![]() |
|
#1
|
||||
|
||||
|
There are two anti-malware programs in my computer.
COMODO Firewall 3.12.111745.560 Sandboxie 3.40 XP SP3,NTFS 1.I execute a virus with sandboxed. 2.COMODO displays an alert"virus access the memory of explorer.exe" 3.I click allow 4.The virus pass sandbpxie,because it creat a file "C:\WINDOWS:svchost.com" out of the sandbox -------------- Then, I unistall COMODO Firewall. The virus can not pass sanboxie. Last edited by a256886572008 : October 25th, 2009 at 01:39 AM. |
|
#2
|
||||
|
||||
|
Quote:
__________________
Emsisoft Anti-Malware 7.0/WebRo0t AntiVirus 2o13 |
|
#3
|
||||
|
||||
|
Keep Sandboxie.
Cheers
__________________
http://subsetlines.wordpress.com |
|
#4
|
||||
|
||||
|
Quote:
![]()
__________________
Emsisoft Anti-Malware 7.0/WebRo0t AntiVirus 2o13 |
|
#5
|
||||
|
||||
|
Check the sandboxie forum. I believe there was an issue between Comodo stuff and Sandboxie.
I agree that I'd keep Sandboxie myself. |
|
#6
|
|||
|
|||
|
Quote:
Quote:
Be sure to read the entire thread: http://www.sandboxie.com/phpbb/viewt...ghlight=comodo |
|
#7
|
|||
|
|||
|
There was a similar issue when testing some of Matousec's POCs sandboxed with Malware Defender present. The POCs would bypass Sandboxie when Malware Defender was installed. Uninstalling Malware Defender was the only workaround at the time. Tzuk fixed the issue with 3.40. I would post your findings at the Sandboxie forum along with a link to your sample.
__________________
Nick |
|
#9
|
||||
|
||||
|
What if you have only some programs be the only programs allowed to run in Sandboxie? I'm sure that will stop this problem.
__________________
I have Windows 7 64 bit Comodo Firewall 6 set to block, Avast Free Edition, K9 Web Protection set to block malicious and phishing sites only, Zemana Free Anti Keylogger, Comodo DNS, Firefox with Noscript, Adblock Plus, WOT set to block, Secunia PSI, and common sense. ^_^ |
|
#11
|
|||
|
|||
|
thats way sandboxie is the best
![]()
__________________
Sandboxie / Shadow Defender / OpenDNS / Avira AntiVir + MBAM Pro + SAS (On demand) |
|
#12
|
||||
|
||||
|
Heh take that malware.
![]()
__________________
I have Windows 7 64 bit Comodo Firewall 6 set to block, Avast Free Edition, K9 Web Protection set to block malicious and phishing sites only, Zemana Free Anti Keylogger, Comodo DNS, Firefox with Noscript, Adblock Plus, WOT set to block, Secunia PSI, and common sense. ^_^ |
|
#13
|
|||
|
|||
|
Quote:
Isn't this the same guy who allways posting links directly to viruses, trying to get members of this forum infected ? check his post history, I'm pretty sure it's the same guy.That being said, who really cares if he got a virus on his PC ? I for one could care less ![]() |
|
#14
|
|||
|
|||
|
well looking again at his username.. looks kind a fishy already!
__________________
Sandboxie / Shadow Defender / OpenDNS / Avira AntiVir + MBAM Pro + SAS (On demand) |
|
#16
|
||||
|
||||
|
Which one is your file system?
NTFS FAT32 |
|
#17
|
||||
|
||||
|
That's it!! Dump a full clip of hollow points on the messenger!!
No,seriously,I have never understood why people post these "I have found a giant hole in,or this maleware owns, Sandboxie,Returnil,DefenceWall,etc!!" Threads here,before they raise the issue at the website-forum of the application concerned. If the issue is real,it will be from there, it is solved. |
|
#19
|
||||
|
||||
|
Finally, I find that it can not pass sandboxie with COMODO installed.
Becase I use the anti-rookit program "Xue Tr", the virus can pass sandboxie at this time. http://i234.photobucket.com/albums/e...2008/vv1-1.png Last edited by a256886572008 : October 25th, 2009 at 02:42 AM. |
|
#20
|
|||
|
|||
|
Quote:
__________________
Nick |
|
#21
|
|||
|
|||
|
Quote:
Rule #1 for Sandboxie. We don't ourselves move programs out of the sandbox and execute them unless we are reasonably certain that they are safe. Rule #2 for Sandboxie. We don't allow programs on our computer to move programs out of the sandbox and/or execute them unless we are reasonably certain they are safe. Last edited by Cadillakin : October 25th, 2009 at 09:24 AM. |
|
#22
|
|||
|
|||
|
Clicking allow should not mean that the end user is letting any program dictate actions to SB.
That just does not make sense. "Sandboxie runs your programs in an isolated space which prevents them from making permanent changes to other programs and data in your computer. " I don't understand why people are saying it's user error when SB has allowed another program, in this case Comodo, to recover a file. Also, telling people to modify propgrams to stop this action would leave the novice or average user, those not involved in this forum, in the position of not being protected properly. I use SB paid and enjoy the protection it affords. But the posts here and at the SB forum which was linked to in this thread do make me feel vulnerable. Nothing should be able to get to my drive when I'm running SB. However, I also know that Tzuk is fantastic about addressing problems. Hugger |
|
#23
|
|||
|
|||
|
Quote:
Sandboxie only controls the sandbox and what is initiated from within. It doesn't make the user smart, nor does it prevent the user from doing things to harm their own computer. If you take something out of the sandbox or allow other programs to take something out of the sandbox, all bets are off. These actions referred to in this thread are not occuring remotely, by outside users or those interested in doing you harm..The actions of Comodo in this instance are essentially user-initiated or user-condoned actions - imo not much different than allowing a batch file to copy files out of your sandbox... If you allowed a batch file to copy files out of the sandbox, I would say you were foolish to do so.. I wouldn't blame it on Sandboxie... And if you allow Comodo to do the same thing, I say the same thing.... It's your fault. |
|
#24
|
|||
|
|||
|
Cadillakin,
I understand what you are saying. But 'or allow other programs to take something out of the sandbox' is where I have a problem. When I read the SB web site and then read your statement I think that they are conflicting statements. Sandboxie has it's control over what goes to the hard drive. Shouldn't that be the only way for SB to be manipulated? Thanks. Hugger |
|
#25
|
|||
|
|||
|
Quote:
Doesn't make sense to me either. Clicking 'allow' on Comodo is surely allowing the action that would otherwise have occurred without Comodo installed. I don't see any "actions of Comodo". Clicking allow means "don't take any action" for Comodo. The virus was initiated from within the sandbox after all. EDIT: or are you saying that by clicking "allow" then Comodo proactively performs the action that would otherwise have been allowed? i.e. it didn't just suspend the action. Last edited by Scoobs72 : October 25th, 2009 at 12:39 PM. |
| « Previous Thread | Next Thread » |
| Thread Tools | Search this Thread |
|
|