AppGuard 4.x 32/64 Bit - Releases

Discussion in 'other anti-malware software' started by Jryder54, Oct 29, 2013.

Thread Status:
Not open for further replies.
  1. pegr

    pegr Registered Member

    Joined:
    Apr 8, 2008
    Posts:
    2,280
    Location:
    UK
    This is from the help file:

    "Power Applications are exempt from AppGuard protections. They are not guarded (even when launched by a Guarded Application)."
     
  2. pegr

    pegr Registered Member

    Joined:
    Apr 8, 2008
    Posts:
    2,280
    Location:
    UK
    If PERRLA is listed as a Power Application, it won't be guarded if it runs under Word, even if Word is guarded.

    In any case, Word should ideally be a guarded application because of the ability to run code embedded in documents.
     
  3. pegr

    pegr Registered Member

    Joined:
    Apr 8, 2008
    Posts:
    2,280
    Location:
    UK
    To be fair to him, he may be thinking about the advisability of maintaining some kind of additional real-time protection for times when AppGuard protection is lowered, e.g. software installation.
     
  4. Peter2150

    Peter2150 Global Moderator

    Joined:
    Sep 20, 2003
    Posts:
    20,590
    @DoctorPC

    With a little snooping you should be able to resolve your problem with out PowerApps. Example.

    I use Adobe Acrobat XI Pro. I run it guarded for protection against a malicious PDF file. Suddenly I noticed that Adobe would throw up an error message indicating an installation problem, and that I should uninstall/reinstall and if that failed then contact my administrator. Not a very helpful message.

    Finally I looked at Appguards activity report and it showed Appguard was blocking write to c:\Program Files(x86)\Common Files\Adobe . So that is why Adobe was failing. The solution. Go to appguards guarded apps tab, click on the setting button near the bottom, and add that folder, being sure to give it read/write permissions. Problem solved. Adobe guarded, but can write to that one folder.

    This is the best way to track down problems and get them solved in Appguard.

    Pete

    PS Since they have a free trial, I may give it a play this weekend.
     
  5. Barb_C

    Barb_C Developer

    Joined:
    Jan 7, 2011
    Posts:
    1,234
    Location:
    Virginia
    Sorry, I guess I posted and ran last night.

    I believe the answer to your question is yes. Would you send your request to AppGuard@BlueRidge.com? Our customer operations department handles the licenses. If you've used the second license already, you may have to uninstall and re-install, but customer service will work it out with you. In your email, provide them with both license ids and let them know which one you want to use. I'll alert them that it is on its way.
     
    Last edited: Feb 28, 2014
  6. Barb_C

    Barb_C Developer

    Joined:
    Jan 7, 2011
    Posts:
    1,234
    Location:
    Virginia
    Chris, Thanks! We do recommend AV - only to clean up any dormant viruses that may have made it onto the machine (but rendered impotent by AppGuard). When the AV signatures finally catch up and can detect the virus, they're good at cleaning up the system.
     
  7. Barb_C

    Barb_C Developer

    Joined:
    Jan 7, 2011
    Posts:
    1,234
    Location:
    Virginia
    Thanks! I agree, an import/export feature would be good.
     
  8. Barb_C

    Barb_C Developer

    Joined:
    Jan 7, 2011
    Posts:
    1,234
    Location:
    Virginia
    LOL. We put AppGuard on my father-in-law's PC. He doesn't even know it's there (we took the GUI out of the startup run key and removed the shortcut from the desktop).
     
  9. jmonge

    jmonge Registered Member

    Joined:
    Mar 20, 2008
    Posts:
    13,744
    Location:
    Canada
    that is exctly what I do here in my house or just password protect it;)
     
  10. Peter2150

    Peter2150 Global Moderator

    Joined:
    Sep 20, 2003
    Posts:
    20,590
    That is hilarious. Love it. But it does testify to the power of Appguard.

    Pete
     
  11. jmonge

    jmonge Registered Member

    Joined:
    Mar 20, 2008
    Posts:
    13,744
    Location:
    Canada
    very powerfull:thumb:
     
  12. Rasheed187

    Rasheed187 Registered Member

    Joined:
    Jul 10, 2004
    Posts:
    17,559
    Location:
    The Netherlands
    Hi,

    I'm currently looking for a new HIPS for Win 8.

    Can anyone perhaps give some feedback, for some reason I can't figure it out. :)

    Is it designed to block drive by attacks only?

    Can I use it as an anti exe (whitelisting) app?

    Will it also alert you about suspicious behavior when you're executing an app manually?
     
  13. Peter2150

    Peter2150 Global Moderator

    Joined:
    Sep 20, 2003
    Posts:
    20,590
    See PEGR's guide in post #5 of this thread. It will answer all your questions.

    Pete
     
  14. DoctorPC

    DoctorPC Banned

    Joined:
    Jan 9, 2014
    Posts:
    810
    Gotcha, so power-app supercedes guarded-app. Easy enough, and I will test that this evening.

    I worked on a machine awhile back that had 1649 trojans/viruses, 1640 being mostly traces/remnants, but an actual 9 trojans running at the same time. (yes, an AV was on it but they failed to pay the subscription about a year before) Installing Appguard would have been a lifesaver, but then again it would have killed my $725.00 visits every month. I need to look into Enterprise aspects of Appguard pretty soon here. I can see deployment of this would be a good thing under some conditions, provided I can upsell it a good bit. :thumb:

    Import/Export of configurations would be an absolute essential addition for Enterprise - by the way. I can't deploy a security product effectively with either that, or console managed deployment/control. I assume Appguard has neither?
     
  15. DoctorPC

    DoctorPC Banned

    Joined:
    Jan 9, 2014
    Posts:
    810
    Word set to default (Guarded).

    Perrla set to Power Application.

    Getting the following errors/logs.. "Gasp" Perrla is written in VB. Anyway;

    Going to try Peter's advice based on this log.
     

    Attached Files:

  16. pegr

    pegr Registered Member

    Joined:
    Apr 8, 2008
    Posts:
    2,280
    Location:
    UK
    Try adding c:\perrla\perrlamaster.db3 to User Space with Include set to Yes. If it doesn't let you add a file with a .db3 extension then add try adding the entire c:\perrla folder to User Space. Just to clarify this, the problem appears to be that Word, a guarded application, is trying to write to System Space.

    Alternatively, you could temporarily suspend guarded execution for Word by right clicking the AppGuard system tray icon before writing back to the database if the other suggestions don't work. Finally, as a last resort, you could try removing Word from the Guarded Applications list.
     
    Last edited: Feb 28, 2014
  17. Barb_C

    Barb_C Developer

    Joined:
    Jan 7, 2011
    Posts:
    1,234
    Location:
    Virginia
    We have an enterprise version that is centrally managed. The policy is controlled by the management console and is pushed out to AppGuard agents. The policy is much more granular and you can even have location aware policy. You can lock it down so that the end-user can't change anything. There is also a stealth mode where there is no GUI.
     
  18. Barb_C

    Barb_C Developer

    Joined:
    Jan 7, 2011
    Posts:
    1,234
    Location:
    Virginia
    Actually AppGuard is preventing Word from writing to c:\perrla\perrlamaster.db3. So you have to set it as an exception "folder" on the Guarded Apps tab (you can set a file as an exception here - another GUI mod in our future):
    GuardedApps.png
    Note, you can type the file name into the edit box even if you can't browse to it:
    Wilders2.png
    Then change the "type" to "Read/Write". I would first start by setting the file as an exception. If that doesn't work, then set the entire perrla folder as an exception:
    Wilders3.png

    I also think that you might be able to remove PERRLA from the power app list after making this change.

    P.S. PEGR - sorry to jump in here, your advice is usually right-on, but I think I'm correct. In fact, even though I'm an AppGuard developer, I am hesitant to overrule you because you usually answer questions better than I do. You have me second guessing myself.
     
    Last edited: Feb 28, 2014
  19. Barb_C

    Barb_C Developer

    Joined:
    Jan 7, 2011
    Posts:
    1,234
    Location:
    Virginia
    Please see my response to PEGR's advice to you (above). Normally he provides very good answers - better than mine, but I think that my suggestion is what is required.
     
  20. Peter2150

    Peter2150 Global Moderator

    Joined:
    Sep 20, 2003
    Posts:
    20,590
    That's exactly what I had to do with Adobe Acrobat, just a different folder. Should work.

    Pete
     
  21. FleischmannTV

    FleischmannTV Registered Member

    Joined:
    Apr 7, 2013
    Posts:
    1,093
    Location:
    Germany
    @Barb_C

    Regarding making AppGuard more user friendly, I think it would be nice to add more applications to the default guarded list, so that they don't have to be added manually. For example popular Microsoft Office, Adobe Reader or media player alternatives. It's a pain to manually add all those LibreOffice / OpenOffice processes manually.
     
  22. rdsu

    rdsu Registered Member

    Joined:
    Jun 28, 2003
    Posts:
    4,537
    +1

    We can also suggest some...
     
  23. rdsu

    rdsu Registered Member

    Joined:
    Jun 28, 2003
    Posts:
    4,537
    Very good and useful tutorial!

    Thanks a lot ;)
     
  24. DoctorPC

    DoctorPC Banned

    Joined:
    Jan 9, 2014
    Posts:
    810
    Well then, I will surely be in contact soon on that level. I can see deployment of this, especially in stealth mode, would literally be a lifesaver for some of the clients. Most of the whitelist/blacklist stuff we use is simply too aggressive IMO. Appguard would be a perfect replacement, without causing much trauma.

    Perrla is fixed now, I had done the read/write rule earlier to success, without Perrla under power apps. I just didn't have a chance to check back in until now. Thanks.

    I sent an engineer I know over to your website the other day, he supposedly purchased a half dozen licenses to test out for potential enterprise deployments. So far he seems quite happy with it.
     
  25. Cutting_Edgetech

    Cutting_Edgetech Registered Member

    Joined:
    Mar 30, 2006
    Posts:
    5,694
    Location:
    USA
    Good deal :thumb:
     
Thread Status:
Not open for further replies.
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.