AppGuard 4.x 32/64 Bit - Releases

Discussion in 'other anti-malware software' started by Jryder54, Oct 29, 2013.

Thread Status:
Not open for further replies.
  1. Tyrizian

    Tyrizian Registered Member

    Joined:
    Apr 26, 2012
    Posts:
    2,839
    Thank you
     
  2. Tyrizian

    Tyrizian Registered Member

    Joined:
    Apr 26, 2012
    Posts:
    2,839
    Thank you
     
  3. acr1965

    acr1965 Registered Member

    Joined:
    Oct 12, 2006
    Posts:
    4,995
    Are most people who are running AppGuard also running a real time antivirus or just on demand?
     
  4. fearlessscientist

    fearlessscientist Registered Member

    Joined:
    Sep 6, 2013
    Posts:
    166
    Location:
    USA
    I run realtime antivirus as well. IMO antivirus is absolute necessity.
     
  5. pegr

    pegr Registered Member

    Joined:
    Apr 8, 2008
    Posts:
    2,280
    Location:
    UK
    @everyone: I'd like to discuss Sandboxie a little further because it raises some interesting issues in relation to AppGuard.

    The sandbox resembles a Unix chroot jail in that it creates a virtual representation of the entire file system within a folder, with the sandbox within the parent sandbox container folder acting as the apparent root of the virtual file system.

    AppGuard splits the real file system into two spaces: system space and user space, with some folders in system space and some in user space. AppGuard can be configured to change the default behaviour, which can result in hybrid folders that are partially in system space and partially in user space in terms of AppGuard file access and application launch permissions/restrictions. Hybrid folders have a potential to slightly weaken AppGuard's drive-by download protection capability.

    With the virtual file system created by Sandboxie, the situation is different. The AppGuard file access and application launch permission/restriction applied to the sandbox container folder is automatically inherited by every sandbox sub-folder within it. The entire virtual file system will reside in system space, user space, or some hybrid combination of the two, depending on how the sandbox container folder is configured within AppGuard. This has implications if Sandboxie is used for software testing in addition to sandboxing guarded system-space applications, e.g. web browsers.

    As Sandboxie virtualization involves redirecting disk writes to a sandbox within the sandbox container folder, for Sandboxie to run guarded applications sandboxed, sandboxes must have any AppGuard write restriction removed. Whether or not this will require AppGuard configuration, depends on where the sandbox container folder is located.

    If the sandbox container folder is in its default location of c:\sandbox, it is in system space and AppGuard configuration is needed to change the folder file access permission to Read/Write, which partially puts it into user space. Unless the folder is explicitly added to the User Space tab with the include flag set to Yes, it will remain in system space in terms of application launch permission. If the sandbox container is relocated to an alternate drive, then the sandbox container folder is already fully in user space, both in terms of file access permission and application launch restriction, without AppGuard configuration.

    For any sandbox used for running guarded applications that reside in system space, e.g. web browsers, it is slightly safer if the sandbox is fully in user space. AppGuard also provides a more convenient way of handling start/run restrictions within the sandbox than using Sandboxie's own start/run feature to control execution (see post #298 above).

    For software testing, the situation is different. AppGuard's application launch restriction, if enabled, will interfere with the ability to install and test applications within a sandbox. The approach used to overcome this will partly depend on whether a separate dedicated sandbox is being used for software testing, or whether a single sandbox is being used for software testing and web browsing.

    One way is to exclude the sandbox container folder from AppGuard application launch restriction then optionally add it to any individual sandboxes used to sandbox guarded applications run from system space. If the sandbox container folder is in its default location of c:\sandbox, this means leaving it in system space in terms of application launch permission, without adding it to the User Space tab. If the sandbox container folder has been relocated to an alternate drive, the folder is added to the User Space tab with the Include flag set to No to disable application launch restriction. This assumes that multiple sandboxes are in use.

    An alternative way is to ensure that the sandbox container folder is fully in user space then disable application launch restriction from any individual sandboxes used to test software run from within the sandbox, using the method described above. This also assumes that multiple sandboxes are in use.

    A third way is to ensure that the sandbox container folder is fully in user space then use the system tray icon menu to temporarily allow user space launches in order to test software within a sandbox. This may be particularly useful for anyone using a single sandbox for multiple purposes, but would also work just as well with multiple sandboxes. This is my preferred option. To my way of thinking, this approach fits the concept of AppGuard better, as it avoids the need for hybrid folders that are neither properly in system space, nor user space; but it's just my opinion, others may disagree.
     
    Last edited: Nov 21, 2013
  6. pegr

    pegr Registered Member

    Joined:
    Apr 8, 2008
    Posts:
    2,280
    Location:
    UK
    I'm running avast! in real-time.
     
  7. iammike

    iammike Registered Member

    Joined:
    Jun 13, 2012
    Posts:
    342
    Location:
    SE Asia
    I am running Appguard together with Emsisoft AM (Real Time)
     
  8. Antarctica

    Antarctica Registered Member

    Joined:
    Feb 25, 2003
    Posts:
    2,181
    Location:
    Canada
    Same for me.;)
     
  9. stapp

    stapp Global Moderator

    Joined:
    Jan 12, 2006
    Posts:
    24,220
    Location:
    UK
    AppG and Emsisoft real time here also.
     
  10. Peter2150

    Peter2150 Global Moderator

    Joined:
    Sep 20, 2003
    Posts:
    20,590
    Neither, No AV on board. I will rarely scan with Emsisoft's Emergency Took Kit, but not offen. With SBIE, Appuard, and ExeRadarPro, I don't see the need, and my system runs better.

    Pete

    PS. Been running this way a while, and have never seen anything when I do scan.
     
  11. Barb_C

    Barb_C Developer

    Joined:
    Jan 7, 2011
    Posts:
    1,234
    Location:
    Virginia
    Have you removed it from Startup? Did that solve the problem?
     
  12. blacknight

    blacknight Registered Member

    Joined:
    Sep 25, 2007
    Posts:
    3,351
    Location:
    Europe, UE citizen
    AppGuard and ExeRadarPro together are not redundant ? And no conflict ?
     
  13. TomAZ

    TomAZ Registered Member

    Joined:
    Feb 27, 2010
    Posts:
    1,131
    Location:
    USA
    Using them together here. No conflict at all.
     
  14. Peter2150

    Peter2150 Global Moderator

    Joined:
    Sep 20, 2003
    Posts:
    20,590
    No and No.
     
  15. dja2k

    dja2k Registered Member

    Joined:
    Feb 15, 2005
    Posts:
    2,121
    Location:
    South Texas, USA
    Yes removing it solves the problem, but I have yet to find a solution to have Dropbox enabled at startup and not see that behavior.

    Warning: The event <1074003977> happened 3 times within 63 millisecond.
    Args: <C:\Users\\AppData\Roaming\Dropbox\bin\Dropbox.exe>, <C:\Windows\explorer.exe>.

    dja2k
     
    Last edited: Nov 21, 2013
  16. Overkill

    Overkill Registered Member

    Joined:
    Mar 16, 2012
    Posts:
    2,343
    Location:
    USA
    Where in AG do you add permissions to Read/Write for sbie?
     
  17. roady

    roady Registered Member

    Joined:
    Mar 27, 2005
    Posts:
    262
    Do you have to apply different settings for the SandBoxie's sandboxed webbrowser and let's say,a test folder when SandBoxie's Container folder is setup in userspace?
    I would like to run SandBoxie's sandboxed webbrowser without having to set Appguard to install mode....I only want to do that when testing apps in a sandbox.
     
  18. Peter2150

    Peter2150 Global Moderator

    Joined:
    Sep 20, 2003
    Posts:
    20,590
    Customize>guarded apps>settings. Add c:\Sandbox as a custom folder, and set type to read/write.

    Pete
     
  19. blacknight

    blacknight Registered Member

    Joined:
    Sep 25, 2007
    Posts:
    3,351
    Location:
    Europe, UE citizen

    Why rather don't use AppGuard ( or ExeRadarPro ) and a complete HIPS ?
     
  20. Barb_C

    Barb_C Developer

    Joined:
    Jan 7, 2011
    Posts:
    1,234
    Location:
    Virginia
    What OS are you running? I have installed Dropbox using standard settings and am not seeing any issue. I added Dropbox as Guarded Application in Privacy Mode and it appears to be working fine. I'm running Win 7 64-bit. I did not add any dropbox user-space exclusions. I did notice that my bootup time took a little longer after installing Dropbox, but no AppGuard Dropbox blocking events in my event log.
     
  21. Peter2150

    Peter2150 Global Moderator

    Joined:
    Sep 20, 2003
    Posts:
    20,590
    Because most of them(and there are few remaining) are a pain to use. I could care less about each and every registry event etc. Most extra stuff they monitor would not happen if the offending program couldn't run.

    I've run hips, and in fact my firewall Online Armor has a HIPS built in. It is considered a good one. I've disabled it as it is a pain to me and I don't feel I need it.
     
  22. dja2k

    dja2k Registered Member

    Joined:
    Feb 15, 2005
    Posts:
    2,121
    Location:
    South Texas, USA
    I am running Windows 8.1 x64. Its even worse for me not having it excluded in the user-space. Non-stop block entries in the AppGuard log, 1000+ and counting.

    dja2k
     
  23. Barb_C

    Barb_C Developer

    Joined:
    Jan 7, 2011
    Posts:
    1,234
    Location:
    Virginia
    I'll ask our QA department to look into this. Thanks.
     
  24. SLE

    SLE Registered Member

    Joined:
    Jun 30, 2011
    Posts:
    361
    strange. I'm on the same OS, Dropbox runs guarded - no exclusions and no log warnings here.
     
  25. FleischmannTV

    FleischmannTV Registered Member

    Joined:
    Apr 7, 2013
    Posts:
    1,093
    Location:
    Germany
    dja2k,

    did you upgrade from Windows 8 to 8.1 with AppGuard installed? I have seen some weird behaviour in that case, because I was noticing blocking events from unguarded system-space applications after the upgrade. I've uninstalled and reinstalled AppGuard and then everything was back in order.
     
Thread Status:
Not open for further replies.
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.