AppGuard 4.x 32/64 Bit - Releases

Discussion in 'other anti-malware software' started by Jryder54, Oct 29, 2013.

Thread Status:
Not open for further replies.
  1. Lockdown

    Lockdown Registered Member

    Joined:
    Oct 28, 2016
    Posts:
    772
    Location:
    Wilders Security
    Please post recurring messages you want to ignore.
     
  2. Peter2150

    Peter2150 Global Moderator

    Joined:
    Sep 20, 2003
    Posts:
    20,590
    This was a sample. So far 79 today. Thanks, Pete


    03/21/17 14:00:01 Prevented process <schtasks.exe> from launching from <\Device\HarddiskVolume1\windows\system32>.
    03/21/17 12:05:07 Prevented <Microsoft Outlook> from writing to <\registry\machine\software\wow6432node\microsoft\windows\currentversion\internet settings\zonemap>.
    03/21/17 12:05:07 Prevented <Microsoft Outlook> from writing to <\registry\machine\software\wow6432node\redemption>.
    03/21/17 12:05:07 Prevented process <Microsoft Outlook> from writing to <c:\xlog\pdfmnoutlook_log\pdfmoutlooklog.txt>.
    03/21/17 12:03:11 Prevented <Microsoft Outlook> from writing to <\registry\machine\software\wow6432node\redemption>.
    03/21/17 12:03:10 Prevented process <Microsoft Outlook> from writing to <c:\xlog\pdfmnoutlook_log\pdfmoutlooklog.txt>.
    03/21/17 12:03:08 Prevented <Microsoft Outlook> from writing to <\registry\machine\software\wow6432node\microsoft\windows\currentversion\internet settings\zonemap>.
    03/21/17 11:16:33 Prevented <Microsoft Outlook> from writing to <\registry\machine\software\wow6432node\redemption>.
    03/21/17 11:14:36 Prevented <Microsoft Outlook> from writing to <\registry\machine\software\wow6432node\redemption>.
    03/21/17 11:14:20 Prevented <Microsoft Outlook> from writing to <\registry\machine\software\wow6432node\redemption>.
    03/21/17 11:12:36 Prevented <Microsoft Outlook> from writing to <\registry\machine\software\wow6432node\redemption>.
    03/21/17 11:11:35 Prevented <Microsoft Outlook> from writing to <\registry\machine\software\wow6432node\redemption>.
    03/21/17 11:09:50 Prevented <Microsoft Outlook> from writing to <\registry\machine\software\wow6432node\redemption>.
    03/21/17 10:02:50 Prevented <Microsoft Excel> from writing to <\registry\machine\software\wow6432node\microsoft\windows\currentversion\internet settings\zonemap>.
     
  3. Lockdown

    Lockdown Registered Member

    Joined:
    Oct 28, 2016
    Posts:
    772
    Location:
    Wilders Security
    Did you add or did you try to add anything to Ignore Messages on the Alerts tab ?

    The reason I ask is that this one is already in the default Ignore Messages - so it should not appear in the Activity Report:

    03/21/17 14:00:01 Prevented process <schtasks.exe> from launching from <\Device\HarddiskVolume1\windows\system32>.

    The Ignore Messages is flaky at the moment. If you tick "For all users" it might cause an Ignore Messages and alerts breakage. Once that breakage happens, alerts for schtasks and wmic will appear - which by default are suppressed. The only way to fix it is to re-install AppGuard.
     
  4. Peter2150

    Peter2150 Global Moderator

    Joined:
    Sep 20, 2003
    Posts:
    20,590
    Okay thanks Jeff. Who knows what I may have done. Can I pull out the policy file uninstall and reinstall pop the policy file back in and will that fix it. Also could you post an example on one of them of how to correctly do the ignore message.
     
  5. boredog

    boredog Registered Member

    Joined:
    Feb 1, 2015
    Posts:
    2,499
    Pete

    I think you just write click on the message and select ignore message. that is how I have been doing it but could be wrong.
     
  6. Lockdown

    Lockdown Registered Member

    Joined:
    Oct 28, 2016
    Posts:
    772
    Location:
    Wilders Security
    Would you please move to PM ?... it will be better troubleshooting first before jumping straight to the nuclear option.
     
  7. Lockdown

    Lockdown Registered Member

    Joined:
    Oct 28, 2016
    Posts:
    772
    Location:
    Wilders Security
    Yes. That is the way to do it. Just don't tick the setting option "For all users."
     
  8. guest

    guest Guest

    I always set Ignore Messages to "For All Users", but i haven't seen any breakage yet :cautious:
     
  9. Lockdown

    Lockdown Registered Member

    Joined:
    Oct 28, 2016
    Posts:
    772
    Location:
    Wilders Security
    Enabling that setting might or might not cause a breakage. It's willy-nilly. In v. 4.4.6.1 I could always manage to cause a breakage. And I know there has been nothing done to the Ignore Messages module internally for 5.2.9.1. So it could happen on 5.2.9.1 tool.
     
  10. guest

    guest Guest

    Ok. I rarely add something to Ignored Messages. I have added less than 10 Ignored Messages after installation, maybe i was only lucky to be not affected from this.
     
  11. Lockdown

    Lockdown Registered Member

    Joined:
    Oct 28, 2016
    Posts:
    772
    Location:
    Wilders Security
    At this time, as far as I am aware, BRN is not doing giveaways. Besides, the giveaway header states that they are giving away version 5, but what they are actually giving away is 4.4.6.1 AppGuard Pro - as explained towards the bottom. 4.4.6.1 is End-of-Life !!

    "For this giveaway Blue Ridge Networks Product Management has provided us 5 licenses for AppGuard Professional ver4.4.6.1 which as explained above is a "lifetime license". The winners can avail of upgrades to version 5.2 via a special link that will be provided by Blue Ridge Networks Product Management. The information will be made available to the winners."

    However, they could be using old 4.4.6.1 license keys that were never issued\activated.

    Also, it is possible that I was not informed of this giveaway by BRN operations.

    I am checking, but at this moment in time - until I obtain official BRN operations confirmation - I can't say anything about the legitimacy of the giveaway.
     
    Last edited: Mar 21, 2017
  12. Lockdown

    Lockdown Registered Member

    Joined:
    Oct 28, 2016
    Posts:
    772
    Location:
    Wilders Security
    I don't know if it is legit or something else. Waiting for confirmation. I edited my initial post about the giveaway. Please re-read it.
     
  13. guest

    guest Guest

    Some days ago i terminated the service of AG to find out what will happen :isay:, and then i got a complete lockdown of the system, no new processes couldn't be spawned.
    Is this some kind of self-protection of AG?
     
  14. guest

    guest Guest

    you didn't did it today? because someone mentioned it in another popular thread :p

    AG Enterprise's self-protection is functioning the way you described, for the home user version, i didn't tried; so i believe it is the same based from your description.
     
  15. boredog

    boredog Registered Member

    Joined:
    Feb 1, 2015
    Posts:
    2,499
    Did you have to do a hard boot to get back control of your system?
     
  16. boredog

    boredog Registered Member

    Joined:
    Feb 1, 2015
    Posts:
    2,499
    AppGuardSetup-4-4-6-1.exe: Stopped AG service via task manager. Locked PC down. Could still right click on a few tray programs and access but all desktop stuff was locked.
     
  17. Peter2150

    Peter2150 Global Moderator

    Joined:
    Sep 20, 2003
    Posts:
    20,590
    Hmm Kill the GUI had no effect. Couldn't stop anything via taskmanager
     
  18. boredog

    boredog Registered Member

    Joined:
    Feb 1, 2015
    Posts:
    2,499
    Peter you have to try ending the service more then once, maybe two or three times.
     
  19. Peter2150

    Peter2150 Global Moderator

    Joined:
    Sep 20, 2003
    Posts:
    20,590
    5 attempts good enough. Didn't kill
     
  20. Peter2150

    Peter2150 Global Moderator

    Joined:
    Sep 20, 2003
    Posts:
    20,590
    Let me ask. How would something get on my machine to kill it with task manager
     
  21. boredog

    boredog Registered Member

    Joined:
    Feb 1, 2015
    Posts:
    2,499
    that is the same issue as I understand it on the Voodoo thread. Shut down Voodoo service via task manager. Right?
    and it could be you are on a different OS?
     
  22. Peter2150

    Peter2150 Global Moderator

    Joined:
    Sep 20, 2003
    Posts:
    20,590
    Yes, and I am on Win 7
     
  23. boredog

    boredog Registered Member

    Joined:
    Feb 1, 2015
    Posts:
    2,499
    ah ok. win 10 here and funny I can get AG to lockdown but not Voodoo. Seems just the opposite for you.
     
  24. Lockdown

    Lockdown Registered Member

    Joined:
    Oct 28, 2016
    Posts:
    772
    Location:
    Wilders Security
    Kill AppGuardAgent.exe (the service), and AppGuard's proprietary protection locks the system down - requiring a hard shutdown.

    That's the only detail I will confirm.
     
  25. Peter2150

    Peter2150 Global Moderator

    Joined:
    Sep 20, 2003
    Posts:
    20,590
    Hmm. It doesn't let me kill the AppGuardAgent.exe
     
Thread Status:
Not open for further replies.
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.