AppGuard 4.x 32/64 Bit - Releases

Discussion in 'other anti-malware software' started by Jryder54, Oct 29, 2013.

Thread Status:
Not open for further replies.
  1. justenough

    justenough Registered Member

    Joined:
    May 13, 2010
    Posts:
    1,549
    Should the Sandboxie folder in the Guarded app tab be set to read/write?
     
  2. justenough

    justenough Registered Member

    Joined:
    May 13, 2010
    Posts:
    1,549
    Is AppGuard enough to protect against CryptoLocker?
     
  3. ruinebabine

    ruinebabine Registered Member

    Joined:
    Aug 6, 2007
    Posts:
    1,096
    Location:
    QC
    Fyi, the timeout value was 15 min. after upgrading from v.3.5.
     
  4. Peter2150

    Peter2150 Global Moderator

    Joined:
    Sep 20, 2003
    Posts:
    20,590
    Yes. If you don't Sandboxie will be prevented from workinig. You might try as it does demonstrate Appguard doing it's job.

    Pete
     
  5. Peter2150

    Peter2150 Global Moderator

    Joined:
    Sep 20, 2003
    Posts:
    20,590
    I think when you do an upgrade install it keeps your old setting.
     
  6. Peter2150

    Peter2150 Global Moderator

    Joined:
    Sep 20, 2003
    Posts:
    20,590
    I would answer that yes. But it still requires a bit of planning which is wise anyway.

    First be sure critical documents are under one general folder. Then in Appguard go to the Guard Apps folder, then settings and add that folder there. Set it to deny access

    Then when you download some exe you want to test, and aren't sure of, add it to the guarded app list with the privacy setting to yes.

    So for example I just tested with a folder of PDF files. I added as I descriped with setting set to deny.

    I use acrobat Pro, and it is guarded with privacy set to no. I could read my pdf files fine. Then I set privacy to yes, and acrobat could not open these pdf files. So it works.

    Also from what I read cyrpto locker has to set a registry key. If you run it guarded it can't do that.

    Actually anytime I want to run an unknown exe file I have it on my desktop. By guarding it, it is allowed to run and I am protected. This is my standard practice.

    Pete

    PS I always run Lockdown Mode
     
    Last edited: Nov 4, 2013
  7. FleischmannTV

    FleischmannTV Registered Member

    Joined:
    Apr 7, 2013
    Posts:
    1,093
    Location:
    Germany
    On protection level "Locked Down" it should not be able to run all. On "medium" it will not be able run, if it doesn't have a digital signature. If it has a digital signature, it will run guarded and with privacy mode enabled. If it runs guarded, it will be able to encrypt everything inside user-space, except those user-space folders which have been designated as "read-only" and "deny access" (private folders).

    I don't know about digitally signed malware, so I cannot predict your chances of running into a digitally signed version of CryptoLocker.
     
  8. TomAZ

    TomAZ Registered Member

    Joined:
    Feb 27, 2010
    Posts:
    1,131
    Location:
    USA
    Not trying to take this off-topic, but what if you add NVP ERP into the equation along with AppGuard?
     
  9. ruinebabine

    ruinebabine Registered Member

    Joined:
    Aug 6, 2007
    Posts:
    1,096
    Location:
    QC
    Using now AppGuard 4, I see many blocked events in AG Activity Report.

    All seems to work ok, but it's quite a list ! o_O
    (many items make use of "rundll32.exe" and/or are part of my printer)
     
  10. Jryder54

    Jryder54 Registered Member

    Joined:
    Sep 3, 2013
    Posts:
    212
    Maybe add canon to the publisher list?
     
  11. ruinebabine

    ruinebabine Registered Member

    Joined:
    Aug 6, 2007
    Posts:
    1,096
    Location:
    QC
    Thanks for your reply but I added "Canon Inc." to the publisher list, AG continues to report all those events each time I use the printer. All Canon's DLLs are not signed if it count for something.

    (also, with ERP I have to put setting to "Trust" mode)
     
  12. pegr

    pegr Registered Member

    Joined:
    Apr 8, 2008
    Posts:
    2,280
    Location:
    UK
    I have the same problem with my Canon printer. Try adding the c:\programdata\canonbj\ijprinter\cnmwindows\canon mp250 series printer\languagemodules folder to the User-Space tab and set the Include flag to No.
     
  13. ruinebabine

    ruinebabine Registered Member

    Joined:
    Aug 6, 2007
    Posts:
    1,096
    Location:
    QC
    It works, AG does not report any blocked event for my printer now.

    Thanks much for your help pegr !
     
  14. Peter2150

    Peter2150 Global Moderator

    Joined:
    Sep 20, 2003
    Posts:
    20,590
    Since it is a social engineering thing you and you have to download it from an email attachment, no it won't. If you are silly enough to do all that you will probably allow it in NVP ERP and that as they say is that. On the other hand you can do that with Appguard and it would still protect you.

    Pete
     
  15. TomAZ

    TomAZ Registered Member

    Joined:
    Feb 27, 2010
    Posts:
    1,131
    Location:
    USA
    Hi Pete,

    What exactly happens when you set a folder to "Deny Access?" Does it literally prevent any access from that folder so you can't read from it or write to it?
     
  16. FleischmannTV

    FleischmannTV Registered Member

    Joined:
    Apr 7, 2013
    Posts:
    1,093
    Location:
    Germany
    Indeed TomAZ,

    if you deny access, you won't even be able to open the folder.
     
  17. pegr

    pegr Registered Member

    Joined:
    Apr 8, 2008
    Posts:
    2,280
    Location:
    UK
    Yes, but only for guarded applications where the Privacy flag is set to On. Unguarded applications running from System-Space and Guarded Applications where the Privacy flag is set to Off should still be able to read from the folder.
     
    Last edited: Nov 4, 2013
  18. pegr

    pegr Registered Member

    Joined:
    Apr 8, 2008
    Posts:
    2,280
    Location:
    UK
    You're welcome. :)
     
  19. mick92z

    mick92z Registered Member

    Joined:
    Apr 27, 2007
    Posts:
    548
    Location:
    Nottingham
    Hello, just got an unexpected email from Blueridge, with a new license for version 4.
    My concern is regarding Sandboxie. I am using version 4.04
    Settings are
    C:\Sandbox in user space

    memory guard exceptions
    sbiesvc.exe - read/write
    sbiectrl.exe - read
    sandboxiepcss.exe - read/write

    Guarded apps exception folder
    c:/sandbox read - write

    Will these settings work with Appguard 4 ?
    Many thanks in advance :)
     
  20. FleischmannTV

    FleischmannTV Registered Member

    Joined:
    Apr 7, 2013
    Posts:
    1,093
    Location:
    Germany
    mick92z,

    as of AppGuard 4.x memory guard exceptions are no longer needed (and no longer possible, because these settings no longer exist).

    C:\Sandbox as user-space or C:\Sandbox with read/write permissions should be enough. I think read/write permissions are only necessary, if C:\Sandbox is not designated as a user-space folder, though it doesn't hurt. Your settings should be adopted if you install the new version of AppGuard on the same machine.
     
  21. AaLF

    AaLF Registered Member

    Joined:
    Feb 20, 2005
    Posts:
    986
    Location:
    Sydney
  22. FleischmannTV

    FleischmannTV Registered Member

    Joined:
    Apr 7, 2013
    Posts:
    1,093
    Location:
    Germany
    @AaLF

    Peter2150 and I have written something at #131 /ff
     
  23. TomAZ

    TomAZ Registered Member

    Joined:
    Feb 27, 2010
    Posts:
    1,131
    Location:
    USA
    Anyone know if the little program I saw over at Softpedia (CryptoPrevent) would conflict with AppGuard?
     
  24. Tyrizian

    Tyrizian Registered Member

    Joined:
    Apr 26, 2012
    Posts:
    2,839
    Version 4 working great, Thank You :D

    Congratulations to the Blue Ridge team, for such a wonderful new release

    Keep up the good work :thumb:
     
  25. Peter2150

    Peter2150 Global Moderator

    Joined:
    Sep 20, 2003
    Posts:
    20,590
    Exactly
     
Thread Status:
Not open for further replies.
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.