View Full Version : Sandboxie and AV? How can this be.
trjam
August 15th, 2007, 02:30 PM
This is not about a AV not doing its job but about 2 that do. I have Sandboxie and I know a site that if I go there a trojan is found. Both Nod and Kaspersky find it and Quarantine the trojan. The thing is since I am sandbox how come the trojan is still in boths Quarantine file. I thought when you closed Sandboxie everything gets deleted, but not in this case. And good work to both AVs.
Pedro
August 15th, 2007, 02:36 PM
I think the answer is that since the AV is not sandboxed (treated as a trusted program), it can access the sandbox.
It's when a sandboxed application tries to access/modify files outside the sandbox that SandboxIE blocks it.
trjam
August 15th, 2007, 02:39 PM
but it did because if I clicked on restore in Quarantine in either AV it would then be active. If thats the case then Sandboxie really isnt that secure. Also a good reason web scanning is important.
stapp
August 15th, 2007, 02:53 PM
Yesterday while surfing sandboxed with opera avira popup up to say it had found a virus, what did I want to do.
I quarantined it, closed opera and then deleted the contents from the sandbox.
Nothing in quarantine.
Trjam, did you delete the contents of the sandbox, or just close the sandbox?
trjam
August 15th, 2007, 02:54 PM
I have it set to delete the contents on sandboxie on closing.
solcroft
August 15th, 2007, 05:41 PM
Your antivirus software is not sandboxed. Since that is the case, when it detects the virus, it moves the virus out from inside the sandbox into its quarantine area OUTSIDE the sandbox. Since your antivirus quarantine area isn't inside the sandbox at all, I don't see why you should be alarmed that emptying your sandbox has no effect on your antivirus quarantine.
19monty64
August 15th, 2007, 06:58 PM
Then why is Stapp's quarantine empty, but not Trjam's???
aigle
August 15th, 2007, 07:11 PM
-{ Quote: "Yesterday while surfing sandboxed with opera avira popup up to say it had found a virus, what did I want to do.
I quarantined it, closed opera and then deleted the contents from the sandbox.
Nothing in quarantine." }--{ Quote: "Then why is Stapp's quarantine empty, but not Trjam's???" }-
Antivir just failed to quarantine here.
aigle
August 15th, 2007, 07:12 PM
-{ Quote: "Your antivirus software is not sandboxed. Since that is the case, when it detects the virus, it moves the virus out from inside the sandbox into its quarantine area OUTSIDE the sandbox. Since your antivirus quarantine area isn't inside the sandbox at all, I don't see why you should be alarmed that emptying your sandbox has no effect on your antivirus quarantine." }-
You are exactly right!
There is nothing wrong/ unusual in the scenario posted by trjam.
innerpeace
August 15th, 2007, 09:25 PM
-{ Quote: "Antivir just failed to quarantine here." }-
Hi aigle, is there anything I can change within Sbie or Avira to fix this? Or are you just saying that this was a rare occurrence. Thanks
aigle
August 16th, 2007, 01:34 AM
It,s my guess and it must be a rare occurance, nothing wrong with Antivir or SBIE.
Contents of Sandbox are a pert of ur HD and ur AV can delete/ quarantine anything from ur HD!
http://www.wilderssecurity.com/showthread.php?t=126406&highlight=sandboxie
If u want confirmation, try downloading Eicar test file via ur sandboxed browser.
innerpeace
August 16th, 2007, 02:02 AM
Thank you for your reply aigle. I didn't think there was anything wrong. I just installed Avira last night so I'm not that familiar with it. I'm also still using Sbie 2.86 and haven't messed with it much. I didn't know if I missed a setting or anything. Thanks for the link, it helped a lot.
Thanks, innerpeace
aigle
August 16th, 2007, 03:05 AM
There seems nothing wrong with Antivir settings. Just a miss or something like that I suspect. I don,t think there uis any reason to worry about.
Franklin
August 16th, 2007, 03:26 AM
-{ Quote: "but it did because if I clicked on restore in Quarantine in either AV it would then be active. If thats the case then Sandboxie really isnt that secure. Also a good reason web scanning is important." }-
Look at it in a different light.
If the Trojan was a zero day what would have protected you better, SB at a meg installed or your AV at around 30 meg installed :-*
With SB, Returnil and ghost images here I don't care about scanners for web pages.Even have website checking turned off in Firefox.
The Stumbleupon addon will take me anywhere and I couldn't care less with no realtime blacklists implemented here.
vBulletin® Copyright ©2000-2012, Jelsoft Enterprises Ltd.
Copyright ©2002 - 2012, Wilders Security Forums