1
Something stops the windows firewall. If I restart it, it is again stopped within 2 minutes.
How can I track which software/process stops it?
Or how to configure the event manager in order to track what is stopping the firewall?
Thanks in advance
Thanks a lot:
The application is this one
C:\Windows\SysWOW64\netsh.exe
Is it that some script is launching it? I have now to track what is launching netsh, no? – Alex – 2017-01-02T11:32:33.437
And modifying user is the System
S-1-5-18
which is not the current userS-1-5-21-4001752...
– Alex – 2017-01-02T11:37:07.697Are you on a home network or in a work/domain network? If you're in a work network I would advise you to call your IT-Administrator immediately and let him know that someone or something is messing with your firewall. If you are on your home network I would advise you to give us some more information. Which antivirus you use etc. – Bungicasse – 2017-01-02T13:53:40.623
Computer is on the home network, with various Windows and Linux machines on this network. The only protection is the Windows Defender. – Alex – 2017-01-02T16:27:41.933
A scan searching for
advfirewall
only found agatherNetworkInfo.vbs
script andAuthFWSnapIn
andMIGUIControls.resources
DLLs. No other scripts or executable – Alex – 2017-01-02T16:29:51.153The faulty action seems to be something with the same effect as the command
C:\Windows\SysWOW64\netsh.exe advfirewall set allprofiles state off
.Is it possible to track it? – Alex – 2017-01-02T16:37:06.393