SBGuard Anti-Ransomware hardens Windows

Status
Not open for further replies.

Av Gurus

Level 29
Thread author
Verified
Honorary Member
Top Poster
Malware Hunter
Well-known
Sep 22, 2014
1,767
Anyone heard/try this software?

===============================================================
Source: SBGuard Anti-Ransomware hardens Windows - gHacks Tech News

SBGuard Anti-Ransomware is a free program for Microsoft Windows devices that hardens the operating system to block ransomware attacks dead in their track.

While there are plenty of anti-ransomware tools out there for the Windows operating system, there is little information about hardening the system to block ransomware from installing itself on it.

SBGuard Anti-Ransomware tries to change that by offering an on/off solution that applies around 700 Registry entries to the Windows Registry that limit software execution.

It injects around 700 registry entries to force Windows Group Policy to use inbuilt software execution restriction capabilities in certain locations and prevent certain file types from executing.

Additionally, it blocks Windows Gadgets, and "several other system actions Ransomware will attempt to perform to encrypt the data".

If that sounds awfully vague, it is. One of the main issues with solutions like this is false positives. While the program may very well block most -- the company claims all known and many future -- ransomware attacks, you may experience issues running or installing legitimate software relying on functionality that is blocked.

SBGuard_screen1-300x246.jpg


The only solution provided by the company that creates SBGuard Anti-Ransomware is to turn it off during installation of software to avoid issues related to it.

Turning it off on the other hand means no protection while software is installed, so users better make sure the software is legitimate before performing the operation.

The installation of SBGuard Anti-Ransomware should not pose any issues even inexperienced users. Please note that it requires the Microsoft .NET Framework 3.5 to run. Also, you are required to enter an email address on the developer site to download the program. The download link is sent to the email address you enter.

The program itself is dead easy to use. Start it with elevated rights after installation, and click on the enable or disable buttons to toggle the protection status of the operating system.

There is also a handy restart button. You need to restart the computer before the changes take effect.

As mentioned earlier, the program adds a number of restriction mechanisms and modifications to Windows using the Windows Registry. It is highly recommended to back up the Windows Registry, or even better, the whole system disk, before enabling the application's protective features.

The company behind the product released a demo video that showcases how ransomware is blocked after enabling the program's protection on a Windows computer.


SBGuard Anti-Ransomware protects against ransomware threats such as Cryptolocker, CryptoWAll, Teslacrypt, CTB-Locker, Zepto and others according to the company.

It also mentions on the product page that it monitors ransomware development and will implement protective measures against new attack forms as soon as they become known.

The program does not display notifications right now if the execution is blocked. A future update will introduce the feature and others, such as an option to run the program as a service for advanced security options.

Closing Words

SBGuard Anti-Ransomware hardens Windows machines against ransomware attacks. In fact, it protects at least partially against other forms of malicious software as well, but is no replacement for anti-virus programs.

The application could use a whitelist feature that enables you to allow programs to run while the protection is enabled.

Also, the devs should consider publishing a list of changes that the program makes as many users and most admins won't install it otherwise.
 

_CyberGhosT_

Level 53
Verified
Honorary Member
Top Poster
Content Creator
Well-known
Aug 2, 2015
4,286
This looks interesting to me, seeing I tend to focus on Signature-less protection.
I will look into this and give it a whirl soon. I will be sure to do a fresh clone before
installing it. I have never heard of this software, Thanks for the heads up @Av Gurus .
I will download it tonight and install. and give feedback by morning.
PeAcE
EDIT: after reading a little on the products homepage I have a sinking feeling my Stardock windows software will no longer function, but I am going to try it anyways.
 
Last edited:

_CyberGhosT_

Level 53
Verified
Honorary Member
Top Poster
Content Creator
Well-known
Aug 2, 2015
4,286
Ok, I created a "restore point" and installed, I know I should have cloned, buy hey I took the risk.
So far no issues, and if there were going to be I think I am running 2 software that I think have a big chance at creating conflict.
!. Voodoo Shield
2. WinAntiRansomware
After the download I went into WAR and whitelisted the installer, I then placed Voodoo Shield into "Install Mode"
Just after the install and activating the protection (But Before Re-Starting), I again went into WAR and navigated to the install location,
for me it was C:\ Programfilesx86, and I whitelisted the SB exe file so that I could eliminate any issues at restart with SB and WAR.
After restarting I had no issues and I was surprised. So far things are quiet and stable. I dont like that there is no indication that this thing is on
or working ie no tray notification, I found nothing in Process Lasso either to indicate a running process. I will message their team and inquire weather this is normal or not.
I included a SS of it installed so you can see it is indeed installed and what I had running alongside it. I will post back if I experience any issues.
SB_SS_08302016.png

Hope this helps :)
 
Last edited by a moderator:
H

hjlbx

What is so problematic about this ?:

"The only solution provided by the company that creates SBGuard Anti-Ransomware is to turn it off during installation of software to avoid issues related to it."

If the user is downloading and installing widely-trusted programs, then turning SBGuard off to allow the installation is not a problem.

Besides, there is virtualization (like Sandboxie, Shadow Defender) and snapshot (like Rollback Rx) softs to perform the install and protect the system during an initial "test" installation for less reputable files.

Macros should be turned off, don't open unknown\unsolicited emails, etc - all stuff that security-conscious users already know.

SBGuard is not intended for typical user. Most of what we discuss here at MT and other security forums is not for n00bs, novices, and the plug-n-play security crowd.

* * * * *

What I have a problem with is this:

"The installation of SBGuard Anti-Ransomware should not pose any issues even inexperienced users."

My response: "Horse hockey."

Which is also a response to this - which will cause many inexperienced users to disable and execute files:

"The program does not display notifications right now if the execution is blocked."

* * * * *

Not ready for prime-time...
 

SBGuard

From SBGuard
Verified
Aug 31, 2016
29
Ok, I created a "restore point" and installed, I know I should have cloned, buy hey I took the risk.
So far no issues, and if there were going to be I think I am running 2 software that I think have a big chance at creating conflict.
!. Voodoo Shield
2. WinAntiRansomware
After the download I went into WAR and whitelisted the installer, I then placed Voodoo Shield into "Install Mode"
Just after the install and activating the protection (But Before Re-Starting), I again went into WAR and navigated to the install location,
for me it was C:\ Programfilesx86, and I whitelisted the SB exe file so that I could eliminate any issues at restart with SB and WAR.
After restarting I had no issues and I was surprised. So far things are quiet and stable. I dont like that there is no indication that this thing is on
or working ie no tray notification, I found nothing in Process Lasso either to indicate a running process. I will message their team and inquire weather this is normal or not.
I included a SS of it installed so you can see it is indeed installed and what I had running alongside it. I will post back if I experience any issues.
SB_SS_08302016.png

Hope this helps :)

Thank you for testing SBGuard Anti-Ransomware.
We would be more than happy to answer any questions you have right here, so please do reply on our comment.
In regards to why there's no running process or tray notification, it is simply because once SBGuard injects a large number of registry policies and restrictions, and you close it, Windows does the rest. This is more than enough to prevent Ransomware execution.
There are new methods and techniques we are working on for the next release, which will have SBGuard running as a service. Until then, Enable Protection and that's all you need to do.
P.s until we implement blocking notifications, you can use Windows Events > Application > ID 866 will show anything blocked using SBGuard's rules. Cheers
 

SBGuard

From SBGuard
Verified
Aug 31, 2016
29
What is so problematic about this ?:

"The only solution provided by the company that creates SBGuard Anti-Ransomware is to turn it off during installation of software to avoid issues related to it."

If the user is downloading and installing widely-trusted programs, then turning SBGuard off to allow the installation is not a problem.

Besides, there is virtualization (like Sandboxie, Shadow Defender) and snapshot (like Rollback Rx) softs to perform the install and protect the system during an initial "test" installation for less reputable files.

Macros should be turned off, don't open unknown\unsolicited emails, etc - all stuff that security-conscious users already know.

SBGuard is not intended for typical user. Most of what we discuss here at MT and other security forums is not for n00bs, novices, and the plug-n-play security crowd.

* * * * *

What I have a problem with is this:

"The installation of SBGuard Anti-Ransomware should not pose any issues even inexperienced users."

My response: "Horse hockey."

Which is also a response to this - which will cause many inexperienced users to disable and execute files:

"The program does not display notifications right now if the execution is blocked."

* * * * *

Not ready for prime-time...

Thank you for your comment. SBGuard Anti-Ransomware was originally created by us for internal use and family and friends only. It was intended for novice users, so we are a bit surprised that several forums are saying that it's not for inexperienced users. We have learned from this and we will look into ways to make it more newbie friendly. Our intention is to protect the most vulnerable, regular users that have very little knowledge on how to detect Ransomware and protect from it. It is very difficult to embed maximum protection, without making some compromises. Although, except for TeamViewer (not launching) and some Norton programs, we had no issues.

All comments and feedbacks are appreciated.
 

_CyberGhosT_

Level 53
Verified
Honorary Member
Top Poster
Content Creator
Well-known
Aug 2, 2015
4,286
@SBGuard
Thanks for taking the time out of what must be a busy schedule to stop in ;)
I like its ease of install, and will be glad when the improvements are implemented,
thanks for not keeping this one "in house" and sharing it. I have noticed no issues
and have disabled it only once to re-install FireFox and promptly re-enabled it, all
went off without a hiccup. It even survived a HD cloning from Macrium Reflect.
Tell your Dev's they are appreciated :)
 

SBGuard

From SBGuard
Verified
Aug 31, 2016
29
So this is very similar to CryproPrevent or...?
What's the difference?
CryptoPrevent is great and is one of the programs we have learned a lot from when building SBGuard. There are differences:
1. SBGuard has significantly more rules included - and a lot more coming
2. SBGuard offers only maximum protection. CryptoPrevent offers several protection levels, but we can guarantee you, that anything less than the maximum one, will let some Ransomware in. I understand the fact it lets you chose your level or security is somewhat appealing, but we did not want to compromise on security.
3. SBGuard is free and always will be. We believe best things in life should come at no cost. We also offer custom versions for free as well, ooooppss.. :)
 

SBGuard

From SBGuard
Verified
Aug 31, 2016
29
@SBGuard
Thanks for taking the time out of what must be a busy schedule to stop in ;)
I like its ease of install, and will be glad when the improvements are implemented,
thanks for not keeping this one "in house" and sharing it. I have noticed no issues
and have disabled it only once to re-install FireFox and promptly re-enabled it, all
went off without a hiccup. It even survived a HD cloning from Macrium Reflect.
Tell your Dev's they are appreciated :)
That's great mate, glad it works well.
Any questions, please email us at sbguard@sydneybackups.com.au as we may not always be able to monitor forums and respond promptly.

Cheers
 

Overkill

Level 31
Verified
Honorary Member
Feb 15, 2012
2,128
Hi guys, I asked cruelsister about this app and here's her comments...

When you get a chance, can you test SBGuard Anti-Ransomware?
SBGuard Anti-Ransomware - Sydney Backups
SBGuard Anti-Ransomware hardens Windows - gHacks Tech News
Reply

cruelsister1 1 day ago
As I'm still on assignment I won't be publishing anything until October. However I was aware of SBGuard and actually did a test of it to pass the time on my flight back this weekend.

In short, it is without value. Not only does it not prevent infection from stuff like Petya, Satanana, Putty, and Bart, but it didn't even protect against an old CTBlocker (which it should have), and will not protect AT ALL anything outside of the Documents folder- this I tested with a Fortress class sample.

Total garbage!

Hope this helped,

In addition to the things I mentioned previously, SBGuard does protect against some Locky samples, but does not protect at all against BandArchor (which is popular recently). Policy based ransomware protection (like CryptoPrevent) was very good idea a few years ago, but currently is not a good idea at all.
 

SBGuard

From SBGuard
Verified
Aug 31, 2016
29
Hi guys, I asked cruelsister about this app and here's her comments...
If the test was performed by simply running a Ransomware executable from a USB drive or somewhere else on the computer, of course it will not block it. SBGuard does not work that way. It blocks the execution and payload delivery via internet or email. 99% of Ransomware is delivered this way and SBGuard will block any attempt to execute it.
Just making sure we are on the same page on the expectations.

Please let us know as we are very curious about this.

Thanks
 
Status
Not open for further replies.

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top