AppGuard 4.x 32/64 Bit - Releases

Discussion in 'other anti-malware software' started by Jryder54, Oct 29, 2013.

Thread Status:
Not open for further replies.
  1. hjlbx

    hjlbx Guest

    You have to use the main GUI and untick "Automatically resume protection after 20 minutes." You can modify this time also on the Advanced tab.

    Other security software should be added to Power Apps if AppGuard blocks something and it causes the security soft to malfunction.

    Block events that do not break anything should be ignored.
     
  2. bjm_

    bjm_ Registered Member

    Joined:
    May 22, 2009
    Posts:
    4,458
    Location:
    .
    AppGuard Auto resume checkbox.PNG
    Download AppGuard Personal 4.3 User Guide.
     
  3. bjm_

    bjm_ Registered Member

    Joined:
    May 22, 2009
    Posts:
    4,458
    Location:
    .
    User added <c:\users\bjms\documents> to private folder list.
    ---------------------------------
    Prevented process <Firefox> from accessing to <c:\users\bjms\documents>.
    Prevented process <Firefox> from accessing to <c:\users\bjms\documents\desktop.ini>.
    Prevented process <Firefox> from accessing to <c:\users\bjms\documents\contacts\desktop.ini>.
    ----------------------------------
    Did not realize calling Firefox calls Documents\....
    Afaik I don't have documents\desktop.ini or documents\contacts\desktop.ini
    ?
     
    Last edited: May 30, 2016
  4. stackz

    stackz Registered Member

    Joined:
    Dec 27, 2007
    Posts:
    646
    Location:
    Sydney Australia
    You should see them if you go into Folder Options and uncheck "Hide protected operating system files"
     
  5. hjlbx

    hjlbx Guest

    normal. ignore.
     
  6. bjm_

    bjm_ Registered Member

    Joined:
    May 22, 2009
    Posts:
    4,458
    Location:
    .
    Yes.... Thanks
     
  7. bjm_

    bjm_ Registered Member

    Joined:
    May 22, 2009
    Posts:
    4,458
    Location:
    .
    Yes, Normal & Ignore. Curious, why call browser calls Documents.
    Prevented process <Internet Explorer> from accessing to <c:\users\bjms\documents>.
    Does call browser, call any other...?
    AG default is \documents\myprivatefolder(empty), so I added \documents to see what happens.
     
    Last edited: May 30, 2016
  8. bjm_

    bjm_ Registered Member

    Joined:
    May 22, 2009
    Posts:
    4,458
    Location:
    .
    Q: restore earlier AppGuardPolicy/appguardpolicy
    I have earlier copy of AppGuardPolicy and appguardpolicy saved.
    Just tried to paste/move earlier to current (x86) and Roaming.
    AG Customize does not change. TamperGuard Off.
    Is there trick to import earlier Customize.

    Update: maybe just Roaming appguardpolicy
     
    Last edited: Jun 2, 2016
  9. CoolWebSearch

    CoolWebSearch Registered Member

    Joined:
    Sep 30, 2007
    Posts:
    1,247
    What happened with Lockdown mode?
    Lockdown mode is the most secure protection level and security level there is, and yet it was abandoned? Why?
     
  10. guest

    guest Guest

    it is still there, only available via tray icon.
     
  11. bjm_

    bjm_ Registered Member

    Joined:
    May 22, 2009
    Posts:
    4,458
    Location:
    .
    see page 9 here > Download AppGuard Personal 4.3 User Guide.
     
  12. guest

    guest Guest

    IMPORTANT FACT :

    if Appguard is installed while Rollback RX monitor the System partition, it cant guard apps on non-system partition not monitored by RX .

    however i dont know if it can guard the apps if the non-system partitions are also monitored by RX
     
  13. XhenEd

    XhenEd Registered Member

    Joined:
    Mar 31, 2014
    Posts:
    536
    Location:
    Philippines
    I have RollBack Rx along with AppGuard installed, and I successfully guarded DNS Jumper that is in my D://. It launched without any errors coming from AppGuard, although it blocked, obviously, the operation to change DNS.

    Edit: I was wrong. DNS Jumper successfully changed the DNS server. The blocked message in the log probably applies to the registry operation.
     
  14. guest

    guest Guest

    Does D:// is under RX monitoring?
     
  15. XhenEd

    XhenEd Registered Member

    Joined:
    Mar 31, 2014
    Posts:
    536
    Location:
    Philippines
    No. Only C: is under monitoring by RollBack Rx.
     
  16. guest

    guest Guest

    uhm...ok, so i wonder what causes my issue. I will wait the next build.
     
  17. BoerenkoolMetWorst

    BoerenkoolMetWorst Registered Member

    Joined:
    Dec 22, 2009
    Posts:
    4,873
    Location:
    Outer space
    Does AG block executing of .js files in user-space?
     
  18. hjlbx

    hjlbx Guest

    Yes. It blocks *.js files executed in User Space. However, it doesn't block javascript code -- otherwise things like browsers wouldn't work. There is a difference between a *.js file and javascript code.
     
  19. BoerenkoolMetWorst

    BoerenkoolMetWorst Registered Member

    Joined:
    Dec 22, 2009
    Posts:
    4,873
    Location:
    Outer space
    Yes, I'm aware of that, thanks. But I didn't know you .js file are executable in Windows until I just read advice on disabling their execution via Group Policy.
     
  20. bjm_

    bjm_ Registered Member

    Joined:
    May 22, 2009
    Posts:
    4,458
    Location:
    .
    Q: anyone add KeePass (or similiar) to Guarded Apps
     
  21. hjlbx

    hjlbx Guest

    You could -- and see if AppGuard blocks any actions that result in KeePass breakage. The only reason to add KeePass to Guarded Apps is if you are paranoid about an exploit involving KeePass -- which is extremely unlikely.
     
  22. bjm_

    bjm_ Registered Member

    Joined:
    May 22, 2009
    Posts:
    4,458
    Location:
    .
    I was thinking Memory Guard for KeePass open (data) in memory.
    Upon call KeePass master password dialog >
    Prevented <CTF Loader> from writing to <\registry\user\s-1-5-21-nnnnn-1004\software\microsoft\windows\currentversion\run>.
    Prevented process <KeePass> from writing to <c:\windows\cryptoguard\328af9a1>.
    Head scratch why KeePass wants to write to empty C:\Windows\CryptoGuard folder (Alert 3.5 installed with service Stop).
    So, thought I'd ask if KeePass was logical as Guarded App.
    KeePass saved creds work okay and Ignore quiets AppGuard.
    Note: have not tried to add new KeePass creds.

    Edit: just had > Prevented process <Firefox> from writing to <c:\windows\cryptoguard\9ad97749>.
     
    Last edited: Jun 12, 2016
  23. guest

    guest Guest

    c:\windows\cryptoguard Is in System Space and you have HMP.A installed.
    You have to make this an Exception Folder (Read/Write)
     
  24. bjm_

    bjm_ Registered Member

    Joined:
    May 22, 2009
    Posts:
    4,458
    Location:
    .
    D'Oh!, I forgot, I've been resting 3.1. Recent install 3.5 (and I forgot Exception).
    Hmm, even with Alert service stopped..?
    Thanks!
    So, is KeePass (or similiar) logical as Guarded App..?...OnOnOn...?
     
    Last edited: Jun 13, 2016
  25. Grumlo

    Grumlo Registered Member

    Joined:
    Nov 14, 2015
    Posts:
    176
    Guys where can I find 4.4.4.1 Appguard Version ?
     
Thread Status:
Not open for further replies.
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.