Behavior:Win32/WDBlockFirewallRule.P

or maybe was it GlassWire v1.1.15b

@Flo

If you used that old version then yes, it should have this error because it had the error before the fix.

oh god is this still not fixeded?

1 Like

We believe this error is related to using other firewall tools. We are unable to recreate the issue.

may be ask microsft how to fix? they are busy with vaccines now so maybe not reply to you?

To solve the issue:

  1. Uninstall other firewalls or “hardening” tools that are most likely causing the issue.
  2. Uninstall GlassWire
  3. Go to the Windows Firewall control panel and choose “restore default”
  4. Reboot
  5. Install our latest version with “reset firewall” and “clean install” checked.

The issue should not happen again.

i no longer use glasswire but when i had this issue i did not use any other firewalls or “hardening” tools. just fresh windows install like others said. so problem is definitely with glasswire or with windows itself

GlassWire Software Version Changes List This was fixed in February of 2021.

“Made a firewall change to solve a Windows Defender false positive related to “ask to connect” and “block all” firewall modes in GlassWire.”

but people keep reporting the same problem? maybe they are hallucinating ?

i suspect the issue may had to do with windows update, like if you install glasswire between certain security updates and not restart the pc. originally when i had the problem i installed glasswire while windows was updating, then i reinstalled windows updated fully then restarted and then installed glasswire i havent had the problem after that

Anyone can read the thread and decide for themselves. We put out the fix and nobody posted any issues from March, then someone posted in June and confirmed they used a third party tool that is known to have this issue.

If anyone else is having the issue the instructions here should solve it.

Please don’t bump the thread anymore if you aren’t having the issue, thanks!

Alright then, gotcha!

Thanks for these details @Geri123. I will share it with our team.

Im having this issue on win 10 20h2 and Glasswire 2.3.343.
No other av/fw or “hardening tools” installed.

grafik

The Windows defender alert popped up at the exact moment (note the timestamps), that Glasswire reported new activity from “Antimalware Service Executable” (which is defender)

grafik

I’m in ask to connect mode. My guess is, that defender got updated (since a windows update was running) and glasswire detected that and blocked defender for a second (even though this is a system process and can’t be blocked by the user)

so - problem still exists with the newest gw version…

Sorry for the issue @shadeless.

If you go to your Firewall screen is msmpeng.exe blocked there, or does it show it cannot be blocked by our firewall? Could you post a screenshot of that row with that executable?

What Windows version do you have, can you update it?

I’ts not blocked according to the gui. Glasswire detects the process as system process:

grafik

I’m using Windows 10 20H2

If it’s possible to update your Windows version with Windows Update it will probably solve the issue.

My system is fully up to date. (if your talking about 21h1, windows currently doesn’t offer that update for my hw config)
The issue occured during the last windows update - which also updated defender - which got blocked by gw. thus the alert from defender

21H1 is offered to all PCs now. Curious why you’re not getting it. Perhaps use the Media Creation Tool to upgrade. Select Upgrade this PC in the options.

1 Like

Yep, upgraded to 21H1 (even though glasswire should still work with older versions of windows which are still supported by microsoft)

Just got the same Windows defender message again today…

Not happy with the development of GW over the years I must say - new features get introduced all the time because they look good on changelogs and for marketing purposes, but years old issues don’t get fixed

1 Like

you’re preaching to the choir. they either dont care, cant fix it or glasswire has become a genuine threat that defender recognizes somehow. neither of these would surprise me.

1 Like