Hotkeys
Hotkeys
Built in dedicated Hotkeys that can't be circumvented to the terminate command would be of help against some ransom/screenlockers type malware.
I know they are contained but hotkeys could save a reset.
I know they are contained but hotkeys could save a reset.
Hunting the Hunter!
I explained the problem at the bottom of this post:
http://www.sandboxie.com/phpbb/viewtopic.php?t=9338
I've not fixed that yet, but what I described there is going to be the approach that I will take to deal with this issue.
http://www.sandboxie.com/phpbb/viewtopic.php?t=9338
I've not fixed that yet, but what I described there is going to be the approach that I will take to deal with this issue.
tzuk
Ok thanks tzuk.
For those that are testing these ransom/screenlockers the below batch file will run the terminate command every 30 seconds whilst the command window is open.
Thanks to majoMo wilders.
For those that are testing these ransom/screenlockers the below batch file will run the terminate command every 30 seconds whilst the command window is open.
Thanks to majoMo wilders.
Code: Select all
::30=30 sec.
@echo off
:START
ping 127.0.0.1 -n 30 > nul
start "" "C:\Program Files\Sandboxie\Start.exe" /box:DefaultBox /terminate
GOTO START
Hunting the Hunter!
Thanks Oneder. In a followup post in that thread http://www.wilderssecurity.com/showpost ... ostcount=6 Franklin says:Oneder wrote:For those that are testing these ransom/screenlockers the below batch file will run the terminate command every 30 seconds whilst the command window is open.[/code]
The batchflie must be already running before executing the malware.I was using WinHotKey here but some of these new Ransom/Winlock/Screenlockers lock everything up where hotkeys just won't work whereas the batchfile, which has to be running before executing the malware, works a treat.
This may be nice for those testing malware (not me!)

soccerfan
Franklin and I are always testing malware so the batch works a treat in not having to reset with these screenlockers.soccerfan wrote: The batchflie must be already running before executing the malware.
This may be nice for those testing malware (not me!)

On my XP VM's where I'm not using SB I point the batch to RogueKiller.
Yes you can use Task scheduler to run a normal terminate bat but minimum wait to execute is a minute.
Hunting the Hunter!
The program, named Extractor, is used to extract contents from all kind of packed files: archives, setups, embedded files, etc.Oneder wrote:Sounds good buster, wouldn't mind a look at it if OK by you.
It supports: 7z, ZIP, GZIP, BZIP2, TAR, RAR, CAB, ISO, ARJ, LZH, CHM, Z, CPIO, RPM, DEB, NSIS, ACE, EML, Inno Setup, Microsoft SZDD, Microsoft TNEF, RTF, Gentee, Setup Factory, RapSFX, Thraex´s Astrum InstallWizard, SEA, Instyler, BInstall, Cexe, Quick Batch File Compiler, WScript, Smart Install Maker, Stubbie SFX Extractor, ARC, ZOO, SIS and virtually any executable compressed file format.
I can show you a screenshot of the project:

Extractor is an improved version of Universal Extractor: http://legroom.net/software/uniextract
In fact I started coding Extractor in 2007 because I was not satified with UE. Right now Extractor is the best program of its kind (there are not many of them

Here you can see some statistics:

Wow. I have been using uniextract for quite a while but your Extractor even wraps it all in sandboxie.Buster wrote:Extractor is an improved version of Universal Extractor:...
In fact I started coding Extractor in 2007 because I was not satified with UE...

Buster, do you have any plans of a public release (or a contributed utility)?
soccerfan
Well, Extractor uses a combination of 7Zip, Sandboxie and other custom extraction procedures.soccerfan wrote:Wow. I have been using uniextract for quite a while but your Extractor even wraps it all in sandboxie.![]()
As you can see in the statistics, 7Zip does the job most of the time and Sandboxie usually does the rest.
No, I don´t have plans of releasing this tool.soccerfan wrote:Buster, do you have any plans of a public release (or a contributed utility)?
Who is online
Users browsing this forum: No registered users and 1 guest