Once again I ran into an annoyance. The problem is R-Admin. While it certainly has potentially hostile implications it is not inherently malware, I should be allowed to whitelist it at the time of detection. I shouldn't have to pause the protection and go manually construct a rule.
If you don't want to simply make it work that why, how about a switch to always allow construction of a rule for those of us who actually know what we are doing?
