AppGuard 4.x 32/64 Bit - Releases

Discussion in 'other anti-malware software' started by Jryder54, Oct 29, 2013.

Thread Status:
Not open for further replies.
  1. pegr

    pegr Registered Member

    Joined:
    Apr 8, 2008
    Posts:
    2,280
    Location:
    UK
    What blocked events are you seeing?
     
  2. acr1965

    acr1965 Registered Member

    Joined:
    Oct 12, 2006
    Posts:
    4,995
    Apparently it is working now. The log entry was 12/15/13 23:31:52 Prevented process <Google Chrome> from writing to <c:\program files\google\chrome\application\31.0.1650.63\debug.log>.

    So maybe it was a problem with something else.
     
  3. pegr

    pegr Registered Member

    Joined:
    Apr 8, 2008
    Posts:
    2,280
    Location:
    UK
    Glad it's working now. :)
     
  4. Peter2150

    Peter2150 Global Moderator

    Joined:
    Sep 20, 2003
    Posts:
    20,590
    I leave it in lockdown all the time. The only issue is so minor as to be a non issue. If I want to change the delay time on the screen saver, I have to drop it down. That, other than installs, is the only issue I've had.

    Pete
     
  5. TomAZ

    TomAZ Registered Member

    Joined:
    Feb 27, 2010
    Posts:
    1,131
    Location:
    USA
    Pete-

    I would assume this works, but I haven't tried it yet. However, does it prohibit the use of (adding new files and/or editing the existing ones) in the My Documents folder, or do you still have full access to it?
     
  6. roady

    roady Registered Member

    Joined:
    Mar 27, 2005
    Posts:
    262
    Great tip,as usual!:thumb:
    Using AppGuard and ERP together is also a solution for gamers who use Steam,Origin or Uplay on a different partition.
    Exclude those folders from AppGuard and let ERP do it's job on those folders.......works quite well for me...:)
     
  7. bo elam

    bo elam Registered Member

    Joined:
    Jun 15, 2010
    Posts:
    6,147
    Location:
    Nicaragua
    Another great tip.:thumb:

    Bo
     
  8. TomAZ

    TomAZ Registered Member

    Joined:
    Feb 27, 2010
    Posts:
    1,131
    Location:
    USA
    Exactly, how did you do this?
     
  9. FleischmannTV

    FleischmannTV Registered Member

    Joined:
    Apr 7, 2013
    Posts:
    1,094
    Location:
    Germany
    When you configure the block access settings and add a program, a blue exclamation mark box appears on the right. If you click it, it will mean "all programs except...". Then add your profile folder.

    block except firefox.PNG
     
  10. Peter2150

    Peter2150 Global Moderator

    Joined:
    Sep 20, 2003
    Posts:
    20,590
    Not at all. It only blocks access to the guard apps you have set the privacy option to yes. So in my case it only applys to my browsers and Outlook.

    Pete
     
  11. Barb_C

    Barb_C Developer

    Joined:
    Jan 7, 2011
    Posts:
    1,234
    Location:
    Virginia
    Thanks. So you're saying that AppGuard will not recognize a Private Folder if it is located on a removable media device? I'll pass it along.
     
  12. Jryder54

    Jryder54 Registered Member

    Joined:
    Sep 3, 2013
    Posts:
    214
    Yes. Well I put it for the root of the drive i.e. G:\ but it works for the other drives. Thanks Barb_C!
     
  13. Barb_C

    Barb_C Developer

    Joined:
    Jan 7, 2011
    Posts:
    1,234
    Location:
    Virginia
    Yes, I was able to recreate this as well. I'm going to enter it as a bug in our bugzilla database.
     
  14. Tyrizian

    Tyrizian Registered Member

    Joined:
    Apr 26, 2012
    Posts:
    2,839
    Would this be a proper way to get games to work with AppGuard?

    Add games directory to User Space, include = No

    And...

    I know this might sound like a dumb question, but would AppGuard be considered suitable on an SSD drive?
     
  15. Barb_C

    Barb_C Developer

    Joined:
    Jan 7, 2011
    Posts:
    1,234
    Location:
    Virginia
    I wanted to let you all know that there is another coupon available for the holidays: APPGUARDXMAS

    It is good for $5 off of AppGuard version 4.0 (3-activation license).
     
  16. TheKid7

    TheKid7 Registered Member

    Joined:
    Jul 22, 2006
    Posts:
    3,576
    Yesterday I started leaving AppGuard set at Locked Down. Today, I turned on the PC and noticed that the boot time was somewhat longer than expected. I checked the AppGuard Activity Report and saw the following:
    How do you turn off Microsoft's Anti-Malware protection (whatever it is called)? Or maybe adjust AppGuard's options to allow Microsoft's Anti-Malware software to update its signatures? Which is best/recommended?

    Thanks in Advance.

    Operating System: Windows 7 Home Premium 64 bit

    Edit: I uploaded both of the files listed above to VirusTotal and there were No Malware detections.

    mpsigstub.exe Windows Explorer File Properties Description: Microsoft Malware Protection Signature Update Stub
    mpas-fe_bd.exe Windows Explorer File Properties Description: AntiMalware Definition Update

    Question: Why are some of the Windows System32 files hidden when I try to find them to do an upload to VirusTotal? I can see the files in Windows Explorer. I used Windows Explorer to copy mpsigstub.exe to another location so that I could upload it to VirusTotal. I had no problem finding mpas-fe_bd.exe to upload it to VirusTotal.
     
    Last edited: Dec 17, 2013
  17. HAN

    HAN Registered Member

    Joined:
    Feb 24, 2005
    Posts:
    2,098
    Location:
    USA
    I have a couple of questions but this thread is too large to be a practical resource. (Over 500 posts!!)

    I'm seriously thinking about beginning use of AppGuard. I have Win 7 Home Premium 64-bit. I have downloaded the AG Quick Start Guide and plan to go over it in detail. Is there any other beginner resource available?

    Beyond that, are there any special considerations for running AG as a Standard/Limited User? 99% of my use on the web is as a non-admin.

    Thanks in advance for any help anyone can give!
     
  18. fearlessscientist

    fearlessscientist Registered Member

    Joined:
    Sep 6, 2013
    Posts:
    166
    Location:
    USA
    I have Libre Office as a guarded app and privacy mode turned on. Its still able to write to a folder which I have granted 'read only' permission. Does anyone with Libre Office experience this ?
     
  19. Peter2150

    Peter2150 Global Moderator

    Joined:
    Sep 20, 2003
    Posts:
    20,590
    I just tested it with word. Was able to open a doc, and change it, but couldn't save it. So it worked with office.
     
  20. FleischmannTV

    FleischmannTV Registered Member

    Joined:
    Apr 7, 2013
    Posts:
    1,094
    Location:
    Germany
    I think Libre Office is a bit more complicated with its processes than Microsoft Office. There are not only the actual applications like swriter.exe (the Word equivalent) to consider, but also soffice.exe and soffice.bin.

    Do you have soffice.exe guarded? If not, try it.
     
  21. fearlessscientist

    fearlessscientist Registered Member

    Joined:
    Sep 6, 2013
    Posts:
    166
    Location:
    USA
    Thanks Peter & FleischmannTV.
    Yes, I have soffice.exe guarded as well, but soffice.bin is not an exe file, so couldn't add to guarded app.
     
  22. dja2k

    dja2k Registered Member

    Joined:
    Feb 15, 2005
    Posts:
    2,121
    Location:
    South Texas, USA
    I keep adding these log events to the ignore list and they seem to still come out.

    dja2k
     

    Attached Files:

  23. fearlessscientist

    fearlessscientist Registered Member

    Joined:
    Sep 6, 2013
    Posts:
    166
    Location:
    USA
    You may want to use wild card characters(*) to make the path generic in your ignore command. Try putting a * like this after temp\pft7ea3~temp\* folder.
     
  24. dja2k

    dja2k Registered Member

    Joined:
    Feb 15, 2005
    Posts:
    2,121
    Location:
    South Texas, USA
    Ok thanks but I need to create a wild card character (*) entry for the Field1 instead of Field2 since the dll that activates rundll32 changes but seems to be the same temp folder name?

    Would it be something like this?
    * | C:\Windows\System32\rundll32.exe

    dja2k
     

    Attached Files:

  25. roady

    roady Registered Member

    Joined:
    Mar 27, 2005
    Posts:
    262
    @ dja2k,it seems that Appguard is blocking parts,or an update of your sound control software....
     
Thread Status:
Not open for further replies.
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.