AppGuard 4.x 32/64 Bit - Releases

Discussion in 'other anti-malware software' started by Jryder54, Oct 29, 2013.

Thread Status:
Not open for further replies.
  1. itman

    itman Registered Member

    Joined:
    Jun 22, 2010
    Posts:
    8,410
    Location:
    U.S.A.
  2. Lockdown

    Lockdown Registered Member

    Joined:
    Oct 28, 2016
    Posts:
    772
    Location:
    Wilders Security
    Are you looking for this ?:

    https://www.appguard.us/personal#purchase
     
  3. itman

    itman Registered Member

    Joined:
    Jun 22, 2010
    Posts:
    8,410
    Location:
    U.S.A.
  4. XhenEd

    XhenEd Registered Member

    Joined:
    Mar 31, 2014
    Posts:
    536
    Location:
    Philippines
    Lately, my MS Word couldn't start stating, "Sorry, something went wrong and Word was unable to start." I'm not sure if AppGuard is the cause, since it doesn't have any block messages about MS Word apart from the usual block messages of MemWrite. Only MS Word has this problem. Only system restarts solves this.
    • Windows version: Windows 10 Home Single Language
    • Windows 64-bit
    • Office365 32-bit
    • AppGuard Protected
    • AppGuard v4.4.6.1
     
  5. Lockdown

    Lockdown Registered Member

    Joined:
    Oct 28, 2016
    Posts:
    772
    Location:
    Wilders Security
    I have seen similar issue, but re-starting WinWord.exe fixed the issue and it worked OK afterwards.

    The few reports state it happens with Outlook, Excel and Word. Sometimes with only one program, sometimes with more than one.

    @XhenEd did you see any strange HKLM registry write blocks in Activity Report ?

    @XhenEd please keep me posted. If you should encounter anything else, then please let me know.
     
    Last edited: Jul 23, 2017
  6. XhenEd

    XhenEd Registered Member

    Joined:
    Mar 31, 2014
    Posts:
    536
    Location:
    Philippines
    I'll keep you posted, @Lockdown. :) I'll inform you if the error occurs again. :)
     
  7. Cutting_Edgetech

    Cutting_Edgetech Registered Member

    Joined:
    Mar 30, 2006
    Posts:
    5,654
    Location:
    USA
    Word would not start for me either 2 days ago. I tried restarting Word several time, but it would not start. I received an error message from Word, but I don't remember what the error message was now. I had to save all my work, and reboot my computer. After rebooting the problem when away.

    AppGuard reported blocking Word from writing to it's own memory space. Below is my AppGuard Report, but it really doesn't show any details. It shows the blocks occurring, but you can't see the paths, or the executable names so it want be much help. Those process ID blocks occurred right after attempting to open Word. It would have been really helpful if it would have given me a process name instead. I tried opening Excel also during this period, and it was blocked also.
     

    Attached Files:

  8. Cutting_Edgetech

    Cutting_Edgetech Registered Member

    Joined:
    Mar 30, 2006
    Posts:
    5,654
    Location:
    USA
    I have been using AppGuard, and Eset together since AppGuard version 1. I have not experienced any conflicts, but I don't tinker with Eset HIPS much.
     
  9. newyorkjet

    newyorkjet Registered Member

    Joined:
    Jan 17, 2013
    Posts:
    63
    Location:
    UK
    I get the same as Cutting_Edgetech.

    Again it started two or three days ago with Appguard blocking Word writing to it's own memory space. Word works in safe mode. Excel works OK (at the moment) without any intervention.

    Win 10 64 F-Secure Hitmanpro Alert Appguard 4.4.6.1.
     
  10. Mr.X

    Mr.X Registered Member

    Joined:
    Aug 10, 2013
    Posts:
    4,050
    Location:
    Mexico
    What's the complete version number of latest AppGuard 5.x?
     
  11. illumination

    illumination Guest

    5.2.9.1
     
  12. Mr.X

    Mr.X Registered Member

    Joined:
    Aug 10, 2013
    Posts:
    4,050
    Location:
    Mexico
    Thank you.
     
  13. Lockdown

    Lockdown Registered Member

    Joined:
    Oct 28, 2016
    Posts:
    772
    Location:
    Wilders Security
    The unresolved PID issue is never going to change because of Windows APIs. It is what it is.

    We are looking for Activity Report entries that show blocked registry writes by any Microsoft Office program.

    Microsoft Office is flaky and the installer\updates will sometimes generate various errors.

    What was reported is after an Office update, Outlook or Excel or Word would not launch and there would be blocked registry write events in the Activity Report. For example, Outlook was prevented from writing to somewhere in HKLM.
     
  14. Lockdown

    Lockdown Registered Member

    Joined:
    Oct 28, 2016
    Posts:
    772
    Location:
    Wilders Security
    Did any Microsoft Office program fail to start or would not function correctly ?

    What exactly was reported in the Activity Report ? Please post the log here.

    Were there any blocked registry writes in the Activity Report by a Microsoft Program ?
     
  15. Cutting_Edgetech

    Cutting_Edgetech Registered Member

    Joined:
    Mar 30, 2006
    Posts:
    5,654
    Location:
    USA
    Microsoft Word would not start at all. I received an error message when I attempted to launch Word. I don't remember what the error message said. I also was unable to launch Excel, and received the same error message.

    You can look at my Activity Report that I attached with my Initial post above. Each time I attempted to launch Word AppGuard blocked Word from writing to it's own memory, and also blocked some process ID's from writing to the memory of another Process ID.

    I didn't see any registry blocked associated with Word, but I think I may have seen that occur in the past.
     
  16. Cutting_Edgetech

    Cutting_Edgetech Registered Member

    Joined:
    Mar 30, 2006
    Posts:
    5,654
    Location:
    USA
    Here is my AppGuard Activity Report in case the log file is not working for you above. It does not work above unless you click on the text part of the attachment.
    Code:
    07/20/17 19:03:17 Protection level is set to <locked down>.
    
    07/20/17 19:12:09 Prevented process <RealPlayer> from writing to <c:\rpstartuptime.txt>.
    
    07/20/17 19:13:43 Prevented process <pid: 7044> from writing to <c:\rpstartuptime.txt>.
    
    07/20/17 23:39:18 Prevented process <Adobe Reader and Acrobat Manager> from writing to <c:\program files (x86)\common files\adobe\arm\1.0\temp>.
    
    07/20/17 23:41:07 Prevented process <pid: 5860> from writing to <c:\program files (x86)\common files\adobe\arm\1.0\temp>.
    
    07/21/17 00:23:25 Prevented <Microsoft Word> from writing to memory of <Microsoft Word>.
    
    07/21/17 00:23:27 Prevented <Windows Problem Reporting> from reading memory of <Windows Explorer>.
    
    07/21/17 00:24:23 Prevented <Microsoft Word> from writing to memory of <Microsoft Word>.
    
    07/21/17 00:25:08 Prevented <pid: 1052> from reading memory of <Windows Explorer>.
    
    07/21/17 00:25:08 Prevented <pid: 5816> from writing to memory of <pid: 6416>.
    
    07/21/17 00:26:14 Prevented <pid: 9712> from writing to memory of <pid: 6056>.
    
    07/21/17 00:28:17 Prevented <Microsoft Word> from writing to memory of <Microsoft Word>.
    
    07/21/17 00:30:05 Prevented <pid: 7304> from writing to memory of <pid: 4804>.
    
    07/21/17 00:30:17 Protection level is set to <off>.
    
    07/21/17 00:30:29 Protection level is set to <locked down>.
    
    
     
  17. Lockdown

    Lockdown Registered Member

    Joined:
    Oct 28, 2016
    Posts:
    772
    Location:
    Wilders Security
    There is no useful infos in the above log. I would need to see the Microsoft Office error message.
     
  18. Cutting_Edgetech

    Cutting_Edgetech Registered Member

    Joined:
    Mar 30, 2006
    Posts:
    5,654
    Location:
    USA
    Yeah, I know lol That's what i was saying in my initial post. I will see what information I can capture when it happens again. I was trying to finish a couple of assignments when it happened, and was in a rush. I don't think the error message will help a lot either though. I will also see if an application crash dump is created. When I have time I will see if anything was logged in any of the numerous Windows Log files.
     
  19. Lockdown

    Lockdown Registered Member

    Joined:
    Oct 28, 2016
    Posts:
    772
    Location:
    Wilders Security
    I am trying to develop an easy way for consumer users to track and report this issue. Since registry writes to HKLM are suppressed in Ignore Messages, that ignore message along with the ones for at.exe, schtasks.exe, and wmic.exe would have to be disabled too. Currently we are trying to replicate in Enterprise. I will post something back here as I have seen various Office error messages saying this or that had an error, but I have always been able to close the program and then relaunch it without issue.

    What Version and bitness of Windows are you using ?

    We only have reports for x86 Windows.
     
  20. Cutting_Edgetech

    Cutting_Edgetech Registered Member

    Joined:
    Mar 30, 2006
    Posts:
    5,654
    Location:
    USA
    I'm using Windows 10 Professional Version 1607 Build 14393.1480, Microsoft Office 365 ProPlus Version 1706 Build 8229.2086, and Microsoft Visio 2016 Version 1706 Build 8229.2086.

    OfficeClicktoRun.exe is being blocked from doing whatever it does quite often. Every time its blocked Microsoft dials out for error reporting. It does not appear in my log above though. The problem started with the blocked entry below which I know is not help.

    07/21/17 00:30:05 Prevented <pid: 7304> from writing to memory of <pid: 4804>.
     
  21. Lockdown

    Lockdown Registered Member

    Joined:
    Oct 28, 2016
    Posts:
    772
    Location:
    Wilders Security
    x86 or x64 ?
     
  22. Cutting_Edgetech

    Cutting_Edgetech Registered Member

    Joined:
    Mar 30, 2006
    Posts:
    5,654
    Location:
    USA
    Opps, sorry! X64
     
  23. Lockdown

    Lockdown Registered Member

    Joined:
    Oct 28, 2016
    Posts:
    772
    Location:
    Wilders Security
    @XhenEd, @Cutting_Edgetech, @newyorkjet

    Set AppGuard permanently to OFF for as long as it takes for Office to update once or twice. If anything doesn't work with AppGuard set to OFF, then it isn't AppGuard.

    Or better yet, completely uninstall AppGuard and see if the Office program issues persist over a few weeks without AppGuard installed. Microsoft has released official advisories about a wide range of similar issues with Office365 2016 all versions and Office 2016 all versions.
     
  24. Peter2150

    Peter2150 Global Moderator

    Joined:
    Sep 20, 2003
    Posts:
    20,590
    Weren't there some issues with the newer versions of Office updates this past month. I know there were issues with Outlook
     
  25. Lockdown

    Lockdown Registered Member

    Joined:
    Oct 28, 2016
    Posts:
    772
    Location:
    Wilders Security
    @Peter2150 - this request is extremely important. Can you point me to any online reference - especially an official MS one ?
     
Thread Status:
Not open for further replies.
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.