PROCESSGUARD V3

Discussion in 'ProcessGuard' started by Infinity, Sep 10, 2004.

Thread Status:
Not open for further replies.
  1. TheQuest

    TheQuest Registered Member

    Joined:
    Jun 9, 2003
    Posts:
    2,304
    Location:
    Kent. UK by the sea
    Hi, Paranoid2000

    Have you taken it out of the Security Options.

    Take Care,
    TheQuest :cool:
     
  2. Pilli

    Pilli Registered Member

    Joined:
    Feb 13, 2002
    Posts:
    6,217
    Location:
    Hampshire UK
    Do you have snapshot.exe in your protection list? And if so what privileges does it have?
     
  3. Jason_DiamondCS

    Jason_DiamondCS Former DCS Moderator

    Joined:
    Nov 11, 2002
    Posts:
    1,046
    Location:
    Perth, Western Australia
    Here are my results :-
     

    Attached Files:

  4. Paranoid2000

    Paranoid2000 Registered Member

    Joined:
    May 2, 2004
    Posts:
    2,839
    Location:
    North West, United Kingdom
    Here's my results - here is Snapshot taking a backup with the PG Alerts screen (BTW I did try removing Snapshot from the Security list - aside from bringing up the Execution Protection prompt to run it, it made no difference):
     

    Attached Files:

    Last edited: Sep 30, 2004
  5. Jason_DiamondCS

    Jason_DiamondCS Former DCS Moderator

    Joined:
    Nov 11, 2002
    Posts:
    1,046
    Location:
    Perth, Western Australia
    Show your protection and main tabs also. :)
     
  6. Paranoid2000

    Paranoid2000 Registered Member

    Joined:
    May 2, 2004
    Posts:
    2,839
    Location:
    North West, United Kingdom
    And here's my PG Protection settings - nothing for Snapshot and no drivers for Services...
     

    Attached Files:

  7. Paranoid2000

    Paranoid2000 Registered Member

    Joined:
    May 2, 2004
    Posts:
    2,839
    Location:
    North West, United Kingdom
    ...and here's my PG Main settings.
     

    Attached Files:

  8. Paranoid2000

    Paranoid2000 Registered Member

    Joined:
    May 2, 2004
    Posts:
    2,839
    Location:
    North West, United Kingdom
    BTW this is on Windows 2000 SP4 - your screenshot Jason suggests you tested on Windows XP. If so, could that make the difference?
     
  9. Jason_DiamondCS

    Jason_DiamondCS Former DCS Moderator

    Joined:
    Nov 11, 2002
    Posts:
    1,046
    Location:
    Perth, Western Australia
    Ok, we will do some testing tomorrow to ensure. In the meanwhile try the new version. :)
     
  10. Paranoid2000

    Paranoid2000 Registered Member

    Joined:
    May 2, 2004
    Posts:
    2,839
    Location:
    North West, United Kingdom
    Well, I've installed the final beta and encountered the same problem...sort of. ;)

    Basically, ProcessGuard can catch the first attempt to install SNAPSHOD - but if it is allowed, further attempts will not be blocked if permissions are revoked. This is a different situation from other programs that install drivers (e.g. PageDefrag or DbgView - remove their Install Drivers privilege and subsequent attempts are then blocked) and appears to be down to services.exe doing the driver install (revoking driver install permissions for services.exe does not seem to block subsequent installs - or maybe services.exe is smart enough to detect previously installed drivers and do nothing on subsequent attempts ;)).

    This I presume is the services.exe issue you were referring to earlier Jason. If any program can use it to install drivers, is there any chance of being able to restrict it to specific programs/drivers only? Allowing it to install anything seems to open the door to mischief while blocking it totally may cause other utilities to fail.
     
  11. Jason_DiamondCS

    Jason_DiamondCS Former DCS Moderator

    Joined:
    Nov 11, 2002
    Posts:
    1,046
    Location:
    Perth, Western Australia
    Please see a few posts back. It isn't going to be an easy finding a solution to this problem, but hopefully there will be one.
     
  12. Peter2150

    Peter2150 Global Moderator

    Joined:
    Sep 20, 2003
    Posts:
    20,590
    I also use Drive Snapshot, but given my overall experimenting with lots of backup and imaging software, and several E-Mails back and forth with Tom Ehlert the author of Drive Snapshot, I have gotten into the habit of Disabling Process Guard, Worm Guard, and my Virus Software before doing any imaging/backup stuff. Then I just leave the system alone, even though supposedly you can continue working. Just avoids conflicts and potential restore problems.
     
Thread Status:
Not open for further replies.
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.