Sandbox is and disabling of anti-virus

If it's not about a problem in the program
Post Reply
Dreblue
Posts: 1
Joined: Mon Sep 25, 2017 8:15 pm

Sandbox is and disabling of anti-virus

Post by Dreblue » Tue Sep 26, 2017 4:21 am

So the other day I used sandboxie to execute a suspicious program using a fairly new laptop. And I was surprised to see that seconds during the execution of this program, I got a notification stating that my anti virus was disabled? I was wondering whether this is possible for a sandboxed program to do this or whether sandboxie creates a virtualized version of the anti virus and it was in fact this virtualized copy that was 'disabled' rather than my outside one? I must add that the program did require uac permission which it was given. Does that impact on it too? I'm a bit concerned, however, if it was in fact a virus trying to infect me, would deleting the sandboxed contents mean removal of the virus or did the virus in fact bypass sandboxie security?

Barb@Invincea
Sandboxie Support
Sandboxie Support
Posts: 2337
Joined: Mon Nov 07, 2016 3:10 pm

Re: Sandbox is and disabling of anti-virus

Post by Barb@Invincea » Tue Sep 26, 2017 11:39 am

Hello Dreblue,

Isolated applications inside Sandboxie cannot modify applications running on your host, unless you explicitly opened a path for them (for example, some templates allow communication between Sandboxed apps and the host, in order to make modifications) .
Deleting the contents of your Sandbox ensures anything inside of it gets deleted.

If you could provide more information, as well as repro steps, I will test the scenario:
viewtopic.php?f=11&t=19746

Regards,
Barb.-

Post Reply

Who is online

Users browsing this forum: No registered users and 1 guest