I want to love GlassWire. It has worked great over the last year. In the last month or so, it has consistently lost track of publisher and version information.
After a bit, it will rediscover the publisher and version information. Then it will lose it again. Each of these events generates alerts in the system tray, making them practically useless as a threat alerting tool.
I’ve uninstalled. I’ve clean installed. I’ve found GlassWire folders in C:\Users[me]\AppData and C:\ProgramData and deleted them for really, really clean installs.
Nothing doing.
I don’t know if this started from a Windows 10 update, a GlassWire update (2.3.369) or something else.
Is it possible the apps are really losing their certificates somehow? If you check “properties” on the apps, what does it show?
Is the date/time correct for your PC?
The reason I ask is because this is not a common problem, in fact I have never seen this reported before in our forum or to our helpdesk (I monitor all our support).
I was sure it was a database corruption issue, but it appears I was wrong about that… so I am not sure what to suggest next. It’s quite unusual to see this unfortunately.
Could you make logs and recreate the issue, and email them to us?
IMPORTANT - Don’t send the logs until the issue happens again.
How do I make technical support logs with GlassWire?
-Stop the GlassWire service via the TaskManager.
-Open C:\ProgramData\GlassWire\service-full (or -lite, depends on the version the user runs). - In your case I believe it’s full.
-Open glasswire.conf as administrator.
-Set the following parameters and save the file:
LogLevel = 255
LogEnabled = true
Start the GlassWire service via the TaskManager.
Repeat the problem and wait a few minutes.
Send us the logs from C:\ProgramData/glasswire/service-full/log (or service-lite, depends on the version) Contact GlassWire - Please include a link to this thread. Please include a screenshot of your task manager also if possible.
Immediately when I started GlassWire after, I got a BSOD.
In any case, after booting up after the BSOD, I am capturing logs.
I already have the scenario where it is going from not-signed=>signed. I will wait until I get a scenario of signed=>not-signed and then ZIP and sned the logs.
I noticed there was a new build since my original post and an e-mail I received saying to look for a fix soon.
In any case, these new bits seem stable for now. It’s been 2 days and no incorrect coming/going of entries in the audit. Just the appropriate scenarios.
Anywho… if this is truly fixed for me and any of you had anything to do with it, I say to you Thank You and Well Done.
If I do get a repro, I’ll post back just so you know it is present in this build.