View Full Version : PG compatibility issue with FILEMON
bluekey23
April 3rd, 2004, 04:28 AM
Hello,
I occasionally use a couple of programs from sysinternals: FILEMON and REGMON. Both of these evidently have to instlall a driver in order to run each time. When I try to open up FILEMON, I see
"Failed to create key"
After experimenting a little, I discovered that both FILEMON and REGMON would run if I uncheded block drivers and services in PG. So, in options for both of these programs I checked allow drivers and services and then went back and checked block drivers and services in the global protection menu. This took care of the problem for REGMON, but FILEMON still won't run(unless I uncheck block drivers/services in the global menu). Can anyone help solve this problem?
Thanks
Pilli
April 3rd, 2004, 06:48 AM
Hello Bluekey23,
I believe a couple of the beta testers run filemon and regmon, hopefully they can impart the settings thay use.
Anyway, after you have enabled Process Guard General Block Drivers & services and enabled Allow drivers and services for the individual files you may have to reboot for the changes to take effect.
HTH Pilli
Bowserman
April 3rd, 2004, 07:26 AM
Hi bluekey23...welcome to Wilders :).
I have these settings in Process Guard for Filemon, and it works just fine...try the settings and see if it works ;):
-{ Quote: "---016-----------------------------------------------
Long Path :- c:\ntfilmon\filemon.exe
Short Path :- c:\ntfilmon\filemon.exe
Blocked Flags :- Write,Terminate,Suspend,SetInfo
Allow Flags :- None
Option Flags :- Allow Drivers/Service Install
" }-
Regards,
Jade.
Peter2150
April 3rd, 2004, 09:19 AM
I also am running with filemon with the same settings as Bowserman. Something else that may effect it is I also had to give services.exe the option to install services and drivers. I had to do this for AOL to be able to connect, but it might be necessary for filmon also.
Try that and see if it helps.
nameless
April 3rd, 2004, 02:40 PM
Why would you have to reboot after changing Process Guard settings like that? You don't.
Bluekey23: Filemon (and some other utilities) were an issue with a prior version of Process Guard. The problem is thought to have been resolved. I'm the one who reported the issue originally (I think I am anyway), and it has been solved for me in any event.
Make sure you are running the latest versions of Process Guard and Filemon. You don't say what versions you are running, nor even what OS you have, so it's kind of hard to be more specific than that.
bluekey23
April 3rd, 2004, 05:45 PM
To All,
Thanks for your helpful advice. Peter's settings worked for me, and FILEMON(latest release) is now able to run.
nameless
April 3rd, 2004, 08:01 PM
Services.exe does need driver/service install privs under some circumstances, but if services.exe had needed it, there would have been a log entry for it. But whatever--it works.
vBulletin® Copyright ©2000-2012, Jelsoft Enterprises Ltd.
Copyright ©2002 - 2012, Wilders Security Forums