DeepGuard & application blocking (2024)

Peter_B Posts: 7 New Member

March 2022 edited September 2022 in F-Secure Internet Security

Hello

I run F-Secure SAFE 18.2 on Windows 10.

Yesterday I started up an app on my PC and a notification was immediately displayed saying that DeepGuard had blocked the application because it had "tried to change another application". The same notification popped up several times over the next minute or so. The app, however, continued to run perfectly (it's an app called 'Soundly', a sound effects library, which I know is perfectly harmless).

My question is - why did the app continue to run if F-Secure thought it had blocked it?

0 Like Awesome

  • Jaims Posts: 846 Former F-Secure Employee

    March 2022 Answer ✓

    Hi @Peter_B

    This is possibly because the app "Soundly" tries to re-execute the same process when it fails.

    It seems like there is a false positive on our detection.

    Kindly create a ticket using the below link with the detection name and the process that triggered the detection and let our lab team handle it.

    https://www.f-secure.com/en/web/labs_global/submit-a-sample

    2 2Like Awesome

Answers

  • Peter_B Posts: 7 New Member

    March 2022

    Thanks Jaims. Ticket created.

    On a more general point, how does F-secure prevent a piece of malware re-starting itself and causing damage?

    0 Like Awesome

  • Jaims Posts: 846 Former F-Secure Employee

    March 2022

    Hi @Peter_B

    DeepGuard makes sure that you use only safe applications. The safety of an application is verified from the trusted cloud service. If the safety of an application cannot be verified, DeepGuard starts to monitor the application behavior.

    Potentially harmful system changes that DeepGuard detects include:

    • System setting (Windows registry) changes
    • Attempts to turn off important system programs
    • Attempts to edit important system files

    2 2Like Awesome

  • Peter_B Posts: 7 New Member

    March 2022

    Hi Jaims.

    That's all great, but my question was more specifically about how F-Secure deals with applications that attempt to keep re-starting themselves.

    F-Secure SAFE has now blocked two applications on my machine (both false positives, and I've created support tickets for both) and in both cases the app continued to function perfectly, whilst F-Secure continued to display notifications every few seconds that it had blocked the app.

    It's left me wondering how effective F-Secure would actually be in dealing with a piece of malware that also keeps re-starting itself?

    0 Like Awesome

  • Ukko Posts: 3,650 Superuser

    March 2022

    Hello,

    Sorry for the discussion.

    whilst F-Secure continued to display notifications every few seconds that it had blocked the app.

    Could you check your "Quarantine" - called as "File and App Control" - and its DeepGuard part. Is something listed there?

    // If so - there is an option to exclude / allow (Allow applications that DeepGuard has blocked | SAFE | Latest | F-Secure User Guides)

    I mean, is it really Soundly blocked? Or certain type of action / operation?

    How DeepGuard toast / prompt looked like? And what is information in "Recent Events" list.

    Perhaps, if Soundly tried to run some scripts -> that action is blocked. Or if tried to access one of "Protected Folders" (Ransomware Protection) -> that operation is blocked.

    So, application itself still working and continued to function.. while certain activities were blocked / denied. And application tried to re-run them (or so).

    Just as a random thoughts.. otherwise it is a too tricky and vulnerable design of DeepGuard.

    Thanks!

    2 2Like Awesome

  • Peter_B Posts: 7 New Member

    March 2022

    Thanks Ukko.

    Notifications started popping up as soon as I launched Soundly. I wasn't actively using Soundly, but, as you say, Soundly may well have been doing something in the background.

    Notifications just said that DeepGuard had blocked an application. The Recent Events list had lots of identical entries saying that Soundly 'tried to change another application'.

    Nothing in the Quarantine list.

    I've added the Program Files folder that soundly.exe lives in, and this has stopped all notifications, so I don't have a problem using Soundly now.

    Take your point that we don't know exactly what F-Secure was blocking. In fact, it would actually be more helpful if F-Secure gave more details other than 'tried to change another application' in the recent events list. Would help understand situations like this.

    1 1Like Awesome

  • Ukko Posts: 3,650 Superuser

    March 2022

    Hello,

    Thanks for your feedback and response!

    I will try to play with Soundly a bit later.. just to check if I could reproduce this (of course, if your submission to F-Secure Labs with no results yet).

    One point about more information - could you try to open Windows "Event Viewer" (I do it, usually, by right click Windows (start) logo and then "Event Viewer" entry). This is kind of Windows journal. My experience is about F-Secure SAFE beta - but I suppose that stable with related design - and Event Viewer with custom place for other services.

    With my system - it is the last 'entry' in menu list (Applications & Services Logs or so). There could be F-Secure Ultralight SDK directory. Most of events about detections can be there. So, try to check one of them (about Soundly block event) and see if something more visible there.

    For example, if I will try to launch tricky .bat file - then toast and F-Secure Recent Events will be with the only generic wording about. Like "application blocked because tried to open malicious website or document" and exact blocked application / detection name.

    In Windows Event Viewer - I can see "content" of .bat-file, hash, path to executable (cmd.exe), process ID and other internal technical data.

    Thanks!

    2 2Like Awesome

This discussion has been closed.

DeepGuard & application blocking (2024)

FAQs

How do I allow apps in DeepGuard? ›

Allow applications that DeepGuard has blocked
  1. Open WithSecure Server Security from the Windows Start menu.
  2. On the main page, select .
  3. Select Quarantine and exclusions. ...
  4. Select the Blocked tab.
  5. Find the application that you want to allow and select Allow.
  6. Select Yes to confirm that you want to allow the application.

What is application blocking? ›

Application control gives businesses the ability to block, restrict, or allow applications from executing on network devices. App blocking is a measure that improves your application security by preventing application-based threats on individuals and organizations.

How do I turn off F-secure DeepGuard? ›

Accepted Answer
  1. Open the F-Secure app.
  2. On the main view, select the top-left menu button.
  3. Select Settings.
  4. Select Edit Settings and grant the administrator rights needed to edit the settings.
  5. Select Viruses & Threats.
  6. Select Virus Protection and turn it off.
  7. Select DeepGuard and turn it off.
Jun 7, 2024

How to solve access to websites is blocked for your protection? ›

  1. Unblock websites using a VPN.
  2. Unblock websites using Tor.
  3. Unblock websites using a web proxy.
  4. Unblock websites using a browser extension.
  5. Use a URL shortener.
  6. Try switching protocols.
  7. Use web archive.
  8. Use Google translate.
Apr 5, 2024

How do I allow restricted apps? ›

Important:
  1. On your Android device, open the Settings app.
  2. Tap Apps.
  3. Tap the app that you want to turn on a restricted setting for. Tip: If you can't find it, first tap See all apps or App info.
  4. Tap More. Allow restricted settings.
  5. Follow the on-screen instructions.

How do I allow access to my apps? ›

Change permissions based on their type
  1. On your device, open the Settings app.
  2. Tap Security & Privacy Privacy. Permission manager.
  3. Tap a permission type. If you allowed or denied permission to any apps, you'll find them here.
  4. To change an app's permission, tap the app, then choose your permission settings.

How do I unblock an application? ›

Right-click the downloaded file and select its properties. If an option to unblock is available, checkmark it. After ensuring the install file is not blocked, it is also recommended that you run it as an administrator.

How do I stop my firewall from blocking apps? ›

Access the Windows Defender Firewall. Select Allow an app or feature through Windows Firewall from the left pane. Click Change Settings. If the program in question isn't listed, select Allow another app instead.

Which app is best for blocking? ›

Freedom efficiently blocks apps and websites across a range of devices including iPhones, iPads, Mac computers, Windows computers, Android devices, and Chrome devices.

What is DeepGuard? ›

DeepGuard offers proactive, instant protection against unknown threats. DeepGuard monitors applications to detect and stop potentially harmful changes to the system in real-time. It makes sure that you use only safe applications. The safety of an application is verified from the trusted cloud service.

Where is F-Secure DeepGuard? ›

You can access the DeepGuard setting also from the product settings by selecting Device Protection > Settings. Tip: If you want F-Secure to add your application to the allowed applications list, submit your application for analysis here.

How do I stop F-Secure from popping up? ›

As such, you need to open Settings (doubleclick desktop F-Secure logo or rightclick tray-logo -> Open Settings), In Settings, switch to the Browsing Protection tab where you can find "Trusted Shopping" option. When disabled - no popups.

How do I stop websites from being blocked? ›

The best, most secure way to unblock forbidden websites is to use a VPN, a virtual private network that secures and encrypts your data.

How do I stop antivirus from blocking a website? ›

If you need regular access to a site your antivirus app considers unsafe, you can add it to the exclusions list to exempt it from scans permanently (or until you change your mind). Save your changes; Make sure there is a check mark next to Do not scan web traffic from trusted URLs.

Why have I been blocked this website is using a security? ›

Why have I been blocked? This website is using a security service to protect itself from online attacks. The action you just performed triggered the security solution. There are several actions that could trigger this block including submitting a certain word or phrase, a SQL command or malformed data.

How do I allow an app through Bitdefender? ›

How to allow an app through Bitdefender Firewall
  1. Click on the Protection button, situated on the left sidebar of the Bitdefender interface.
  2. Click the Settings button in the Firewall module.
  3. Select the Rules tab. ...
  4. To add an application rule, click the Add rule button.

How do I allow app installation permission? ›

Part 1. Give an App Permission on Android
  1. Unlock your Android phone and open the Settings tab from the menu. Then click on the 'Apps' tab to view a list of apps.
  2. Select the app. Now click on the 'App management' tab to view and select any app to make changes.
  3. Select the Permissions tab. ...
  4. Select Permission.
Dec 18, 2023

How do I allow an app through virus protection? ›

Add an exclusion to Windows Security
  1. Select Start , then open Settings . ...
  2. Under Virus & threat protection settings, select Manage settings, and then under Exclusions, select Add or remove exclusions.
  3. Select Add an exclusion, and then select from files, folders, file types, or process.

How do I allow certain apps through my firewall? ›

Select the Start menu, type Allow an app through Windows Firewall, and select it from the list of results. Select Change settings. You might be asked for an administrator password or to confirm your choice. To add an app, select the check box next to the app, or select Allow another app and enter the path for the app.

References

Top Articles
30+ Low-Calorie Vegan Recipes For Weight Loss
Italian Lemon Ricotta Cake | Light & Moist Recipe
Dainty Rascal Io
Fighter Torso Ornament Kit
Garrison Blacksmith Bench
Avonlea Havanese
Katmoie
Rainbird Wiring Diagram
Mohawkind Docagent
Delectable Birthday Dyes
Produzione mondiale di vino
Mlifeinsider Okta
ExploreLearning on LinkedIn: This month's featured product is our ExploreLearning Gizmos Pen Pack, the…
Chastity Brainwash
Race Karts For Sale Near Me
Walgreens Tanque Verde And Catalina Hwy
Aldi Bruce B Downs
Popular Chinese Restaurant in Rome Closing After 37 Years
Bible Gateway passage: Revelation 3 - New Living Translation
Spn 520211
Optum Urgent Care - Nutley Photos
8005607994
Play Tetris Mind Bender
How do you get noble pursuit?
Lcsc Skyward
Used 2 Seater Go Karts
Armor Crushing Weapon Crossword Clue
Adecco Check Stubs
Seymour Johnson AFB | MilitaryINSTALLATIONS
Texas Baseball Officially Releases 2023 Schedule
Orangetheory Northville Michigan
Muma Eric Rice San Mateo
The Mad Merchant Wow
Walgreens Agrees to Pay $106.8M to Resolve Allegations It Billed the Government for Prescriptions Never Dispensed
Compare Plans and Pricing - MEGA
Kerry Cassidy Portal
968 woorden beginnen met kruis
R/Moissanite
Uvalde Topic
Bartow Qpublic
Lonely Wife Dating Club בקורות וחוות דעת משתמשים 2021
Jetblue 1919
Seven Rotten Tomatoes
Guy Ritchie's The Covenant Showtimes Near Grand Theatres - Bismarck
Dragon Ball Super Super Hero 123Movies
Lucyave Boutique Reviews
Craigslist Rooms For Rent In San Fernando Valley
Ups Authorized Shipping Provider Price Photos
Ehc Workspace Login
Big Brother 23: Wiki, Vote, Cast, Release Date, Contestants, Winner, Elimination
Automatic Vehicle Accident Detection and Messageing System – IJERT
The Hardest Quests in Old School RuneScape (Ranked) – FandomSpot
Latest Posts
Article information

Author: Tyson Zemlak

Last Updated:

Views: 6409

Rating: 4.2 / 5 (63 voted)

Reviews: 94% of readers found this page helpful

Author information

Name: Tyson Zemlak

Birthday: 1992-03-17

Address: Apt. 662 96191 Quigley Dam, Kubview, MA 42013

Phone: +441678032891

Job: Community-Services Orchestrator

Hobby: Coffee roasting, Calligraphy, Metalworking, Fashion, Vehicle restoration, Shopping, Photography

Introduction: My name is Tyson Zemlak, I am a excited, light, sparkling, super, open, fair, magnificent person who loves writing and wants to share my knowledge and understanding with you.