Wilders Security Forums  

Go Back   Wilders Security Forums > Archived Forums > Closed Sub-Forums > Archive of DiamondCS Support Forums > ProcessGuard
User Name
Password
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

 
 
Thread Tools Search this Thread
  #1  
Old December 9th, 2006, 09:49 PM
knowbodynow knowbodynow is offline
Infrequent Poster
 
Join Date: Sep 2005
Posts: 48
Default Sygate Firewall informing me that ProcessGuard has changed!

Hello,

Recently I have had one or two alerts from my Sygate Firewall that ProcessGuard has changed. Here is a sample of the latest report:

------------------------

The executable has changed since the last time you used: C:\Program Files\ProcessGuard\procguard.exe
File Version : 3.4.1.0
File Description : GUI Aspect of ProcessGuard
File Path : C:\Program Files\ProcessGuard\procguard.exe
Process ID : 0x468 (Heximal) 1128 (Decimal)

------------------------

What does this mean? Has ProcessGuard been nobbled? I've run various checks including AVG, Counterspy, Spybot S&D and Hijack This. No malware has been detected.

Hope someone can help.

Thanks,

CaH
  #2  
Old December 10th, 2006, 12:09 AM
KDNeese's Avatar
KDNeese KDNeese is offline
Frequent Poster
 
Join Date: Dec 2005
Posts: 236
Default Re: Sygate Firewall informing me that ProcessGuard has changed!

Quote:
Originally Posted by knowbodynow
Hello,

Recently I have had one or two alerts from my Sygate Firewall that ProcessGuard has changed. Here is a sample of the latest report:

------------------------

The executable has changed since the last time you used: C:\Program Files\ProcessGuard\procguard.exe
File Version : 3.4.1.0
File Description : GUI Aspect of ProcessGuard
File Path : C:\Program Files\ProcessGuard\procguard.exe
Process ID : 0x468 (Heximal) 1128 (Decimal)

------------------------

What does this mean? Has ProcessGuard been nobbled? I've run various checks including AVG, Counterspy, Spybot S&D and Hijack This. No malware has been detected.

Hope someone can help.

Thanks,

CaH

I wouldn't get too excited about it. It's basically speaking of the MD5 signature of the program. Many times when programs are updated the MD5 hash changes. Most firewalls keep track of programs' hashes, and alert you when it has changed. This happens all the time with certain security software that I use, especially after an update. I don't know if you have updated PG recently, but if you have, that's probably your answer. There are multiple reasons why security software hashes change, but if you're other security software didn't find any problems, I wouldn't worry about it. I get those kind of messages all the time from my firewall, and I know my system is clean. I've gotten pretty used to warnings. Also, you can always verify the MD5 hash at the PG website and make sure everything is in order. From your warning message there seems to be some alteration to the user interface. Did you add or remove any menus, functions, etc? If so, that would generate the warning from Sygate, most likely.
  #3  
Old December 10th, 2006, 05:51 AM
knowbodynow knowbodynow is offline
Infrequent Poster
 
Join Date: Sep 2005
Posts: 48
Default Re: Sygate Firewall informing me that ProcessGuard has changed!

Thanks for the reply. I haven't updated ProcessGuard recently, nor changed the settings. I'd be grateful if you would tell me how do I go about verifying the MD5 hash. I've never done this before and I couldn't see any information about it at the DiamondCS site.

Thanks again,

CaH
  #4  
Old December 11th, 2006, 02:07 PM
Paranoid2000's Avatar
Paranoid2000 Paranoid2000 is offline
Security Expert
 
Join Date: May 2004
Location: North West, United Kingdom
Posts: 2,839
Default Re: Sygate Firewall informing me that ProcessGuard has changed!

ProcGuard.exe should not change under normal circumstances so either Sygate is in error or some other program is "interfering" (PG itself should alert on a changed ProcGuard so I would suspect the former).

You can use an MD5 checksum utility (MD5File being a simple one) to check the file manually or run another program that verifies program checksums like System Safety Monitor (SSM does a similar job to PG but adds many other features). If neither of these confirm any change in ProcGuard then give Sygate a good seeing to for raising a false alarm.

Last edited by Paranoid2000 : December 11th, 2006 at 02:14 PM.
  #5  
Old December 11th, 2006, 05:25 PM
knowbodynow knowbodynow is offline
Infrequent Poster
 
Join Date: Sep 2005
Posts: 48
Default Re: Sygate Firewall informing me that ProcessGuard has changed!

Thanks for the reply, I've been thinking of trying out System Safety Monitor. Is it possible to run it with ProcessGuard running or would it be be best to disable or uninstall ProcessGuard?

Cheers,
CaH
  #6  
Old December 11th, 2006, 05:38 PM
Paranoid2000's Avatar
Paranoid2000 Paranoid2000 is offline
Security Expert
 
Join Date: May 2004
Location: North West, United Kingdom
Posts: 2,839
Default Re: Sygate Firewall informing me that ProcessGuard has changed!

SSM will run with PG perfectly well - SSM's installation does need to load a driver (like most other security software nowadays) so you need to uncheck PG's "Block Rootkit..." option while installing it but that should be the only issue.
  #7  
Old December 12th, 2006, 12:58 AM
redwolfe_98's Avatar
redwolfe_98 redwolfe_98 is offline
Frequent Poster
 
Join Date: Feb 2002
Location: South Carolina, USA
Posts: 518
Default Re: Sygate Firewall informing me that ProcessGuard has changed!

if you are going to run "system safety monitor", i wouldn't run PG along with it since i would expect SSM to provide the same type of protection that PG does..
  #8  
Old December 13th, 2006, 10:27 PM
Ice_Czar's Avatar
Ice_Czar Ice_Czar is offline
Frequent Poster
 
Join Date: May 2002
Location: Boulder Colorado
Posts: 696
Default Re: Sygate Firewall informing me that ProcessGuard has changed!

Quote:
Originally Posted by KDNeese
I don't know if you have updated PG recently.

exactly

while my firewall can do some rudimentary checking on aps
Ive been using FileChecker (install as a Windows Service) for years now to monitor my security aps for changes with only a slight delay to real time. Installed as a service with Processguard watching it its sort of a chicken and the egg problem Id think for the vast majority automated malware. Which then needs to go and wipe its NT event log.

the idea occurs to me to use a .bat file to generate my own security checksum benchmarks on a regular basis with fsum or Hash. Virtually eliminating the possibility that an automated tool can find all the logs.
__________________
ceterum censeo (in my opinion) Vista delenda est. (Vista must be destroyed)
It's time to switch
 

Wilders Security Forums > Archived Forums > Closed Sub-Forums > Archive of DiamondCS Support Forums > ProcessGuard « Previous Thread | Next Thread »

Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Settings
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump


All times are GMT -4. The time now is 09:40 AM.


Powered by vBulletin® Copyright ©2000 - 2013, Jelsoft Enterprises Ltd.
Copyright ©2002 - 2013, Wilders Security Forums