AtGuard Forum Index AtGuard
AtGuard Support Forum
 
 FAQFAQ   SearchSearch   MemberlistMemberlist   UsergroupsUsergroups   RegisterRegister 
 ProfileProfile   Log in to check your private messagesLog in to check your private messages   Log inLog in 

Completely disabling AtGuard using AUTORUNS

 
Post new topic   Reply to topic    AtGuard Forum Index -> Installation
View previous topic :: View next topic  
Author Message
Bill_MI
AtGuard User
AtGuard User


Joined: 10 Apr 2006
Posts: 30
Location: Michigan, USA

PostPosted: Wed Jun 28, 2006 12:07 pm    Post subject: Completely disabling AtGuard using AUTORUNS Reply with quote

SysInternals has a slick little utility (AUTORUNS) to view and disable any driver/service/app running at startup. I've used it successfully to disable several things but AtGuard is elusive. The IAMAPP.EXE runs regardless of settings (though AtGuard seems to be totally disabled). Anyone successful? Any clues what's starting iamapp.exe?

Sure enough, this technique has proved AtGuard is responsible for doing something with Steve Gibson's menu research - the problem disappears with AtGuard disabled this way (only). All web filters are normally OFF and no combo of disabling AtGuard by normal means clears up this problem - as long as drivers are running.

On a secondary note, if you're running Firefox 1.5.0.4 and AtGuard 3.22.11 on Win2K/SP4 with tcpip.sys 5267 what do YOU see at: http://www.grc.com/grcmenu.htm under the Freeware menu? The Utilities text screwed up? I have two machines doing the same thing and AtGuard is 99% suspect. Steve is playing a lot with coding so this problem may not last.

Here's the (7) things that are disabled in AUTORUNS that causes that page to work properly:

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
iamapp IAMAPP.EXE (Not verified) WRQ, Inc. c:\program files\atguard\iamapp.exe
BUT IT STILL RUNS!!!???

HKLM\System\CurrentControlSet\Services
iamServ IAMSERV.EXE (Not verified) WRQ, Inc. c:\program files\atguard\iamserv.exe

HKLM\System\CurrentControlSet\Services
DNSFILT AtGuard DNS Filter (Not verified) WRQ, Inc. c:\program files\atguard\dnsfilt.sys
FWFILT AtGuard Firewall Filter (Not verified) WRQ, Inc. c:\program files\atguard\fwfilt.sys
HTTPFILT AtGuard HTTP Filter (Not verified) WRQ, Inc. c:\program files\atguard\httpfilt.sys
Iamdrv AtGuard Filter (Not verified) WRQ, Inc. c:\program files\atguard\iamdrv.sys
NDISFILT c:\program files\atguard\ndisfilt.sys

On a tertiary note - it sure would be nice to be abe to *completely* disable AtGuard (even if it takes a reboot like this does). It's golden as a debug tool and proven over and over that just drivers loaded affects things.
_________________
Expert Opinions $5 ... Shut Up $10
Back to top
View user's profile Send private message
Bill_MI
AtGuard User
AtGuard User


Joined: 10 Apr 2006
Posts: 30
Location: Michigan, USA

PostPosted: Sat Jul 22, 2006 7:46 pm    Post subject: Reply with quote

If anyone's interested, I FOUND THE PROBLEM. It has to do with SysInternal's AUTORUNS program having an apparent deficiency.

AUTORUNS tries to hide programs from running in this registry key:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

...by hiding such disabled entries in the created key:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\AutorunsDisabled

Well, this o/s (Win2K/SP4 up-to-date) RUNS IT ANYWAY!!! I proved this by intentionally breaking this entry and that makes all the difference.

This is just a curiosity since running iamapp.exe with no drivers doesn't hurt anything - it just bugged me why a disabled program ran to begin with.

Now, back to the AtGuard 3.3 wait. Very Happy
_________________
Expert Opinions $5 ... Shut Up $10
Back to top
View user's profile Send private message
Bill_MI
AtGuard User
AtGuard User


Joined: 10 Apr 2006
Posts: 30
Location: Michigan, USA

PostPosted: Tue Oct 31, 2006 5:59 pm    Post subject: Reply with quote

Again (if anyone's interested), I found an issue with this technique. Perhaps someone with more knowledge how Windows hooks and dependencies work could enlighten me more. It boils down to this...

Because I've used Autoruns to disable a driver, I create the following System Error:

Quote:
The DHCP Client service depends on the Iamdrv service which failed to start because of the following error:
The service cannot be started, either because it is disabled or because it has no enabled devices associated with it.


First, the DHCP client service does NOT list such a dependency - yet the system knows it's there. Curious. Shocked

Second, I never saw any result of this because I never use DHCP on my LAN machines. However, it directly relates to flaky DHCP behavior on my notebook computer.

Oh well, when you klooge things it's not unexpected. Wink
_________________
Expert Opinions $5 ... Shut Up $10
Back to top
View user's profile Send private message
Display posts from previous:   
Post new topic   Reply to topic    AtGuard Forum Index -> Installation All times are GMT
Page 1 of 1

 
Jump to:  
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum


phpBB © 2001, 2002 phpBB Group