 |
AtGuard AtGuard Support Forum
|
| View previous topic :: View next topic |
| Author |
Message |
Bill_MI AtGuard User

Joined: 10 Apr 2006 Posts: 30 Location: Michigan, USA
|
Posted: Wed Jun 28, 2006 12:07 pm Post subject: Completely disabling AtGuard using AUTORUNS |
|
|
SysInternals has a slick little utility (AUTORUNS) to view and disable any driver/service/app running at startup. I've used it successfully to disable several things but AtGuard is elusive. The IAMAPP.EXE runs regardless of settings (though AtGuard seems to be totally disabled). Anyone successful? Any clues what's starting iamapp.exe?
Sure enough, this technique has proved AtGuard is responsible for doing something with Steve Gibson's menu research - the problem disappears with AtGuard disabled this way (only). All web filters are normally OFF and no combo of disabling AtGuard by normal means clears up this problem - as long as drivers are running.
On a secondary note, if you're running Firefox 1.5.0.4 and AtGuard 3.22.11 on Win2K/SP4 with tcpip.sys 5267 what do YOU see at: http://www.grc.com/grcmenu.htm under the Freeware menu? The Utilities text screwed up? I have two machines doing the same thing and AtGuard is 99% suspect. Steve is playing a lot with coding so this problem may not last.
Here's the (7) things that are disabled in AUTORUNS that causes that page to work properly:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
iamapp IAMAPP.EXE (Not verified) WRQ, Inc. c:\program files\atguard\iamapp.exe
BUT IT STILL RUNS!!!???
HKLM\System\CurrentControlSet\Services
iamServ IAMSERV.EXE (Not verified) WRQ, Inc. c:\program files\atguard\iamserv.exe
HKLM\System\CurrentControlSet\Services
DNSFILT AtGuard DNS Filter (Not verified) WRQ, Inc. c:\program files\atguard\dnsfilt.sys
FWFILT AtGuard Firewall Filter (Not verified) WRQ, Inc. c:\program files\atguard\fwfilt.sys
HTTPFILT AtGuard HTTP Filter (Not verified) WRQ, Inc. c:\program files\atguard\httpfilt.sys
Iamdrv AtGuard Filter (Not verified) WRQ, Inc. c:\program files\atguard\iamdrv.sys
NDISFILT c:\program files\atguard\ndisfilt.sys
On a tertiary note - it sure would be nice to be abe to *completely* disable AtGuard (even if it takes a reboot like this does). It's golden as a debug tool and proven over and over that just drivers loaded affects things. _________________ Expert Opinions $5 ... Shut Up $10 |
|
| Back to top |
|
 |
Bill_MI AtGuard User

Joined: 10 Apr 2006 Posts: 30 Location: Michigan, USA
|
Posted: Sat Jul 22, 2006 7:46 pm Post subject: |
|
|
If anyone's interested, I FOUND THE PROBLEM. It has to do with SysInternal's AUTORUNS program having an apparent deficiency.
AUTORUNS tries to hide programs from running in this registry key:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
...by hiding such disabled entries in the created key:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\AutorunsDisabled
Well, this o/s (Win2K/SP4 up-to-date) RUNS IT ANYWAY!!! I proved this by intentionally breaking this entry and that makes all the difference.
This is just a curiosity since running iamapp.exe with no drivers doesn't hurt anything - it just bugged me why a disabled program ran to begin with.
Now, back to the AtGuard 3.3 wait.  _________________ Expert Opinions $5 ... Shut Up $10 |
|
| Back to top |
|
 |
Bill_MI AtGuard User

Joined: 10 Apr 2006 Posts: 30 Location: Michigan, USA
|
Posted: Tue Oct 31, 2006 5:59 pm Post subject: |
|
|
Again (if anyone's interested), I found an issue with this technique. Perhaps someone with more knowledge how Windows hooks and dependencies work could enlighten me more. It boils down to this...
Because I've used Autoruns to disable a driver, I create the following System Error:
| Quote: | The DHCP Client service depends on the Iamdrv service which failed to start because of the following error:
The service cannot be started, either because it is disabled or because it has no enabled devices associated with it. |
First, the DHCP client service does NOT list such a dependency - yet the system knows it's there. Curious.
Second, I never saw any result of this because I never use DHCP on my LAN machines. However, it directly relates to flaky DHCP behavior on my notebook computer.
Oh well, when you klooge things it's not unexpected.  _________________ Expert Opinions $5 ... Shut Up $10 |
|
| Back to top |
|
 |
|
|
You cannot post new topics in this forum You cannot reply to topics in this forum You cannot edit your posts in this forum You cannot delete your posts in this forum You cannot vote in polls in this forum
|
phpBB © 2001, 2002 phpBB Group
|