AppGuard 4.x 32/64 Bit - Releases

Discussion in 'other anti-malware software' started by Jryder54, Oct 29, 2013.

Thread Status:
Not open for further replies.
  1. Lockdown

    Lockdown Registered Member

    Is this a brand new machine or the same one that you have reported issues with AppGuard in the past ?

    What were the error messages ? - please post a screenshot of the error messages here.

    Please explain what you mean by the term "formatting" as people use this term interchangeably to mean different things - do you mean a wipe of the drive and then reinstall of the OS ?

    What did you set - MBR or GPT for BIOS\UEFI ?

    Does this system have TPM ?

    Are you dual-booting using Linux ?

    How many drives and how many partitions for each drive ?

    Do you have external drives connected to the machine ?
     
  2. harlan4096

    harlan4096 Registered Member

    @hamo:

    Standalone "Kaspersky Protection" add-on for FireFox, to install manually in case You don't have it:
    If You are using FireFox x64, sometimes the add-on does not install automatically, and You should install it manually...
     
  3. XhenEd

    XhenEd Registered Member

    Ooohhh... I never found that...

    Do you have any idea why it wants to launch reg.exe? Can you please log it using your monitoring tools, like Process Explorer or anything, if it does? That Kaspersky add-on launching reg.exe is what we're trying to figure out.
     
  4. Peter2150

    Peter2150 Global Moderator

    I just did an upgrade of my win 7 test machine to the new insider build 10563 of win 10 Pro. Appguard is humming right along.
     
  5. Lockdown

    Lockdown Registered Member

    I've had CU for days. Didn't see anything unwanted yet.
     
  6. Lockdown

    Lockdown Registered Member

  7. hamo

    hamo Registered Member

    The photo best than words ......!
     

    Attached Files:

  8. Lockdown

    Lockdown Registered Member

    @hamo

    Capture.PNG
     
    Last edited: Apr 3, 2017
  9. Lockdown

    Lockdown Registered Member

    That's an antivirus\internet security suite for you... messing with the browser and making it do stuff it shouldn't.
     
  10. Cutting_Edgetech

    Cutting_Edgetech Registered Member

    I thought it may have had 2 file paths, but I had never noticed because I rarely use it for Security reasons.
     
  11. Cutting_Edgetech

    Cutting_Edgetech Registered Member

    Yes, I tried that multiple times.
     
  12. Cutting_Edgetech

    Cutting_Edgetech Registered Member

    No this is a different machine. It's about 6 years old.

    I'm using an MBR. I'm using BIOS, not using UEFI.

    Yes, it has a TPM chip, but i'm not using Bitlocker. I would have to check the BIOS to see if it's enabled

    It's not a dual-boot.

    It has a single drive, and only one partition. (C:\)

    I'm not currently on the machine in question. I will look through the BIOS for anything that might be causing the issue a little later today.

    Below is a screen shot of the error message i'm receiving.

    Btw.. this is off topic, but i'm having an issue with this Windows 10 machine (not the machine in question). I encrypted a .RAR file with Windows encryption by right clicking the file choosing properties from the General Tab, then clicking Advanced, and ticking the Encrypt Content to Secure data. Now every new file I create on this machine has a Gold Lock icon on it so I guess it is encrypting the file. Why is it encrypting all new files? Anyone know the answer to this one? Again, this is not the machine i'm having the AG problem on.
     

    Attached Files:

  13. guest

    guest Guest

    Go to the properties of the parent folder and look if the encryption for this folder was activated. If yes, disable it (if you don't want to see all new files encrypted)
    But you should see a message box before the encryption of files: "do you want to encrypt only this file or the file and the parent folder (recommended)"
    The encryption of the file and the folder is activated by default, so if you have not selected "only this file", Windows is encrypting all new files and the file you have selected.

    End of OT :)
     
  14. Lockdown

    Lockdown Registered Member

    Do you have a cloud drive installed on the system - like pCloud Drive - or anything similar ?

    If yes, such drives are currently not supported and AppGuard will throw the error as shown in the image you attached to your previous post.

    If no, then I would check if TPM is enabled in the BIOS. Disable it and reinstall AppGuard and see if that corrects the issue. Enabled TPM can cause soft installation problems and subsequent misbehavior. If needed, reboot the system after disabling TPM. Then reinstall AppGuard.

    The same would apply to Bitlocker. Bitlocker is notorious for causing all manner of problems on systems. I know you state that you are not using it, but I recommend that you check Bitlocker just in case. If needed, reboot the system after disabling Bitlocker. Then reinstall AppGuard.

    Check Windows Disk Management carefully for any problems.
     
  15. Roberteyewhy

    Roberteyewhy Registered Member

    Windows Defender will not update manually. AppGuard blocks the install (Lock Down). Also, in Windows Update I get an error message when trying to install Defender Updates. When I put AppGuard in Protected mode no problems.

    As per Lockdown's suggestion I have this in User Space.

    c:\users\user name\appdata\local\temp\*\mpsigstub.exe (No)
    c:\users\user name\appdata\local\temp\mpam-*.exe (No)

    What else do I need to put in User Space in order to get rid of this error?

    Thanks,
    Robert
     
    Last edited: Apr 3, 2017
  16. Lockdown

    Lockdown Registered Member

    The problem is the file path that you've made in the User Space list.

    c:\users\user name\appdata\local\temp\*\mpsigstub.exe (No)
    c:\users\user name\appdata\local\temp\mpam-*.exe (No)

    Replace "user name" above with the actual user name of your user profile. It's the same as your Windows login user name. You can also find it here:

    C:\Users\*

    Capture.PNG
     
  17. Roberteyewhy

    Roberteyewhy Registered Member

    I changed that before I added the exclusions. It is the correct path.

    c:\users\robert xxxxx\appdata\local\temp\*\mpsigstub.exe

    Lockdown, I cleared Activity, but it was something like mpsig.exe

    Robert
     
  18. Lockdown

    Lockdown Registered Member

    Please post the block events from Activity Report please.

    Please post the error message regarding Windows Defender definition updates from Windows Update.
     
  19. Roberteyewhy

    Roberteyewhy Registered Member

    OK. Will do that when the latest definitions become available.

    Thanks Lockdown,
    Robert
     
  20. Lockdown

    Lockdown Registered Member

    Hehe... could be something new from the IT masters in Redmond.
     
  21. Roberteyewhy

    Roberteyewhy Registered Member

    Probably so. Like you said before, with Creator Update coming in a week, file paths might change.

    Robert
     
  22. Lockdown

    Lockdown Registered Member

    In Creator's Update I have already seen one User Space change made by Microsoft.

    Perhaps they have changed the process name for Defender updates ahead of schedule - as you state.

    I haven't seen any Defender manual update SNAFU on Creator's Update - yet.

    Anyhow...your Activity Report block events will show what's up in all its red-highlighted glory.
     
  23. Roberteyewhy

    Roberteyewhy Registered Member

    To bad AppGuard does not turn red if the file path is invalid in User Space. Sure would make it easier if the user knows that so as he/she can correct it. With every new major release for Win 10, this is bound to happen.

    Robert
     
  24. Roberteyewhy

    Roberteyewhy Registered Member

    Lockdown, here is what you asked for. This is in Lock Down.

    Image 3.png Image 4.png

    Thanks,
    Robert
     
  25. Lockdown

    Lockdown Registered Member

Thread Status:
Not open for further replies.
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.
    Dismiss Notice