Wilders Security Forums  

Go Back   Wilders Security Forums > Archived Forums > Closed Sub-Forums > Archive of DiamondCS Support Forums > ProcessGuard
User Name
Password
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

 
 
Thread Tools Search this Thread
  #1  
Old December 2nd, 2003, 02:42 PM
Storm Storm is offline
Infrequent Poster
 
Join Date: Nov 2003
Posts: 46
Default Still Problems with AV-Services getting killed by apt method #5

Hi there!
(Hi Pilli, this time the correct forum )

Okay... I'm still having trouble with PG not protecting my AV-Services
(AVKService.exe and AVKWCtl.exe/GDATA Antivirenkit 2004)

I tried the things Pilli mentioned here:
After adding AVK-Stuff, I closed and restarted PG...
And I rebooted... and tried in different combinations...

But no chance... Method #5 (Debug Active Process) still kills the AV Services... PG logs the access but seems to do nothing to stop it!

Logfile:

[20:30:44] [P] - d:\dcs\apt\apt.exe [432] tried to gain WRITE,TERMINATE,SET INFO,SUSPEND access on d:\antivirenkit 2004\avkwctl.exe [676]
[20:30:54] [P] - d:\dcs\apt\apt.exe [1608] tried to gain WRITE,TERMINATE,SET INFO,SUSPEND access on d:\antivirenkit 2004\avkservice.exe [660]


Hope you have some more ideas
Storm
  #2  
Old December 2nd, 2003, 03:39 PM
Pilli's Avatar
Pilli Pilli is offline
Incredibly Massive Poster
 
Join Date: Feb 2002
Location: Hampshire UK
Posts: 6,217
Default Re:Still Problems with AV-Services getting killed by apt method #5

Storm, At one time when we were beta testing we had a similar problem but after doing the fixes you tried and leaving pg alone for quite few minutes then trying again it worked, not sure if it is a timing thing or not. Having said that I know Jason will look very carefully before replying as he does like to nail the nits
Just one more thing, I assume you do have both General Protection option enabled?
__________________
"Education is not the filling of a pail, but the lighting of a fire"
Pilli's website http://www.pilliwinks.net
  #3  
Old December 2nd, 2003, 03:58 PM
Storm Storm is offline
Infrequent Poster
 
Join Date: Nov 2003
Posts: 46
Default Re:Still Problems with AV-Services getting killed by apt method #5

Yes... both general options are enabled
(see attached Screenshot)

Storm
Attached Images
 
  #4  
Old December 2nd, 2003, 04:04 PM
Pilli's Avatar
Pilli Pilli is offline
Incredibly Massive Poster
 
Join Date: Feb 2002
Location: Hampshire UK
Posts: 6,217
Default Re:Still Problems with AV-Services getting killed by apt method #5


Anyway one of the things that Jason and DCS are very aware of is the amount of undocumented call within MS, so there still may be some calls that are misiing, also the way that different apps use thes calls.
I am sure Jason will reply tomorrow.
__________________
"Education is not the filling of a pail, but the lighting of a fire"
Pilli's website http://www.pilliwinks.net
  #5  
Old December 2nd, 2003, 04:31 PM
Storm Storm is offline
Infrequent Poster
 
Join Date: Nov 2003
Posts: 46
Default Re:Still Problems with AV-Services getting killed by apt method #5

Yeah, I'm sure the guys will figure it out!

Thanks anyway, Pilli!

Greets

Storm
  #6  
Old December 2nd, 2003, 04:38 PM
Pilli's Avatar
Pilli Pilli is offline
Incredibly Massive Poster
 
Join Date: Feb 2002
Location: Hampshire UK
Posts: 6,217
Default Re:Still Problems with AV-Services getting killed by apt method #5

OK Storm, Sorry I could do no more.
__________________
"Education is not the filling of a pail, but the lighting of a fire"
Pilli's website http://www.pilliwinks.net
  #7  
Old December 2nd, 2003, 11:01 PM
Jason_DiamondCS's Avatar
Jason_DiamondCS Jason_DiamondCS is offline
Former DCS Moderator
 
Join Date: Nov 2002
Location: Perth, Western Australia
Posts: 1,046
Default Re:Still Problems with AV-Services getting killed by apt method #5

This *may* be fixed in the next version. Ask the beta testers in a few hours.

-Jason-
__________________
Jason - DiamondCS Programmer
DiamondCS (Est. 1986) - The System Security Specialists
CryptoSuite - Protect your information today!
TDS - Powerful anti trojan software
  #8  
Old December 3rd, 2003, 07:33 AM
Pilli's Avatar
Pilli Pilli is offline
Incredibly Massive Poster
 
Join Date: Feb 2002
Location: Hampshire UK
Posts: 6,217
Default Re:Still Problems with AV-Services getting killed by apt method #5

I disabled all PG protection, closed PG & uninstalled PG prior to installing the beta

The new beta appears to be more stable & so far I have had no problems.

XP Pro, Both General options enabled but no CHM
KAV - Using APT K1 - K7 cannot be killed
SMC.exe - K1 - K7 cannot be killed

Server 2003, Both General options enabled & CHM on Outpost V2 only

NOD32kui.exe - K7 cannot be killed
NOD32krn.exe - K7 cannot be killed
Outpost.exe - K7 cannot be killed

Will continue with more testing ...
__________________
"Education is not the filling of a pail, but the lighting of a fire"
Pilli's website http://www.pilliwinks.net
 

Wilders Security Forums > Archived Forums > Closed Sub-Forums > Archive of DiamondCS Support Forums > ProcessGuard « Previous Thread | Next Thread »

Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Settings
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump


All times are GMT -4. The time now is 08:00 AM.


Powered by vBulletin® Copyright ©2000 - 2013, Jelsoft Enterprises Ltd.
Copyright ©2002 - 2013, Wilders Security Forums