CIS 5.4.xxx.1355 - D+ asks always for some files. [Issue Report]

The bug/issue

  1. What you did: I add some files/installers to 1.) Shellcode injections exclusions, 2.) Computer Security Policy > Defense+ Rules(treat as, trusted), 3.) Trusted Files of Defense+.
  2. What actually happened or you actually saw: The Defense+ asks always for these files/installers in the future. This is the problem, files/installers are in the exclusions and comes the questions of D+.
  3. What you expected to happen or see: D+ alert.
  4. How you tried to fix it & what happened: Can not be solved by the user.
  5. If its an application compatibility problem have you tried the application fixes here?: N/A
  6. Details (exact version) of any application involved with download link: N/A
  7. Whether you can make the problem happen again, and if so exact steps to make it happen: N/A
  8. Any other information (eg your guess regarding the cause, with reasons): N/A

Files appended. (Please zip unless screenshots).

  1. Screenshots illustrating the bug: Attached
  2. Screenshots of related CIS event logs and the Defense+ Active Processes List: N/A
  3. A CIS config report or file: Attached
  4. Crash or freeze dump file: N/A

Your set-up

  1. CIS version, AV database version & configuration used: 5.4.xxx.1355, 8871, Internet Security profile.
  2. a) Have you updated (without uninstall) from CIS 3 or 4: No
    b) if so, have you tried a clean reinstall (without losing settings - if not please do)?: Yes
  3. a) Have you imported a config from a previous version of CIS: No
    b) if so, have U tried a standard config (without losing settings - if not please do)?: Yes
  4. Have you made any other major changes to the default config? (eg ticked ‘block all unknown requests’, other egs here.): some modifications (config file attached)
  5. Defense+, Sandbox, Firewall & AV security levels: D+ = Safe, Sandbox = Enabled, Firewall = Safe, AV = Stateful, “Will be treated as” = Untrusted.
  6. OS version, service pack, number of bits, UAC setting, & account type: Vista SP2 32 bit, UAC disabled, Admin account.
  7. Other security and utility software installed: No
  8. Virtual machine used (Please do NOT use Virtual box): No

[attachment deleted by admin]

Thank you for your Issue report.

Moved to verified.

Thank you

Dennis

Confirmed also in 5.5.xxx.1382.

Or like this: Portable, self updating, 64bit Codecs

[attachment deleted by admin]