Behavior:Win32/WDBlockFirewallRule.P

Im having this issue on win 10 20h2 and Glasswire 2.3.343.
No other av/fw or “hardening tools” installed.

grafik

The Windows defender alert popped up at the exact moment (note the timestamps), that Glasswire reported new activity from “Antimalware Service Executable” (which is defender)

grafik

I’m in ask to connect mode. My guess is, that defender got updated (since a windows update was running) and glasswire detected that and blocked defender for a second (even though this is a system process and can’t be blocked by the user)

so - problem still exists with the newest gw version…

Sorry for the issue @shadeless.

If you go to your Firewall screen is msmpeng.exe blocked there, or does it show it cannot be blocked by our firewall? Could you post a screenshot of that row with that executable?

What Windows version do you have, can you update it?

I’ts not blocked according to the gui. Glasswire detects the process as system process:

grafik

I’m using Windows 10 20H2

If it’s possible to update your Windows version with Windows Update it will probably solve the issue.

My system is fully up to date. (if your talking about 21h1, windows currently doesn’t offer that update for my hw config)
The issue occured during the last windows update - which also updated defender - which got blocked by gw. thus the alert from defender

21H1 is offered to all PCs now. Curious why you’re not getting it. Perhaps use the Media Creation Tool to upgrade. Select Upgrade this PC in the options.

1 Like

Yep, upgraded to 21H1 (even though glasswire should still work with older versions of windows which are still supported by microsoft)

Just got the same Windows defender message again today…

Not happy with the development of GW over the years I must say - new features get introduced all the time because they look good on changelogs and for marketing purposes, but years old issues don’t get fixed

1 Like

you’re preaching to the choir. they either dont care, cant fix it or glasswire has become a genuine threat that defender recognizes somehow. neither of these would surprise me.

1 Like

The solution has been posted above in this thread:

To solve the issue:

-Uninstall other firewalls or ‘hardening’ tools that are most likely causing the issue.
-Uninstall GlassWire
-Go to the Windows Firewall control panel and choose “restore default”
-Reboot
-Install our latest version with “reset firewall” and “clean install” also checked (clean install will remove your history and settings, but it may also help with this issue).

The issue should not happen again. This issue is due to other tools being installed with GlassWire, or it’s possible you used an older version of GlassWire that had this issue.

You can read here GlassWire Software Version Changes List how this was solved with our February 24th update, so yes we do care. However, currently with our up to date software we cannot recreate this and we aren’t receiving any reports about this issue to our helpdesk.

When this issue happens we get bombarded by emails to our helpdesk, and posts in our forum, along with uninstall reports. We then quickly make changes to solve the issue and release an update.

ah well i guess some people in this thread that are reporting the issue are making up stuff. better ban them because issue does not exist

1 Like

Sorry for any confusion. I have re-read the thread, and I saw one person above said they used an old GlassWire version.

If others are actively having this issue in October of 2021, please feel free to post here so I can assist you.

For anyone having the issue, please first try the fix suggestion above: Behavior:Win32/WDBlockFirewallRule.P - #102 by Ken_GlassWire

You are having this issue right now @leo?

No i no longer use glasswire. I come here because i am still subscribed to the thread so whenever someone replies i get notified and check what its going on. But good luck with fixing the issu!

1 Like

Just got this on a fresh install of 2.3.359. Followed the instructions above in #102. System is running Advanced Threat Protection and have Ask to Connect turned on after reinstalling. The Windows toast for this popped up right after the event “Antimalware Service Executable initiated its first network connection” most likely from approving it to connect to the ATP service?

Maybe your issue been caused by “other firewalls or ‘hardening’ tools” ? You must uninstall those.

Sorry for the issue. Can you give me the link to download/install that? Is it separate from Windows, or built in?

Hi Ken. I had periodically getting the notification from Windows Defender “found Behavior:Win32/WDBlockFirewallRule.P” and had been ignoring it. When I went looking for a solution today, I came across this thread. I followed the instructions to uninstall GlassWire, reset Windows Firewall to defaults, reboot, install fresh (newest) GlassWire and choose the options to do clean install and reset firewall on installation.

After installation completed, I went into GlassWire and set it to “Ask to Connect” Of course a flurry of messages started popping up asking to connect. And then all of a sudden the dreaded Windows Defender message.

I am on Windows 10 21H1. GlassWire 2.3.359

I don’t believe I am running anything else that would be classified as a firewall product.

@CTaylor

Thanks for these details. If you go to the GlassWire firewall tab, do you have any parts of Defender blocked? If so could you send a screenshot of the file details (location and version)? It will help us find and fix the issue.

And of course if you have no parts of Defender blocked please let me know that also.

Nothing blocked. Here is what that screen looks like now.

@CTaylor

Thanks. We will keep trying to reproduce this and solve it. I apologize for the issue.

No problemo!

I know I can just ignore this “error” that Windows Defender throws.

If there is anything I can do to help, just let me know. You have my email if you prefer to take it off forum.

Chris