Search found 310 matches
- Sun Jan 30, 2011 9:52 pm
- Forum: Feature Requests
- Topic: New 64-bit root-kit gave me an idea...
- Replies: 28
- Views: 16226
Sandboxie already protects the MBR oneder... Sandboxie protects against everything that I have thrown at it and yes I should of stated that the Seftad Ransomware sample is contained if run sandboxed. MBRguard could be a usefull install where the user is too lazy to use a decent security app like Sa...
- Sun Jan 30, 2011 7:18 pm
- Forum: Feature Requests
- Topic: New 64-bit root-kit gave me an idea...
- Replies: 28
- Views: 16226
Re: New 64-bit root-kit gave me an idea...
There are now root-kits that hi-jack the Master Boot record in order to load their drivers into windows, and hide themselves. You could have a look at MBRguard for 32 bit installs? http://www.blueridgenetworks.com/support/mbguard/mbguard.php Tested against Seftad Ransomware sample and MBRguard prot...
- Thu Dec 30, 2010 7:33 pm
- Forum: Problem Reports
- Topic: Win 7 Snipping Tool
- Replies: 1
- Views: 1368
Win 7 Snipping Tool
If I run the installer for the rogue AV "Antivirus 8" via SB then try to grab a snip of the rogue the Snipping Tool seems to lock up till I terminate the rogue installer.
As soon as it's terminated the snip proceeds.
!http://www.mediafire.com/file/ep26e980c ... 3_brs7.rar
As soon as it's terminated the snip proceeds.
!http://www.mediafire.com/file/ep26e980c ... 3_brs7.rar
- Thu Dec 30, 2010 6:37 am
- Forum: Feature Requests
- Topic: Hotkeys
- Replies: 12
- Views: 5968
- Wed Dec 29, 2010 7:34 pm
- Forum: Feature Requests
- Topic: Hotkeys
- Replies: 12
- Views: 5968
- Wed Dec 29, 2010 10:02 am
- Forum: Feature Requests
- Topic: Hotkeys
- Replies: 12
- Views: 5968
The batchflie must be already running before executing the malware . This may be nice for those testing malware (not me!) :wink: Franklin and I are always testing malware so the batch works a treat in not having to reset with these screenlockers. :wink: On my XP VM's where I'm not using SB I point ...
- Wed Dec 29, 2010 12:21 am
- Forum: Feature Requests
- Topic: Hotkeys
- Replies: 12
- Views: 5968
Ok thanks tzuk. For those that are testing these ransom/screenlockers the below batch file will run the terminate command every 30 seconds whilst the command window is open. Thanks to majoMo wilders. ::30=30 sec. @echo off :START ping 127.0.0.1 -n 30 > nul start "" "C:\Program Files\Sandboxie\Start....
- Mon Dec 27, 2010 11:21 pm
- Forum: Feature Requests
- Topic: Hotkeys
- Replies: 12
- Views: 5968
Hotkeys
Built in dedicated Hotkeys that can't be circumvented to the terminate command would be of help against some ransom/screenlockers type malware.
I know they are contained but hotkeys could save a reset.
I know they are contained but hotkeys could save a reset.
- Wed Dec 22, 2010 2:30 am
- Forum: Problem Reports
- Topic: Can't Delete Exe
- Replies: 3
- Views: 1757
- Sat Dec 11, 2010 1:08 pm
- Forum: Problem Reports
- Topic: Can't Delete Exe
- Replies: 3
- Views: 1757
- Tue Nov 23, 2010 3:20 am
- Forum: Problem Reports
- Topic: Malware Sample
- Replies: 19
- Views: 7043
Thanks for testing nick s. Hotkeys pointing to SB's terminate.bat works fine in killing that sample as do hotkeys pointing to RogueKiller which I keep handy. http://www.sur-la-toile.com/RogueKiller/ The latest sample I posted the hotkeys don't seem to work in an XP VM. If ran sandboxed the rogue is ...
- Mon Nov 22, 2010 10:09 pm
- Forum: Problem Reports
- Topic: Malware Sample
- Replies: 19
- Views: 7043
For those that can't test the first sample via Sandboxie/Win 7 then try the one below via Sandboxie/XP.
My hotkeys pointing to Terminate.bat doesn't work with this one.
Warning - PRON.
!http://www.mediafire.com/file/lb98consx ... btkzhr.rar
My hotkeys pointing to Terminate.bat doesn't work with this one.
Warning - PRON.
!http://www.mediafire.com/file/lb98consx ... btkzhr.rar
- Thu Nov 18, 2010 9:53 pm
- Forum: Problem Reports
- Topic: Prompt To Recover Exe
- Replies: 6
- Views: 2085
- Thu Nov 18, 2010 5:11 pm
- Forum: Problem Reports
- Topic: Prompt To Recover Exe
- Replies: 6
- Views: 2085
Hmmm, seems it might be just this one sample that I picked up and ran as I'm not getting the prompt with other samples. It was the very first exe I ran after installing the latest beta. You may wanna have a look? !http://www.mediafire.com/file/vx97buno2279xj6/setup4.rar http://www.virustotal.com/fil...
- Thu Nov 18, 2010 7:37 am
- Forum: Problem Reports
- Topic: Prompt To Recover Exe
- Replies: 6
- Views: 2085
Prompt To Recover Exe
XP VM, SB beta 3.51.03
If I run an exe from desktop in a default sandbox then delete the contents the exe I ran is prompted to recover.
If I run an exe from desktop in a default sandbox then delete the contents the exe I ran is prompted to recover.