Prevent program installations from running

Page 2 of 3 FirstFirst 123 LastLast

  1. Posts : 16,949
    Windows 10 Home x64 Version 22H2 Build 19045.4170
       #11

    Mike,

    MikeMecanic said:
    Why Tor browser(s) bothers you that much?
    For the reason stated in the OP's very first paragraph.

    MikeMecanic said:
    Those who download it are smarter than average
    Common civility prevents me from posting the single word retort that such an outlandish claim deserves.

    All the best,
    Denis
      My Computer


  2. Posts : 55
    Windows 10
    Thread Starter
       #12

    MikeMecanic said:
    This is what you have to block for the Alpha version. The location is user choice.
    Code:
    Tor Browser\Browser\firefox.exe
    How would I block this though? With the registry example above in this thread? Would changing the filename bypass it or would changing this filename prevent it from actually working?

    - - - Updated - - -

    I just tested if the Tor Browser would still if launch if I renamed the Tor Browser\Browser\firefox.exe file and it still launched.

    Just tried another file located in Tor Browser\Browser\TorBrowser\Tor\tor.exe

    Now if I rename "tor.exe" it won't launch. Does that mean I can use that registry prevention method and it will prevent the Tor Browser from ever launching even with file renames? Referring to this one:

    Callender said:
    Try this reg file.

    Contents:
    Does the above already target "Tor Browser\Browser\TorBrowser\Tor\tor.exe" and if not how do I rewrite the registry hack mentioned above to target it?
      My Computer


  3. Posts : 6,849
    22H2 64 Bit Pro
       #13

    MikeGreo said:
    Now if I rename "tor.exe" it won't launch. Does that mean I can use that registry prevention method and it will prevent the Tor Browser from ever launching even with file renames? Referring to this one:



    Does the above already target "Tor Browser\Browser\TorBrowser\Tor\tor.exe" and if not how do I rewrite the registry hack mentioned above to target it?
    No need. Any process named tor.exe regardless of location will launch trhe script via debugger
      My Computer


  4. Posts : 188
    Win10 Pro X64 22H2 build 19045.3803
       #14

    In general, the best way to prevent such things is administrative, not technical. It could be made part of their terms of employment or of access to computers that they must not not download and install programs which are deemed inappropriate. If they violate those terms, they can be punished appropriately, perhaps by loss of employment or by loss of access.

    Have you investigated using AppLocker? Essentially, you can take a "snapshot" of allowed programs on a baseline system, and users are not allowed to run any other software. See https://docs.microsoft.com/en-us/win...ocker-overview
      My Computer


  5. Posts : 5,452
    Windows 11 Home
       #15

    MikeGreo said:
    But this is not a very realistic approach. I have to scour the internet for every website that it might be possible to download Tor Browser. Which I had done, but it's possible to always miss some, and new websites popup over time.
    When I want to download TOR I have to do it via TOR, because virtually all downloads are linked to the original webpage. I have it blocked via NextDNS blocking VPNs. But he can get installer via USB or he can send it to himself via an email, so that is not the way to do it.

    Prevent program installations from running-capture_11112021_093009.jpg

    TOR connects via other TCP ports, so you can block all TCP Out 1025-65535.
    Technically if you block all but allowed apps, that would do as well.
    You can try this trick, is is easy to bypass, but it is worth a shot.

    Code:
    reg add "HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer" /v "DisallowRun" /t REG_DWORD /d "1" /f
    reg add "HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\DisallowRun" /v "1" /t REG_SZ /d "firefox.exe" /f
    reg add "HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\DisallowRun" /v "2" /t REG_SZ /d "tor.exe" /f
      My Computer


  6. Posts : 1,079
    10 + Linux
       #16

    Dear Mike, another layer if you will at a higher level,
    To learn more about the Tor project, read the file properties signature. Such users are not dummies on four legs and for now they challenge you. Be aware that together they have the aptitudes and abilities to be troublemakers.
    Take good note also, that by blocking the USB ports, the executable file and its related target, rigidity leads to unexpected results.
    Here's what the tarball package (alpha) returns when defaulted:
    Code:
    Google Chrome cannot determine or set the default browser
    Without Tor, in some areas of the world humanity is in danger.
    Last edited by MikeMecanic; 30 Nov 2021 at 13:58.
      My Computer


  7. Posts : 6,849
    22H2 64 Bit Pro
       #17

    RE: Reg file. Note that Tor should not function (be unable to connect) even if the browser launches. In any case if the regular firefox browser is not required to be installed then you can modify the reg file to block firefox.exe. Tor uses aversion of firefox ESRi.
      My Computer


  8. Posts : 55
    Windows 10
    Thread Starter
       #18

    Just found out that the program Onion Connect(which seems to also use Tor Browser) also bypasses the protections. It also installed without UAC.

    Isn't there a way to write protect the entire HDD? Would this be problematic? Seriously considering making the whole HDD write protected.

    I don't want anything installed anyway.
      My Computer


  9. Posts : 2,800
    Windows 7 Pro
       #19

    I think you missed Selden response in post #14 Prevent program installations from running

    Try it. It will resolve your issue.
      My Computers


  10. Posts : 6,849
    22H2 64 Bit Pro
       #20

    MikeGreo said:
    Just found out that the program Onion Connect(which seems to also use Tor Browser) also bypasses the protections.
    That's not correct. It uses TOR Network and default browser (or any installed browser). I use it myself sometimes.


    Firefox:

    Prevent program installations from running-onionfruit-connect-2021.1008.png

    Edge Chromium:


    Prevent program installations from running-location-edge.png

    As already suggested try group policy + applocker. That's not something I know much about.
    Last edited by Callender; 12 Nov 2021 at 18:30.
      My Computer


 

  Related Discussions
Our Sites
Site Links
About Us
Windows 10 Forums is an independent web site and has not been authorized, sponsored, or otherwise approved by Microsoft Corporation. "Windows 10" and related materials are trademarks of Microsoft Corp.

© Designer Media Ltd
All times are GMT -5. The time now is 06:28.
Find Us




Windows 10 Forums