run without my having to change the VM setting to 'Allow programs to run normally' every time?

In RVS 2008, I used to get anoption to allow/disallow and that always worked!

Thanks in advance

philby
__________________
Sandboxie + Macrium on Windows 8 Pro 64
  #2  
Old September 27th, 2010, 10:20 AM
Coldmoon's Avatar
Coldmoon Coldmoon is offline
Returnil Moderator
 
Join Date: Sep 2006
Location: North Carolina USA
Posts: 2,744
Default Re: Exclude Process Explorer in VG log

Quote:
Originally Posted by philby
Hello

I have VM set to 'Trust Programs from Real Disk Only'.

When I run PE, I get this message: 'Unable to extract x64 image. Run PE from a writeable directory'.

That's as expected.

However, if I then go to the AV log and exclude the entry for PE shown below, I still can't open it - i.e. it has not been succesfully excluded.

Attachment 222151

How can I exclude PE correctly so it can run without my having to change the VM setting to 'Allow programs to run normally' every time?

In RVS 2008, I used to get anoption to allow/disallow and that always worked!

Thanks in advance

philby

After highlighting the entry and selecting the Exclude button, is the entry added to the exclusions list (Virus Guard > Scan > AV Exclusions > Define List link)?

If not, what happens after adding the folder/files to the list manually?

Mike
__________________
Returnil: The Real Security!
Follow us on Facebook
  #3  
Old September 27th, 2010, 11:13 AM
philby's Avatar
philby philby is offline
Frequent Poster
 
Join Date: Jan 2008
Posts: 922
Default Re: Exclude Process Explorer in VG log

Highlight > Exclude fails to add anything to the exclusions list.

I can add C:\procexp.exe to the list manually and that sticks
I can't add C:\procexp64.exe manually - that doesn't stick.
I can also add C:\Users\philby\AppData\Local\Temp\procexp64.exe manually and that sticks.

I can then open PE, but I get continual and unceasing 'Untrustworthy program...' warnings about C:\Windows\System32\Drivers\Procexp141.sys - even after I close PE. Correction - they eventually stop!

I cannot add ...141.sys manually - the file is not shown even with the necessary hide boxes unchecked in Explorer.

Checking those warnings and adding them to the Exclusion list via VG > Log doesn't help either.

philby
__________________
Sandboxie + Macrium on Windows 8 Pro 64

Last edited by philby : September 27th, 2010 at 11:21 AM.
  #4  
Old September 27th, 2010, 12:59 PM
philby's Avatar
philby philby is offline
Frequent Poster
 
Join Date: Jan 2008
Posts: 922
Default Re: Exclude Process Explorer in VG log

Mike - I just rebooted (VM on / drop all) and got another 3 warnings re. C:\Windows\System32\Drivers\Procexp141.sys

Even after a reboot?

philby

PS Maybe this is connected to my open support ticket 508649, regarding Win7 64 and SSD issues.
__________________
Sandboxie + Macrium on Windows 8 Pro 64
 

Wilders Security Forums > Official Returnil Support Forum > Returnil releases « Previous Thread | Next Thread »

Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Settings
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump


All times are GMT -4. The time now is 04:10 AM.


Powered by vBulletin® Copyright ©2000 - 2013, Jelsoft Enterprises Ltd.
Copyright ©2002 - 2013, Wilders Security Forums