Wilders Security Forums  

Go Back   Wilders Security Forums > Software, Hardware and General Services > sandboxing & virtualization
User Name
Password
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

 
 
Thread Tools Search this Thread
  #1  
Old April 1st, 2012, 10:55 AM
crykid crykid is offline
Infrequent Poster
 
Join Date: Mar 2012
Posts: 6
Default Do i need Sandboxie?

Hi, i just started using sandboxie, i executed firefox within sandboxie and ran some spycar registry tests and avast web shield managed to successfully block them all. When i disabled the webshield, the file shield interfered and quarantined the file that was saved in the sandbox.

I disabled all the avast shields, ran the tests again, and comodo defense+ would alert me about all the registry modifications, i allowed them because i wanted to see what would happen, because i was using sandboxie they werent in fact modifying the intended keys.

So my question is, do i really need sandboxie when i have real time shields and a HIPS program?

My next question is, does using real time shields compromise sandboxie protection, because as i noticed, avast would immediately detect the malware inside the sandbox folder and quarantine it, so sandbox does not serve its purpose. Thank you.
  #2  
Old April 1st, 2012, 01:34 PM
bo elam bo elam is offline
Very Frequent Poster
 
Join Date: Jun 2010
Posts: 1,041
Default Re: Do i need Sandboxie?

Quote:
Originally Posted by crykid

So my question is, do i really need sandboxie when i have real time shields and a HIPS program?

My next question is, does using real time shields compromise sandboxie protection, because as i noticed, avast would immediately detect the malware inside the sandbox folder and quarantine it, so sandbox does not serve its purpose. Thank you.
You can use your real time anti virus to detect known threats and use SBIE to get rid of threats that are still unknown to Avast. Thats a great combination and its how most of us use SBIE when we first start using it.

The Sandboxie folder can be accessed by programs outside the sandbox, like your antivirus, since they are not running sandboxed. If a file gets detected by the AV, you can either quarantine it or delete the sandbox. Either way its fine.

Bo
  #3  
Old April 1st, 2012, 07:59 PM
kjdemuth's Avatar
kjdemuth kjdemuth is offline
Very Frequent Poster
 
Join Date: Jul 2005
Location: Boston, MA
Posts: 2,340
Default Re: Do i need Sandboxie?

Yes. 'Nuff said.
__________________
Realtime:
WSA AV (Maxed Settings), Sandboxie Paid ( Dropmyrights and Browsers sandboxed) Lifetime license, NVT EXE Radar Pro (Lockdown mode). K9 Web protection. (malware, phishing and HTTPS force) Norton DNS.
On-Demand:
MBAM+EAM
Hitman pro (Scans daily)
 

Wilders Security Forums > Software, Hardware and General Services > sandboxing & virtualization « Previous Thread | Next Thread »

Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Settings
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump


All times are GMT -4. The time now is 01:20 PM.


Powered by vBulletin® Copyright ©2000 - 2013, Jelsoft Enterprises Ltd.
Copyright ©2002 - 2013, Wilders Security Forums