I currently use Sandboxie to capture malware in the wild and it would probably extremely useful (maybe as an option) to hide the existence of Sandboxie's processes, files and registry keys to anything that is running sandboxed. As of today, not much malware detects it (but some apparently do), but in theory any sandboxed process can easily check whether Sandboxie is currently running and terminate itself if it finds it (much like many do with VMWare).
Hide Sandboxie's existence to sandboxed programs
-
TNT
Hide Sandboxie's existence to sandboxed programs
Well, is it possible? 
I currently use Sandboxie to capture malware in the wild and it would probably extremely useful (maybe as an option) to hide the existence of Sandboxie's processes, files and registry keys to anything that is running sandboxed. As of today, not much malware detects it (but some apparently do), but in theory any sandboxed process can easily check whether Sandboxie is currently running and terminate itself if it finds it (much like many do with VMWare).
I currently use Sandboxie to capture malware in the wild and it would probably extremely useful (maybe as an option) to hide the existence of Sandboxie's processes, files and registry keys to anything that is running sandboxed. As of today, not much malware detects it (but some apparently do), but in theory any sandboxed process can easily check whether Sandboxie is currently running and terminate itself if it finds it (much like many do with VMWare).
When we are here i would like to mention that the game Audiosurf may be using some of these techniques to discover that is sandboxed. All of my games run successfully sandboxed except this one. I've tried moving out of the box and running sandboxed but no sucess. Anyone can check this with the demo. http://www.audio-surf.com
I said it may be using. And if it's using then that technique is not a direct one. The program is trying o access something that it's blocked or something like that. When i am here, i forgot to run trace and see if something is really blocked and the game detects that. I'll report.tzuk wrote:Emider you're jumping to conclusions.
Who is online
Users browsing this forum: No registered users and 1 guest
