Wilders Security Forums  

Go Back   Wilders Security Forums > Security Products > other anti-malware software
User Name
Password
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

 
 
Thread Tools Search this Thread
  #1  
Old March 12th, 2011, 10:14 AM
shadek's Avatar
shadek shadek is offline
Very Frequent Poster
 
Join Date: Feb 2008
Location: Sweden
Posts: 1,789
Default AppGuard 3.x 32/64 Bit

Eirik (from Blue Ridge Networks) suggested a new thread to be created with this topic. Any questions or remarks about the software with version number 3.x should be posted here.
  #2  
Old March 12th, 2011, 03:44 PM
shadek's Avatar
shadek shadek is offline
Very Frequent Poster
 
Join Date: Feb 2008
Location: Sweden
Posts: 1,789
Default Re: AppGuard 3.x 32/64 Bit

Quote:
Originally Posted by Blackcat
Anyone seen this update today? New version or a bug?

I haven't got a pop-up about it yet on any of the three machines I'm using at home with AppGuard.
  #3  
Old March 12th, 2011, 03:48 PM
Blackcat's Avatar
Blackcat Blackcat is offline
Massive Poster
 
Join Date: Nov 2002
Location: UK
Posts: 3,826
Default Re: AppGuard 3.x 32/64 Bit

Pop-up here.
Attached Images
 
  #4  
Old March 12th, 2011, 03:52 PM
Peter2150's Avatar
Peter2150 Peter2150 is offline
Global Moderator
 
Join Date: Sep 2003
Posts: 11,805
Default Re: AppGuard 3.x 32/64 Bit

I downloaded it recently and that is the version I got.

Pete
  #5  
Old March 12th, 2011, 04:05 PM
shadek's Avatar
shadek shadek is offline
Very Frequent Poster
 
Join Date: Feb 2008
Location: Sweden
Posts: 1,789
Default Re: AppGuard 3.x 32/64 Bit

Quote:
Originally Posted by Peter2150
I downloaded it recently and that is the version I got.

Pete

Odd. I just downloaded and installed on a new machine. Same version as before; meaning we're getting different versions.
  #6  
Old March 12th, 2011, 08:21 PM
jmonge's Avatar
jmonge jmonge is offline
Incredibly Massive Poster
 
Join Date: Mar 2008
Location: Calgary,Canada
Posts: 11,766
Default Re: AppGuard 3.x 32/64 Bit

am i getting an older version?
__________________
Emsisoft Anti-Malware 7.0/WebRo0t AntiVirus 2o13
  #7  
Old March 13th, 2011, 07:19 AM
trjam's Avatar
trjam trjam is offline
Incredibly Massive Poster
 
Join Date: Aug 2006
Location: North Carolina
Posts: 8,620
Default Re: AppGuard 3.x 32/64 Bit

Quote:
Originally Posted by jmonge
am i getting an older version?
jmonge, mine is the older.
__________________
Webroot SecureAnywhere
  #8  
Old March 13th, 2011, 07:45 AM
Kees1958's Avatar
Kees1958 Kees1958 is offline
Massive Poster
 
Join Date: Jul 2006
Posts: 5,857
Default Re: AppGuard 3.x 32/64 Bit

My change request:

An option to allow windows update for all
  #9  
Old March 13th, 2011, 12:57 PM
shadek's Avatar
shadek shadek is offline
Very Frequent Poster
 
Join Date: Feb 2008
Location: Sweden
Posts: 1,789
Default Re: AppGuard 3.x 32/64 Bit

How well does AppGuard protect the registry? AppGuard on 'normal protection' certainly blocks files installed when executing a malicious file... but what about registry?
  #10  
Old March 13th, 2011, 01:39 PM
Greg S Greg S is offline
Very Frequent Poster
 
Join Date: Mar 2009
Location: A l a b a m a
Posts: 1,039
Default Re: AppGuard 3.x 32/64 Bit

Quote:
Originally Posted by Kees1958
My change request:

An option to allow windows update for all
That would be nice but might be tricky for them to do. If one has external hard drives, MS on some updates will use the largest HD with the most available/free disk space to launch the update installer.


What I really need is a way to stop AG's Event viewer writing. Specifically when it comes to WMP. Even though AG is excluded in my AV, it continually monitors the continuous events being written to the event viewer when WMP is open. I get thousands of these in a matter of just a few hours.

Last edited by Greg S : March 13th, 2011 at 02:52 PM.
  #11  
Old March 13th, 2011, 02:16 PM
shadek's Avatar
shadek shadek is offline
Very Frequent Poster
 
Join Date: Feb 2008
Location: Sweden
Posts: 1,789
Default Re: AppGuard 3.x 32/64 Bit

It would be nice to see in the log of what's blocked writing to registry entries.
  #12  
Old March 13th, 2011, 07:44 PM
fredra's Avatar
fredra fredra is offline
Frequent Poster
 
Join Date: Jul 2004
Posts: 365
Default Re: AppGuard 3.x 32/64 Bit

Quote:
Originally Posted by Kees1958
My change request:

An option to allow windows update for all
+1
Cheers
__________________
"The weak can never forgive. Forgiveness is the attribute of the strong."
Gandhi
  #13  
Old March 14th, 2011, 04:13 PM
Eirik Eirik is offline
Frequent Poster
 
Join Date: Oct 2008
Location: Chantilly, Virginia
Posts: 544
Default Re: AppGuard 3.x 32/64 Bit

Hi All,

If you right-click on the AppGuard tray icon and select 'About', you'd see the following:



If you see 3.0.13.0 when doing this, you have the latest version.

Cheers,

Eirik
  #14  
Old March 14th, 2011, 05:28 PM
Dave53 Dave53 is offline
Regular Poster
 
Join Date: Feb 2009
Posts: 107
Default Re: AppGuard 3.x 32/64 Bit

On the AppGuard support page on your website it shows the version number as 3.0.13.1

Dave
  #15  
Old March 14th, 2011, 06:20 PM
Blackcat's Avatar
Blackcat Blackcat is offline
Massive Poster
 
Join Date: Nov 2002
Location: UK
Posts: 3,826
Default Re: AppGuard 3.x 32/64 Bit

We are going round in circles again.

Although the latest version is supposedly 3.0.13.0, some people in this thread say they have 3.0.13.1

I have seen the pop-up for the "new" version several times; generally after a fresh install. And the information about the latest version, if it is still 3.0.13.0, on the AppGuard web-site has still not been corrected

Can Eirik clarify?
  #16  
Old March 15th, 2011, 11:13 AM
Eirik Eirik is offline
Frequent Poster
 
Join Date: Oct 2008
Location: Chantilly, Virginia
Posts: 544
Default Re: AppGuard 3.x 32/64 Bit

The total version number is indeed 3.0.13.1, as noted on the support web page. The version number indicated in the 'About' GUI states 3.0.13.0, however. If you find this inconsistent and confusing, so do I. I hope to eliminate this source of confusion with the next release.

The fourth decimal group indicates installation package version. In this case the difference between 0 and 1 was a newer help file. However, the version reported in the 'About' GUI is NOT the absolute authority on this decimal group (see next paragraph). While I'm at it, the third decimal group reflects build number (e.g., bug fixes, tweaks, but no new features). And finally, the second group reflects a difference in features or how they are implemented (e.g., new GUI, EirikGuard, etc.).

If one goes to the Windows Control panel, locates AppGuard in the "Add/Remove Software" control, one should find the software version listed there to be 3.0.13.1 when on the same host the 'About' window says 3.0.13.0.

I would appreciate a little help from folk on fleshing out a possibility I'd like to "rule out". Some have reported a prompt saying there's a newer version of "3.0.13.1". To those folk, I ask, please indicate what version is reported in the 'About' window. My point here is to determine if there's something more that needs to be investigated.

Please accept my apologies for the confusion.

Cheers,

Eirik
  #17  
Old March 15th, 2011, 12:38 PM
Blackcat's Avatar
Blackcat Blackcat is offline
Massive Poster
 
Join Date: Nov 2002
Location: UK
Posts: 3,826
Default Re: AppGuard 3.x 32/64 Bit

Quote:
Originally Posted by Eirik
I would appreciate a little help from folk on fleshing out a possibility I'd like to "rule out". Some have reported a prompt saying there's a newer version of "3.0.13.1". To those folk, I ask, please indicate what version is reported in the 'About' window. My point here is to determine if there's something more that needs to be investigated.
My pop-up says "a newer version is available" but my "About" says version 3.0.13.0. I have seen this prompt only after a fresh install of AG; after awhile it disappears.

Glad to hear that I was not the only one who is confused
  #18  
Old March 15th, 2011, 03:45 PM
starfish_001's Avatar
starfish_001 starfish_001 is offline
Very Frequent Poster
 
Join Date: Jan 2005
Posts: 1,015
Default Re: AppGuard 3.x 32/64 Bit

I have had an issue on cold reboot the last couple of days where no user space app can be launched and the gui does not seem to influence or change the protection level. I have to reboot again to access the system


Is there a log file I can read to see what is going on ?
The system is windows 7 x64
  #19  
Old March 15th, 2011, 07:23 PM
Eirik Eirik is offline
Frequent Poster
 
Join Date: Oct 2008
Location: Chantilly, Virginia
Posts: 544
Default Re: AppGuard 3.x 32/64 Bit

Quote:
Originally Posted by starfish_001
Is there a log file I can read to see what is going on ?
The system is windows 7 x64

Yes, all AppGuard blocking events are stored in your Windows Event Log. Events that appear in the 'status' window of AppGuard's GUI disappear with a restart.

Cheers,

Eirik
  #20  
Old March 16th, 2011, 04:14 PM
starfish_001's Avatar
starfish_001 starfish_001 is offline
Very Frequent Poster
 
Join Date: Jan 2005
Posts: 1,015
Default Re: AppGuard 3.x 32/64 Bit

Hi likely event detail are as follows any idea?


Day 1

Faulting application name: AppGuardAgent.exe, version: 3.0.13.0, time stamp: 0x4d530420
Faulting module name: AppGuardAgent.exe, version: 3.0.13.0, time stamp: 0x4d530420
Exception code: 0xc0000005
Fault offset: 0x00006a88
Faulting process id: 0x788
Faulting application start time: 0x01cbe27dc722b2ae
Faulting application path: C:\Program Files (x86)\Blue Ridge Networks\AppGuard\AppGuardAgent.exe
Faulting module path: C:\Program Files (x86)\Blue Ridge Networks\AppGuard\AppGuardAgent.exe
Report Id: 27ba06df-4e71-11e0-8916-005056c00008


then

C:\Program Files (x86)\Blue Ridge Networks\AppGuard\AppGuardAgent.exe
c:\windows\syswow64\werfault.exe

then

Fault bucket , type 0
Event Name: APPCRASH
Response: Not available
Cab Id: 0

Problem signature:
P1: AppGuardAgent.exe
P2: 3.0.13.0
P3: 4d530420
P4: AppGuardAgent.exe
P5: 3.0.13.0
P6: 4d530420
P7: c0000005
P8: 00006a88
P9:
P10:

Attached files:
C:\Windows\Temp\WER4C0C.tmp.appcompat.txt
C:\Windows\Temp\WER4EAC.tmp.WERInternalMetadata.xml
C:\Windows\Temp\WER4F0B.tmp.hdmp
C:\Windows\Temp\WER567B.tmp.mdmp

These files may be available here:
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\AppCrash_AppGuardAgent.ex_158bc39d3936f46083a5cf86cbd5a45b8afdf6e2_cab_081d56e5

Analysis symbol:
Rechecking for solution: 0
Report Id: 27ba06df-4e71-11e0-8916-005056c00008
Report Status: 4





Day 2

Faulting application name: AppGuardAgent.exe, version: 3.0.13.0, time stamp: 0x4d530420
Faulting module name: AppGuardAgent.exe, version: 3.0.13.0, time stamp: 0x4d530420
Exception code: 0xc0000005
Fault offset: 0x00006a88
Faulting process id: 0x7d8
Faulting application start time: 0x01cbe347e52086e8
Faulting application path: C:\Program Files (x86)\Blue Ridge Networks\AppGuard\AppGuardAgent.exe
Faulting module path: C:\Program Files (x86)\Blue Ridge Networks\AppGuard\AppGuardAgent.exe
Report Id: 50215dc6-4f3b-11e0-a0f2-005056c00008
  #21  
Old March 19th, 2011, 05:27 AM
pegr pegr is offline
Very Frequent Poster
 
Join Date: Apr 2008
Location: UK
Posts: 1,608
Default Re: AppGuard 3.x 32/64 Bit

I know I've raised this issue before but so far I've never received a reply.

Can somebody from BRN please explain why processes belonging to Prevx and Trusteer Rapport are continually blocked from writing to the memory of guarded applications even though they have been added to the MemoryGuard Application Exception List.

These are the only two applications where I have seen this happen. All other applications that I have added to the MemoryGuard Application Exception List have been allowed to write to the memory of guarded applications, as expected.

Is this something that will be investigated with a view to resolution in the next release?
  #22  
Old March 19th, 2011, 08:26 AM
Barb_C Barb_C is offline
Frequent Poster
 
Join Date: Jan 2011
Location: Virginia
Posts: 492
Default Re: AppGuard 3.x 32/64 Bit

Quote:
Originally Posted by pegr
Is this something that will be investigated with a view to resolution in the next release?
Hi, Pegr. Will you please send your policy file and a copy of the events where Prevx and Trusteer Rapport are blocked to AppGuard@BlueRidgeNetworks.com. The agent’s policy file is in the following location: On XP: Documents and Settings\All Users\Application Data\Blue Ridge Networks\AppGuard\AppGuardPolicy.xml. On VISTA, the file will be in C:\users\<user_name>\AppData\Roaming\ Blue Ridge Networks\AppGuard\AppGuardPolicy.xml. Thanks!
  #23  
Old March 20th, 2011, 05:26 AM
starfish_001's Avatar
starfish_001 starfish_001 is offline
Very Frequent Poster
 
Join Date: Jan 2005
Posts: 1,015
Default Re: AppGuard 3.x 32/64 Bit

Quote:
Originally Posted by starfish_001


Barc ... can you comment on my issue ...
  #24  
Old March 20th, 2011, 09:33 AM
ellison64 ellison64 is offline
Very Frequent Poster
 
Join Date: Oct 2003
Posts: 2,167
Default Re: AppGuard 3.x 32/64 Bit

Im having the same problem.Not all the time but perhaps once every other day.Im also using w7 64 bit.Ive just checked my event viewer logs,

12/03/2011

Faulting application name: AppGuardAgent.exe, version: 3.0.13.0, time stamp: 0x4d530420
Faulting module name: AppGuardAgent.exe, version: 3.0.13.0, time stamp: 0x4d530420
Exception code: 0xc0000005
Fault offset: 0x00006a88
Faulting process id: 0x6e4
Faulting application start time: 0x01cbe0c5d2b50422
Faulting application path: C:\Program Files (x86)\Blue Ridge Networks\AppGuard\AppGuardAgent.exe
Faulting module path: C:\Program Files (x86)\Blue Ridge Networks\AppGuard\AppGuardAgent.exe
Report Id: 40c2c699-4cb9-11e0-b4d0-705ab6c6f9e1

14/03/2011

Faulting application name: AppGuardGUI.exe, version: 3.0.13.0, time stamp: 0x4d5303ce
Faulting module name: MSVCR80.dll, version: 8.0.50727.4927, time stamp: 0x4a2752ff
Exception code: 0xc0000005
Fault offset: 0x0001500a
Faulting process id: 0x11cc
Faulting application start time: 0x01cbe22cc5c69c95
Faulting application path: C:\Program Files (x86)\Blue Ridge Networks\AppGuard\AppGuardGUI.exe
Faulting module path: C:\Windows\WinSxS\x86_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.4927_none_d08a205e442db5b5\MSVCR80.dll
Report Id: 7737012e-4e20-11e0-bea1-705ab6c6f9e1

16/03/2011

Faulting application name: AppGuardAgent.exe, version: 3.0.13.0, time stamp: 0x4d530420
Faulting module name: AppGuardAgent.exe, version: 3.0.13.0, time stamp: 0x4d530420
Exception code: 0xc0000005
Fault offset: 0x00006a88
Faulting process id: 0x87c
Faulting application start time: 0x01cbe3ec3e6d4cf1
Faulting application path: C:\Program Files (x86)\Blue Ridge Networks\AppGuard\AppGuardAgent.exe
Faulting module path: C:\Program Files (x86)\Blue Ridge Networks\AppGuard\AppGuardAgent.exe
Report Id: aa6af7bd-4fdf-11e0-a3e5-705ab6c6f9e1


ellison
  #25  
Old March 21st, 2011, 11:55 AM
pegr pegr is offline
Very Frequent Poster
 
Join Date: Apr 2008
Location: UK
Posts: 1,608
Default Re: AppGuard 3.x 32/64 Bit

Quote:
Originally Posted by Barb_C
Hi, Pegr. Will you please send your policy file and a copy of the events where Prevx and Trusteer Rapport are blocked to AppGuard@BlueRidgeNetworks.com. The agent’s policy file is in the following location: On XP: Documents and Settings\All Users\Application Data\Blue Ridge Networks\AppGuard\AppGuardPolicy.xml. On VISTA, the file will be in C:\users\<user_name>\AppData\Roaming\ Blue Ridge Networks\AppGuard\AppGuardPolicy.xml. Thanks!
Hi Barb,

I've done as you requested and sent a copy of the Application Event Log showing the blocked events together with a copy of the AppGuard agent's policy file in the following location: "C:\Documents and Settings\Administrator\Application Data\Blue Ridge Networks\AppGuard\AppGuardPolicy.xml".

I sent the policy file located in the Administrator profile and not the one located in the All Users profile, because it's the one located in my personal user profile (i.e. Administrator) that contains the MemoryGuard Application Exceptions List. Please let me know if you also need the policy file for the All Users profile.

Regards
 

Wilders Security Forums > Security Products > other anti-malware software « Previous Thread | Next Thread »

Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Settings
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump


All times are GMT -4. The time now is 06:28 PM.


Powered by vBulletin® Copyright ©2000 - 2013, Jelsoft Enterprises Ltd.
Copyright ©2002 - 2013, Wilders Security Forums