AppGuard 4.x 32/64 Bit - Releases

Discussion in 'other anti-malware software' started by Jryder54, Oct 29, 2013.

Thread Status:
Not open for further replies.
  1. hjlbx

    hjlbx Guest

    I use c:\Windows\*\csc.exe. It is a lot less work for me...

    Either way will work.
     
  2. boredog

    boredog Registered Member

    Joined:
    Feb 1, 2015
    Posts:
    2,499
    i noticed today when trying to launch quietzones firefox tor browser it was blocked, so I am assuming I need to add that exe to power apps also?
     
  3. hjlbx

    hjlbx Guest

    What is the quietzone file path that was blocked ?
     
  4. boredog

    boredog Registered Member

    Joined:
    Feb 1, 2015
    Posts:
    2,499
    06/21/16 15:36:34 Prevented process <firefox.exe | c:\program files\quietzone\rqz\rvsgui.exe> from launching from <c:\programdata\quietzone\rqz\tor browser\browser>.
     
  5. hjlbx

    hjlbx Guest

    Just exclude this file path from User Space (Add to User Space list and select "No" from Yes\No drop-down menu):

    c:\programdata\quietzone\rqz\rvsgui.exe

    There might be more processes in quietzone folder that will be blocked. If there are enough, then you can exclude this file path from User Space:

    c:\programdata\quietzone\*

    For best security exclude the specific file path.

    Use Power Apps very sparingly.
     
    Last edited by a moderator: Jun 21, 2016
  6. hjlbx

    hjlbx Guest

    For Lock Down mode on W8/10, exclude

    c:\Users\user\appdata\local\temp\*\dismhost.exe,

    (where user = name you have assigned to your user profile)

    from User Space.

    Do not add it to Power Apps.
     
  7. guest

    guest Guest

    i think you mean c:\programdata\ ? Not Program Files
     
  8. hjlbx

    hjlbx Guest

    Yeah... typo. I fixed it. Thanks for pointing it out @mood.
     
  9. boredog

    boredog Registered Member

    Joined:
    Feb 1, 2015
    Posts:
    2,499
    adding to user and selecting no does not work.
    c:\program data\quietzone\rqz\rvsgui.exe

    c:\program data\quietzone\rqz\rvsgui.exe

    There might be more processes in quietzone folder that will be blocked. If there are enough, then you can exclude this file path from User Space:

    c:\program data\quietzone\*

    appguard still stops it.

    mood? I only posted the activity report appguard gave.
    06/21/16 15:36:34 Prevented process <firefox.exe | c:\program files\quietzone\rqz\rvsgui.exe> from launching from <c:\programdata\quietzone\rqz\tor browser\browser>.
     
  10. hjlbx

    hjlbx Guest

    The file path doesn't have a space between program and data; should be

    c:\programdata\quietzone\rqz\rvsgui.exe
     
    Last edited by a moderator: Jun 21, 2016
  11. guest

    guest Guest

    06/21/16 15:36:34 Prevented process <firefox.exe | c:\program files\quietzone\rqz\rvsgui.exe> from launching from <c:\programdata\quietzone\rqz\tor browser\browser>.
    rvsgui.exe (quietzone) is launching firefox.exe. But Firefox is in User-Space.
    a) Exclude c:\programdata\quietzone from User-Space (Include=No)
    b) if not already added: add c:\programdata\quietzone\rqz\tor browser\browser\firefox.exe as a Guarded App
    now firefox has to start now o_O theoretically...
     
  12. boredog

    boredog Registered Member

    Joined:
    Feb 1, 2015
    Posts:
    2,499
    "The file path doesn't have a space between program and data; should be

    c:\programdata\quietzone\rqz\rvsgui.exe"

    YES Taking the space out worked
    Thank you
     
  13. hjlbx

    hjlbx Guest

    @boredog - you have not added firefox.exe to the Guarded App list ?

    If you have not added it, then you should; browsers should always be run Guarded.
     
  14. guest

    guest Guest

    I found an additional wildcard-bug, reported it and it has been replicated from their side.
     
  15. paulderdash

    paulderdash Registered Member

    Joined:
    Dec 27, 2013
    Posts:
    4,644
    Location:
    Under a bushel ...
    Thank you, my Appguard tutors :)
     
  16. hjlbx

    hjlbx Guest

    @mood - I suppose it allows execution despite being in User Space ?
     
  17. guest

    guest Guest

    I have added a folder to User-Space, no specific executable.
    The folder itself is in System Space, i "converted" it to User-Space with Include=Yes.

    Locked Down (+wildcard) = Execution is allowed in this folder. Without wildcard = Execution blocked.
    But if i specify the executable in the user-space entry, using wildcards is fine.
     
  18. boredog

    boredog Registered Member

    Joined:
    Feb 1, 2015
    Posts:
    2,499
    "you have not added firefox.exe to the Guarded App list ?

    If you have not added it, then you should; browsers should always be run Guarded."

    even if it is quietzones version of firefox? I always thought it was run from quietzone. one thing I have not done yet is add quietzone to power apps.
     
  19. hjlbx

    hjlbx Guest

    I don't know much about Returnil. In fact, I have never used it.
     
  20. hjlbx

    hjlbx Guest

    @mood

    For C:\Any_Folder_In_System_Space\* added to User Space (Yes) the sub-objects can execute ?

    LOL... I thought BRN completely fixed the wildcard bugs.
     
  21. guest

    guest Guest

    Make several subfolders and put the * somewhere in the middle.
    c:\example\1\2 (Include=Yes)
    c:\example\*\2 (Include=Yes)
    One of them is allowing files within the folder c:\example\1\2 in Locked Down... Try it :D
     
  22. guest

    guest Guest

    And then do it within User Space, but now with Include=No.
    Programs should execute now, but they are blocked.

    User-Space Entries with * in the middle and no executable at the end doesn't seem to change anything.
    System Space stays System Space and User Space stays User Space.
     
  23. XhenEd

    XhenEd Registered Member

    Joined:
    Mar 31, 2014
    Posts:
    536
    Location:
    Philippines
    The bugs might have been fixed by 4.4.6.1. Hopefully...
     
  24. Mr.X

    Mr.X Registered Member

    Joined:
    Aug 10, 2013
    Posts:
    4,814
    Location:
    .
    May I ask where to download this new version 4.4.6.1?
     
  25. XhenEd

    XhenEd Registered Member

    Joined:
    Mar 31, 2014
    Posts:
    536
    Location:
    Philippines
    It auto-updated to me after turning on my laptop a while ago. You can probably manually check for updates now.
     
Thread Status:
Not open for further replies.
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.