PDA

View Full Version : Still No ProcessGuard


LFC
March 10th, 2005, 10:23 AM
hi ive just my money off to buy this baby to run alongside my TDS-3 and antivirus do i need to download the trial and wait for my key to be sent like TDS-3 to make it full or do i get a link to download the full version

thnx

Dave

Pilli
March 10th, 2005, 10:39 AM
Hi LFC
Yes you can do that, your key should then enable the disabled features :)

LFC
March 10th, 2005, 10:57 AM
thnx pilli how long does it take to recieve my key i sent the money through paypal about 2 hrs ago uk time

Pilli
March 10th, 2005, 11:05 AM
Hi I think it is automated for ProcessGuard now so should arrive soon hopefully :)

Have fun. Pilli

LFC
March 10th, 2005, 11:14 AM
nice i cant wait cos ive just heard a m8 of mine got rooted by an auto rootkit
which was sent to him by a bad person does it actually stop these kind of rootkits aswell hope so

thnx

Dave

Pilli
March 10th, 2005, 11:29 AM
-{ Quote: "does it actually stop these kind of rootkits aswell hope so" }-Ther are at least two ways it can stop rootkits.
!. the rootkit probably uses a dropper .exe and PG's security list will ask if you want to allow it to run.
2. Most rootkits need to install a driver/service again ProcessGuard will alert asking if you really want to install.


HTH Pilli.

LFC
March 10th, 2005, 11:34 AM
brilliant brilliant now i cant wait to set it up just wish diamondcs would hurry with my key ;D ;D

Pilli
March 10th, 2005, 11:46 AM
Should be with you soon: See this thread: http://www.wilderssecurity.com/showpost.php?p=394070&postcount=

Pilli

LFC
March 10th, 2005, 11:56 AM
cool that means we in uk and other countries dont have to wait for the time diff in australia then do we

LFC
March 10th, 2005, 02:14 PM
i sent my money through paypal at dinnertime uk time and still no reply
i was hoping to have this program up and running before i went to bed but doesnt look like it now :'( :'(

LFC
March 10th, 2005, 02:24 PM
and now ive just seen this in this forum im wondering wots going on

If you purchase online you'll receive your license usually within 10 minutes after the purchase, as it's now an automated process for your convenience.

We hope you enjoy the program!
The DiamondCS Team

Pilli
March 10th, 2005, 02:43 PM
-{ Quote: "i was hoping to have this program up and running before i went to bed but doesnt look like it now" }- I am sorry to hear that:( Did you get a confirmation of payment back from PayPal? As this is usually very quick within minutes, then the rest of the process is automatic.
To be sure that you have your key info' by the morning please drop a quick email with your purchase information to support@diamondcs.com.au

I also note that ntl (my isp) is having severe problems with their email servers ATM and this could also be a problem if they are your ISP.

Again sorry for any inconvenience. Pilli

LFC
March 10th, 2005, 02:58 PM
no i am on blueyonder and yes ive just sent them an email i hope there isnt any problems i really really want this software and in fact i might even be tempted to buy the rest wormguard is interesting me aswell

hopefully i will have it sooner rather than later

LFC
March 10th, 2005, 05:52 PM
ive now waited 10hrs for my key for processguard and still not got it not bad for something thats suppose to take 10 minutes >:(

Pilli
March 10th, 2005, 06:11 PM
LFC, There normally is no problem but you did not answer my earlier question. Did you receive an payment advice from PayPal with your purchase details? This usually happens almost instantly.

DCS will be at work soon so hopefully the problem will be resolved ASAP.

Thanks. Pilli

LFC
March 10th, 2005, 06:15 PM
yes i thought i posted that i sent em an email sorry yes i sent them an email and yes i got my confirmation from paypal but still no luck as yet

LFC
March 10th, 2005, 08:16 PM
has anybody got ideas why its taking so long plzz :'(

snowbound
March 10th, 2005, 08:20 PM
-{ Quote: "has anybody got ideas why its taking so long plzz :'(" }-

Quoting Pilli,

-{ Quote: "DCS will be at work soon so hopefully the problem will be resolved ASAP." }-

As he said, when the DCS crew arrives, your problem will be corrected.

Just be patient a little longer. ;)


snowbound

Wayne - DiamondCS
March 10th, 2005, 09:58 PM
Purchases made through Paypal can not be automatically processed sorry, the automatic processing occurs with purchases made through Regsoft but you should receive your license within the next hour or so. :)
We hope you enjoy the program

hollywoodpc
March 10th, 2005, 10:25 PM
Pilli
Love the avatar ! Awesome !!! . Oh . Better get back to topic before I get booted . Um , err , I LOVE PG !!!!

Pilli
March 11th, 2005, 02:41 AM
Hi LFC, Sorry for your delay I was not aware of the situation regarding PayPal

I do hope that all is well now, please feel free to ask any further questions you may have regarding ProcessGuard

Pilli

Gavin - DiamondCS
March 11th, 2005, 03:10 AM
Hi all :)

Regarding ROOTKITS, PG blocks all rootkits

There is a type of kit known to me, as a HACK KIT. These are a dropper which in most cases install a ServU server, Iroffer, mIRC, scripts, etc etc. These do then register the tools as services, so you wont see them. In a sense PG stops these too :D

What to watch out for ? Well when executing one of these kits, it will of course give you many execution alerts. The files will be dropped into an obscure folder, often a new folder hidden many layers deep under the System32 folder. You would see many executions in this folder, often the ServU server would have a green U icon. You would also see service alerts from PG, and it would be a good idea to then deny ALL executions and make note of the folder they tried to run from. You can always contact us for support if you think you got one of these nasties !

TDS-3 detects a LOAD of these, and I've started naming new ones HackKit.<whatever> to make it clear :)

LFC
March 11th, 2005, 05:56 AM
thanx a bunch i was worried because i didnt know about paypal either so i thought there was a problem but not to worry now i got my PG up and running now so am a very happy chappy running sweet alongside my TDS-3
and yes im aware of all the rootkits distinguished with mirc as i use mirc myself to chat to my friends and im very glad to hear it stops these these so-called nasty rootkits as a m8 of mine got himself rooted not 2 days ago with a file sent to him by an idiot called an auto rootkit or something like that

anyway thnx again for the help and if i have any more probs im sure i wont hesitate to post ;D ;D

Dave

spiff5000
March 11th, 2005, 10:50 PM
I just need to understand something here... PG will provide an alert that something (ie. a rootkit) is trying to install drivers but it won't identify it as such. If you have TDS-3, will it work in conjuncture with PG to state specifically if the thing that has triggered the alert is a rootkit, trojan, etc?

Pilli
March 12th, 2005, 02:42 AM
Hi spiff5000, There are many rootkit definitions in the TDS3 database these are identified in the TDS3 primary list. So yes TDS3 will jump up and tell you about known rootkits, the problem is that rootkits can be modified easily so that no AV / AT can identify them. ProcessGuard will help in two ways, firstly the identification of the dropper executable when it tries to run and secondly identifying that the dropper wants to enable a service/driver install.
If these events occur other than when you are installing trusted programs from trusted sources then disallow the action until you have done a thorough investigation. First do a web search about the object then either post here on the forums and .zip and or send to DCS for analysiss if you are uncertain.

HTH Pilli