PG prevents 'Giant' termination

Discussion in 'ProcessGuard' started by TopperID, Nov 30, 2004.

Thread Status:
Not open for further replies.
  1. TopperID

    TopperID Registered Member

    Joined:
    Oct 1, 2004
    Posts:
    1,527
    Location:
    London
    Currently I am trialing Giant AS and for the last two days I have received alerts from PG that svchost.exe, which supports the RpcSs (Remote Procedure Call) service, has attempted to terminate gcasdtserv.exe (the Giant AntiSpyware Data Service) whose 'parent' is also svhost.exe (though with a different PID and supporting different services).

    PG has prevented these terminations, but why would svchost.exe be wanting to to terminate Giant in this way? I have found Giant to be mighty 'buggy' but has anyone else experienced this, or have any ideas about it?
     
  2. Pilli

    Pilli Registered Member

    Joined:
    Feb 13, 2002
    Posts:
    6,217
    Location:
    Hampshire UK
    Hi Topper, svchosts is a special case within ProcessGuard, you should allow svchosts "Access to Physical memory" plus the default settings.
    Both Giant gcasdtserv.exe & gcasserv.exe need to be on the Protection list with the default allows.

    EDIT: I have just been updating the latest Giant definitions and found that Giant got stuck on services (part of the Quick scan test) I had an alert from PG stating that gcasdtserv.exe needed to terminate gcasserv.exe so I shutdown Giant and gave gcasdtserv.exe the Terminate allow and now the scan is running correctly.
    So I am now not sure what is going on as it may be to do with the latest Defs :(

    HTH Pilli
     
    Last edited: Nov 30, 2004
  3. TopperID

    TopperID Registered Member

    Joined:
    Oct 1, 2004
    Posts:
    1,527
    Location:
    London
    Thanks Pilli, in fact I have these settings. Clearly something is wrong with Giant (and not for the first time!). It's just a little odd that RPC should want to do the terminating - unless it is being used by a Giant module??

    This has now turned into a Spyware thread rather than PG. Other than to say that without PG I would not have been aware of what was happening on my system! :cool:
     
  4. Peter2150

    Peter2150 Global Moderator

    Joined:
    Sep 20, 2003
    Posts:
    17,039
    I haven't had any problems with Giant including with latest "defs". I had it running when I installed the latest PG and I just let learning mode do its thing.
     
  5. Pilli

    Pilli Registered Member

    Joined:
    Feb 13, 2002
    Posts:
    6,217
    Location:
    Hampshire UK
    Thanks Peter, Can you please state your settings for giant?

    Pilli
     
Thread Status:
Not open for further replies.