Search found 29 matches

by raid
Sun Sep 30, 2012 8:47 pm
Forum: Contributed Utilities & Templates
Topic: Buster Sandbox Analyzer
Replies: 948
Views: 481594

Due the BSA package was generating too much traffic, the owner of the website where BSA is hosted requested I move the file to an external host. So the file will not be available at http://bsa.isoftware.nl/bsa.rar anymore. You can find the link in the website or in the first post of this thread. Hi...
by raid
Wed Dec 30, 2009 4:48 pm
Forum: Anything Else
Topic: A program on my computer says it's Sandboxie
Replies: 22
Views: 10094

tzuk should decide what's with this file, becouse he knows his files:) Decide? Well I decide this malware should stop spreading Start.exe program, probably trying to get anti-malware software to detect Sandboxie Start.exe as malware. So I've decided, now what? :) I don't know if this helps or not, ...
by raid
Wed Dec 16, 2009 9:58 pm
Forum: Anything Else
Topic: Does Sandboxie protect the "flash bios" ?
Replies: 35
Views: 12068

On the contrary, CMOS is very significant because this is where BIOS memory and settings are kept. Viruses out there are already tailred for corrupting cmos :http://www.viruslist.com/en/viruses/encyclopedia?virusid=5951 Old viruses, you really have no/next to no chance of encountering today... Unle...
by raid
Tue Dec 15, 2009 11:07 pm
Forum: Anything Else
Topic: Does Sandboxie protect the "flash bios" ?
Replies: 35
Views: 12068

I just confirmed, I am able to run my cmoscon utilitity sandboxed and it does have access to the cmos; I just copied the cmos contents to a file. As this is done with hardware calls directly, I don't think it would be an issue writing back the data either. This still doesn't mean I could actually r...
by raid
Mon Dec 14, 2009 8:15 pm
Forum: Anything Else
Topic: Does Sandboxie protect the "flash bios" ?
Replies: 35
Views: 12068

I just confirmed, I am able to run my cmoscon utilitity sandboxed and it does have access to the cmos; I just copied the cmos contents to a file. As this is done with hardware calls directly, I don't think it would be an issue writing back the data either. This still doesn't mean I could actually re...
by raid
Mon Dec 14, 2009 8:14 pm
Forum: Anything Else
Topic: Does Sandboxie protect the "flash bios" ?
Replies: 35
Views: 12068

You need no virus to check SandBoxie and your PC. IF [USER.OK= True ] AND [BIOS.FLASH_ROM= Enabled ] AND [MOTHERBOARD.OPTIONAL_JUMPERS= Enabled ] AND [WINDOWS.FLASH_PROGRAM= Available ] AND [VENDOR.BIOS_UPDATE= Available ] AND [WINDOWS.SANDBOXIE.CAN_RUN_THIS_PROGRAM= True ] AND [WINSOWS.ANTIVIRUS.L...
by raid
Tue Oct 13, 2009 12:02 pm
Forum: Feature Requests
Topic: Malware looks for Sandboxie EXE. option to change EXE name.
Replies: 26
Views: 18234

I know.. It's a feature tzuk is in no hurry to add. But, it doesn't hurt to ask, and ask again as versions change... Perhaps in the future, he'll humour those of us who desire the feature. Granted, not everybody uses sandboxie for what we do with it, and he didn't intend that when he originally wrot...
by raid
Sat Oct 10, 2009 12:21 pm
Forum: Problem Reports
Topic: Possible exploit
Replies: 21
Views: 8239

Tso could anyone help him reproduce the problem and give more information on this critte, tzuk will take care of the problem when he has time to do it. I don´t think he needs help reproducing the problem. Anyway I can tell you that bug is pretty rare. I doubt very much you will reproduce the proble...
by raid
Mon Oct 05, 2009 10:50 pm
Forum: Feature Requests
Topic: Malware looks for Sandboxie EXE. option to change EXE name.
Replies: 26
Views: 18234

Request: Sandboxie hide its presence from sandbox toggle.

I too would like the ability to toggle sandboxie's hiding its presence from the sandbox. Nothing fancy mind you, just no Sandboxie exes and what not are visible in taskmanager to anything being run from that particular sandbox. Some really sophisticated malware which checks for all sorts of vm like ...
by raid
Tue May 05, 2009 6:54 pm
Forum: Problem Reports
Topic: Any info re : sandboxie bypassed by 'stop.exe' and other??
Replies: 14
Views: 4683

I appreciate all the hard work you put into the software Tzuk. It's allowed for excellent malware study. :)
by raid
Thu Apr 30, 2009 3:22 pm
Forum: Anything Else
Topic: 3.36 vs.3.36.04
Replies: 11
Views: 3511

crofttk wrote:Where? I just downloaded and installed from http://www.sandboxie.com/index.php?DownloadSandboxie and Help/About gives me 3.36.04.

I followed the beta link. It would be a little easier if tzuk would mention when betas are released, but his time is better spent on other things. :)
by raid
Wed Apr 29, 2009 8:56 pm
Forum: Anything Else
Topic: 3.36 vs.3.36.04
Replies: 11
Views: 3511

I found v.05.. shouldn't we be using it instead of .04?
by raid
Sun Mar 01, 2009 6:33 pm
Forum: Problem Reports
Topic: Major problem with IE8 & FF3
Replies: 4
Views: 2650

Sadly, it sounds like your PC has issues that just didn't come to light until a standard installer was run.

You might want to try re-installing ie8. You are of course warned, running beta software does have it's own risks.
by raid
Tue Feb 17, 2009 3:13 pm
Forum: Problem Reports
Topic: Interesting malware file
Replies: 59
Views: 33509

Re: Interesting malware file

Thanks Darth, that will help me check things out. -- Well, it's a dropper program that's SandBoxie aware. Will not run under sandboxie 3.35.08; Doesn't work under v3.34 either. Will not create the file hack.exe unless run outside of SandBoxie. It'll be going into defs for mbam tho, as it certainly ...
by raid
Mon Feb 16, 2009 8:34 pm
Forum: Problem Reports
Topic: Cannot recover files created by malware
Replies: 5
Views: 1716

Re: Cannot recover files created by malware

Yes, I have it turned on. I'm pretty sure the program in question is just deleting the files before they can be recovered. From what I understand, there's no way to prevent files from being deleted inside of sandboxie - I found a thread that talked about injecting a custom DLL into the sandbox, but...