AppGuard 3.x 32/64 Bit

Discussion in 'other anti-malware software' started by shadek, Mar 12, 2011.

Thread Status:
Not open for further replies.
  1. Dave53

    Dave53 Registered Member

    Joined:
    Feb 23, 2009
    Posts:
    123
    I don't know about the compatibility with RollBack RX, but as I recall you can disable MBR Guard in the AppGuard settings and then reboot. I would definitely recommend that you have a fresh image of your drive before testing these together.
     
  2. Peter2150

    Peter2150 Global Moderator

    Joined:
    Sep 20, 2003
    Posts:
    20,590
    I have no trouble with FDISR, but I don't know about Rollback type programs.
     
  3. LM1

    LM1 Registered Member

    Joined:
    Nov 7, 2004
    Posts:
    40
    I had compatibility problems with Rollback RX, but only with MBR Guard active; after permanently deactivating MBR Guard (which is of course no problem), the two programs work flawlessly together.
     
  4. Greg S

    Greg S Registered Member

    Joined:
    Mar 1, 2009
    Posts:
    1,039
    Location:
    A l a b a m a
    I have no problems with CTM or Eaz-Fix. Ever which one I'm using at the time, If I uninstall/install either or update the baseline, I will disable MBR guard then re-enable when done.
     
  5. Greg S

    Greg S Registered Member

    Joined:
    Mar 1, 2009
    Posts:
    1,039
    Location:
    A l a b a m a
    Well so much for memory, lol. I finally made it back home, updated all the girls laptops and have spent the entire weekend trying to debug and run WEI. Everytime ended in couldn't measure the storage performance. After many searches, I noticed one said that Comodo System Cleaner was a possible culprit but none of the systems have that. On a hunch, I disabled MBR, re-booted on one system and WEI worked. Man it's tough getting older and not being able to remember things. Enjoy your youth to it's fullest potential whilst you can!

    I have another issue and am wondering if MBR could be related. After installing Win 7, for months I could use the System Image Backup tool in Win 7 for making images of the hard drive. For months now, I'm not able to do it anymore. Has anyone had any issues with this and could MBR be a possibility? The errors were storage related which are false becasue the drive and destination of the image have plenty of space.
     
    Last edited: May 30, 2011
  6. Eirik

    Eirik Registered Member

    Joined:
    Oct 6, 2008
    Posts:
    544
    Location:
    Chantilly, Virginia
    Hi All,

    We're looking to do another AppGuard release soon, probably in June barring the unknown. We've not finalized features yet. In addition to a number of bug fixes, here's a sampling of what may be in the release:
    - Renaming what is currently called "High" protection mode to "Locked-Down" to better set expectations with novices that only specified applications may launch from user-space
    - Trusted Publishers whereby AppGuard will treat digitally signed items differently (e.g., let any Adobe signed (valid) installation occur)
    - add extensions to system-space (e.g., declare portions of another drive/partition where applications are installed to be treated as part of system-space such that guarded applications cannot write into these areas)
    - self-diagnostics (tray icon changes to indicate AppGuard is not operating properly, possibly due to a conflict with something else)

    Again, above list may change.

    Cheers,

    Eirik
     
  7. 1000db

    1000db Registered Member

    Joined:
    Jan 9, 2009
    Posts:
    718
    Location:
    Missouri
    There should be an option to turn off allowing digitally signed applications as some malware is being generated with seemingly valid digital signatures. I'll see if I can find an example if you need. Or will the user be able to decide who is a trusted vendor? I like the third idea; that could be helpful.
     
  8. MerleOne

    MerleOne Registered Member

    Joined:
    Mar 6, 2006
    Posts:
    1,336
    Location:
    France
    Thanks for letting us know. I would just like to add the following proposal : add some kind of learning mode, that would be optional and only activable after several warnings, so that the average user (if he/she exists...) would not bother, but advanced ones could tuneup more easily the application.
     
  9. Eirik

    Eirik Registered Member

    Joined:
    Oct 6, 2008
    Posts:
    544
    Location:
    Chantilly, Virginia
    Trusted publishers would be vendor specific: Adobe, Google, Microsoft, Apple, etc. We generally consider most web browser roots of trust as untrusted. Until I know better, we may limit this quite a bit as even legit vendors might use less than legit providers as their 'root of trust'. I haven't even seen a story-board of our implementation so I really can't get very specific yet.

    Cheers,

    Eirik
     
  10. Antarctica

    Antarctica Registered Member

    Joined:
    Feb 25, 2003
    Posts:
    2,181
    Location:
    Canada
    Thank you Eirik:) great to know that you are working hard to improve this very nice program as I am using it as my first line of defense...
     
  11. Eirik

    Eirik Registered Member

    Joined:
    Oct 6, 2008
    Posts:
    544
    Location:
    Chantilly, Virginia
    Would you please describe the problems you wish to solve with such a capability? Success is all about fleshing out the critical details.

    Thanks,

    Eirik
     
  12. guest

    guest Guest

    I have read this excellent explanation (the website lacks of it or try to make it much more easier but I didn't get it :D )

    I'm using CIS and/or Spyshelter, will appguard give me much more popups?, as far as have read is not exactly and HIPS, it's more like an flexible sandbox, but I like a lot the idea.

    It's the app in spanish?
     
  13. pegr

    pegr Registered Member

    Joined:
    Apr 8, 2008
    Posts:
    2,280
    Location:
    UK
    AppGuard is policy restriction software so you won't get any popups. It's a kind of behaviour blocker that silently blocks certain types of behaviour, depending on how the program is configured. The Events panel in the GUI will show which actions have been blocked.

    I don't know whether it is available in Spanish: That's one for Eirik or Barb to answer. The licence used to be lifetime but I'm not sure if that's still the case. :)
     
  14. guest

    guest Guest

    Thanks, but as far I understood only will block the applications for which you have configure it, no?
    So is useful to restrict browsers and something else?
     
  15. pegr

    pegr Registered Member

    Joined:
    Apr 8, 2008
    Posts:
    2,280
    Location:
    UK
    Yes, that's right. It's useful to restrict any program that can potentially be exploited by malware. That includes Internet facing applications such as browsers, email clients, instant messaging, plus programs such as office applications, media players, document viewers, etc.

    EDIT: I should have added that any programs that run from user space will automatically be guarded as will any processes that are launched by a program in the guarded applications list.
     
  16. guest

    guest Guest


    But EMET do the same thing for free, no?
    Is appguard adding something else? more protection or it's just more configurable?
    Which are the main differences?

    Thanks
     
  17. chris1341

    chris1341 Guest

    The Memory Gaurd of AppGaurd has some crossover with EMET but they are very different products designed for different purposes.

    Good explanation of EMET and its capabilities here http://www.dedoimedo.com/computers/windows-emet.html

    pegr's explanation of what AppGaurd does that you have already commented on is pretty damn comprehensive in my view.

    Basically EMET tries to limit the possibility of known or unknown expoits (or just plain poor coding) wrecking/hijacking your internet facing/EMET restricted apps.

    AppGaurd restricts the behavior of guarded apps (similar to but stronger than running LUA/SU) and will prevent unguarded apps from executing from user space. In the default mode this effectively prevents your guarded apps from dropping malware to critical/System Space and prohibits anything unguarded from executing in User Space. So if it can't write to to somewhere where it can execute and can't execute from somewhere it can write to you're pretty much covered.

    EMET, while useful, gives you none of that additional restriction and execution prevention.

    Cheers
     
    Last edited by a moderator: Jun 3, 2011
  18. jmonge

    jmonge Registered Member

    Joined:
    Mar 20, 2008
    Posts:
    13,744
    Location:
    Canada
    :thumb: good explanaTION:thumb:
     
  19. Cutting_Edgetech

    Cutting_Edgetech Registered Member

    Joined:
    Mar 30, 2006
    Posts:
    5,694
    Location:
    USA
    Is EMET available for XP Pro?
     
  20. chris1341

    chris1341 Guest

    Yes, with Service Pack 3 and above and .Net 2.0 or above installed.

    Cheers
     
  21. Dave53

    Dave53 Registered Member

    Joined:
    Feb 23, 2009
    Posts:
    123
    Hi Eirik,

    How are things going with the new release? Do you think that we will see it this month?

    Thanks!
     
  22. Kees1958

    Kees1958 Registered Member

    Joined:
    Jul 8, 2006
    Posts:
    5,857
    AppGuard is like Restriced Mode of Spyshelter. A lot of HIPS will warn you about a certain intrusion: you have the choice to allow or disallow (or auto allow when Microsoft or signed as with Spyshelter).

    When you run as Admin on Vista and Windows7, the UAC will protect you against a lot of things. AppGuard adds a Restricted Mode (to protect system space) plus deny execute (to protect user space). When you understand the sequence of events of an intrusion the only worry left is memory intrusion (via the direct way or via exploited buffer overflows). EMET reduces the risk of buffer overflow exploits, but still allows regular memory intrusions. The big plus of AppGuard is that it does not allow or deny memory intrusion for an application, but has a tuned memory intrusion protection. Most HIPS will alert you and ask you to allow memory alterations for IE9, but Appguard won't. So in that sense it offers better protection as HIPS programs since it auto allows only the memory intrusion which are normal within IE9 and auto blocks the others. Its memory protection is more granular than other HIPS programs
     
  23. jmonge

    jmonge Registered Member

    Joined:
    Mar 20, 2008
    Posts:
    13,744
    Location:
    Canada
    you think so my friend:)
     
  24. Eirik

    Eirik Registered Member

    Joined:
    Oct 6, 2008
    Posts:
    544
    Location:
    Chantilly, Virginia
    Hi Dave,

    We're looking at mid-July and I'm seeking permission from senior management to do a very brief beta or early release announced to Wilders-only because this involves a non-trivial driver change. This would take place just after the 4th of July holiday.

    Cheers,

    Eirik
     
  25. Dave53

    Dave53 Registered Member

    Joined:
    Feb 23, 2009
    Posts:
    123
    Thanks for the update Eirik!

    Dave :)
     
Thread Status:
Not open for further replies.
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.