Wilders Security Forums  

Go Back   Wilders Security Forums > Archived Forums > Closed Sub-Forums > Archive of DiamondCS Support Forums > ProcessGuard
User Name
Password
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

 
 
Thread Tools Search this Thread
  #1  
Old June 9th, 2005, 11:04 PM
Wayne - DiamondCS's Avatar
Wayne - DiamondCS Wayne - DiamondCS is offline
Security Expert
 
Join Date: Jul 2002
Location: Perth, Oz
Posts: 1,533
Default Notice for PG users who use the Block Rootkit\Driver Install feature

For ProcessGuard users who take advantage of the "Block Rootkit\Driver\Service Installation" feature, it is recommended that you disallow system32\services.exe from being able to install drivers, as some programs are (legitimately) using services.exe to install drivers on behalf of the calling program.

Thanks to gottadoit for his testing and assistance with this.
__________________
DiamondCS (Est. 1986) - Celebrating 20 Years ...
Home of Port Explorer, ProcessGuard, and check out all our other freeware security tools!
  #2  
Old June 10th, 2005, 02:24 AM
linney linney is offline
Regular Poster
 
Join Date: Feb 2002
Posts: 174
Default Re: Notice for PG users who use the Block Rootkit\Driver Install feature

Are you saying the "driver install" Allow for Services.exe should be turned On only in a case by case scenario when legitimate software request it?

Can you clarify how and when we should allow Services.exe to install a driver and when we shouldn't, or are you saying we shouldn't, full stop?
  #3  
Old June 10th, 2005, 03:27 AM
Wayne - DiamondCS's Avatar
Wayne - DiamondCS Wayne - DiamondCS is offline
Security Expert
 
Join Date: Jul 2002
Location: Perth, Oz
Posts: 1,533
Default Re: Notice for PG users who use the Block Rootkit\Driver Install feature

It's best to leave it off by default so that services.exe drivers are initially blocked. If you do get any drivers installing via services.exe for programs that you want to use then you can easily re-enable it, run the program and then re-disable it. Most programs install drivers themselves as opposed to going via services.exe so they won't be affected by settings changes to services.exe.
__________________
DiamondCS (Est. 1986) - Celebrating 20 Years ...
Home of Port Explorer, ProcessGuard, and check out all our other freeware security tools!
  #4  
Old June 10th, 2005, 03:57 AM
Paranoid2000's Avatar
Paranoid2000 Paranoid2000 is offline
Security Expert
 
Join Date: May 2004
Location: North West, United Kingdom
Posts: 2,839
Default Re: Notice for PG users who use the Block Rootkit\Driver Install feature

Wayne,

This was an issue with PG3 beta Services.exe installing a driver (PG3 final) that was supposed to have been fixed (with both services.exe and the calling program needing Install Drivers privilege) - are you saying that this is not 100% reliable?
  #5  
Old June 10th, 2005, 04:16 AM
Wayne - DiamondCS's Avatar
Wayne - DiamondCS Wayne - DiamondCS is offline
Security Expert
 
Join Date: Jul 2002
Location: Perth, Oz
Posts: 1,533
Default Re: Notice for PG users who use the Block Rootkit\Driver Install feature

That's correct, we had developed a unique method to determine which program was using services.exe but at this stage it seems it isn't always possible to determine this, unfortunately. No other program has ever been able to do it, if that gives you an idea of how tricky this is. At this stage it's not possible for us to say if we'll be able to extend it to determine the original caller of all services.exe-invoked driver installations - it just might not be possible (not everything is), so for now it's recommended you simply turn off Allow Driver Installation for services.exe if you use the Block Rootkit\Driver Installation feature. This is only related to one feature of ProcessGuard, and has no affect on any of the other features.
__________________
DiamondCS (Est. 1986) - Celebrating 20 Years ...
Home of Port Explorer, ProcessGuard, and check out all our other freeware security tools!
  #6  
Old June 30th, 2005, 08:02 AM
nice to see you :)
 
Posts: n/a
Default Re: Notice for PG users who use the Block Rootkit\Driver Install feature

do you mean is uncheak instal driver box in service.exe
  #7  
Old June 30th, 2005, 09:12 AM
richrf richrf is offline
Very Frequent Poster
 
Join Date: Dec 2003
Posts: 1,907
Default Re: Notice for PG users who use the Block Rootkit\Driver Install feature

Hi Wayne,

For informational purposes, when I remove install services privileges from services. exe, I cannot turn off system restore from the machine. It needs to be re-enabled and then disabled.

Rich
  #8  
Old August 31st, 2005, 05:02 PM
Nevoeci Nevoeci is offline
Infrequent Poster
 
Join Date: Aug 2005
Posts: 4
Default Re: Notice for PG users who use the Block Rootkit\Driver Install feature

Hey guys, I a newbie, after purchasing processguard ther was a note stating

if you use rootkit blocking to disallow system32\services.exe from being able to install drivers,

how is this done and wahte effect will it have and the rest of the OS

Thanks,nevoeci
  #9  
Old September 7th, 2005, 12:28 AM
redwolfe_98's Avatar
redwolfe_98 redwolfe_98 is offline
Frequent Poster
 
Join Date: Feb 2002
Location: South Carolina, USA
Posts: 518
Default Re: Notice for PG users who use the Block Rootkit\Driver Install feature

nevoeci, just go to "protection", select "services.exe", then, down at the botton, uncheck the box for "install driver/services"..

i wish that we could allow "services.exe" to only install selected drivers.. my isp program (AOL 9.0 optimized) uses "services.exe" to install a driver every time i log on to the internet..
  #10  
Old September 7th, 2005, 01:41 AM
gottadoit's Avatar
gottadoit gottadoit is offline
Security Expert
 
Join Date: Jul 2004
Location: Australia
Posts: 589
Default Re: Notice for PG users who use the Block Rootkit\Driver Install feature

Quote:
Originally Posted by redwolfe_98
nevoeci, just go to "protection", select "services.exe", then, down at the botton, uncheck the box for "install driver/services"..

i wish that we could allow "services.exe" to only install selected drivers.. my isp program (AOL 9.0 optimized) uses "services.exe" to install a driver every time i log on to the internet..
redwolfe_98,
I had hoped that DCS might have provided a solution to this issue by now, the workaround is fine as a short term fix but a real solution would be appreciated, lets hope that a fix or even an extension of this functionality is included in one of the next round of updates.

There are obvious limitations in not showing what the originating program *might* be in the alert because it raises the requirement for the end user to know what is happening.

There is also the small issue that "Learning" mode could quite easily give services.exe that privilege back again and turning it off could easily be overlooked

Regdefend is also useful for blocking drivers and services and you can specify the "driver name" that each program is allowed to install. It is also more usable by giving an allow/deny prompt so you are not fiddling around in the PG GUI configuration all the time

This is a step further along in being able to specify what programs are allowed to load drivers as you have requested, but it doesn't ensure that the correct driver file is specified in the imagepath for the driver/service or that the correct file is on disk, but seeing as I have both PG and GSS/RD I have opted to use the more user friendly of the two to block drivers

Regards
  #11  
Old September 26th, 2005, 07:57 AM
Incognito
 
Posts: n/a
Default Re: Notice for PG users who use the Block Rootkit\Driver Install feature

Keeps re-enabling itself on my PC, usually after running installers. Are you sure this actually accomplishes anything?
  #12  
Old September 26th, 2005, 07:59 AM
Paranoid2000's Avatar
Paranoid2000 Paranoid2000 is offline
Security Expert
 
Join Date: May 2004
Location: North West, United Kingdom
Posts: 2,839
Default Re: Notice for PG users who use the Block Rootkit\Driver Install feature

Quote:
Originally Posted by Incognito
Keeps re-enabling itself on my PC, usually after running installers. Are you sure this actually accomplishes anything?
This is a symptom of running PG in Learning Mode - check that you have it disabled (it should only be used when setting up PG).
  #13  
Old September 26th, 2005, 09:16 AM
Incognito
 
Posts: n/a
Default Re: Notice for PG users who use the Block Rootkit\Driver Install feature

I haven't used learning mode since I installed PG. After I've allowed a few game installers to install drivers/services (they fail otherwise) they modify services.exe.

I'll use Battlefield 2 as my example since it has it's own [well publicized] problems with PG.

I guess it's just another reason to disable PG when running installers.
  #14  
Old October 29th, 2005, 09:40 AM
The Seeker's Avatar
The Seeker The Seeker is offline
Frequent Poster
 
Join Date: Oct 2005
Location: Buxton, UK
Posts: 859
Default Re: Notice for PG users who use the Block Rootkit\Driver Install feature

After following Wayne's advice my ProcessGuard is no longer able to initialise after a reboot, therefore I cannot re-enable the change I made.

Has this happened to anyone else and if so, how did you remedy it?

Thanks in advance.

Edit - Never mind, I just rebooted again and it seems to be working fine.

While I'm here though, has anyone else's PG not been able to initialise on start up? I found it a bit worrying as it was providing no protection.

Last edited by The Seeker : October 29th, 2005 at 09:50 AM.
  #15  
Old November 3rd, 2005, 12:43 AM
gottadoit's Avatar
gottadoit gottadoit is offline
Security Expert
 
Join Date: Jul 2004
Location: Australia
Posts: 589
Default Re: Notice for PG users who use the Block Rootkit\Driver Install feature

That happens to me from time to time, something that I have to check after a reboot, I agree that it can be a little annoying at times but hopefully that will be fixed by the time of the next release

Edit: The thing that usually alerts me to the fact that it isn't running when I forget is when a rundll32 execution takes place (opening control panel or plugging in a USB HDD) because I have rundll32 set to prompt and I just put up with the popup fatigue that it creates and read the command line arguments each time
  #16  
Old December 3rd, 2005, 11:04 PM
Jan J's Avatar
Jan J Jan J is offline
Infrequent Poster
 
Join Date: Dec 2005
Location: Skokie, Illinois
Posts: 22
Default Re: Notice for PG users who use the Block Rootkit\Driver Install feature

My first post here....

It took me a while to determine what was preventing new hardware driver to load, until I remembered this thread, and re-checked that "install driver" box on services.exe....

I had just re-loaded computer, and was new to Processguard, too (After reading this thread a couple days ago) it was the first time I re-attached my DV Transverter to the Firewire port since the re-load, and it didn't load the driver -- or work.

Checked the box, logged out, back in, and re-connected the Transverter, loaded driver, verified that Transverter worked, and then un-checked the "install driver" box for services.exe.

That's the proper way to add hardware, correct?
  #17  
Old February 24th, 2006, 09:36 PM
iNsuRRecTioN's Avatar
iNsuRRecTioN iNsuRRecTioN is offline
Frequent Poster
 
Join Date: Sep 2003
Location: Germany
Posts: 303
Question Re: Notice for PG users who use the Block Rootkit\Driver Install feature

Hey,

@Jan J, nooo that's the wrong way..

srry, just joking, its correct

But back to the topic, are there any news to this?

Is the problem now solved with PG 3.3 ?!

Hopefully there is now a way way to permit specified drivers to install and deny all others..

best regards,

iNsuRRecTiON
__________________
..One of the best Ad-Blocker, filters popups and other "normal" ads, fast, tiny and works with every web browser:AdMuncher!
(Now almost for free if you "pay" with TrialPay..!)
Emails to me at Insurrection_MailNOSPAMPLEASE ([at-sign]) gmx dot NET
  #18  
Old March 22nd, 2006, 06:11 PM
zoril's Avatar
zoril zoril is offline
Frequent Poster
 
Join Date: May 2005
Posts: 243
Default Re: Notice for PG users who use the Block Rootkit\Driver Install feature

Re the above posts regarding services.exe - drivers/services apart, what are the other recommended settings for this key?

Do you suggest leaving the other boxes enabled or disabled? - I mean under "other option" - install Global Hooks/Access Physical Memory/ Secure Message handling and under "Authorize to" - terminate/modify/read...

What do most of you have your settings configured to for Services.exe?

Howard
  #19  
Old March 22nd, 2006, 06:48 PM
redwolfe_98's Avatar
redwolfe_98 redwolfe_98 is offline
Frequent Poster
 
Join Date: Feb 2002
Location: South Carolina, USA
Posts: 518
Default Re: Notice for PG users who use the Block Rootkit\Driver Install feature

for "services.exe", under "other options", the default setting is to have "install driver/services" checked with none of the other options there checked..

however, it is advised to not have "install drivers/services" checked (for "services.exe").. the problem is that many times, "services.exe" wants to legitimately install dirivers/services.. so, in that case, you can leave it checked, or you will have to switch the setting back and forth..

most people would probably leave it checked, but i recently started trying to switch the setting, back and forth.. so, i have to switch it on before starting a certain program, and then switch if off after i have started the program..

i only have one program that requires that services.exe be allowed to isntall a driver/service, AOL..
  #20  
Old March 22nd, 2006, 07:00 PM
zoril's Avatar
zoril zoril is offline
Frequent Poster
 
Join Date: May 2005
Posts: 243
Default Re: Notice for PG users who use the Block Rootkit\Driver Install feature

Thanks for that information)

Re "Authorize to" - terminate/modify/read for services.exe is the default normally enabled or disabled for any, or all of them?

.....Howard
  #21  
Old March 22nd, 2006, 07:16 PM
redwolfe_98's Avatar
redwolfe_98 redwolfe_98 is offline
Frequent Poster
 
Join Date: Feb 2002
Location: South Carolina, USA
Posts: 518
Default Re: Notice for PG users who use the Block Rootkit\Driver Install feature

"protect this application from"

reading, unchecked, the others checked

"authorize this applicaton to"

terminate protected applications, UNCHECKED, the others, checked..
  #22  
Old March 22nd, 2006, 08:13 PM
zoril's Avatar
zoril zoril is offline
Frequent Poster
 
Join Date: May 2005
Posts: 243
Default Re: Notice for PG users who use the Block Rootkit\Driver Install feature

Thanks again for that))

I wonder if having "protection enabled" unticked, would completely disable PG - like at times when I need to install new software/system restore/ or download/install drivers etc, or would the settings ticked/unticked earlier still remain in place and cause a problem, if they were incorrectly configured?

Howard
  #23  
Old March 22nd, 2006, 08:57 PM
redwolfe_98's Avatar
redwolfe_98 redwolfe_98 is offline
Frequent Poster
 
Join Date: Feb 2002
Location: South Carolina, USA
Posts: 518
Default Re: Notice for PG users who use the Block Rootkit\Driver Install feature

if you uncheck "protection enabled" on PG's "main" panel, then PG's protection is completely disabled.. it won't matter what the settings are in PG's "protection"..

incidentally, you should disable PG's protection and close all of PG's running processes before uninstalling PG, if you ever want to uninstall it..

if you think that you have goofed up PG's "protection" settings, you can "reset to default", on PG's "protection" panel, and start over..

i usually disable all of the protection on my computer when installing things like windows updates, drivers, or other programs, but i will still scan my downloads with my av before installing something.. i guess that it is up to the individual whether or not they want to temporarily disable PG's protection for whatever reason, and others might know better than i do..
  #24  
Old March 22nd, 2006, 09:17 PM
zoril's Avatar
zoril zoril is offline
Frequent Poster
 
Join Date: May 2005
Posts: 243
Default Re: Notice for PG users who use the Block Rootkit\Driver Install feature

I will remember that if I ever need to uninstall or install programs/drivers
  #25  
Old June 17th, 2006, 02:19 AM
biteater's Avatar
biteater biteater is offline
Infrequent Poster
 
Join Date: Jun 2006
Location: near Amsterdam, The Netherlands
Posts: 3
Default Re: Notice for PG users who use the Block Rootkit\Driver Install feature

Checking on and off "install driver/services" for "services.exe" is not very handy. "services.exe" NEEDS this privelege for starting McAfee Virusscan 8i right; otherwise the driver for bufferoverflow-protection & the networkprotection is not loaded. Do you have any suggestion please?
Thanks, Fred


Quote:
Originally Posted by redwolfe_98
for "services.exe", under "other options", the default setting is to have "install driver/services" checked with none of the other options there checked..

however, it is advised to not have "install drivers/services" checked (for "services.exe").. the problem is that many times, "services.exe" wants to legitimately install dirivers/services.. so, in that case, you can leave it checked, or you will have to switch the setting back and forth..

most people would probably leave it checked, but i recently started trying to switch the setting, back and forth.. so, i have to switch it on before starting a certain program, and then switch if off after i have started the program..

i only have one program that requires that services.exe be allowed to isntall a driver/service, AOL..
 

Wilders Security Forums > Archived Forums > Closed Sub-Forums > Archive of DiamondCS Support Forums > ProcessGuard « Previous Thread | Next Thread »

Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Settings
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump


All times are GMT -4. The time now is 02:59 AM.


Powered by vBulletin® Copyright ©2000 - 2013, Jelsoft Enterprises Ltd.
Copyright ©2002 - 2013, Wilders Security Forums