Unusual rules created

Discussion in 'ESET Smart Security' started by Jenee, Jan 10, 2008.

Thread Status:
Not open for further replies.
  1. Jenee

    Jenee Registered Member

    Joined:
    Dec 27, 2007
    Posts:
    185
    I have two rules that have been created that I don't understand and are different to those referred to in the thread Phantom Rules.

    The first is called Rule b0500001
    Direction Out is Allow TCP_UDP
    Remote Side is For every IP address Port 524
    Local Side is For every port and Application is Winlogin.exe

    The second rule is b0500002
    Direction Both Allow UDP
    Remote Side is Trusted Zone Port 427
    Local Side is Port 427 and application is System

    The other PCs don't have these rules. How do I delete them.
     
  2. kringles

    kringles Registered Member

    Joined:
    Aug 5, 2005
    Posts:
    52
    To delete rules select 'Advanced setup', 'Personal firewall', 'rules and zones', select 'Setup' in 'Zones and rule editor', toggle to detailed view of all rules, select the desired rule and delete. After deleting all desired rules select apply.

    Note pop ups requesting permission may appear again if this communication is requested. These requests may be valid and might not appear on the other PCs due to different software configurations. so far as I have seen all rules added are a result of an operator response to a pop up request in 'interactive mode'. The rules you mention appear to be specific and related to an application unlike the so called 'phantom' rule mentioned in the thread you referenced.

    regards
     
  3. Jenee

    Jenee Registered Member

    Joined:
    Dec 27, 2007
    Posts:
    185
    The ESS installation on all my PCs does not allow deletion of any system type rules (the delete function is not available). All rules relating to installed programs can be deleted. When I display all the rules as you describe above, all the system type rules are in an area that is coloured light gray.
     
  4. kringles

    kringles Registered Member

    Joined:
    Aug 5, 2005
    Posts:
    52
    Ok, I had thought it was a rule from an installed program since the rules in the 'Phantom Rule' thread were from responses to pop ups and did not appear in the greyed out area. The greyed out rules can not be removed in my version (or probably any version) of ESS either. A quick check does not reveal either of these rules in any of my three PCs with ESS installed. Two PCs have XP and one has Vista.

    regards
     
  5. Jacqui D

    Jacqui D Registered Member

    Joined:
    Nov 26, 2007
    Posts:
    31
    I can confirm the presence of these rules also, they can only be viewed when "All rules (including system)" is selected as the Information displayed in the rule editor found under Personal Firewall / Rules and zones. They cannot be deleted.

    Jacqui
     
Thread Status:
Not open for further replies.