applocker problem

Discussion in 'other security issues & news' started by jakosamlud, Mar 11, 2011.

Thread Status:
Not open for further replies.
  1. jakosamlud

    jakosamlud Registered Member

    Joined:
    Jun 10, 2010
    Posts:
    12
    I recently format my system and had to setup Applocker again. I created default rules, set service to automatic etc, and it was working. But when I create custom rule, it's not working ... For example, if i create rule to deny access to notepad.exe, i can still open notepad. I also tried to allow .exe files which are outside programfiles and it didn't work. Basically only ''default'' rules are working.
     
  2. katio

    katio Guest

    You need to reboot and make sure the app id service is running.
     
  3. m00nbl00d

    m00nbl00d Registered Member

    Joined:
    Jan 4, 2009
    Posts:
    6,623
    If what user katio mentioned doesn't work, then rather than creating a deny rule for what you want, try to make an exclusion rule instead. It would be how I'd do it.
     
  4. safeguy

    safeguy Registered Member

    Joined:
    Jun 14, 2010
    Posts:
    1,709
    In addition to what the above 2 has mentioned, you may want to look into "Configure Rule Enforcement" and make sure that rules are enforced for the respective rule collection.
     
  5. wat0114

    wat0114 Guest

    Remember the default rules are just to get you started so you don't cripple things, but you don't want to be combining them with your customized rules or you'll have possible conflicts.

    The logs under Event viewer can help you narrow down the problem...

    -http://technet.microsoft.com/en-us/library/ee791749%28WS.10%29.aspx

    When the unexpected happens, check them (they are time & date stamped) to see which rule influenced the events.
     
  6. jakosamlud

    jakosamlud Registered Member

    Joined:
    Jun 10, 2010
    Posts:
    12
    AppID service is set to automatic and running, rules are configured ''enforced'' ... I tried to make exclusion rule and rebooted pc afterwards, doesn't work...

    I checked eventlogs, there are bunch of ''information'' logs and most of them are saying that file was allowed to run(usually some DLL from windows folder)... and just one error, saying ''%OSDRIVE%\USERS\V\APPDATA\LOCAL\APPS\F.LUX\FLUX.EXE was prevented from running.'' And I have rule set to allow Flux.exe to run :) ...

    Anyways, thanks everyone for trying to help.
     
  7. wat0114

    wat0114 Guest

    Which account type are you running as: Administrator or Limited?
     
  8. jakosamlud

    jakosamlud Registered Member

    Joined:
    Jun 10, 2010
    Posts:
    12
    Standard user account / limited
     
Loading...
Thread Status:
Not open for further replies.