AppGuard 4.x 32/64 Bit - Releases

Discussion in 'other anti-malware software' started by Jryder54, Oct 29, 2013.

Thread Status:
Not open for further replies.
  1. hjlbx

    hjlbx Guest

    Is there a way to remove\deactivate Windows Command Processor from Guard List - which should stop it from running in Lock-Down mode ?

    I deselect Windows Command Processor in the Guard List, but it still executes in Lock-Down mode.

    Do I need to remove Microsoft from the Trusted Vendor list to accomplish the above ?

    Obviously I am missing something here...
     
  2. Prodigy

    Prodigy Registered Member

    Joined:
    Apr 15, 2015
    Posts:
    12
    I have just bought AG, is there any new version planned ahead?, last released version was from april, how about the upcoming v5, is there any news, it's near end of the year.
     
  3. Peter2150

    Peter2150 Global Moderator

    Joined:
    Sep 20, 2003
    Posts:
    20,590
    Curious what you are hoping for in a new release. The current build is doing it's job beautifully
     
  4. FleischmannTV

    FleischmannTV Registered Member

    Joined:
    Apr 7, 2013
    Posts:
    1,093
    Location:
    Germany
    I know this question is not directed at me, but I would welcome the ability to create hash and command line based exception rules.
     
  5. Cutting_Edgetech

    Cutting_Edgetech Registered Member

    Joined:
    Mar 30, 2006
    Posts:
    5,694
    Location:
    USA
    I want to see the same as well. The hashing could be used to lock things down even more, and make AG a little more user friendly for some.
     
  6. CoolWebSearch

    CoolWebSearch Registered Member

    Joined:
    Sep 30, 2007
    Posts:
    1,247
    Sorry, but I don't follow you with this advanced computer language: what exactly is "the ability to create hash and command line based exception rules"?
     
  7. hjlbx

    hjlbx Guest

    BRN needs to improve the user-interface; bottom of it is that it just isn't very user friendly.
     
  8. Prodigy

    Prodigy Registered Member

    Joined:
    Apr 15, 2015
    Posts:
    12
    Built-in import-export feature?, better semantics such as for example include into guarded, auto-exclusion for windows update installation.

    Question, how to properly allowing a batch file to running?, i have dnscrypt in which i need to spawn through a batch (*.bat) script.
    Currently i have tried with adding the dnscrypt directory into user space and set include to "no". Is this the proper way in AG?.
     
    Last edited: Sep 9, 2015
  9. Mr.X

    Mr.X Registered Member

    Joined:
    Aug 10, 2013
    Posts:
    4,814
    Location:
    .
    I second this.
     
  10. XhenEd

    XhenEd Registered Member

    Joined:
    Mar 31, 2014
    Posts:
    536
    Location:
    Philippines
    Why do I get these?
    I'm using the Lock down mode.
     
  11. stackz

    stackz Registered Member

    Joined:
    Dec 27, 2007
    Posts:
    646
    Location:
    Sydney Australia
    The first one is due to Microsoft's brilliance in deciding to copy cleanmgr.exe and other components to the current user's temp folder in order to run Disk Cleanup (CleanMgr). The easiest way to prevent AppGuard blocking this is to make cleanmgr.exe a PowerApp.

    As for Prevented <AppGuard Agent Service (x64)> from writing to <\registry\machine\software\wow6432node\blue ridge networks\appguard>, I've never seen that message and have no idea why AppGuard would be blocking itself.
     
  12. XhenEd

    XhenEd Registered Member

    Joined:
    Mar 31, 2014
    Posts:
    536
    Location:
    Philippines
    So, this is not a work of malware. Thank God!
    A bug, again, I think. Sometimes, if I don't restart or shutdown the computer frequently, and just use the sleep mode, I notice that AppGuard would act strangely, just like this error. Other anomaly I notice is that AppGuard would still work even after setting itself to Off. Seldom, AppGuard would consume CPU power in the background until I restart the computer.
     
  13. Cutting_Edgetech

    Cutting_Edgetech Registered Member

    Joined:
    Mar 30, 2006
    Posts:
    5,694
    Location:
    USA
    The second one is strange. It says AG is blocking itself. What OS are you using?
     
  14. XhenEd

    XhenEd Registered Member

    Joined:
    Mar 31, 2014
    Posts:
    536
    Location:
    Philippines
    Windows 10. That is actually the first time I've seen it. It's probably just another "hit or miss" by AppGuard. Everyday, I frequently put my laptop into Sleep mode when I'm away with my laptop. And that's when AppGuard would act strangely.
    Also, I experienced the strange behavior of AppGuard even when I'm using my Windows 8.1 laptop.
     
  15. Cutting_Edgetech

    Cutting_Edgetech Registered Member

    Joined:
    Mar 30, 2006
    Posts:
    5,694
    Location:
    USA
    I have never seen AG block anything from itself, and I have been using AG since it's first alpha/beta release. I think it's possible it could be a bug that only occurs on Windows 10. That's why I asked what OS you are using. I will notify Barb from AG, and see what she thinks.
     
  16. Cutting_Edgetech

    Cutting_Edgetech Registered Member

    Joined:
    Mar 30, 2006
    Posts:
    5,694
    Location:
    USA
    BlueRidge Networks are looking into AG blocking itself from writing to the registry now.
     
  17. hjlbx

    hjlbx Guest

    Whatever happened to MBR Guard ? The last time I remember anything about it was mid to late 2013...
     
  18. blacknight

    blacknight Registered Member

    Joined:
    Sep 25, 2007
    Posts:
    3,351
    Location:
    Europe, UE citizen
    AppGuard blocks on my system Libre Office Portable: I installed it with AP in Install Mode but AP blocked it again. So I added Libre in Power Applications, but AP blocks it again. It's the first software with AP has this behavior.
     
  19. paulderdash

    paulderdash Registered Member

    Joined:
    Dec 27, 2013
    Posts:
    4,644
    Location:
    Under a bushel ...
    Strange - I do not have that issue (Win 8.1 Pro 64-bit). All LibreOffice Portable executables (via PortableApps.com) added to Guarded Apps.
     
  20. blacknight

    blacknight Registered Member

    Joined:
    Sep 25, 2007
    Posts:
    3,351
    Location:
    Europe, UE citizen
    I also did it, but nothing changed. A bug ?
     
  21. paulderdash

    paulderdash Registered Member

    Joined:
    Dec 27, 2013
    Posts:
    4,644
    Location:
    Under a bushel ...
    You could try adding the LibreOfficePortable folder to User Space Include=No (assuming your portable apps are in user space), but you shouldn't have to do that and it would remove protection.
     
  22. blacknight

    blacknight Registered Member

    Joined:
    Sep 25, 2007
    Posts:
    3,351
    Location:
    Europe, UE citizen
    Sorry, I forgot: I tried this too before posting: it doesn't work. Only Mode in which Libre Office portable works is AP in Install Mode. Note: no problem instead with Libre Office installed in the system. I believe that it deals with some Libre portable process.
     
  23. Mr.X

    Mr.X Registered Member

    Joined:
    Aug 10, 2013
    Posts:
    4,814
    Location:
    .
    Yes I've had same issues with some portable apps before. Had to move them inside Program Files and/or Program Files (x86). Then added them as guarded.
     
  24. blacknight

    blacknight Registered Member

    Joined:
    Sep 25, 2007
    Posts:
    3,351
    Location:
    Europe, UE citizen
    Tried: doesn't work. :(
     
  25. hjlbx

    hjlbx Guest

    Hello Guys,

    I am using AG + SBIE + RAM Disk.

    The sandbox folder path is set to R:\Sandbox, where R = RAM Disk and R:\Sandbox is an exception folder with Read\Write permissions.

    For best protection do I need to add R:\Sandbox to User Space?

    It seems to me that would be correct for optimum protection.

    Thanks,

    HJLBX
     
Thread Status:
Not open for further replies.
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.