GlobalProtect app - How to stop PanGPS from opening PanGPA constantly?

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 

GlobalProtect app - How to stop PanGPS from opening PanGPA constantly?

So we are trying to prevent the Palo Alto agent from opening at startup. 

I believe I fixed that initially by removing its entry from"HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run".

However there's a service running, "PANGps" ("C:\Program Files\Palo Alto Networks\GlobalProtect\PanGPS.exe") that appears to continue re-lauching the process "C:\Program Files\Palo Alto Networks\GlobalProtect\PanGPA.exe" eevery time PanGPA.exe is closed, until PanGPS.exe is closed. 

 

Is PanGPS a service required to be running?

Is there a way to prevent PanGPS from continuing to re-launch PanGPA.exe? 

 

10 REPLIES 10

Cyber Elite
Cyber Elite

@BeKindPleaseRewind,

The PanGPS service needs to be running for GlobalProtect to function. You can change the service to 'Manual' and GlobalProtect will launch start the service. However, I don't recall ever seeing an instance where the service launced the executable; what version of the agent are you running? 

It's 4.1.2 version.

 

And I ran Process Monitor and watched the service keep launching the executable.

 

Time of DayProcess NamePIDOperationPath
32:57.2PanGPS.exe5748Process CreateC:\Program Files\Palo Alto Networks\GlobalProtect\PanGPA.exe

 

Then if I run "taskkill /im PanGPA.exe /f"

a second later PanGPS.exe runs the PanGPA.exe again. 

 

Here is a video of this happening: https://youtu.be/9fkbyZZug_k

 

 

 

 

When I terminate both PanGPS and PanGPA, this is the process that goes on before they both start back up.

I also have the Service disabled this entire transaction.

 

I found the "HKLM\SOFTWARE\Palo Alto Networks\GlobalProtect\PanGPS\RestartPanGPA" one particularly interesting. 

 

Time of DayProcess NamePIDOperationPathResultDetail
25:33.0PanGPS.exe15796QueryDirectoryC:\Program Files\Palo Alto Networks\GlobalProtect\PanGPS.logSUCCESSFilter: PanGPS.log, 1: PanGPS.log
25:33.0PanGPS.exe15796CreateFileC:\Program Files\Palo Alto Networks\GlobalProtect\PanGPS.logSUCCESSDesired Access: Generic Write, Read Attributes, Disposition: OpenIf, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: N, ShareMode: None, AllocationSize: 0, OpenResult: Opened
25:33.0PanGPS.exe15796QueryStandardInformationFileC:\Program Files\Palo Alto Networks\GlobalProtect\PanGPS.logSUCCESSAllocationSize: 434,176, EndOfFile: 430,591, NumberOfLinks: 1, DeletePending: False, Directory: False
25:33.0PanGPS.exe15796QueryStandardInformationFileC:\Program Files\Palo Alto Networks\GlobalProtect\PanGPS.logSUCCESSAllocationSize: 434,176, EndOfFile: 430,591, NumberOfLinks: 1, DeletePending: False, Directory: False
25:33.0PanGPS.exe15796WriteFileC:\Program Files\Palo Alto Networks\GlobalProtect\PanGPS.logSUCCESSOffset: 430,591, Length: 435, Priority: Normal
25:33.0PanGPS.exe15796QueryBasicInformationFileC:\Program Files\Palo Alto Networks\GlobalProtect\PanGPS.logSUCCESSCreationTime: 10/25/2018 8:12:34 AM, LastAccessTime: 10/25/2018 8:12:34 AM, LastWriteTime: 10/25/2018 11:22:10 AM, ChangeTime: 10/25/2018 11:22:10 AM, FileAttributes: A
25:33.0PanGPS.exe15796ReadFileC:\Program Files\Palo Alto Networks\GlobalProtect\PanGPS.logSUCCESSOffset: 0, Length: 64
25:33.0PanGPS.exe15796ReadFileC:\Program Files\Palo Alto Networks\GlobalProtect\PanGPS.logSUCCESSOffset: 0, Length: 7
25:33.0PanGPS.exe15796CloseFileC:\Program Files\Palo Alto Networks\GlobalProtect\PanGPS.logSUCCESS 
25:37.1PanGPS.exe15796RegOpenKeyHKLM\Software\Palo Alto Networks\GlobalProtect\PanGPSSUCCESSDesired Access: Read
25:37.1PanGPS.exe15796RegQueryValueHKLM\SOFTWARE\Palo Alto Networks\GlobalProtect\PanGPS\RestartPanGPANAME NOT FOUNDLength: 16
25:37.1PanGPS.exe15796RegCloseKeyHKLM\SOFTWARE\Palo Alto Networks\GlobalProtect\PanGPSSUCCESS 
25:37.3PanGPA.exe8516RegSetValueHKCU\Software\Palo Alto Networks\GlobalProtect\PanMSAgent\PanGPSSUCCESSType: REG_DWORD, Length: 4, Data: 5
25:37.3PanGPA.exe8516RegQueryValueHKCU\Software\Palo Alto Networks\GlobalProtect\PanMSAgent\PanGPSSUCCESSType: REG_DWORD, Length: 4, Data: 5
25:38.0PanGPS.exe15796QueryDirectoryC:\Program Files\Palo Alto Networks\GlobalProtect\PanGPS.logSUCCESSFilter: PanGPS.log, 1: PanGPS.log
25:38.0PanGPS.exe15796CreateFileC:\Program Files\Palo Alto Networks\GlobalProtect\PanGPS.logSUCCESSDesired Access: Generic Write, Read Attributes, Disposition: OpenIf, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: N, ShareMode: None, AllocationSize: 0, OpenResult: Opened
25:38.0PanGPS.exe15796QueryStandardInformationFileC:\Program Files\Palo Alto Networks\GlobalProtect\PanGPS.logSUCCESSAllocationSize: 434,176, EndOfFile: 431,026, NumberOfLinks: 1, DeletePending: False, Directory: False
25:38.0PanGPS.exe15796QueryStandardInformationFileC:\Program Files\Palo Alto Networks\GlobalProtect\PanGPS.logSUCCESSAllocationSize: 434,176, EndOfFile: 431,026, NumberOfLinks: 1, DeletePending: False, Directory: False
25:38.0PanGPS.exe15796WriteFileC:\Program Files\Palo Alto Networks\GlobalProtect\PanGPS.logSUCCESSOffset: 431,026, Length: 862, Priority: Normal
25:38.0PanGPS.exe15796QueryBasicInformationFileC:\Program Files\Palo Alto Networks\GlobalProtect\PanGPS.logSUCCESSCreationTime: 10/25/2018 8:12:34 AM, LastAccessTime: 10/25/2018 8:12:34 AM, LastWriteTime: 10/25/2018 11:25:33 AM, ChangeTime: 10/25/2018 11:25:33 AM, FileAttributes: A
25:38.0PanGPS.exe15796ReadFileC:\Program Files\Palo Alto Networks\GlobalProtect\PanGPS.logSUCCESSOffset: 0, Length: 64
25:38.0PanGPS.exe15796ReadFileC:\Program Files\Palo Alto Networks\GlobalProtect\PanGPS.logSUCCESSOffset: 0, Length: 7
25:38.0PanGPS.exe15796CloseFileC:\Program Files\Palo Alto Networks\GlobalProtect\PanGPS.logSUCCESS 

I renamed the REG_Binary "FailureActions" to "FailureActions_old" at HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\PanGPS. 

Thereafter the process is not restarted every 60 secods by services.exe any longer 

So That key is telling the service to restart, even though under PanGPS service's Recovery tab options I have it set to "Take no action" for all 3 failure options, AND I had the service disabled as well. 

Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!