AppGuard 4.x 32/64 Bit - Releases

Discussion in 'other anti-malware software' started by Jryder54, Oct 29, 2013.

Thread Status:
Not open for further replies.
  1. syrinx

    syrinx Registered Member

    Joined:
    Apr 7, 2014
    Posts:
    427
    My heads been hurting for weeks, chasing my own tail like a crazy dog. =(

    Thanks for the extra information.

    It's sad how using ImDisk has been the only way I can reproduce these issues on demand but I have seen them (at least I think they are a result of the same problems) at other points and on other PCs where ImDisk was not ever installed. Usually a reboot fixed the problem but not even knowing when (or why) AG silently stopped working is my biggest peeve followed by the fact that it can happen in the first place :-/

    I'm not expecting an immediate fix either way [I actually assumed it might require changes that could only be done during a major revision, 5.x anyone?] but at least we're now headed in the right direction.

    At this point I'm just glad you seem to recognize the core of my issue even if you haven't identified all the problem points yet. :D At least you guys have gotten off to a great start by figuring out the cause of one (or is it two now with the soundcard thing?) of them!

    Hopefully I haven't annoyed (spammed with weird theories) you, both in email and here on the forum, to the point where you dread reading my next message but if it's any consolation I plan to take a few days off from my AG tests unless a promising idea suddenly pops into into my head.
     
    Last edited: Feb 11, 2016
  2. guest

    guest Guest

    i read it, but my partitions are already created, before installing AG or any softs. Almost all new computers have at least 2 partitions created (one for the system and one for the datas). Personally i have 2 extra partitions created right away buying my computers. so i have no posibility to do as you mentioned.
     
  3. hjlbx

    hjlbx Guest

    @Barb_C

    4.3.12.1 - Bug (remains)
    • Add new Publisher to Publisher List on Guarded Apps tab
    • Change Level from -- to Install
    • Customary AppGuard alert that accompanies Level change from -- to Install does NOT appear:

      AppGuard Publisher Alert.PNG
    • Select Apply
    • Select OK
    • Select Customize (reopen GUI)
    • Publisher reverted from Install back to --
    If you attempt this repeatedly, the Publisher location within the list will move from top of list to bottom of list - and vice versa.
     
    Last edited by a moderator: Feb 12, 2016
  4. hjlbx

    hjlbx Guest

    @Barb_C

    4.3.12.1 - Bug(s)

    • Right-click tray icon
    • Select any of the following:
    Allow USB Launches
    Allow User Space Launches
    Guarded Execution
    Privacy Mode
    • Select one of the available sub-options from the above - such as Disable Privacy Mode for browser or Allow USB launches Guarded or Unguarded
    • Tray icon converts to green triangle with exclamation mark
    1. Double-click tray icon - tray icon changes back to indicate previous level of protection (but protection disabled earlier is still disabled)
    2. Right-click tray icon - select AppGuard - tray icon changes back to indicate previous level of protection (but protection disabled earlier is still disabled)
    3. Right-click tray icon - select Activity Report - tray icon changes back to indicate previous level of protection (But protection disabled earlier is still disabled)
     
    Last edited by a moderator: Feb 12, 2016
  5. Cutting_Edgetech

    Cutting_Edgetech Registered Member

    Joined:
    Mar 30, 2006
    Posts:
    5,694
    Location:
    USA
    Has anyone experienced their sound stop working inside Firefox web browser? It started recently for me. I don't know if it's a Firefox bug, or if possible one of my Security apps is causing it. I have been using Eset Smart Security, AppGuard, and Malwarebytes Anti-Exploit while testing AG beta builds.

    Edited 2/12/16
    It's strange, my sound just came back in as soon as I logged out of http://voclab.com/en which is a site I use to help build my vocabulary. I did notice that the webpage indicated it was downloading something none stop, and that has happened 3 times over the past week. My sound has gone out each time that has occurred so it has to be their website. It causes the sound to go out on any site I visit. Looks like I will have to run fiddler, or Wireshark on it the next time it occurs.
     
    Last edited: Feb 12, 2016
  6. Peter2150

    Peter2150 Global Moderator

    Joined:
    Sep 20, 2003
    Posts:
    20,590
    On thing I noticed is when updating to the latest beta all the defaults on publishers list came back. I'd like to see a switch to turn that feature off.
     
  7. Mr.X

    Mr.X Registered Member

    Joined:
    Aug 10, 2013
    Posts:
    4,803
    Location:
    .
    We already have a turn off switch PER publisher only, not global. It disables the publisher but not deletes it from the list and I don't think is necessary, just by setting as Install > Deny and Level > -- I think it's enough.
     
  8. Barb_C

    Barb_C Developer

    Joined:
    Jan 7, 2011
    Posts:
    1,234
    Location:
    Virginia
    Even if they are created afterwards, there is no issue as long as they wait until the next reboot before setting rules for these partitions.
     
  9. Barb_C

    Barb_C Developer

    Joined:
    Jan 7, 2011
    Posts:
    1,234
    Location:
    Virginia
    If you added WPS to the Guard List, then it is being Guarded in install mode and AppGuard is functioning as designed.
     
  10. hjlbx

    hjlbx Guest

    I did not add WPS to Guarded List; AppGuard added it after install.

    AppGuard blocked the installation of *.job files required for automatic updates during initial installation of WPS.
     
    Last edited by a moderator: Feb 12, 2016
  11. Barb_C

    Barb_C Developer

    Joined:
    Jan 7, 2011
    Posts:
    1,234
    Location:
    Virginia
    AppGuard does not Guard the WPS program by default. If it is a child (or grandchild) app of another office program or is launched from user-space, then it will be Guarded, but it is not explicitly added to the guard list.
     
  12. hjlbx

    hjlbx Guest

    The issue remains... *.job files should not be blocked during Install as they are needed for proper functioning of automatic updates.

    The block occurred while AppGuard was in Install Mode.
     
  13. Cutting_Edgetech

    Cutting_Edgetech Registered Member

    Joined:
    Mar 30, 2006
    Posts:
    5,694
    Location:
    USA
    Is anyone using Bitdefender with AG? Do they work without conflict? I used Bitdefender not too long ago, and it had many different components. I did not have AG installed at the time.
     
  14. paulderdash

    paulderdash Registered Member

    Joined:
    Dec 27, 2013
    Posts:
    4,644
    Location:
    Under a bushel ...
    I am using security soft Heimdal Pro which auto-updates via C:\Users\Public\Documents\Heimdal Security\Patching\Downloads\Heimdal-beta.msi
    Needless to say the update is blocked by AG.

    I have tried setting
    - the path as Include=No in User Space
    - the (Heimdal) Publisher Install Level to Install
    - the .msi as a Power App, but can't add the .msi, only the containing folder
    but install is still blocked in Protected mode.

    In the end I set AG Protection level to Install and before installing manually.

    Anyone else using Heimdal? Any suggestions how to allow the auto-update in Protected mode?
     
  15. hjlbx

    hjlbx Guest

    I think AppGuard is behaving as intended; InstallGuard will block non-Microsoft *.msi files even in Protected Mode.

    The only option I think is to lower to Install Mode as you have done.

    Did you try excluding installer path from User Space using a wild-card?: Specifically, <C:\Users\Public\Documents\Heimdal Security\Patching\Downloads\*>

    I don't think it will work because of *.msi file extension and not digitally signed by Microsoft.

    This topic is covered partially under Help File > AppGuard Protections > InstallGuard.
     
  16. puff-m-d

    puff-m-d Registered Member

    Joined:
    Feb 13, 2002
    Posts:
    5,703
    Location:
    North Carolina, USA
    Hello,

    This question concerns HitmanPro.Alert with AppGuard.
    Throughout this thread I have seen several different recommendations as to the settings that need to be in AppGuard when using HitmanPro.Alert. If I have followed the discussions correctly, all I need is to add the folder "C:\Windows\CryptoGuard" on the "Guarded Apps" tab > Folders > Settings as Type "Exception (Read/Write)". Am I correct in this being all that I need to do with AppGuard for HitmanPro.Alert to work properly?
    Thanks in advance for either confirming this is all I need to do or correct me if I am wrong...
     
  17. hjlbx

    hjlbx Guest

    I have combined AppGuard and HMP.A.

    I keep AppGuard in Lock-Down mode.

    I have not needed to make any exceptions in AppGuard for HMP.A to function correctly - not even necessary to add to Power Apps.

    You do need to install a permanent copy of HitmanPro on your system - so that it does not execute from AppData - which AppGuard will block.

    Installing a permanent copy of HitmanPro will install to Program Files - which AppGuard does not block.

    I also added SurfRight to Publishers List in AppGuard.
     
  18. paulderdash

    paulderdash Registered Member

    Joined:
    Dec 27, 2013
    Posts:
    4,644
    Location:
    Under a bushel ...
    Also based on the advice in this thread, that is the only setting I applied originally. IIRC this is advised for HMPA to be able to recover from a ransomware attack.
    I also added SurfRight in Publishers List. But some advocate removing all Publishers except BRN due to vulnerabilities in this area.
    I also added hmpalert.exe to Power Apps for good measure, but I don't think it is actually necessary.
    I only ever run AG in Protected mode ...
     
  19. hjlbx

    hjlbx Guest

    @paulderdash - please point to additional infos if at all possible. TIA.
     
  20. paulderdash

    paulderdash Registered Member

    Joined:
    Dec 27, 2013
    Posts:
    4,644
    Location:
    Under a bushel ...
    Yes - actually I was just coming back to edit my post to make that a question, and to say the only way to know for sure would be to test it!
    But I do remember being advised to set c:\windows\cryptoguard as an exception when I first started to use AG (by @Peter2150 I think it was) - not sure where I got the reason!
    If I find it, will post here.
     
  21. hjlbx

    hjlbx Guest

    No bother - I will ask Peter.
     
  22. hjlbx

    hjlbx Guest

    @Peter2150

    If using AppGuard and HMP.A together, should C:\Windows\CryptoGuard be added as an Exception Folder ?
     
  23. paulderdash

    paulderdash Registered Member

    Joined:
    Dec 27, 2013
    Posts:
    4,644
    Location:
    Under a bushel ...
    Last edited: Feb 15, 2016
  24. Peter2150

    Peter2150 Global Moderator

    Joined:
    Sep 20, 2003
    Posts:
    20,590
    Yes c;\windows\cryptoguard does need to be added to exceptions. Go to the settings tab under guarded apps, and add it there with read/write exceptions. If you don't HMPA won't work properly.

    Pete
     
  25. Victek

    Victek Registered Member

    Joined:
    Nov 30, 2007
    Posts:
    6,219
    Location:
    USA
    A friend of mine recently asked me about AOL Tech Fortress, which appears to be a rebranded version of AppGuard that AOL is offering through its proprietary Desktop software. Can anyone say more about this?
     
Thread Status:
Not open for further replies.
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.