AppGuard 3.x 32/64 Bit

Discussion in 'other anti-malware software' started by shadek, Mar 12, 2011.

Thread Status:
Not open for further replies.
  1. Cutting_Edgetech

    Cutting_Edgetech Registered Member

    Joined:
    Mar 30, 2006
    Posts:
    5,694
    Location:
    USA
    I have a license for ProcessGuard, and the last time I checked it still works really well on XP :cool: If you have not already you should give Appguard a try! I've been using it since around 2007, and it's an amazing product! I'm confident it will stop just about anything your throw at it! It also has read / write memory protection. We are beta testing the latest build right now, but I believe the final build will be released soon. We like to really test things thorough around here :D
     
    Last edited: Jul 28, 2013
  2. puff-m-d

    puff-m-d Registered Member

    Joined:
    Feb 13, 2002
    Posts:
    5,703
    Location:
    North Carolina, USA
    Hello,

    You are most welcome ;) ...
     
  3. davidjschenk

    davidjschenk Registered Member

    Joined:
    Aug 27, 2006
    Posts:
    37
    Thanks much, Cutting_Edgetech.

    Yeah, I still use and love PG on my old XP box. So it's decided now--I'm going to give AppGuard+VoodooShield a try and see if that combination doesn't come close to giving me what I want.

    Yours,

    David
     
  4. Barb_C

    Barb_C Developer

    Joined:
    Jan 7, 2011
    Posts:
    1,234
    Location:
    Virginia
    Nothing has been modified in AppGuard to handle these two "attacks". With that being said:

    • Regarding the 16-bit file attack, AppGuard did stop this in locked down. In High, the 16-bit application was able to Install, but the OS will restrict 16 bit applications to run in a 16-bit subsystem and does not have access to the registry and critical file system directories.
    • Regarding the black hole exploit kit vulnerability: I believe that AppGuard already protects against this. Is there a specific post that you're referring to?
     
  5. Barb_C

    Barb_C Developer

    Joined:
    Jan 7, 2011
    Posts:
    1,234
    Location:
    Virginia
    No, AppGuard is not adversely impacted by PatchGuard.
     
  6. Barb_C

    Barb_C Developer

    Joined:
    Jan 7, 2011
    Posts:
    1,234
    Location:
    Virginia
    Did you open a ticket? I have not seen it yet.
     
  7. Barb_C

    Barb_C Developer

    Joined:
    Jan 7, 2011
    Posts:
    1,234
    Location:
    Virginia
    Status Update: The two bugs that were reported here against the beta (Privacy Mode GUI issue and Trusted Publishers being lost upon upgrade) have been fixed and are being tested in our lab. We hope to update the software on the beta link mid-week. The issue related to special characters embedded in the folder policy will be addressed in a future release.
     
  8. pegr

    pegr Registered Member

    Joined:
    Apr 8, 2008
    Posts:
    2,280
    Location:
    UK
    Thanks for the confirmation, Barb.
     
  9. Cutting_Edgetech

    Cutting_Edgetech Registered Member

    Joined:
    Mar 30, 2006
    Posts:
    5,694
    Location:
    USA
    No problem at all!
     
  10. Cutting_Edgetech

    Cutting_Edgetech Registered Member

    Joined:
    Mar 30, 2006
    Posts:
    5,694
    Location:
    USA
    Looking forward to trying the next beta!
     
  11. BoerenkoolMetWorst

    BoerenkoolMetWorst Registered Member

    Joined:
    Dec 22, 2009
    Posts:
    4,873
    Location:
    Outer space
    Yes, there was some Youtube video testing products against Blackhole, here's your reply about developing counter measures:
    https://www.wilderssecurity.com/showpost.php?p=2206587&postcount=2227
     
  12. Barb_C

    Barb_C Developer

    Joined:
    Jan 7, 2011
    Posts:
    1,234
    Location:
    Virginia
  13. garry35

    garry35 Registered Member

    Joined:
    Jan 20, 2009
    Posts:
    480
    i have been using appguard for several months and i have noticed that sometimes when try to run an app (usually a game) that even if i had aleady previously had the app excluded and running normally that it refuses to start showing an error in the appguard log window. when i look to try and track down the problem after trying to re add the app i am told by appguard that the program is already in my list, and only after deleting and re adding am i able to run it as normal. nothing in my system has changed or drives added/removed or re mapped. this seems to happen totally randomly and i cant predict when it will happen again or not.

    Gazzer
     
  14. shadek

    shadek Registered Member

    Joined:
    Feb 26, 2008
    Posts:
    2,538
    Location:
    Sweden
    That is some odd behavior. I've never actually encountered it myself. Perhaps the .exe changed filename? Is it an application that is started from user-space?

    What OS are you running?
     
  15. Cutting_Edgetech

    Cutting_Edgetech Registered Member

    Joined:
    Mar 30, 2006
    Posts:
    5,694
    Location:
    USA
    The bare minimum they will need to trouble shoot this is your Appguard Event Log, and Appguard's policy file. To save the event viewer log right click on the event viewer, and select save as. Save the file to your choice of location. If you are using Windows Vista or Windows 7 AppGuard's policy file can be found at users/username/appdata/roaming/blueridge networks/appguard
    The folder is hidden so you will need to enable viewing of hidden files, folders, and drives. To do this just click on any folder, and select tools from the toolbar. Then select folder option, and then select the view tab. Then select hidden files, folders, and drives. Then click apply, and ok to exit.

    The next time it happens do the following above, and send the event viewer log, and policy file in an archive to AppGuard@BlueRidgeNetworks.com with a description of the problem. Be sure to tell them your operating system specs. I always send them my Windows log files as well, but if they need them they will let you know. If you can get a screen shot of the error you are receiving that would be great to.
     
  16. garry35

    garry35 Registered Member

    Joined:
    Jan 20, 2009
    Posts:
    480
    i am using win7 x64 fully updated. the problem seems to happen with random apps mostly games, i all instances the games had been running with appguard set to high security level and any files or folders that needed excluding added as guarded apps or powerapps if needed. each time the problem happened i tried to re add any exclusions needed as shown in the log window and appguard would complain that the exclusion already existed, after deleting the appropriate exclusion and re adding as if from new the problem went away and everything worked normally.

    as stated above nothing had been added or changed and no drives been re mapped or removed, sometimes a driver had been updated but nothing else.
     
  17. shadek

    shadek Registered Member

    Joined:
    Feb 26, 2008
    Posts:
    2,538
    Location:
    Sweden
    I am not entirely sure why you would need to add games to Powerapps or even set them as Guarded.

    If you install them into system-space, there should be no worries. I play A LOT of games using Steam, running with Lockdown-mode and I never have any issues.
     
  18. garry35

    garry35 Registered Member

    Joined:
    Jan 20, 2009
    Posts:
    480
    i onkly add games as power apps after all else fails. my games are installed to a seperate drive to make backups smaller and have windows run faster.
     
  19. shadek

    shadek Registered Member

    Joined:
    Feb 26, 2008
    Posts:
    2,538
    Location:
    Sweden
    Aha! Have you tried excluding game folders from user-space? I think other harddrives than C:\ are considered user-space. That might cause the issue?
     
  20. Cutting_Edgetech

    Cutting_Edgetech Registered Member

    Joined:
    Mar 30, 2006
    Posts:
    5,694
    Location:
    USA
    I occasionally experience some strange behavior with Appguard's tray icon disappearing. When I look in windows task manager it shows AppGuardGUI.exe to be running. If I access Appguard from the programs menu then the tray icon will appear. I noticed when it happened this time I had just exited Shadow Mode with Shadow Defender which requires a reboot. I wonder if there is a connection. I'm not currently running the beta build of Appguard. I'm using Appguard stable build 3.4.2.0 I'm using Shadow Defender stable build 1.2.0.376
     

    Attached Files:

  21. BoerenkoolMetWorst

    BoerenkoolMetWorst Registered Member

    Joined:
    Dec 22, 2009
    Posts:
    4,873
    Location:
    Outer space
    Thanks, I hope it will be in the next release.
     
  22. sthmptn

    sthmptn Registered Member

    Joined:
    Jul 20, 2009
    Posts:
    44
    Just to confirm, I have seen this myself. The only specific time I can recall is when running ThunderbirdPortable via a Truecrypt volume and also FileZilla (via TC) as GUARDED APPS.

    I think one time, after (a) getting an app error, (b) trying to add as guarded, (c) getting the notification that the app was already in the list, I just closed the dialog box without re-adding it and waited. The app subsequently did start the next time I ran it.

    To be honest, I'm kind of expecting a few issues when running Tbird > TbirdPortable > TrueCrypt > USB with AppGuard on lockdown, so didn't report anything, but I have seen similar.
     
  23. Barb_C

    Barb_C Developer

    Joined:
    Jan 7, 2011
    Posts:
    1,234
    Location:
    Virginia
    Thanks for stepping in here. I appreciate it. I'm still in the middle of my move and things are crazy right now.
     
  24. Cutting_Edgetech

    Cutting_Edgetech Registered Member

    Joined:
    Mar 30, 2006
    Posts:
    5,694
    Location:
    USA
  25. jmonge

    jmonge Registered Member

    Joined:
    Mar 20, 2008
    Posts:
    13,744
    Location:
    Canada
    good program:thumb: the best of the best pound per pound :);)
     
Thread Status:
Not open for further replies.
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.