pg log

Discussion in 'ProcessGuard' started by the mul, Jan 29, 2004.

Thread Status:
Not open for further replies.
  1. the mul

    the mul Registered Member

    Joined:
    Jul 31, 2003
    Posts:
    1,703
    Location:
    scotland
    Can u please help, aol 8.0 shellmon.exe tried to gain access on c:/ programme files/ aol 8.0/waol.exe [terminate] i would like to know how to sort this out.
    I have waol.exe file in pg and write,setinfo,terminate,suspend, boxes ticked, but have also done the same with the allowed boxes for waol.exe, thinking this was the answer to let shellmon gain access, shellmon.exe file is not in pg and could u explain how to fix this please for future reference.


    the mul
     
  2. Dan Perez

    Dan Perez Retired Moderator

    Joined:
    May 18, 2003
    Posts:
    1,495
    Location:
    Sunny San Diego
    Hi the mul :)

    With regard to the one log entry, you do not need to give waol any allow entries (though maybe there were additional reasons that you did that?). You would resolve that one log entry by giving shellmon allow rights for TERMINATE.

    Hope this helps,

    Dan
     
  3. Pilli

    Pilli Registered Member

    Joined:
    Feb 13, 2002
    Posts:
    6,217
    Location:
    Hampshire UK
    Hi Mul
    It would seem that shellmon.exe (not listed in PG) is trying to gain access to terminate waol.exe so it would appear that shellmon should be listed if it needs to terminate waol.exe.

    Remember that listed programmes given individual allows (when highlighted in the list) ONLY gives that programme an Allow to other listed programmes.

    For instance if you have Task Manager listed but do not give it Allows it cannot Kill and listed programme. :)

    HTH Pilli
     
  4. the mul

    the mul Registered Member

    Joined:
    Jul 31, 2003
    Posts:
    1,703
    Location:
    scotland
    Thanks dan and pilli for your help, it has been very much appreciated,i have added shellmon.exe to pg list, and have given shellmon.exe allow rights to terminate.
    Can u also tell me is it worth having task manager added to pg list, and also would u give it the write to terminate.

    Thanks Again

    The Mul
     
  5. siliconman01

    siliconman01 Registered Member

    Joined:
    Mar 6, 2003
    Posts:
    780
    Location:
    West Virginia (USA)
    the mul,

    Here is what I have installed for AOL in PG 1.2. With these, I have found that AOL functions and features word without causing any PG to log any blocks.

    On all of the entries listed below, ALLOW all functions in PG (write, setinfo, terminate, suspend, getinfo, read.

    Be sure the standard BLOCKs are set (write, setinfo, terminate, suspend) on all of the entries listed below.

    c:\program files\America Online 8.0\waol.exe
    c:\program files\America Online 8.0\shellstart.exe
    c:\program files\America Online 8.0\shellmon.exe
    c:\program files\America Online 8.0\rbm.exe
    c:\program files\America Online 8.0\aoltray.exe
    c:\program files\America Online 8.0\aolphx.exe
    c:\program files\America Online 8.0\aoldiag.exe
    c:\program files\America Online 8.0\aol.exe
    c:\program files\America Online 8.0\accdef.exe
    (NOTE: For waol.exe also set OPTIONS for Allow Global Hooks)

    c:\program files\common files\aol\aoltpspd.exe

    c:\program files\common files\aol\acs\acsd.exe
    c:\program files\common files\aol\acs\acssetup.exe
    c:\program files\common files\aol\acs\acsuninstall.exe
    c:\program files\common files\aol\acs\aolacsd.exe
    c:\program files\common files\aol\acs\aoldiag.exe
    c:\program files\common files\aol\acs\aoldial.exe
    c:\program files\common files\aol\acs\ospath.exe
    c:\program files\common files\aol\acs\wanmpsvc.exe

    c:\program files\common files\aolshare\coach\en_en\player\tranplug.exe
    NOTE: On tranplug.exe also set OPTIONS for Allow Global Hooks, Allow Driver/Services Installation

    c:\program files\common files\aol\acs\atwpkt2.sys
    c:\program files\common files\aol\acs\atwpkt2.vxd
    (NOTE: On atwpkt2.sys and atwpkt2.vxd also set OPTIONS for Allow Driver/Services Installation)

    If you find that you do NOT have an executable file as listed above in your America Online 8.0 folders, do NOT worry about it. It means that I'm using America Online 9.0 Optimized which has added features over AOL 8.0.

    The above should allow AOL to function smoothly with PG 1.2.
     
  6. Pilli

    Pilli Registered Member

    Joined:
    Feb 13, 2002
    Posts:
    6,217
    Location:
    Hampshire UK
    Mul, I have TM listed but without the allow to terminate.

    I am not sure if there is any malware that uses TM to terminate other programmes so I protect it with PG but only give it allow privileges if I really have to.

    EDIT: karma from me to Sil & mul - enjoy! :)
     
  7. Dan Perez

    Dan Perez Retired Moderator

    Joined:
    May 18, 2003
    Posts:
    1,495
    Location:
    Sunny San Diego
    Yeah, I agree with Pilli :)

    It's useful (sometimes necessary) to be able to kill a process but I would rather err on the side of caution and have to take the additional manual step of giving allow TERMINATE only when I need to use it. Luckily it doesn't happen all too frequently :D

    Nice list there siliconman01 ! You get a cookie for your trouble :)

    siliconman01 Gobbling Cookies -> [​IMG]
     
  8. the mul

    the mul Registered Member

    Joined:
    Jul 31, 2003
    Posts:
    1,703
    Location:
    scotland
    Thanks for your advise, and i have read an earlier thread on which u were talking about the different configurations for aol and u finally got the set up ok for pg.
    I only had a couple of issues with aol and pg was that i had to allow global hook for waol.exe, and to give shellmon.exe allow rights for terminate, but i do not have aol 8.0 in my pg list, so no other issues have appeared, and should i add it to pg list.

    thanks the mul
     
  9. the mul

    the mul Registered Member

    Joined:
    Jul 31, 2003
    Posts:
    1,703
    Location:
    scotland
    Thanks again dan and pilli for your advise, i have added tm to my list but without any allow privileges, and will only allow to terminate as dan says when u have to.
    your advise and help has been most invaluable to me on this learning curve.

    the mul
     
Thread Status:
Not open for further replies.