Windows Firewall Control (WFC) by BiniSoft.org

Discussion in 'other firewalls' started by alexandrud, May 20, 2013.

  1. Mr.X

    Mr.X Registered Member

    Joined:
    Aug 10, 2013
    Posts:
    4,809
    Location:
    .
    Good idea. Better have millions views in one thread. But then change the title to encompass any version/build in the future, I'd suggest.
    I like that one.
     
  2. godless

    godless Registered Member

    Joined:
    Nov 16, 2006
    Posts:
    19
    Strange issue. I used Process Explorer 16.20 for long time with WFC 4. Now, after update to WFC 5 i have this notification during Process Explorer start. (i removed source IP)

    wfc_pe.png
     
  3. AmigaBoy

    AmigaBoy Registered Member

    Joined:
    Sep 12, 2015
    Posts:
    226
    Thank you for the excellent v5 update! Probably already discussed, but here's a question. I'm reading in the manual about the suggestion to add svchost.exe and System to the Notification exceptions. What's the consensus on these two, is it best for the firewall to block or allow them?
     
  4. bjm_

    bjm_ Registered Member

    Joined:
    May 22, 2009
    Posts:
    4,458
    Location:
    .
    I have no Notification exceptions.
     
    Last edited: Oct 5, 2017
  5. bjm_

    bjm_ Registered Member

    Joined:
    May 22, 2009
    Posts:
    4,458
    Location:
    .
    Can you Allow. I had one notification w Process Explorer w WFC5.
     
  6. Circuit

    Circuit Registered Member

    Joined:
    Oct 7, 2014
    Posts:
    939
    Location:
    Land o fruits and nuts, and more crime.
    Saying not activated, not every re-boot but about every 3 days.
    Using cleaners Privary Eraser, and the CC, every time I shut down.
    So it is random. Yes I have WFC updates BLOCKED, until I see an update here.
     
  7. AmigaBoy

    AmigaBoy Registered Member

    Joined:
    Sep 12, 2015
    Posts:
    226
    Thanks, I meant about allowing them or not to connect (not notify).
     
  8. alexandrud

    alexandrud Developer

    Joined:
    Apr 14, 2011
    Posts:
    2,451
    Location:
    Romania
    I just tried with version 16.21 and I do not receive any notification. However, that IP is from Akamai Technologies.
    Is it best to allow them partially. To be able to browse the Internet, some svchost.exe and System connections must be allowed. Take a look at the WFC recommended rules for a minimum set of rules for these two processes.
    Now, you can't entirely block them because block rules have higher precedence than allow rules in Windows Firewall, and the block rules will override the allow rules. You can allow them entirely and nothing bad would happen. Some users don't like these processes to connect at their will since these connections are encrypted and can contain telemetry data. For this reason, after you have defined some minimal working rules for them, it is easier to just ignore them by adding them in the notifications exceptions list. The connections will be anyway blocked but you shouldn't care anymore unless you notice that something does not work as expected. For example, file sharing.
    - The activation status is read by the WFC service at startup from Windows Registry. Maybe your antivirus blocks WFC service from reading the activation data from Windows Registry during the boot time? Try to add an exception for wfcs.exe in your antivirus. Try to set the startup type of WFC service to Automatic (Delayed startup).
    - If you restart the tray app does the activation status change ? If you restart WFC service, does the activation status change ?
    - How do you solve this ? You just restart the application or do you have to enter again the activation code to be activated again? In the second case, maybe your cleaners remove WFC data from Windows Registry.

    Anyway, it has nothing to do with the fact that you have disabled the checking for new updates.
     
    Last edited: Oct 6, 2017
  9. alexandrud

    alexandrud Developer

    Joined:
    Apr 14, 2011
    Posts:
    2,451
    Location:
    Romania
    If you see this in Connections Log, then on your computer this process tries to make an outbound call. Please ask Mark Russinovich why his tool wants to connect to Internet.
     
  10. bjm_

    bjm_ Registered Member

    Joined:
    May 22, 2009
    Posts:
    4,458
    Location:
    .
    VirusTotal check ?
    1430.png ProcExp Connections Log.png
     
    Last edited: Oct 6, 2017
  11. Access Denied

    Access Denied Registered Member

    Joined:
    Aug 8, 2003
    Posts:
    927
    Location:
    Computer Chair
    I have a rule for svchost.exe that is set to allow, but I keep it disabled until I run something that needs it (Windows Store and Windows Update). These are the only things I have seen that fail to work properly with the rule disabled. I put svchost.exe in the do not notify box as well. I just enable the rule when I need it. This is in Windows 10.
     
  12. godless

    godless Registered Member

    Joined:
    Nov 16, 2006
    Posts:
    19
    Updated Process Explorer to 16.21, no notification.
     
  13. bjm_

    bjm_ Registered Member

    Joined:
    May 22, 2009
    Posts:
    4,458
    Location:
    .
    Q: I appear to create Rule (via Shell) while WFC is Lock.
    1436.png
    upon Unlock. I see Rule.
    1434.png
    Is normal behavior... to create Rule (via Shell) while WFC is Lock.
    Is Lock just Main Panel lock. Does Lock, also lock down rules.
     
    Last edited: Oct 8, 2017
  14. Alpengreis

    Alpengreis Registered Member

    Joined:
    Oct 7, 2013
    Posts:
    681
    Location:
    Switzerland
    The WFC german translation file is sent to Alexandru (the Developer) and should be ready for download on binisoft.org very soon. Sorry about the delay.

    Alpengreis
    Maintainer of WFC DE-Translation file
     
  15. molhopicante

    molhopicante Registered Member

    Joined:
    Aug 8, 2008
    Posts:
    135
    Thanks.
     
  16. alexandrud

    alexandrud Developer

    Joined:
    Apr 14, 2011
    Posts:
    2,451
    Location:
    Romania
    Seems like a bug. I will fix this in the next release. Thank you for reporting this.
    Myself, along WFC I don't use any other malware programs :) nor anti-malware programs. Last time I used an antivirus was a 7 years ago. This in on my Windows 7 machine. However, on my Windows 10 machine, Windows Defender runs in background.
     
  17. Big Mike

    Big Mike Registered Member

    Joined:
    Apr 18, 2015
    Posts:
    17
    Process Explorer will connect to the internet in two cases:
    - If you perform VirusTotal checks (Port 443): Hashes of the files are submitted to virus total
    - If you enable the verification of digital certificates (Port 80): Check if the certificates were revoked (CRL/OCSP)
     
  18. Big Mike

    Big Mike Registered Member

    Joined:
    Apr 18, 2015
    Posts:
    17
    I never saw such a notification window:

    [​IMG]

    Is it possible to get such a notification if an external Application adds/deletes/modifies/enables/disables rules or the whole firewall profile (allow/block in/out/both)?
     
  19. bjm_

    bjm_ Registered Member

    Joined:
    May 22, 2009
    Posts:
    4,458
    Location:
    .
    https://www.ghacks.net/2017/10/05/windows-firewall-control-5-is-out/
     
  20. bjm_

    bjm_ Registered Member

    Joined:
    May 22, 2009
    Posts:
    4,458
    Location:
    .
    Question re: U -@ rules
    Um, does this mean I should add all my U -@ to Authorize group. 1443.png
    Sorry, I'm having a head scratch regarding
    Um, is this correct
    1444.png
    and then I need to add all my U -@ to Group @ ?
    1445.png
    Um, I think all my U - & U -@ rules are Enabled No
    So, do I need to add all my U -@ rules to Group @ ?
     
    Last edited: Oct 7, 2017
  21. bjm_

    bjm_ Registered Member

    Joined:
    May 22, 2009
    Posts:
    4,458
    Location:
    .
    Okay, I did 'Reset all settings to the default values' & did 'Restore Windows Firewall default set of rules' & did 'Restore Windows Firewall Control recommended rules'.
    And now I have no rules names that start with @.
    Why no rules names (now) that start with @? with W10 Home. (see #3509)
    rules start w @.png
    I do have rules that start with U -- I have not set Secure rules.
    U - rule name.png
    Security default.png
    rules that start with U
    U - rules.png
    Why I do have rules that start with U -- I have not set Secure rules.
     
    Last edited: Oct 8, 2017
  22. bjm_

    bjm_ Registered Member

    Joined:
    May 22, 2009
    Posts:
    4,458
    Location:
    .
    I've searched Help regarding 'duplicate rules'.
    Um, are duplicate rules normal? Why? What to do regarding duplicate rules?
    duplicate rules.png
     
    Last edited: Oct 7, 2017
  23. bjm_

    bjm_ Registered Member

    Joined:
    May 22, 2009
    Posts:
    4,458
    Location:
    .
    When I search thru NoVirusThanks EXE Radar Pro
    NVT search 3.png
    default browser opens with search results as normal, as expected & EXE Block Out without notification.
    NVT Block Out.png
    any idea what's blocked?
     
    Last edited: Oct 7, 2017
  24. guest

    guest Guest

    Normally you should see a connection of the service (ERPx64Svc.exe - NoVirusThanks EXE Radar Pro) while you are launching applications which have a digital signature.
    The service of ERP is doing an OCSP request, for example one of these ip's in the list of blocked connections is a connection to ocsp.comodoca.com [178.255.83.1]
     
  25. bjm_

    bjm_ Registered Member

    Joined:
    May 22, 2009
    Posts:
    4,458
    Location:
    .
    Hmm. Okay.
    https://en.wikipedia.org/wiki/Online_Certificate_Status_Protocol.
    So, is Block okay? Should WFC offer notification?

    Edit: at this time, I cannot reproduce Block.
     
    Last edited: Oct 7, 2017
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.