Services.exe trying to terminate vsmon.exe

Discussion in 'ProcessGuard' started by whoman, Nov 15, 2006.

Thread Status:
Not open for further replies.
  1. whoman

    whoman Registered Member

    Joined:
    Nov 15, 2006
    Posts:
    13
    Hello,
    I have been getting the following warning once or twice a day at random times for several weeks now.

    ---Process Guard Log Started---
    Wed 01 - 11:45:11 [TERMINATE] c:\windows\system32\services.exe [452] was blocked from terminating c:\windows\system32\zonelabs\vsmon.exe [1344]

    ---Process Guard Log Started---
    Thu 02 - 15:10:29 [TERMINATE] c:\windows\system32\services.exe [456] was blocked from terminating c:\windows\system32\zonelabs\vsmon.exe [1340]

    If legit, why would services be trying to shut down my firewall? Thanks for any help.
     
  2. ccsito

    ccsito Registered Member

    Joined:
    Jul 27, 2006
    Posts:
    1,579
    Location:
    Nation's Capital
  3. whoman

    whoman Registered Member

    Joined:
    Nov 15, 2006
    Posts:
    13
    Update - I turned my system inside out, looking for maleware and "found" none. Suspecting some type of update conflict, I loaded a pre-error backup image and the 20+windows updates - nothing. I then updated my AV and Zone Alarm -Bang- the fault started. Uninstall ZA and reinstall with PG disabled, problem solved. It seems ZA has a new auto update feature.

    Should ZA be left to its own defense(it is somewhat
    "hardened") or can I configure PG to somehow allow it to properly update unattended ?
    Thanks for any help
     
  4. TopperID

    TopperID Registered Member

    Joined:
    Oct 1, 2004
    Posts:
    1,527
    Location:
    London
    Yes, ZA does have a new auto-update feature; but on my system (I'm using ZAP) this is done through updclient.exe, not vsmon.exe.

    On my system I have not experienced these problems, I have services.exe set in the Protection tab to be authorised to 'terminate' so it would not be blocked by PG from doing so.

    Have you tried putting PG into learning mode while you run manual updates with ZA? In ZAP you can update via the spyware section and also in 'Overview'/'Preferences'/'Check for update'; these are two different types of update but they should both run updclient.exe. It's probably best to do them both. This will set-up PG to correctly handle ZA updates. But I really don't know why services.exe would try to terminate vsmon.exe since this is not involved; however services.exe should be given termination rights as I say.

    If you are running ZAP/ZASS you would also need to allow patch.exe to have permission to 'always' run; this only kicks in with a spyware update when one is available and downloaded.
     
  5. twl845

    twl845 Registered Member

    Joined:
    Apr 12, 2005
    Posts:
    4,186
    Location:
    USA
    It's not clear to me if you are now using ZA, or if you're a former user and have uninstalled ZA but vsmon wasn't deleted during the uninstall.
     
  6. Bubba

    Bubba Updates Team

    Joined:
    Apr 15, 2002
    Posts:
    11,271
    If you are speaking of member whoman....they re-installed ZA "with PG disabled" and everything was fine.

    Bubba
     
  7. twl845

    twl845 Registered Member

    Joined:
    Apr 12, 2005
    Posts:
    4,186
    Location:
    USA
    Bubba- Yes, thanks for explaining.:D
     
  8. redwolfe_98

    redwolfe_98 Registered Member

    Joined:
    Feb 14, 2002
    Posts:
    581
    Location:
    South Carolina, USA
    it looks like you have two options, either give "services" permission to terminate "vsmon" or else turn off zone alarm's auto-updating.. if it was me, i would try to turn off the auto-updating..
     
Thread Status:
Not open for further replies.