AppGuard - General Impression

Status
Not open for further replies.

HarborFront

Level 72
Verified
Top Poster
Content Creator
Oct 9, 2016
6,139
Yes.

AppGuard tray icon > right-click > Protection Level > select option: Off, Allow Installs, Protected, Locked Down




Currently, there is no Export\Import of the settings\configuration file. It is a requested feature that is on the "To Do" list.

However, you can save a back-up of the AppGuard settings\configuration xml (appguardpolicy.xml) that is located in:

c:\users\user\appdata\roaming\blue ridge networks\appguard\appguardpolicy.xml

You can drop the back-up appguardpolicy.xml into the above directory so as to save yourself a lot of configuration time.

Before doing so, you must disable TamperGuard:

AppGuard tray icon > double-click > AppGuard GUI Customize > Advanced > tick Stop Self Protection (TamperGuard) > Apply > OK

After dropping the appguardpolicy.xml into the above directory, do not forget to re-enable Self Protection.

NOTE: There is currently no support for the above when using AppGuard in a Standard User Account (SUA); each time you clean install AppGuard and enable the Standard User Account, you must manually configure AppGuard.

AppGuard configuration works this way because it does not apply the same policy for all users; each user can create their own independent customized configuration. We are thinking about an all user installation whereby the same policy will be applied to all users. Doing it this way would more accurately reflect the way that users actually configure AppGuard - which is the user typically creates the same configuration in all the user profiles.

Hi

Thanks for the reply

Are you one of the developers of AppGuard? I just went to AppGuard website but it says the AppGuard Personal is not available for buy. Is it because a new version is coming out?

Thanks again
 
  • Like
Reactions: aragornnnn
5

509322

Thread author
Hi

Thanks for the reply

Are you one of the developers of AppGuard? I just went to AppGuard website but it says the AppGuard Personal is not available for buy. Is it because a new version is coming out?

Thanks again

I work with Development, but my function is Quality Control.

Here is the download page for AppGuard Personal: AppGuard | Personal

There is no ETA for the next major release of AppGuard consumer products. I expect the next release to be minor one with various fixes plus an enhancement or two.
 

HarborFront

Level 72
Verified
Top Poster
Content Creator
Oct 9, 2016
6,139
I work with Development, but my function is Quality Control.

Here is the download page for AppGuard Personal: AppGuard | Personal

There is no ETA for the next major release of AppGuard consumer products. I expect the next release to be minor one with various fixes plus an enhancement or two.

Thanks. Just downloaded.

Cannot install as no license for the moment. Cannot buy also since website says not available for buy

So, how?
 
  • Like
Reactions: aragornnnn

molhopicante

Level 1
Oct 18, 2011
20
I have 2 "version.4" liceses.
Each license alow me it's use in 3 PCs.

If i buy a "version.5" license, may i use it for 3 PCs like the V.4, or just one?
 

HarborFront

Level 72
Verified
Top Poster
Content Creator
Oct 9, 2016
6,139
HI

Can I know whether AppGuard blocks digitally signed malware? I was testing one from malc0de today and AppGuard fails to block it while it tries to install. Luckily, VS prompted me. VS said the file was digitally signed by AusLogic

This is the one I'm referring to

static.tweakbit.com/en/driver-updater/default/stub/auto/driver-updater-setup.exe (dated 31-10-2016) from malc0de

VT result is here

Antivirus scan for eb088d43e4b03d0a205cd4c6adf677cecd2d8d67a8b7ad6d6558010ee5d9acf7 at 2016-11-01 00:14:24 UTC - VirusTotal

Thanks
 
Last edited:
  • Like
Reactions: XhenEd
5

509322

Thread author
HI

Can I know whether AppGuard blocks digitally signed malware? I was testing one from malc0de today and AppGuard fails to block it while it tries to install. Luckily, VS prompted me. VS said the file was digitally signed by AusLogic

This is the one I'm referring to

static.tweakbit.com/en/driver-updater/default/stub/auto/driver-updater-setup.exe (dated 31-10-2016) from malc0de

VT result is here

Antivirus scan for eb088d43e4b03d0a205cd4c6adf677cecd2d8d67a8b7ad6d6558010ee5d9acf7 at 2016-11-01 00:14:24 UTC - VirusTotal

Thanks

That sample is a potentially unwanted program (PUP) - and it is rated as such because the Auslogics Driver Updater program isn't free and requires a paid subscription to be fully functional. Technically, it is a false-positive.

The installer has a complete digital certificate:

Signers
[+] Auslogics Labs Pty Ltd
[+] COMODO Code Signing CA 2
[+] USERTrust (Code Signing)

Counter signers
[+] Entrust Time Stamping Authority
[+] Entrust Code Signing Certification Authority - L1D
[+] Entrust (2048)


Yes - AppGuard will block digitally signed malware when it is set to Locked Down mode. It will also block digitally signed malware in Protected mode if the entire installer run sequence is not digitally signed all the way through.

For example, Active Presenter Installer.exe (digitally signed) > Active_Presenter_Install.tmp (not signed -> therefore AG blocks any further execution).

When you run AppGuard in Protected mode, it will allow the launch of installers with complete Authenticode certificates - but they will be launched Guarded, MemGuarded and Privacy enabled - unless the digital certificate Subject is on the Trusted Publisher's List.

Guarded prevents the creation of auto-run\startup. After you reboot the system the file will not start and will remain inert on the system - unless you navigate to the file and manually start it.
 
Last edited by a moderator:
D

Deleted member 178

Thread author
lol Jeff You cut the grass under my feet lol, i was ready to post the same ! you just ruined 5mn of writing :p
 
  • Like
Reactions: XhenEd and frogboy

HarborFront

Level 72
Verified
Top Poster
Content Creator
Oct 9, 2016
6,139
Hi

If that's the case how come companies like COMODO, ESET, MalwareBytes, DrWeb, McAfee etc treated it as a malware in VT rather than accepting it? Don't tell me these companies can't tell the difference between a malware and a false positive?

Thanks
 
5

509322

Thread author
Hi

If that's the case how come companies like COMODO, ESET, MalwareBytes, DrWeb, McAfee etc treated it as a malware in VT rather than accepting it? Don't tell me these companies can't tell the difference between a malware and a false positive?

Thanks

It is rated as a PUP - which does not mean malware. A PUP can download and install other software that might turn out to be, indeed, malicious. However, security soft vendors do not install a software and watch every single thing that the software does and then create a signature for it. That isn't how file signatures are created. If vendors had to do all that, then it would take a very long time to create signatures, it would be very expensive, and security soft vendors would never tolerate it.

How file signatures are created is a topic all unto itself.

A PUP can be installed at the user's discretion. The signature detection is just to bring the file to the user's attention.

What some users consider a PUP, other users will not; what one AV company rates as a PUP, another will not.
 
Last edited by a moderator:
  • Like
Reactions: XhenEd
D

Deleted member 178

Thread author
Hi

If that's the case how come companies like COMODO, ESET, MalwareBytes, DrWeb, McAfee etc treated it as a malware in VT rather than accepting it? Don't tell me these companies can't tell the difference between a malware and a false positive?

Thanks

Also, because all the fight is to get the best "detection", some companies would be rated less "nicely" by Average Joe type of users if they don't flag those PUPs.
 
  • Like
Reactions: XhenEd
D

Deleted member 178

Thread author
@Lockdown , I believe the Blue Ridge Networks Store link you posted is no longer accurate (i.e., when I execute the link I receive a page noting "
Not Found
We were unable to find the requested file or resource.").

Can you please provide us the correct, current link?
Home

the website had a massive overhaul since the change of policy toward customers and the merging with Blue Planet.
 
  • Like
Reactions: meltcheesedec

meltcheesedec

Level 2
Verified
Jul 30, 2017
54
You cannot rely exclusively upon AppGuard, or any anti-executable for that matter, to protect your system. Please do as AppGuard recommends and use an AV and firewall... Windows Defender and Windows Firewall are the bare minimum.
.

You can try simple combo like AppGuard, Sandboxie and Adguard.

@Lockdown , what is your preferred configuration of Windows Firewall when paired with AppGuard Personal?
 
Last edited:
Status
Not open for further replies.

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top