Jump to content

How to identify malicious programs in Sandboxie


karachidude

Recommended Posts

@shought:

Well it's your choice if you want to execute an unknown .exe file.

As for me, I always stay on the safe side.

But hey, each to his own ;)

Link to comment
Share on other sites


  • Replies 42
  • Views 4.9k
  • Created
  • Last Reply
@shought:

Well it's your choice if you want to execute an unknown .exe file.

As for me, I always stay on the safe side.

But hey, each to his own ;)

Live on the edge man! :w00t:

Link to comment
Share on other sites


@ Shought

i hope u got my last PM.It was a thank u and a suggestion.

My connection is crapy and bails on me a lot :)

Link to comment
Share on other sites


I'm with shought here :P I'm too lazy to use sandboxie. I just take a hunch running an executable. If I get infected, well... yeaaah :afro:

Link to comment
Share on other sites


  • Administrator

+1. Even I'm too lazy to run it. :P

But I do run it on special programs that have 99% chances of gettin infected.

Link to comment
Share on other sites


i have learnt my lesson..lol...i will use sandboxie from now on to execute keygens :)

Link to comment
Share on other sites


  • Administrator

Good. Even I will do the same from now on.

But I have a question.

Suppose I downloaded a keygen in .zip, .rar whatever format. And I open the compressed file in sandbox. Now when I try to extract/open the keygen, will it be extracted from outside the sandbox from my temp files or inside the sandbox?

Link to comment
Share on other sites


that depends on ur choice,u can force ur FF to always start in sandboxie mode like i do with chrome and IE8,now when u download through a sandbox brower,at the end of the download sandboxie will ask u if u want to recover the file to some folder,if u want to recover the file use the browse option and select any folder u want to send it to.

If u dont recover ur keygen to another place,the keygen wll stay in the sandbox.u can do to the C: drive and explore and find the keygen,or u can explore ur sandbox through provided options in the sandboxie control.Now in this situation the keygen is the sandbox and u can easily run and use it.

But as a matter of fact u dont need to keep the sandbox,u can extract it anywhere on ur harddisk like on the desktop because extration cannot cause exucution of any .exe inside the Winrar or Winzip.

What u really need to do is just drag the keygen to the sandboxie control,and let the sandboxie execute it,and look for bad behaviour.

If u want to play the safest,just let it download in the sandbox,and execute it there directly.Anything executed in the sandbox in safe.

Link to comment
Share on other sites


  • Administrator

Well I wanted the answer for Winzip etc. ANW i got my answer anyway.

Link to comment
Share on other sites


i think i covered that.if it isnt sufficient for u,u can always ask others for advice.

Link to comment
Share on other sites


I'm with shought here :P I'm too lazy to use sandboxie. I just take a hunch running an executable. If I get infected, well... yeaaah :afro:

xDDDDDDDDDDDDDDDDD

I've survived 2 MF rootkits which took me many hours to be free from, and a lame keylogger VERY easy to get rid of.

I'm always saying i'll try Sandboxie, but... i'm way tooooooooooooooo lazy to try new software.

Link to comment
Share on other sites


  • Administrator

I have faced two stealers before I came to know about sandbox. Many people would be knowin that stealers are not easily detectable.

Link to comment
Share on other sites


I'm with shought here :P I'm too lazy to use sandboxie. I just take a hunch running an executable. If I get infected, well... yeaaah :afro:

xDDDDDDDDDDDDDDDDD

I've survived 2 MF rootkits which took me many hours to be free from, and a lame keylogger VERY easy to get rid of.

I'm always saying i'll try Sandboxie, but... i'm way tooooooooooooooo lazy to try new software.

@manpe

I was actually thinking about using that emote as well :P

@Jota.Ce

I just had to clean my parent's PC of a really annoying rootkit. The thing is you can't be 100% sure if you actually fixed it... So I'll have to monitor the situation for a few days :)

Link to comment
Share on other sites


Please remember, Sandboxie, by default in the settings, allows all programs to read all the data on your computer. So a special malware that knows where to look may see what it wants then phone home. It doesn't take much to steal passwords. You still need HIPS, firewall, and antimalware while running programs in Sandboxie. Also make sure that you terminate and delete all the contents in Sandboxie as soon as possible.

I too once used to be lazy. Then I realized that it was more work.

Link to comment
Share on other sites


  • Administrator

Box you are right. How could I miss that. :)

BTW there is nothin to download on the Post #1 and #2 on this thread as your siggy has mentioned. :P

Link to comment
Share on other sites


I too once used to be lazy. Then I realized that it was more work.

+1 Finally, someone who understands my POV :dance2:

Link to comment
Share on other sites


Archived

This topic is now archived and is closed to further replies.

  • Recently Browsing   0 members

    • No registered users viewing this page.
×
×
  • Create New...