Help - Search - Members - Calendar
Full Version: running programs as trusted doesn't work
Gladiator Security Forum > SoftSphere Technologies Support Forums > DefenseWall HIPS
micrei
Hello,

since I updated to Defensewall 2.56 I can't run untrusted programs as trusted anymore by right clicking on the program icon and choosing "run as trusted" from the menu. The program still runs as untrusted. I use Win XP Home SP 3.

Thank you.

Michael
Ilya Rabinovich
It means Windows Explorer is turning into the untrusted group. Please, find c:\windows\dwall__log_file.txt and post it here.
micrei
Here's the log file:

D:\Programme\K-Meleon\k-meleon.exe
Loading untrusted/untrusted created module D:\Programme\K-Meleon\kplugins\adblockplus.dll. Process is untrusted now.
D:\Programme\Registry Defense\sr.exe
Loading untrusted/untrusted created module D:\Programme\Registry Defense\Logger.dll. Process is untrusted now.
D:\Programme\K-Meleon\k-meleon.exe
Loading untrusted/untrusted created module D:\Programme\K-Meleon\kplugins\adblockplus.dll. Process is untrusted now.
D:\Programme\K-Meleon\k-meleon.exe
Loading untrusted/untrusted created module D:\Programme\K-Meleon\kplugins\adblockplus.dll. Process is untrusted now.
D:\Programme\K-Meleon\k-meleon.exe
Loading untrusted/untrusted created module D:\Programme\K-Meleon\kplugins\adblockplus.dll. Process is untrusted now.
D:\Programme\K-Meleon\k-meleon.exe
Loading untrusted/untrusted created module D:\Programme\K-Meleon\kplugins\adblockplus.dll. Process is untrusted now.
C:\Programme\The Bat!\thebat.exe
Loading untrusted/untrusted created module D:\downloads\tbclamwin\TBClamWin.bav. Process is untrusted now.
C:\Programme\The Bat!\thebat.exe
Loading untrusted/untrusted created module D:\downloads\tbclamwin\TBClamWin.bav. Process is untrusted now.
D:\Programme\K-Meleon\k-meleon.exe
Loading untrusted/untrusted created module D:\Programme\K-Meleon\kplugins\adblockplus.dll. Process is untrusted now.
D:\Programme\K-Meleon\k-meleon.exe
Loading untrusted/untrusted created module D:\Programme\K-Meleon\kplugins\adblockplus.dll. Process is untrusted now.
D:\Programme\K-Meleon\k-meleon.exe
Loading untrusted/untrusted created module D:\Programme\K-Meleon\kplugins\adblockplus.dll. Process is untrusted now.
D:\Programme\K-Meleon\k-meleon.exe
Loading untrusted/untrusted created module D:\Programme\K-Meleon\kplugins\adblockplus.dll. Process is untrusted now.
D:\Programme\K-Meleon\k-meleon.exe
Loading untrusted/untrusted created module D:\Programme\K-Meleon\kplugins\adblockplus.dll. Process is untrusted now.
D:\Programme\MAGIX\Video_deluxe_15_Plus\videodeluxe.exe
Loading untrusted/untrusted created module M:\MAGIX\Video_deluxe_2007_PLUS\Plugins\Wave.vfx. Process is untrusted now.
F:\SETUP.EXE
Loading untrusted/untrusted created module F:\KOMPLANG\XLGEWDEU\EWDEU132.SPL. Process is untrusted now.
F:\SETUP.EXE
Loading untrusted/untrusted created module F:\KOMPLANG\XLGEWDEU\EWDEU132.SPL. Process is untrusted now.
D:\Programme\K-Meleon\k-meleon.exe
Loading untrusted/untrusted created module D:\Programme\K-Meleon\kplugins\adblockplus.dll. Process is untrusted now.
Ilya Rabinovich
Strange, I don't see Explorer's process here. Is it possible you did add something inside the untrusted applications rules that made Windows Explorer to be untrusted? Also, it would be great if you could send me (to the support e-mail) two screenshots of the "trusted and untrusted processes details"- before and after you call Windows Explorer's context menu.
SafetyFirst
I didn't want to open a new thread because I have a similar problem.

Right-click context menu doesn't work at all. When I right-click an untrusted application's icon on desktop and click DefenseWall HIPS and then choose either "Run as trusted" or "Change status to trusted", the application status always stays untrusted. When I click "File properties" nothing happens at all (I can't see File properties).

The only way to update other programs on my PC is to completely disable DW's protection.


When I go to C:/Program Files and click on application's folder and choose "Change status to trusted" (assuming that everything that is inside the folder will automatically become trusted) I get "Folder processing is finished" but nothing actually changes. Everything is still untrusted.

I can see that explorer.exe is in Untrusted processes but I don't know how to make it trusted because it's not listed in Untrusted applications (is it possible to change a process' status from within "Trusted and untrusted process details - Running now"?).

Thank you in advance

Ilya Rabinovich
It means your Windows Explorer instance is running untrusted. Do you have c:\windows\dwall_log_file.txt file?
SafetyFirst
QUOTE (Ilya Rabinovich @ Sep 8 2009, 07:46 AM) *
It means your Windows Explorer instance is running untrusted. Do you have c:\windows\dwall_log_file.txt file?


Here it is:


C:\WINDOWS\system32\regsvr32.exe
Loading untrusted/untrusted created module C:\WINDOWS\system32\xvid.ax. Process is untrusted now.
C:\WINDOWS\system32\regsvr32.exe
Loading untrusted/untrusted created module C:\WINDOWS\system32\xvid.ax. Process is untrusted now.
C:\Program Files\Extra CD DVD Ripper\dvdripper_pro.exe
Loading untrusted/untrusted created module C:\WINDOWS\system32\xvidcore.dll. Process is untrusted now.
C:\WINDOWS\system32\vsnapvss.exe
Loading untrusted/untrusted created module C:\WINDOWS\system32\stcsnap.dll. Process is untrusted now.
C:\WINDOWS\system32\regsvr32.exe
Loading untrusted/untrusted created module C:\Program Files\StorageCraft\ShadowProtect\sbimgmnt.dll. Process is untrusted now.
C:\WINDOWS\system32\verclsid.exe
Loading untrusted/untrusted created module C:\Program Files\StorageCraft\ShadowProtect\sbimgmnt.dll. Process is untrusted now.
C:\WINDOWS\explorer.exe
Loading untrusted/untrusted created module C:\Program Files\StorageCraft\ShadowProtect\sbimgmnt.dll. Process is untrusted now.
C:\WINDOWS\explorer.exe
Loading untrusted/untrusted created module C:\Program Files\StorageCraft\ShadowProtect\sbimgmnt.dll. Process is untrusted now.
C:\WINDOWS\explorer.exe
Loading untrusted/untrusted created module C:\Program Files\StorageCraft\ShadowProtect\sbimgmnt.dll. Process is untrusted now.
C:\WINDOWS\explorer.exe
Loading untrusted/untrusted created module C:\Program Files\StorageCraft\ShadowProtect\sbimgmnt.dll. Process is untrusted now.
C:\WINDOWS\explorer.exe
Loading untrusted/untrusted created module C:\Program Files\StorageCraft\ShadowProtect\sbimgmnt.dll. Process is untrusted now.
C:\WINDOWS\explorer.exe
Loading untrusted/untrusted created module C:\Program Files\StorageCraft\ShadowProtect\sbimgmnt.dll. Process is untrusted now.
Khyl
This has happened to me few times. I don't understand why DW runs explorer.exe as untrusted, perhaps Ilya could clarify this. :-)

What you need to do, is to add explorer.exe to Defense Excludes.
SafetyFirst
QUOTE (Khyl @ Sep 8 2009, 08:53 AM) *
What you need to do, is to add explorer.exe to Defense Excludes.


Thanks

Do I have to restart for changes to be accepted?
Ilya Rabinovich
Turning trusted process to untrusted if any dll marked or made by untrusted process is just normal protection practice for DW ("plugin injection protection").

OK, lets back to concrete case.

"Loading untrusted/untrusted created module C:\Program Files\StorageCraft\ShadowProtect\sbimgmnt.dll. Process is untrusted now."

C:\Program Files\StorageCraft\ShadowProtect\sbimgmnt.dll - why it is untrusted? If the module is legitimate- turn it to trusted. Maybe, the whole C:\Program Files\StorageCraft folder is untrusted?

C:\WINDOWS\system32\xvid.ax - if this is legitimate Xvid codec, turn it to trusted.
SafetyFirst
QUOTE (Ilya Rabinovich @ Sep 8 2009, 10:08 AM) *
C:\WINDOWS\system32\xvid.ax - if this is legitimate Xvid codec, turn it to trusted.

How can I do that? It's not listed in Untrusted applications. How can I change a process' status?
andro
QUOTE (SafetyFirst @ Sep 8 2009, 09:25 PM) *
How can I do that? It's not listed in Untrusted applications. How can I change a process' status?

Right click on the file, choose DefenseWall HIPS -> Change status to trusted.
SafetyFirst
QUOTE (andro @ Sep 8 2009, 05:32 PM) *
QUOTE (SafetyFirst @ Sep 8 2009, 09:25 PM) *
How can I do that? It's not listed in Untrusted applications. How can I change a process' status?

Right click on the file, choose DefenseWall HIPS -> Change status to trusted.

That brings us back to the beginning: I can't do that for some reason.
Ilya Rabinovich
The solution is simple- just boot into 'Safe Mode' and do the task.
SafetyFirst
QUOTE (Ilya Rabinovich @ Sep 8 2009, 05:54 PM) *
The solution is simple- just boot into 'Safe Mode' and do the task.

What exactly should I do when I boot in the Safe Mode? Just change xvid.ax to trusted, change C:/WINDOWS/explorer to trusted or something else?
Ilya Rabinovich
You have to check if xvid.ax is valid and legitimate (not malicious) module. Same with C:\Program Files\StorageCraft\ShadowProtect\sbimgmnt.dll file. But you have to check it under normal mode, use the Safe one only to change file's status.
SafetyFirst
MBAM and TrojanHunter say xvid.ax is clean. Avira AntiVir reports "The event log database could not be initialized" (it's the first time I see this prompt from Avira).

While browsing through Windows folder I keep getting something like this from DefenseWall:

"Process C:Windows/explorer.exe attempts to get access to secured file C:/windows/ntkrnlpa.exe"
(if I remember well)



Ilya Rabinovich
Run them through the VirusTotal service.
SafetyFirst
QUOTE (Ilya Rabinovich @ Sep 8 2009, 06:44 PM) *
Run them through the VirusTotal service.

Result: 0/41

Now what? Safe mode and...?
Ilya Rabinovich
Yes, Safe Mode and right-click on a file->"DefenseWall HIPS"->"Change status to trusted". About C:\Program Files\StorageCraft\ShadowProtect\sbimgmnt.dll- check if any of the paths "C:\Program Files\StorageCraft" and "C:\Program Files\StorageCraft\ShadowProtect" are within Untrusted Applications list and, if any, remove from the list with using DW's GUI.
SafetyFirst
OK, but what about Explorer? Do I have to make it trusted in Safe Mode in order to enable the right-click context menu?
Ilya Rabinovich
DefenseWall's driver do not load under "Safe Mode".
SafetyFirst
I've just discovered something new. That I can't even boot into Safe Mode.
The black screen with drivers listing appears and stays like that forever...
Khyl
Go to C:\WINDOWS\ and find explorer.exe. Right-click on it -> DefenseWall HIPS -> Change Status to trusted.
Ilya Rabinovich
QUOTE (SafetyFirst @ Sep 9 2009, 10:26 PM) *
I've just discovered something new. That I can't even boot into Safe Mode.
The black screen with drivers listing appears and stays like that forever...

Here I can't assist you as it's not a DW issue. DefenseWall's driver do not loads under the Safe Mode. You have to find it out on your side. Usually, it happens due to of malware infection (past or present) or system corruption.
Chachazz
SafetyFirst, when your system is repaired and/or 'clean' of any infection, please start a new topic for any issues you may have. (this one is 2 months old). May want to visit our Malware Removal forum and let our Expert take a look..Thanks.
SafetyFirst
QUOTE (Chachazz @ Sep 10 2009, 08:42 PM) *
SafetyFirst, when your system is repaired and/or 'clean' of any infection, please start a new topic for any issues you may have. (this one is 2 months old). May want to visit our Malware Removal forum and let our Expert take a look..Thanks.

Hi, Chachazz!

I don't think my system is infected with malware (I ran many different scanners and they didn't find anything).

However, I managed to boot into Safe Mode after a long time. I suspect it's sptd.sys, a Daemon Tools' driver that was preventing me to boot into Safe Mode. I uninstalled Daemon Tools, cleaned the registry with CCleaner, but when I open regedit I can see that sptd key and its subkeys are still there and can't be deleted (Administrator group doesn't have permissions to Full control of the sptd key!?).

From the Safe Mode I couldn't make any changes to xvid.ax and sbimgmnt.dll or explorer.exe because the DefenseWall's right-click menu doesn't work in Safe Mode either.

Now I have uninstalled DefenseWall. Do you think reinstallation would solve the right-click context menu problem or not?

Or my two licenses for DW will stay unused?
Ilya Rabinovich
I believe, total reinstallation with deleting HKEY_LOCAL_MACHINE\SOFTWARE\SoftSphere Technologies\DefenseWall key may solve the issue. If it will not helps- mail me to support, I'll take a closer look at it.
SafetyFirst
QUOTE (Ilya Rabinovich @ Sep 11 2009, 10:18 AM) *
I believe, total reinstallation with deleting HKEY_LOCAL_MACHINE\SOFTWARE\SoftSphere Technologies\DefenseWall key may solve the issue. If it will not helps- mail me to support, I'll take a closer look at it.

You were right, Ilya! Indeed, the reinstallation solved all the problems. After all I've been put through, now I'm so happy that I can't stop right-clicking and changing program's status to trusted/untrusted and look at the files properties. I enjoy like a child who re-found his favourite toy he had lost. yahoo!.gif

Ilya, I want to thank you for your help and support. Keep up the good work! yourock.gif
Kretpolny
Hi,
I have some similar problem with explorer but the solution with adding it to exclude list is not working for me.
When I use Opera/Firefox and then when I download a program and then when I'm trying to change it from untrusted to trusted by clicking 'open folder' in download section, explorer opens with checked file but explorer is always untrusted and I cannot do with that file anything. I understand it is 'injection' but can I do something to run explorer as a 'trusted'?
Ilya Rabinovich
What's your Windows version?
Kretpolny
XP Pro with SP3.
Ilya Rabinovich
Find and post here c:\windows\dwall_log_file.txt file.
Kretpolny
CODE
F:\SystemUp 2009 RegistryCleaner\regcleaner.exe
Loading untrusted/untrusted created module F:\SystemUp 2009 RegistryCleaner\ZoneLinkTools.dll. Process is untrusted now.
F:\SystemUp 2009 RegistryCleaner\regcleaner.exe
Loading untrusted/untrusted created module F:\SystemUp 2009 RegistryCleaner\ZoneLinkTools.dll. Process is untrusted now.
C:\Program Files\Java\jre6\bin\javaw.exe
Loading untrusted/untrusted created module C:\Documents and Settings\Kret_polny\Dane aplikacji\Sun\Java\Deployment\cache\6.0\23\4b0da1d7-158b3460-1.1.4--n\lwjgl.dll. Process is untrusted now.
C:\Program Files\Java\jre6\bin\javaw.exe
Loading untrusted/untrusted created module C:\Documents and Settings\Kret_polny\Dane aplikacji\Sun\Java\Deployment\cache\6.0\23\4b0da1d7-158b3460-1.1.4--n\lwjgl.dll. Process is untrusted now.
C:\Program Files\Java\jre6\bin\javaw.exe
Loading untrusted/untrusted created module C:\Documents and Settings\Kret_polny\Dane aplikacji\Sun\Java\Deployment\cache\6.0\23\4b0da1d7-158b3460-1.1.4--n\lwjgl.dll. Process is untrusted now.
C:\Program Files\Java\jre6\bin\javaw.exe
Loading untrusted/untrusted created module C:\Documents and Settings\Kret_polny\Dane aplikacji\Sun\Java\Deployment\cache\6.0\23\4b0da1d7-158b3460-1.1.4--n\lwjgl.dll. Process is untrusted now.
C:\Program Files\Java\jre6\bin\javaw.exe
Loading untrusted/untrusted created module C:\Documents and Settings\Kret_polny\Dane aplikacji\Sun\Java\Deployment\cache\6.0\23\4b0da1d7-158b3460-1.1.4--n\lwjgl.dll. Process is untrusted now.
C:\Program Files\Java\jre6\bin\javaw.exe
Loading untrusted/untrusted created module C:\Documents and Settings\Kret_polny\Dane aplikacji\Sun\Java\Deployment\cache\6.0\23\4b0da1d7-158b3460-1.1.4--n\lwjgl.dll. Process is untrusted now.
C:\Program Files\Java\jre6\bin\javaw.exe
Loading untrusted/untrusted created module C:\Documents and Settings\Kret_polny\Dane aplikacji\Sun\Java\Deployment\cache\6.0\23\4b0da1d7-158b3460-1.1.4--n\lwjgl.dll. Process is untrusted now.
F:\Ashampoo Core Tuner\ct.exe
Loading untrusted/untrusted created module F:\Ashampoo Core Tuner\ash_inet.dll. Process is untrusted now.
C:\Program Files\Java\jre6\bin\javaw.exe
Loading untrusted/untrusted created module C:\Documents and Settings\Kret_polny\Dane aplikacji\Sun\Java\Deployment\cache\6.0\23\4b0da1d7-158b3460-1.1.4--n\lwjgl.dll. Process is untrusted now.
C:\Program Files\Java\jre6\bin\javaw.exe
Loading untrusted/untrusted created module C:\Documents and Settings\Kret_polny\Dane aplikacji\Sun\Java\Deployment\cache\6.0\23\4b0da1d7-158b3460-1.1.4--n\lwjgl.dll. Process is untrusted now.
C:\Program Files\Java\jre6\bin\javaw.exe
Loading untrusted/untrusted created module C:\Documents and Settings\Kret_polny\Dane aplikacji\Sun\Java\Deployment\cache\6.0\23\4b0da1d7-158b3460-1.1.4--n\lwjgl.dll. Process is untrusted now.
C:\Program Files\Java\jre6\bin\javaw.exe
Loading untrusted/untrusted created module C:\Documents and Settings\Kret_polny\Dane aplikacji\Sun\Java\Deployment\cache\6.0\23\4b0da1d7-158b3460-1.1.4--n\lwjgl.dll. Process is untrusted now.
C:\Program Files\Java\jre6\bin\javaw.exe
Loading untrusted/untrusted created module C:\Documents and Settings\Kret_polny\Dane aplikacji\Sun\Java\Deployment\cache\6.0\23\4b0da1d7-158b3460-1.1.4--n\lwjgl.dll. Process is untrusted now.
C:\Program Files\Java\jre6\bin\javaw.exe
Loading untrusted/untrusted created module C:\Documents and Settings\Kret_polny\Dane aplikacji\Sun\Java\Deployment\cache\6.0\23\4b0da1d7-158b3460-1.1.4--n\lwjgl.dll. Process is untrusted now.
C:\Program Files\Java\jre6\bin\javaw.exe
Loading untrusted/untrusted created module C:\Documents and Settings\Kret_polny\Dane aplikacji\Sun\Java\Deployment\cache\6.0\23\4b0da1d7-158b3460-1.1.4--n\lwjgl.dll. Process is untrusted now.
C:\Program Files\Java\jre6\bin\javaw.exe
Loading untrusted/untrusted created module C:\Documents and Settings\Kret_polny\Dane aplikacji\Sun\Java\Deployment\cache\6.0\23\4b0da1d7-158b3460-1.1.4--n\lwjgl.dll. Process is untrusted now.
C:\Program Files\Java\jre6\bin\javaw.exe
Loading untrusted/untrusted created module C:\Documents and Settings\Kret_polny\Dane aplikacji\Sun\Java\Deployment\cache\6.0\23\4b0da1d7-158b3460-1.1.4--n\lwjgl.dll. Process is untrusted now.
C:\Program Files\Java\jre6\bin\javaw.exe
Loading untrusted/untrusted created module C:\Documents and Settings\Kret_polny\Dane aplikacji\Sun\Java\Deployment\cache\6.0\23\4b0da1d7-158b3460-1.1.4--n\lwjgl.dll. Process is untrusted now.
C:\Program Files\Java\jre6\bin\javaw.exe
Loading untrusted/untrusted created module C:\Documents and Settings\Kret_polny\Dane aplikacji\Sun\Java\Deployment\cache\6.0\23\4b0da1d7-158b3460-1.1.4--n\lwjgl.dll. Process is untrusted now.
E:\Myst ME\Myst.exe
Loading untrusted/untrusted created module C:\WINDOWS\system32\QuickTime.qts. Process is untrusted now.
E:\Myst ME\Myst.exe
Loading untrusted/untrusted created module C:\WINDOWS\system32\QuickTime.qts. Process is untrusted now.
E:\Myst ME\Myst.exe
Loading untrusted/untrusted created module C:\WINDOWS\system32\QuickTime.qts. Process is untrusted now.
E:\Myst ME\Myst.exe
Loading untrusted/untrusted created module C:\WINDOWS\system32\QuickTime.qts. Process is untrusted now.
E:\Myst ME\Myst.exe
Loading untrusted/untrusted created module C:\WINDOWS\system32\QuickTime.qts. Process is untrusted now.
E:\Myst ME\Myst.exe
Loading untrusted/untrusted created module C:\WINDOWS\system32\QuickTime.qts. Process is untrusted now.
E:\Myst Masterpiece Edition\Myst.exe
Loading untrusted/untrusted created module C:\WINDOWS\system32\QuickTime.qts. Process is untrusted now.
C:\Program Files\Java\jre6\bin\javaw.exe
Loading untrusted/untrusted created module C:\Documents and Settings\Kret_polny\Dane aplikacji\Sun\Java\Deployment\cache\6.0\23\4b0da1d7-158b3460-1.1.4--n\lwjgl.dll. Process is untrusted now.
C:\Program Files\Java\jre6\bin\javaw.exe
Loading untrusted/untrusted created module C:\Documents and Settings\Kret_polny\Dane aplikacji\Sun\Java\Deployment\cache\6.0\23\4b0da1d7-158b3460-1.1.4--n\lwjgl.dll. Process is untrusted now.
C:\Program Files\Java\jre6\bin\javaw.exe
Loading untrusted/untrusted created module C:\Documents and Settings\Kret_polny\Dane aplikacji\Sun\Java\Deployment\cache\6.0\23\4b0da1d7-158b3460-1.1.4--n\lwjgl.dll. Process is untrusted now.
Ilya Rabinovich
Strange, I don't see Explorer's entries here. Do you use anything that may separates Explorer's process instances from each other?
Kretpolny
I'm using Aston Shell( 1.9.5) if it anything changes.
Ilya Rabinovich
It's quite simple to find out what is exactly happens, just check with "Process Details" dialog or Task Manager how many Explorer.exe processes do you have when you push "Open folder" button- one or two?
Kretpolny
One.
Ilya Rabinovich
One more question- did you anything manually to the untrusted list?
Kretpolny
Except adding 'explorer.exe' to the excluded list( as it was advised in this thread) , no.
Ilya Rabinovich
Sorry, but that's the "Excluded" list do you mean?
This is a "lo-fi" version of our main content. To view the full version with more information, formatting and images, please click here.
Invision Power Board © 2001-2009 Invision Power Services, Inc.