Vsmon.exeZoneAlarm settings

Discussion in 'ProcessGuard' started by scootnod, Jan 20, 2005.

Thread Status:
Not open for further replies.
  1. scootnod

    scootnod Registered Member

    Joined:
    Oct 9, 2004
    Posts:
    30
    Hi, I went through the learning mode after installing PG 3 and today when I started my comp, PG blocked Vsmon installing drivers and services. What options should I have enabled or disabled for Vsmon. Right now it is set to modify and read (both checked), protect from termination and modification (both checked). I just checked allow install drivers and services. Everything else is unchecked.

    Thanks
     
  2. Peter2150

    Peter2150 Global Moderator

    Joined:
    Sep 20, 2003
    Posts:
    17,040
    You have the same settings I have for Zone Alarm so you should be okay.

    When you installed with learning mode, did you do the reboots until PG turned off learning mode. That should have picked up the correct ZA settings.

    Pete
     
  3. Pilli

    Pilli Registered Member

    Joined:
    Feb 13, 2002
    Posts:
    6,217
    Location:
    Hampshire UK
    In addition to Peter's advice,
    Did you reboot after ticking "Install drivers/services"?

    Pilli
     
  4. scootnod

    scootnod Registered Member

    Joined:
    Oct 9, 2004
    Posts:
    30
    Yep I did the second reboot with learning mode. I did also reboot after checking allow install drivers and services.

    Thanks
     
  5. Pilli

    Pilli Registered Member

    Joined:
    Feb 13, 2002
    Posts:
    6,217
    Location:
    Hampshire UK
    OK scootnod, Then I'll have to ask ZA users to disclose their settings in ProcessGuard for all of the ZA files that PG needs to protect.

    Any offers? :D

    Thanks. Pilli
     
  6. scootnod

    scootnod Registered Member

    Joined:
    Oct 9, 2004
    Posts:
    30
    Well I haven't received as alerts since I check allow installation of drivers and services.
     
  7. Pilli

    Pilli Registered Member

    Joined:
    Feb 13, 2002
    Posts:
    6,217
    Location:
    Hampshire UK
    That's good, hopefully all will be well now. Any further problems please ask :)

    Cheers. Pilli
     
  8. Peter2150

    Peter2150 Global Moderator

    Joined:
    Sep 20, 2003
    Posts:
    17,040
    If all is normal there shouldn't be any more alerts. I use latest version of ZA Pro and learning mode picked up everything. The settings i mentioned above should be fine.

    Pete
     
  9. bornewi

    bornewi Guest

    We have tried with ZA home user products: ZAP 4.x/5.x & ZASS 5.x
    On our boxes with PG3.100 full ver. installed, these Protection settings are fine for it working well:

    [vsmon.exe]
    BLOCK : { Read + Modification + Termination }
    ALLOW : { Read + Modification }

    [zclient.exe]
    BLOCK : { Read + Modification + Termination }
    ALLOW : { Read }
    Others : { SMH }

    Well, I also try to say something else. After checked out the DCS website for db specified settings for popular executes, we removed all allowance settings from pgaccount.exe and "read" from proguard.exe, the box got problem after a reboot with error msg "pgaccount.exe could not load and can not process execute requests..."; after gave them back "read" right, no problem so far.
     
  10. stopby

    stopby Guest

    [correct]
    Regard with the PG settings for pgaccount.exe/proguard.exe which needed "read" privilege because others have been protected from "reading".
     
Thread Status:
Not open for further replies.