![]() |
|
#1
|
|||
|
|||
|
I have the latest Sandboxie and Avira. This morning I was some where on the web where I shouldn't have been. I have SB set to empty the sandbox when I close the browser. When I closed FF I noticed that my taskbar icon for Avira had moved. So I ran Superantispyware and it found Pup Funmoods toolbar. Then I ran Malwarebytes and it found a whole bunch of trash. I have run several scans and I believe I have cleaned it all out. It has really caused me to question the effectivity of SB. How was this stuff able to get to my system
![]() |
|
#2
|
|||
|
|||
|
Quote:
Good luck Bo |
|
#3
|
|||
|
|||
|
I didn't download anything that I know of.
|
|
#4
|
||||
|
||||
|
I can assure you something like this would never come out of Sandboxie.
You made some mistake. |
|
#5
|
|||
|
|||
|
I know that you are correct but I don't how. I never came out of FF ,so I never left the sandbox. And I didn't download anything.
|
|
#6
|
|||
|
|||
|
Quote:
Bo |
|
#7
|
|||
|
|||
|
I have done several searches and there is nothing left. And there was nothing there before. Some how it got out of SB ,shut down Avira, got on the system then re-started Avira. I know it is hard to understand. But that is how I noticed that the Avira icon in the task bar had moved. It had been re-started.
|
|
#8
|
||||
|
||||
|
Do you have FF to force run in Sandboxie (paid version).
If not, are you absolutely sure FF was sandboxed? When you noticed Avira icon moving did you see the red X in Sandboxie's icon? |
|
#9
|
|||
|
|||
|
I have the paid version of SB and I always watch for the little red X on the SB icon when I close FF. It did that time. So I know it was sandboxed. I always open FF sandboxed.
|
|
#10
|
|||
|
|||
|
Doubtful that we'll ever know what really happened. Malware experts like Buster (who frequents the Sandboxie forum and this one) test thousands and thousands of malware on an ongoing basis using Sandboxie. Not to discount your sincerity, but it seems to me if something was able to escape your sandbox, he'd be aware of it.
|
|
#11
|
|||
|
|||
|
Well Doodler,I have always had faith in SB. I have no idea how it happened. All I know is that it had to have gotten around it some how.
|
|
#12
|
||||
|
||||
|
Quote:
If we were talking about something sophisticated... but even the most perfected malware can't break out of SBIE (up to now)... let alone this simple stuf. |
|
#13
|
|||
|
|||
|
I don't know if this means anything but Superantspyware found the toolbar and Malwarebytes found 33 other things that I know were not there before.
|
|
#14
|
||||
|
||||
|
I tried to install Funmoods inside Sandboxie
|
|
#15
|
||||
|
||||
|
Afterwards I scanned the machine with MBAM and HitmanPro and it came out clean.
|
|
#16
|
|||
|
|||
|
Think "alternative vectors." Is it possible for instance that you plugged in an infected USB stick at some point?
|
|
#17
|
||||
|
||||
|
Quote:
Its easy to test if funmoods can get out the sandbox or not... but i really don´t think that it can. edit: Montmorency already did it Maybe you have recovered the file to the real location or you have your download location with direct access?
__________________
Linux Mint 13 MATE x64 |
|
#18
|
||||
|
||||
|
Quote:
__________________
"Ignorance more frequently begets confidence than does knowledge..." - Charles Darwin - |
|
#19
|
|||
|
|||
|
I am willing to just let it go as something unexplainable. I am an old retired fart that has a computer and my wife has her computer. No one uses this computer but me. I can guarantee you that nothing came up on my display showing anything like what was shown in Montmorency's post.
|
|
#20
|
||||
|
||||
|
The OP made a mistake somewhere, somehow. That PUP did not bypass Sandboxie.
__________________
~ Windows 7 Home Premium x64 ~ Clean Install ~ Router NAT Firewall ~ Windows 7 Firewall ~ EXE Radar Pro ~ MBAM ~ Chrome ~ Ghostery ~ Windows 7 System Image ~ DBone's Common Sense ~ Lady Luck ~ |
|
#21
|
||||
|
||||
|
CAV detected the exe. Will test with Avast soon to see what it detects in it.
__________________
I have Windows 7 64 bit Comodo Firewall 6 set to block, Avast Free Edition, K9 Web Protection set to block malicious and phishing sites only, Zemana Free Anti Keylogger, Comodo DNS, Firefox with Noscript, Adblock Plus, WOT set to block, Secunia PSI, and common sense. ^_^ |
|
#22
|
||||
|
||||
|
Quote:
I was just trying to help rule out some possibilities.
__________________
"Ignorance more frequently begets confidence than does knowledge..." - Charles Darwin - |
|
#23
|
||||
|
||||
|
Quote:
__________________
Samsung Series 7 Chronos & Windows 8 (64bit) “We are the cosmos made conscious and life is the means by which the universe understands itself.” Brian Cox |
| « Previous Thread | Next Thread » |
| Thread Tools | Search this Thread |
|
|