Author Topic: Ask Questions Here - ReHIPS Features & Unexpected Behaviors  (Read 172990 times)

aDVll

  • Active Testers
  • Hero Member
  • *****
  • Posts: 1119
  • Windows 10 latest 64 bit
Re: Ask Questions Here - ReHIPS Features & Unexpected Behaviors
« Reply #660 on: September 11, 2017, 11:35:17 am »
It's possible to change environment variables, it's described here https://forum.rehips.com/index.php?topic=2032.msg16131#msg16131 I think locale settings are also stored in ReHIPS user registry hive and can be changed the similar way. The only problem is to find their registry location. Google says it's Control Panel\International and Control Panel\International\Geo, but I didn't check them.

I can't try it now, but I will test it when I get more time.

Are you sure this was the only change and it solved the issue? This is supposed to be a wildcard, and wildcards were tested. That'd be weird if wildcards are the issue.

I don't know why but ReHIPS detect Office 2007 normally.
btw this path for 2007 "C:\Program Files (x86)\Microsoft Office\Office12" and for 2016 (365) "C:\Program Files (x86)\Microsoft Office\root\Office16"
It should be changed to root\Office1?\EXCEL.EXE and it will work. Basically you have to add root\ in front of all path for office 365. This is what i am doing and i think fixer fixed the rules for the new release to reflect that.

fixer

  • Administrator
  • Hero Member
  • *****
  • Posts: 1395
Re: Ask Questions Here - ReHIPS Features & Unexpected Behaviors
« Reply #661 on: September 11, 2017, 02:01:38 pm »
Yup, this root Office path should already be fixed.

Ozone

  • Jr. Member
  • **
  • Posts: 80
Re: Ask Questions Here - ReHIPS Features & Unexpected Behaviors
« Reply #662 on: September 11, 2017, 07:54:48 pm »
Yup, this root Office path should already be fixed.

great, can't wait for next version :)

btw could you add in Isolated Programs tab column with information in which IE are currently running isolated programs located and option to terminate all programs in selected IE.

fixer

  • Administrator
  • Hero Member
  • *****
  • Posts: 1395
Re: Ask Questions Here - ReHIPS Features & Unexpected Behaviors
« Reply #663 on: September 12, 2017, 12:17:09 pm »
btw could you add in Isolated Programs tab column with information in which IE are currently running isolated programs located and option to terminate all programs in selected IE.
Thank you for your suggestion, we'll add this to our TODO list.

perisanboy

  • Jr. Member
  • **
  • Posts: 72
Re: Ask Questions Here - ReHIPS Features & Unexpected Behaviors
« Reply #664 on: September 14, 2017, 10:02:53 pm »
Add an option to let the user disable Rehips for what ever time he wants like 15 min, 1 hour, 4 hours OR until restart.
Also when you will design a self-protection for rehips?
You said  I will consider it :) I'm waiting for self-protection  :)
Another suggestion: can Rehips has this option to alert the user when he wants to install smth?and ask him do you want to disable Rehips til your install finish?so I don't have to disable it manually when I want to install smth safe :)
« Last Edit: September 14, 2017, 10:19:12 pm by perisanboy »

fixer

  • Administrator
  • Hero Member
  • *****
  • Posts: 1395
Re: Ask Questions Here - ReHIPS Features & Unexpected Behaviors
« Reply #665 on: September 15, 2017, 12:11:01 pm »
Changing Working Mode for some time (like Disable for 15 mins) is already in our TODO list.

We've got self-protection in our TOCONSIDER list, so this one'll take some time as we have a bunch of items in our TODO list with higher priority.

We'll try to modify our process alert and implement another button like "it's a trusted installer", so it won't ask about children of the installer process. Still thinking how to do it best, but we've got this in our TODO list.

perisanboy

  • Jr. Member
  • **
  • Posts: 72
Re: Ask Questions Here - ReHIPS Features & Unexpected Behaviors
« Reply #666 on: September 15, 2017, 01:14:16 pm »
Thnks for the answer it's good you already covered everything In your to do list :)

Tarnak

  • Jr. Member
  • **
  • Posts: 80
Re: Ask Questions Here - ReHIPS Features & Unexpected Behaviors
« Reply #667 on: September 18, 2017, 06:54:33 am »
On occasion I have  seen a CMD box flash briefly, and I managed to see it - UsoClient.exe

Anyhow, I just got an alert for this UsoClient.exe a short time ago, which I allowed as per an extract of ReHIPS log, as follows:

18/09/2017 13:38:36 PM: Program C:\Windows\System32\UsoClient.exe with PID 1208 executing program C:\Windows\System32\conhost.exe with PID 3744 - allowed with children inspection (alert)
18/09/2017 13:38:36 PM: Program C:\Windows\System32\conhost.exe with PID 3744 execution - allowed (rule)
18/09/2017 13:38:36 PM: Program C:\Windows\System32\services.exe with PID 1052 executing program C:\Windows\System32\svchost.exe with PID 12416 - allowed (rule)
18/09/2017 13:38:36 PM: Program C:\Windows\System32\UsoClient.exe with PID 1208 terminated
18/09/2017 13:38:37 PM: Program C:\Windows\System32\conhost.exe with PID 3744 terminated
18/09/2017 13:38:37 PM: Program C:\Windows\System32\services.exe with PID 1052 executing program C:\Windows\System32\svchost.exe with PID 10600 - allowed (rule)
18/09/2017 13:38:40 PM: Program C:\Windows\System32\svchost.exe with PID 1260 executing program C:\Windows\System32\dllhost.exe with PID 10888 - allowed with children inspection (rule)
18/09/2017 13:38:40 PM: Program C:\Windows\System32\dllhost.exe with PID 10888 execution - allowed (rule)
18/09/2017 13:38:45 PM: Program C:\Windows\System32\dllhost.exe with PID 10888 terminated
18/09/2017 13:38:51 PM: Program C:\Windows\System32\svchost.exe with PID 1260 executing program C:\Windows\System32\dllhost.exe with PID 1512 - allowed with children inspection (rule)
18/09/2017 13:38:51 PM: Program C:\Windows\System32\dllhost.exe with PID 1512 execution - allowed (rule)
18/09/2017 13:38:56 PM: Program C:\Windows\System32\dllhost.exe with PID 1512 terminated
18/09/2017 13:38:56 PM: Program C:\Windows\System32\svchost.exe with PID 12416 executing program C:\Windows\System32\wermgr.exe with PID 6852 - allowed with children inspection (rule)
18/09/2017 13:38:56 PM: Program C:\Windows\System32\wermgr.exe with PID 6852 execution - allowed (rule)
18/09/2017 13:38:57 PM: Program C:\Windows\System32\wermgr.exe with PID 6852 terminated
18/09/2017 13:39:37 PM: Program C:\Windows\System32\svchost.exe with PID 10600 terminated
18/09/2017 13:39:45 PM: Program C:\Windows\System32\svchost.exe with PID 1064 terminated

I hope that I did the right thing in allowing it, because there was another popup, and it looks like I have created a rule.  I don't understand why this is/was necessary, or may be I should have disallowed.   
« Last Edit: September 18, 2017, 06:56:36 am by Tarnak »

fixer

  • Administrator
  • Hero Member
  • *****
  • Posts: 1395
Re: Ask Questions Here - ReHIPS Features & Unexpected Behaviors
« Reply #668 on: September 18, 2017, 12:54:48 pm »
Don't worry, UsoClient.exe is a system process and it was added in ReHIPS 2.3.0 initial database with Allow setting.

Ozone

  • Jr. Member
  • **
  • Posts: 80
Re: Ask Questions Here - ReHIPS Features & Unexpected Behaviors
« Reply #669 on: September 22, 2017, 09:31:40 pm »
After editing rules in setting and clicking on OK, highlighted item will remain highlighted but item above will be selected.
This is can cause problem, because I can accidentally edit something else I want to.

crasher

  • ReHIPS team
  • Jr. Member
  • *****
  • Posts: 97
Re: Ask Questions Here - ReHIPS Features & Unexpected Behaviors
« Reply #670 on: September 23, 2017, 08:03:31 pm »
After editing rules in setting and clicking on OK, highlighted item will remain highlighted but item above will be selected.
This is can cause problem, because I can accidentally edit something else I want to.
Thank you for report. Will be fixed in upcoming releases.

perisanboy

  • Jr. Member
  • **
  • Posts: 72
Re: Ask Questions Here - ReHIPS Features & Unexpected Behaviors
« Reply #671 on: September 28, 2017, 09:49:40 pm »
We have a rule In smart mode :
Rehips can understand a Gui is modern or no and will auto allow thing if they have nice GUI.
let's say I run smth bad but it has a nice GUI like a modern GUI.
Will Rehips check my dig list to allow or block that file if the GUI was modern? or if the gui is beauty it will ignore the dig signed list?:-|

aDVll

  • Active Testers
  • Hero Member
  • *****
  • Posts: 1119
  • Windows 10 latest 64 bit
Re: Ask Questions Here - ReHIPS Features & Unexpected Behaviors
« Reply #672 on: September 28, 2017, 09:54:43 pm »
We have a rule In smart mode :
Rehips can understand a Gui is modern or no and will auto allow thing if they have nice GUI.
let's say I run smth bad but it has a nice GUI like a modern GUI.
Will Rehips check my dig list to allow or block that file if the GUI was modern? or if the gui is beauty it will ignore the dig signed list?:-|
What are you talking about? Rehips doesn't allow anything because it has a nice gui. No program in history of software ever allowed something because it had a nothing gui.
Rehips allows by default only programs that are in the allow list or programs that are signed by trusted vendors.

perisanboy

  • Jr. Member
  • **
  • Posts: 72
Re: Ask Questions Here - ReHIPS Features & Unexpected Behaviors
« Reply #673 on: September 28, 2017, 10:01:56 pm »
We have a rule In smart mode :
Rehips can understand a Gui is modern or no and will auto allow thing if they have nice GUI.
let's say I run smth bad but it has a nice GUI like a modern GUI.
Will Rehips check my dig list to allow or block that file if the GUI was modern? or if the gui is beauty it will ignore the dig signed list?:-|
What are you talking about? Rehips doesn't allow anything because it has a nice gui. No program in history of software ever allowed something because it had a nothing gui.
Rehips allows by default only programs that are in the allow list or programs that are signed by trusted vendors.
HAHAHA, xdddd
i just saw smth like this in rehips gui i though it will allow smth if it has nice gui:D

aDVll

  • Active Testers
  • Hero Member
  • *****
  • Posts: 1119
  • Windows 10 latest 64 bit
Re: Ask Questions Here - ReHIPS Features & Unexpected Behaviors
« Reply #674 on: September 28, 2017, 10:04:07 pm »
We have a rule In smart mode :
Rehips can understand a Gui is modern or no and will auto allow thing if they have nice GUI.
let's say I run smth bad but it has a nice GUI like a modern GUI.
Will Rehips check my dig list to allow or block that file if the GUI was modern? or if the gui is beauty it will ignore the dig signed list?:-|
What are you talking about? Rehips doesn't allow anything because it has a nice gui. No program in history of software ever allowed something because it had a nothing gui.
Rehips allows by default only programs that are in the allow list or programs that are signed by trusted vendors.
HAHAHA, xdddd
i just saw smth like this in rehips gui i though it will allow smth if it has nice gui:D
I think it means appcontainer applications but for sure it doesn't auto allow if you have a nice gui.