I have had similar incidence when using WDAC with 3rd party AVs; it always block their AMSI dll components inspite of excluding the entire folder containing the dll.
I noticed this with Avast. Which other AVs get blocked AMSI DLL?
I have had similar incidence when using WDAC with 3rd party AVs; it always block their AMSI dll components inspite of excluding the entire folder containing the dll.
WDAC was blocking AMSI dll of K and SEP, in addition to Avast; for B, it was blocking some other component cannot recall its name.I noticed this with Avast. Which other AVs get blocked AMSI DLL?
That is a good reason for not following my advice the next timehe advised me to install Vivaldi on my hard drive
Blocking the AMSI DLL is mainly unimportant when using WHHLight because it blocks scripts and restricts PowerShell to Constrained Language. It can be important when using MS Office with allowed macros.WDAC was blocking AMSI dll of K and SEP, in addition to Avast; for B, it was blocking some other component cannot recall its name.
WDAC plays nicely only with MD.
Yes, it did not prevent Avast, K, or SEP from launching and scanning; I just noticed this block event, and tried to avoid by exluding the containing folder but with no success.Blocking the AMSI DLL is mainly unimportant when using WHHLight because it blocks scripts and restricts PowerShell to Constrained Language
Vivaldi crashed once, and closed unexpectedly a few times, but I can't blame it, much less Windows Hybrid Hardening Light. @Andy Ful developed this tool to work with MD, not with third-party AVs. I asked him if he had any tips that might help. But I'm going to restore a backup image and find out together with MD.I had Vivaldi crashed a couple of times too, in addition to few bugs; I am back to Edge.
Vivaldi crashed once, and closed unexpectedly a few times, but I can't blame it,
I know, it wasn't your fault. Just because you recommended Vivaldi and it caused problems doesn't mean you're to blame. It was my mistake.That is a good reason for not following my advice the next time![]()
I haven't changed anything in the SWH 'left menu' and ConfigureDefender I haven't touched either. But nevertheless, it CAN work and that is good news@ProblematicPions,
I downloaded the ver. 1.102.3 (as in your post):
Next, I applied MAX settings for ConfigureDefender + FirewallHardening, and almost MAX settings for WHHLight:
View attachment 290245
View attachment 290246
There were no problems with installation and running the application. Did you investigate the possible issue?
2 programs in a folder that is NOT whitelisted. 1 starts and 1 gives the contact your admin screen
...
And what I'm saying is - just let it be - the problem is cleary HERE.
Are OO AppBuster and OO SutUp10 the problems, or do you have problems with those apps when using WHHLight?
EDIT2: Getting more confused by the minute so it's time to turn my brain off in front of the TV.
2 programs in a folder that is NOT whitelisted. 1 starts and 1 gives the contact your admin screen
...
And what I'm saying is - just let it be - the problem is cleary HERE.
View attachment 290259
In H_C, EXE files are restricted by SRP, mainly configured to allow local Administrators (except when run with "-p" switch).@Andy Ful, Could you please clarify why the "Run as administrator" context menu option isn't configurable in WHHLight, like in H_C, or am I overlooking a setting?
But users can bypass WDAC restrictions using "Run as administrator," right? At least, this is what I see when I try to run WDAC-blocked EXE files using "Run as administrator."In WHHLight, EXE files are restricted by WDAC, which also blocks Administrators (no need to hide "Run as administrator").
But users can bypass WDAC restrictions using "Run as administrator," right?
At least, this is what I see when I try to run WDAC-blocked EXE files using "Run as administrator."
I have Comodo IS Offline Installer 12.3.4.8162 saved, which I tried to run; WDAC blocked it, but Run as admin allowed it.Can you share this EXE? It should be blocked by WDAC.
I have Comodo IS Offline Installer 12.3.4.8162 saved, which I tried to run; WDAC blocked it, but Run as admin allowed it.
What do you mean by "It is allowed by WDAC in WHHLight"?It is allowed by WDAC in WHHLight.
WDAC ISG can initially block some executables and then allow them after some time. However, this has nothing to do with "Run as administrator".
Similar behavior can be seen with SAC.