AppGuard 4.x 32/64 Bit - Releases

Discussion in 'other anti-malware software' started by Jryder54, Oct 29, 2013.

Thread Status:
Not open for further replies.
  1. FleischmannTV

    FleischmannTV Registered Member

    Joined:
    Apr 7, 2013
    Posts:
    1,093
    Location:
    Germany
    In AppGuard go to Customize, then Guarded Apps tab and Add Programm. You can leave MemWrite and MemRead set to On, but might want to set Privacy to Off. I don't know the programm but it seems to be some kind of file search engine for your pc. If you have designated folders under Guarded Apps with Deny Access, it might not be able to find files which are located in these folders.
     
  2. justenough

    justenough Registered Member

    Joined:
    May 13, 2010
    Posts:
    1,549
    I try not to duplicate security processes, so I'm interested which other specific programs or types of programs you'd consider AppGuard to be a good-to-excellent replacement for?
     
  3. Peter2150

    Peter2150 Global Moderator

    Joined:
    Sep 20, 2003
    Posts:
    20,590

    I added a folder to user space that was already in user space.

    Pete
     
  4. FleischmannTV

    FleischmannTV Registered Member

    Joined:
    Apr 7, 2013
    Posts:
    1,093
    Location:
    Germany
    The question is not aimed at me, but maybe I can offer you my opinion as well.

    I consider AppGuard a replacement for:

    • Realtime Anti-Virus
      because, if the system is clean, system-space cannot be compromised by guarded apps and drive-by downloads won't start. Anything else can be scanned on demand.
    • HIPS
      because it blocks unwanted action right away and does not prompt the user. If I want to change anything intentionally, I can lower the protection level.
    • Anti-Executable
      because, depending on protection level, it will block all launches from user-space and guarded apps cannot drop an executable in system-space to launch it from there. An Anti-Executable is only beneficial, if you really want to manually control launches from system-space.
    • Exploit Payload Protection
      Many anti-exploit programs or so called features of security suites do not really mitigate the exploitation attempt but chime in at the time of the payload download or execution, so they are really only smart anti-executables and regarding anti-executables see above

    Further, AppGuard also provides additional protection if a process is taken over. Many security programs regard a process like your browser as trusted, because the program itself is not malware. But they ignore the fact that the browser itself might be taken over and do the deed a separate dedicated malware executable would do. Yet I am not sure how exactly each AV or HIPS would react, if a trusted process starts to act suspicously.
     
  5. acr1965

    acr1965 Registered Member

    Joined:
    Oct 12, 2006
    Posts:
    4,995
    that seemed to work, thanks
    privacy is off mem read /write are on
     
  6. justenough

    justenough Registered Member

    Joined:
    May 13, 2010
    Posts:
    1,549
    That's very helpful FleischmannTV, thank you for the list and the explanations. I hadn't realized how much territory AppGuard can cover.
     
  7. Overkill

    Overkill Registered Member

    Joined:
    Mar 16, 2012
    Posts:
    2,343
    Location:
    USA

    In my experience, when AG and ERP is installed I never get alerts from ERP only AG o_O
     
  8. Peter2150

    Peter2150 Global Moderator

    Joined:
    Sep 20, 2003
    Posts:
    20,590
    I get alerts, as it is mainly when I am installing something so I have to drop Appguard to install. Then ERP kicks in. With Appguard at Lockdown, nothing much that would trigger ERP can happen.

    Pete
     
  9. Overkill

    Overkill Registered Member

    Joined:
    Mar 16, 2012
    Posts:
    2,343
    Location:
    USA
    I never had alerts when they were both installed, I have no clue why so I had to get rid of ERP.
     
  10. TomAZ

    TomAZ Registered Member

    Joined:
    Feb 27, 2010
    Posts:
    1,131
    Location:
    USA
    Do you also think this guards against the the whole "CryptoLocker" thing?
     
  11. pegr

    pegr Registered Member

    Joined:
    Apr 8, 2008
    Posts:
    2,280
    Location:
    UK
    On its default settings, ERP automatically allows launches from Program Files and Windows folders, which duplicates the way AppGuard works. IMO the point of using an AE alongside AppGuard is to monitor system space launches, so it may be better to configure ERP to do this when using ERP and AppGuard together.
     
  12. Peter2150

    Peter2150 Global Moderator

    Joined:
    Sep 20, 2003
    Posts:
    20,590
    Ironically, I managed to find this beast for real tonight. Never had a chance to see what Appguard would do. Never got past Sandboxie.

    Pete
     
  13. pegr

    pegr Registered Member

    Joined:
    Apr 8, 2008
    Posts:
    2,280
    Location:
    UK
    IMO this is a perfectly valid point of view, and I have said previously that if I were forced to use just one security application it would be AppGuard. Fortunately, that isn't the case though. Personally, I don't believe in the all-eggs-in-one-basket approach. I prefer a layered security, so that if one layer fails another layer may succeed in containing an attack.

    BRN themselves have never marketed AppGuard as a replacement for AV, as evidenced by the following quote from their website:

    "...buy the time you need for traditional signature-based anti-virus software to delete or quarantine the malware without fear of network compromise before their job is done."

    If anyone is using AppGuard on its own for real-time protection, it would be prudent to run regular on-demand AV scans to ensure that any malware that may be lurking in user space is removed. You may be hinting at that because you did say you consider AppGuard a replacement for real-time AV, not for AV per se.

    For users who don't want to use real-time AV, AppGuard works well with other security aproaches: AE, HIPS, application sandboxes, light virtualization, etc. My own preference is virtualization because there is no duplication with policy restriction. Even if malware did get past AppGuard, it would still have to escape the application sandbox or bypass the virtualized system before the real system can be touched. Virtualization ensures complete remediation.

    Don't get me wrong. I'm not saying there's anything wrong with relying solely on AppGuard. I'm just expressing my own point of view that for most users, a layered security is probably safer than relying on a single application, however good.
     
    Last edited: Dec 15, 2013
  14. acr1965

    acr1965 Registered Member

    Joined:
    Oct 12, 2006
    Posts:
    4,995
    Out of curiosity, how did you come across this? Spam email attachment, click on a compromised ad or something else?
     
  15. pegr

    pegr Registered Member

    Joined:
    Apr 8, 2008
    Posts:
    2,280
    Location:
    UK
    Hi Pete,

    This shows what a powerful combination AppGuard and Sandboxie make, used together.

    BTW did you configure ERP to monitor system space by unchecking the settings to automatically allow launches from Program Files and Windows folders? I'm just curious to know what settings you run it with alongside AppGuard.

    Kind regards
    pegr
     
  16. Jryder54

    Jryder54 Registered Member

    Joined:
    Sep 3, 2013
    Posts:
    212
    I have a bug to report. If I set privacy mode on Google Chrome or Firefox it blocks access as intended to drives that I list, except if I block access to removable drives. One is formatted as Fat32 and one is NTFS if that makes any difference. OS:Windows 8.1
     
    Last edited: Dec 15, 2013
  17. Peter2150

    Peter2150 Global Moderator

    Joined:
    Sep 20, 2003
    Posts:
    20,590
    Unfortunately I don't know. Wasn't an email attachment, but surfing a bit on the dark side. Problem is I don't know where I picked up, I just suddenly notice an extra tab open.

    Pete
     
  18. Peter2150

    Peter2150 Global Moderator

    Joined:
    Sep 20, 2003
    Posts:
    20,590
    Yes I do have them unchecked, but I also have everything in those folders whitelisted.

    On a different note, there has been a lot of concern about cryptolocker, and I finally figured out how to configure Appguard to match Sandboxies settings. I was a bit concerned as with a new add in I found I had to take outlook out of Sandboxie.

    What I did is add all the my docs folder and my extra drives under the guarded apps settings tab, and set them to deny. Then I set Outlook Privacy option on, and essentially I now have the same protection, just not the delete ability.

    Appguard is really powerful.

    Pete
     
  19. TheKid7

    TheKid7 Registered Member

    Joined:
    Jul 22, 2006
    Posts:
    3,579
    I am thinking about leaving AppGuard set to "Locked Down" most of the time, with the exception of when installing Windows Updates. Has anyone experienced any issues with leaving AppGuard set to "Locked Down" most of the time?

    Thanks in Advance.
     
  20. TomAZ

    TomAZ Registered Member

    Joined:
    Feb 27, 2010
    Posts:
    1,131
    Location:
    USA
    Doing exactly that here and no problems at all.
     
  21. pegr

    pegr Registered Member

    Joined:
    Apr 8, 2008
    Posts:
    2,280
    Location:
    UK
    I thought that's probably what you do. ERP looks like a good addition to AppGuard when configured that way. :thumb:

    I use Sandboxie only for web browsing and I too use AppGuard privacy protection, set up in much the same way as you. All my data is held on a separate partition, with the entire partition set as a Private Folder. Firefox and Thunderbird both have the Privacy flag set to On.

    My Firefox and Thunderbird profiles are also held on the data partition, set as Exception Folders to allow Read/Write access. Sandboxie is configured to block access to the Firefox profile folder for all programs other than Firefox, and the Thunderbird profile folder for all programs other than Thunderbird (retaining the option to run Thunderbird sandboxed).

    I agree, AppGuard is powerful. :)
     
  22. pegr

    pegr Registered Member

    Joined:
    Apr 8, 2008
    Posts:
    2,280
    Location:
    UK
    This is what I do - no issues here.
     
  23. TomAZ

    TomAZ Registered Member

    Joined:
    Feb 27, 2010
    Posts:
    1,131
    Location:
    USA
    What exactly does privacy protection do - block access to that item?
     
  24. acr1965

    acr1965 Registered Member

    Joined:
    Oct 12, 2006
    Posts:
    4,995
    In locked down mode I am unable to share a link on my Google+ page using Chrome. I'm able to do this in medium protection though. Is Google Chrome needing to write something to the registry every time I make a post to share a link on a web page?
     
  25. pegr

    pegr Registered Member

    Joined:
    Apr 8, 2008
    Posts:
    2,280
    Location:
    UK
    Prevents any guarded application where the Privacy flag is set to On from accessing a folder designated as a Private Folder.
     
Thread Status:
Not open for further replies.
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.