AppGuard 3.x 32/64 Bit

Discussion in 'other anti-malware software' started by shadek, Mar 12, 2011.

Thread Status:
Not open for further replies.
  1. Barb_C

    Barb_C Developer

    Joined:
    Jan 7, 2011
    Posts:
    1,234
    Location:
    Virginia
    Sorry, not at this time.
     
  2. pegr

    pegr Registered Member

    Joined:
    Apr 8, 2008
    Posts:
    2,280
    Location:
    UK
    I've just got round to trying AppGuard again and I'm pleased to report that the latest release is working well on my 32-bit Windows XP Pro system.

    The previously reported problems that I experienced with earlier AppGuard versions appear to have been resolved with the final release of 3.1.6.0. :)
     
  3. ViVek

    ViVek Registered Member

    Joined:
    Aug 7, 2008
    Posts:
    584
    Location:
    Moon
    Hi, Barb_C :)
    When can we expect right click feature ?
     
  4. Dave53

    Dave53 Registered Member

    Joined:
    Feb 23, 2009
    Posts:
    123
    I was wondering the same thing. :)
     
  5. abels

    abels Registered Member

    Joined:
    Apr 14, 2007
    Posts:
    103
    Location:
    Danang, VN
    It's great if Appguard recognizes windows update package. Hope this would be improved soon.
     
  6. pegr

    pegr Registered Member

    Joined:
    Apr 8, 2008
    Posts:
    2,280
    Location:
    UK
    Agreed. I've just had to put it into install mode to apply Windows "Patch Tuesday" updates.
     
  7. Barb_C

    Barb_C Developer

    Joined:
    Jan 7, 2011
    Posts:
    1,234
    Location:
    Virginia
    It should have been improved with the latest version. What kind of blocks were you getting before putting into install mode? Were you running in Locked Down mode? Are you running on XP?
     
  8. Barb_C

    Barb_C Developer

    Joined:
    Jan 7, 2011
    Posts:
    1,234
    Location:
    Virginia
    I've noted the feature request, but I can't promise a delivery date. Sorry.
     
  9. pegr

    pegr Registered Member

    Joined:
    Apr 8, 2008
    Posts:
    2,280
    Location:
    UK
    AppGuard was running in High mode on Windows XP Pro SP3. On my system, this month's "Patch Tuesday" updates consisted of the following: -

    1. Security Update for Microsoft Office 2007 System (KB2584063)
    2. Security Update for the 2007 Microsoft Office System (KB2553074)
    3. Security Update for Windows XP (KB2570947)
    4. Security Update for Microsoft Office 2007 System (KB2553089)
    5. Windows Malicious Software Removal Tool - September 2011 (KB890830)
    6. Update for Windows XP (KB2616676)
    7. Security Update for Microsoft Office 2007 System (KB2553090)

    After the first two updates failed (AppGuard blocked access to the Windows Installer as I recall), I switched to Install mode after which the remaining five updates installed successfully. I was then able to manually download the first two updates again and install them using Install mode.
     
  10. Barb_C

    Barb_C Developer

    Joined:
    Jan 7, 2011
    Posts:
    1,234
    Location:
    Virginia
    Thanks for the details. We'll look into it.
     
  11. Greg S

    Greg S Registered Member

    Joined:
    Mar 1, 2009
    Posts:
    1,039
    Location:
    A l a b a m a
    I have a suggestion, name your setup file to reflect the current build number. Maybe I'm anal but I despise downloading something to the Downloads folder where a previous file with the same name already resides. As we all know, the latest version is renamed with the trailing (#).
     
  12. Barb_C

    Barb_C Developer

    Joined:
    Jan 7, 2011
    Posts:
    1,234
    Location:
    Virginia
    We'll consider this.
     
  13. Barb_C

    Barb_C Developer

    Joined:
    Jan 7, 2011
    Posts:
    1,234
    Location:
    Virginia
    Apparently Microsoft is still using unsigned files when installing on XP. That is why the first two updates failed. Hopefully we won't see these on Vista or Win7.
     
  14. pegr

    pegr Registered Member

    Joined:
    Apr 8, 2008
    Posts:
    2,280
    Location:
    UK
    I thought it might be something like that. Thanks for looking into it. :)
     
  15. 3TAMMUZ

    3TAMMUZ Registered Member

    Joined:
    Jan 30, 2009
    Posts:
    38
    I've very recently installed the Norton Antivirus 2012, and I got this message popped up by the Appguard from today:

    09/29/11 18:45:31 Prevented process <cceraser.dll> from launching from <c:\programdata\norton\{0c55c096-0f1d-4f28-aaa2-85ef591126e7}\nav_19.1.0.28\definitions\virusdefs\20110928.032>.
     
  16. TheMozart

    TheMozart Former Poster

    Joined:
    Jan 6, 2010
    Posts:
    1,486
    Just installed Appguard.

    But when I try to open KeyNote which loads a text editor and text files, it won't allow me to open it and I get this message:

    09/30/11 12:14:42 Prevented process <keynote.exe> from launching from <j:\program files\keynote>.

    If I turn APpguard to Medium and not High, then keynote loads ok.

    So what is the solution to keep AppGuard on High and still have Keynote load?

    And why is it blocking Keynote.exe? For what reason exactly?

    Maybe this has to do with keynote.exe and some other programs being located on my J: drive which is a TrueCrypt container? Not only keynote.exe refuses to load, but some other programs too from J: drive.
     
    Last edited: Sep 29, 2011
  17. TheMozart

    TheMozart Former Poster

    Joined:
    Jan 6, 2010
    Posts:
    1,486
    Unfortunately I had to remove and uninstall AppGuard, a real shame too.:'(

    But it was not liking all my portableapps on my TrueCrypt container partition and even when I added some of the apps to the allow list, the apps still would get blocked. Everything outside the TrueCrypt container partition ran fine however, so it seems that AppGuard doesn't like apps running from a TrueCrypt container partition. Shame indeed.
     
  18. pegr

    pegr Registered Member

    Joined:
    Apr 8, 2008
    Posts:
    2,280
    Location:
    UK
    Your J: drive is in extended user space which is why AppGuard is preventing you from launching programs.

    To solve this, click on Customize... and add the J: drive to the list of folders in the User-Space tab with the Include option set to No. You should then be able to launch programs from your J: drive.
     
  19. abels

    abels Registered Member

    Joined:
    Apr 14, 2007
    Posts:
    103
    Location:
    Danang, VN
  20. TheMozart

    TheMozart Former Poster

    Joined:
    Jan 6, 2010
    Posts:
    1,486
    Did this...but some apps load fine and some are still getting blocked all the time, even if I add them individually to the allow list! No idea why, and I don't have the experience and patience to try to figure this out and messing around with it, so I had to uninstall AppGuard unfortunately.:'(

    It seems AppGuard has a problem with extended user space TrueCrypt containers. But in all fairness to AppGuard, I have come across problems before with other HIPS and security programs when it comes to my apps running from the TrueCrypt container. It seems to confuse a lot of security programs for some reason.
     
  21. pegr

    pegr Registered Member

    Joined:
    Apr 8, 2008
    Posts:
    2,280
    Location:
    UK
    Agreed. I've had similar problems in the past with TrueCrypt. It's a shame that AppGuard isn't working for you. Perhaps Eirik or Barb can suggest something.
     
  22. TheMozart

    TheMozart Former Poster

    Joined:
    Jan 6, 2010
    Posts:
    1,486
    It's a real shame too, because I really liked AppGuard. But yeah, especially Truecrypt containers, many security applications don't cope very well at all with it.
     
  23. Barb_C

    Barb_C Developer

    Joined:
    Jan 7, 2011
    Posts:
    1,234
    Location:
    Virginia
    You could try making the sandbox folder an exception folder. Refer to the help section "User Interface->Configuration Interface->Guarded Applications".
     
  24. Barb_C

    Barb_C Developer

    Joined:
    Jan 7, 2011
    Posts:
    1,234
    Location:
    Virginia
    Hi TheMozart. Sorry that you're having the problem. Is AppGuard preventing the applications from launching after you've excluded the TrueCrypt container directory from user space? If so, I'll get our lab to try and reproduce. If the apps are able to launch, but are being blocked from preventing operations (writing to system space or the registry), then they may not be "well behaved" enough to be guarded - remove them from the Guard List. You could also send a copy of your events to AppGuard@BlueRidgeNetworks.com.
     
    Last edited: Oct 1, 2011
  25. Barb_C

    Barb_C Developer

    Joined:
    Jan 7, 2011
    Posts:
    1,234
    Location:
    Virginia
    You could try one of the following:

    1. Exclude this directory from user space (refer to the help section on "User Interface->Configuration Interface->User Space" - be sure to change the "Include" column to "No").
    2. Add Norton to the trusted publisher list (if the dll is digitally signed). Refer to the help section on "User Interface->Configuration Interface->Trusted Publisher List."
     
Thread Status:
Not open for further replies.
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.