AppGuard 4.x 32/64 Bit - Releases

Discussion in 'other anti-malware software' started by Jryder54, Oct 29, 2013.

Thread Status:
Not open for further replies.
  1. pegr

    pegr Registered Member

    Joined:
    Apr 8, 2008
    Posts:
    2,280
    Location:
    UK
    You only need to add the one that will get executed, which on Windows XP is the one in system32 (don't know about Windows 7). It wouldn't hurt to add both of them to the User Space tab though, just to be sure. You also need to check whether notepad.exe is digitally signed on Windows 7. If it is, you would first need to find an unsigned executable, physically located somewhere in System Space, to use for the test.
     
    Last edited: Jul 2, 2014
  2. stackz

    stackz Registered Member

    Joined:
    Dec 27, 2007
    Posts:
    646
    Location:
    Sydney Australia
    Hi pegr,

    I tested with v4.0.17.0 on Win 7 x64.
    Appguard would not even let me add anything from Program Files or Windows directory (+ sub directories) to user space.
    I moved an unsigned executable in an alternate system space directory to user space and execution was blocked in both Locked Down and Medium levels.
     
  3. Cutting_Edgetech

    Cutting_Edgetech Registered Member

    Joined:
    Mar 30, 2006
    Posts:
    5,694
    Location:
    USA
    I know, but I do not know which one will get executed. I will have to read up on it to see were notepad executes from, and under what circumstances. I'm thinking it's in both locations to share resources depending on what you are using Notepad for. AG 4.0 did not allow me to add notepad.exe to the userspace. I tried adding it from System32 Folder, SysWow64 Folder, and C:\Windows\. Notepad was located in all those locations on Windows 7X64. I got the following message in the screen shot below when attempting to add notepad.exe to the userspace. I will try adding notepad.exe to the userspace with 4.1 beta later today.
     

    Attached Files:

  4. Cutting_Edgetech

    Cutting_Edgetech Registered Member

    Joined:
    Mar 30, 2006
    Posts:
    5,694
    Location:
    USA
    Looks like stackz beat me to it lol At least we got the same result.
     
  5. Cutting_Edgetech

    Cutting_Edgetech Registered Member

    Joined:
    Mar 30, 2006
    Posts:
    5,694
    Location:
    USA
    If I launch Notepad, and then click open file location for Notepad in Windows Task Manager it takes me to the System32 Folder. I may not be able to add anything from the System Folder in AG 4.1 also. We will have to wait, and see. Everyone needs to create a folder at C:\, and add it to the userspace. Then try executing some executables from that folder, and make sure AG is taking the appropriate actions based on it's settings. For example just create a folder called, "Test Folder" for testing purposes (C:\Test Folder). In lock down mode AG should not allow executables to launch from that folder at all unless they are on the guarded apps list. In Medium Mode AG should only allow executables to launch from that folder if they are signed.
     
  6. J_Whacka

    J_Whacka Registered Member

    Joined:
    May 30, 2014
    Posts:
    13
    I am about to try out AppGuard on my x64 bit machine but was wondering before i do is there anything i will have to set in AppGuard as i have EAM 9 and Webroot AV and Sandboxie. Also should anything be added for programs like Steam?.
     
  7. shadek

    shadek Registered Member

    Joined:
    Feb 26, 2008
    Posts:
    2,538
    Location:
    Sweden

    EAM 9 and Webroot AV will work out of the box with AppGuard! There is no need, but just to play it safe, I add their executables to Power Apps.

    You will need to make some minor adjustments in AppGuard to make it work optimally with Sandboxie. I think you need to make an 'exception' for C:\Sandbox folder so that Sandboxie may write to that folder when AppGuard guards the application. You may also add C:\Sandbox to user-space to make sure that AppGuard guards the sandboxed program. This will strengthen the sandbox even more.

    I use Steam and I recommend not adding any game or Steam itself to Guarded apps. Just leave it be.
     
  8. WSFfan

    WSFfan Registered Member

    Joined:
    May 10, 2012
    Posts:
    374
    Location:
    The Earth
    With the latest beta version 4.1.41.2,i was able to reproduce the bug on Windows 7 x64 for notepad.exe located on System32 folder as well as SysWOW64 folder.Though notepad.exe in C:\Windows gets blocked in Lockdown mode,it was able to open a .txt file located in MyPrivateFolder in Medium mode.

    So i was able to add notepad.exe in System32,SysWOW64 and Windows folders to User Space with Include flag set to 'Yes'.Also i was able to access Private folders when launching notepad.exe from C:\Windows folder in Medium mode.
     
    Last edited: Jul 2, 2014
  9. J_Whacka

    J_Whacka Registered Member

    Joined:
    May 30, 2014
    Posts:
    13
    Thanks, will try it out now and see how it goes.

    So add the 3 files "sandboxiecrypto.exe, sandboxiedcomlaunch.exe, sandboxiepcss.exe" to power apps and add c:\Sanbox to user space and add the c:\sandbox to guard apps folder and i should be good to go?
     
    Last edited: Jul 2, 2014
  10. shadek

    shadek Registered Member

    Joined:
    Feb 26, 2008
    Posts:
    2,538
    Location:
    Sweden
    Yes!

    Regarding: "add the c:\sandbox to guard apps folder and i should be good to go?"

    Make sure the Guarded apps folder is set to 'Exception'.

    Please report back if there are any troubles!
     
  11. SLE

    SLE Registered Member

    Joined:
    Jun 30, 2011
    Posts:
    361
    "Power apps" feature is not needed for Sandboxie processes.
     
  12. pegr

    pegr Registered Member

    Joined:
    Apr 8, 2008
    Posts:
    2,280
    Location:
    UK
    In order to clarify this, I uninstalled AG 4.1 and installed AG 4.0, then performed the same test I carried out earlier today. Next, I reinstalled AG 4.1 and retested. What I found is that the behaviour has changed between 4.0 and 4.1, and the bug is only in 4.1. Here is a summary of what I found with each version.

    AG 4.0
    Nothing from Program Files or Windows directories may be added to the User Space tab (subfolders or individual executables). This agrees with your finding. In order to perform the test, I copied notepad.exe from c:\windows\system32 to c:\ then added c:\notepad.exe to the User Space tab with Include set to Yes. AppGuard blocked c:\notepad.exe from launching at both the Medium and Locked Down protection levels, as expected.

    AG 4.1
    Subfolders in the Program Files and Windows directories may not be added to the User Space tab, but individual executables are allowed (e.g. notepad.exe). Although this is a change from AG 4.0, it is not necessarily a bug, as it allows tighter control of execution from System Space, on a per application basis, than was possible with AG 4.0. Whether this is a design change or a bug only Barb can say. Personally, I think it is not a bad thing as it allows the user to supplement the two c:\windows\system32 entries that are there by default, namely: schtasks.exe and at.exe, with their own additions.

    In order to repeat the test I performed earlier today, I also added c:\windows\system32\notepad.exe to the User Space tab with Include set to Yes, in addition to the entry for c:\notepad.exe used to test AG 4.0.

    c:\notepad.exe continued to be blocked from launching at both the Medium and Locked Down protection levels, as expected. c:\windows\system32\notepad.exe was blocked at the Locked Down protection level but was allowed to run at the Medium protection level with Privacy Mode enabled - I was unable to use it to access a Private Folder. This is clearly a bug that didn't exist in AG 4.0, as notepad.exe is unsigned on my system. Either I shouldn't have been able to add c:\windows\system32\notepad.exe to the User Space tab or, if this is a design change from AG 4.0, it shouldn't have been allowed to run with Include set to Yes.
     
    Last edited: Jul 2, 2014
  13. pegr

    pegr Registered Member

    Joined:
    Apr 8, 2008
    Posts:
    2,280
    Location:
    UK
    See my reply to stackz above.
     
  14. pegr

    pegr Registered Member

    Joined:
    Apr 8, 2008
    Posts:
    2,280
    Location:
    UK
    Thanks for trying this and confirming the bug, although your ability to access a Private Folder was different to the test result I got. Maybe there's a difference between Windows XP and Windows 7 in this respect. While I think of it, did you check whether notepad.exe is signed on Windows 7? It isn't on Windows XP, but maybe things are different with Windows 7.
     
  15. Cutting_Edgetech

    Cutting_Edgetech Registered Member

    Joined:
    Mar 30, 2006
    Posts:
    5,694
    Location:
    USA
    Notepad is not signed on Windows 7 either.
     
  16. Cutting_Edgetech

    Cutting_Edgetech Registered Member

    Joined:
    Mar 30, 2006
    Posts:
    5,694
    Location:
    USA
    I was busy all night working on another project. I will try installing AG 4.1 beta again a little later since 4 does not allow you to add anything from the Windows folder to the userspace.
     
  17. pegr

    pegr Registered Member

    Joined:
    Apr 8, 2008
    Posts:
    2,280
    Location:
    UK
    Okay, thanks. The behaviour should be the same as on Windows XP then.
     
  18. Syobon

    Syobon Registered Member

    Joined:
    Dec 27, 2009
    Posts:
    469
    does the XML being unicode now helps compatibility with asian software?
     
  19. Cutting_Edgetech

    Cutting_Edgetech Registered Member

    Joined:
    Mar 30, 2006
    Posts:
    5,694
    Location:
    USA
    Yes, AG should now work on Chinese, and Japanese OS's. Barb, mentioned this in post 1526.
     
  20. Syobon

    Syobon Registered Member

    Joined:
    Dec 27, 2009
    Posts:
    469
    thanks, one more reason to upgrade to 4.1 when its ready.
     
  21. J_Whacka

    J_Whacka Registered Member

    Joined:
    May 30, 2014
    Posts:
    13
    Thanks, i clicked on guarded apps tab and clicked on settings under folders and added c:\Sandbox and set it to read/write works perfectly!

    Only thing in activity report im not sure of and cant find nothing from searching is:

    Prevented process <pid: 2756> from writing to <c:\bootsqm.dat> and <pid: 3380> from writing to <c:\windows\appcompat\programs\recentfilecache.bcf>

    Apart from them two which im unsure of its working perfectly fine with WSA, EAM and Sandboxie. Also i mostly use it in locked down when downloading/installing steam games is is best to set it to install/medium?.

    Soon as the 10 day trial is up im gona buy a copy such a awsome piece of software and has no effect on my machine its like it aint there, great job :D
     
  22. shadek

    shadek Registered Member

    Joined:
    Feb 26, 2008
    Posts:
    2,538
    Location:
    Sweden
    I get those alerts too so no worries! I don't get them in Medium though (I also run in Locked-down mode most of the time).

    I usually set AppGuard to Install when starting a game for the first time so that everything with the game can be installed. The next time I keep AppGuard to Locked-down mode. After the game is first installed, automatic updates via Steam does not require you to lower defense to Install again. :)
     
  23. J_Whacka

    J_Whacka Registered Member

    Joined:
    May 30, 2014
    Posts:
    13
    Ah thanks same as what i do. I did forget the 1st time when grabbing the cs go update so had to run it again i just got to remember to change that slider.
     
  24. cybergary

    cybergary Registered Member

    Joined:
    Dec 6, 2006
    Posts:
    28
    First time ever, I'm encountering AppGuard blocking Netbeans from saving files
    --------
    I removed all rules added today and rebooted, problem gone.
     
    Last edited: Jul 6, 2014
  25. shadek

    shadek Registered Member

    Joined:
    Feb 26, 2008
    Posts:
    2,538
    Location:
    Sweden
    Even for the pre-configured programs?
     
Thread Status:
Not open for further replies.
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.