Not a trick question: Seriously, how do you scan a file?

If it doesn't fit elsewhere, it goes here
Post Reply
Jen898
Posts: 9
Joined: Sat Jan 01, 2011 2:32 pm
Location: San Diego, CA

Not a trick question: Seriously, how do you scan a file?

Post by Jen898 » Sun Jan 30, 2011 3:18 pm

This is not a trick question gotta say that as I'm sure some experienced computer users out there will think I'm stupid for asking this question. Fact is some people are new to computers.

I'd like to know how a person scans an individual file to make sure that it isn't malicious once you've opened it up in Sandboxie and decided that you want to save that file to your hard drive.

For peace of mind please tell new users the >steps to take to make 1000% certain that the file is not something that will ruin your operating system >and that it's okay to go ahead and copy said file to your hard drive. Thank you :)

WindowsXP
Avast Anti-virus
IE7
Firefox3.6
Chrome8.0
Opera11.01
Safari5.0
Avant11.7

Hank52
Posts: 203
Joined: Sun Apr 08, 2007 2:42 pm
Location: Canada

Post by Hank52 » Sun Jan 30, 2011 3:45 pm

I'm not sure how Avast works, but with Avria version 9, I just navigate to the File and right-Click on the File and Select Scan selected Files with Antivir. You would think Avast would have something similar?

I've looked on Google about Avast's Scanning method and I think you will have to look in Avasts settings to get a pop-up to tell you the results of the Scan, however if you should have a Virus, it's supposed to give you an alert sound.

If you were to get a Virus, just leave it there and let Sandboxie Delete the Sandbox.

One more thing. Even though the Virus will be Deleted, If avast detected it, it might have Quarantined it in Avasts Quarantine Folder. Don't worry about this. That Virus can't harm your computer in any way, and you can just remove the entry from Avast. You might also find that Avast will find a "Virus" in the System Restore when you Scan later. Not to Worry I'm told. That's just a "Windows thing" That can't hurt your Computer either. It's just another neutered copy of that Virus. Just Delete that System Restore point so you won't get anymore notifications from your Anti-virus Scanner.

Ken: :)
System Specs: = Win XP SP2 (32bit),[OutLook Express 6.] [ FireFox 19.0, - NoScript, - Sandboxie 3.76 - 32 bit, - FireWall - Comodo 5.3 ]

BoredNow
Posts: 56
Joined: Sat Sep 25, 2010 4:49 pm

Post by BoredNow » Mon Jan 31, 2011 10:20 pm

Yeah, like Hank52 said, just right-click and scan.

There's two ways to get there.

The first way scans your entire 'Sandbox'...the second way scans the specific file.

(1) Open My Computer > Local Disk (C) > Right-click Sandbox and choose 'Scan with Avast'

(2) Open My Computer > Local Disk (C) > Open Sandbox > Open (your name)>
Open the sandbox the file is in...eg.DefaultBox > Open User > Open Current >
Open the location you saved it to ..eg. Desktop > Right click the file and choose
'Scan with Avast'

I'm assuming Avast has the 'right-click scan' capability.

I usually just do the first method. If I find something then I track down the file
that I downloaded (method 2) and scan it again to confirm that it's the file my
AV scan caught.
Windows 7 Home Premium 64-bit
SandboxIE 5.2.1.2

BoredNow
Posts: 56
Joined: Sat Sep 25, 2010 4:49 pm

Post by BoredNow » Mon Jan 31, 2011 10:45 pm

Hank52 wrote:
:)
FireWall - Comodo 2.4 ??? ...two point four??...LoL..that's sooooo 2008.
:shock:
Windows 7 Home Premium 64-bit
SandboxIE 5.2.1.2

bs1
Posts: 565
Joined: Fri May 16, 2008 12:32 pm

Post by bs1 » Tue Feb 01, 2011 8:53 am

@Jen898,

Follow BoredNow's and Hank52's instructions regarding how to scan, using your resident anti-malware software, a sandboxed file before recovering it to your real system.

But, if you want to go one step further to be "1000% certain" (as you phased it), then you should consider scanning the file via Virustotal. Virustotal (and there other sites like it) is a free online scanning service that will scan a file using over two dozen anti-malware engines. The more scanners, the greater the likelihood that at least one of them will detect a new virus (or zero day exploit) that others might miss.

Using Virustotal is simple. Go to their web site, click the Browse button, and navigate to the sandboxed file that you want to scan.

FYT

Post by FYT » Mon Jul 16, 2012 6:23 am

I wanted to ask a closely related question so I thought I would just revive this thread rather than start a new topic. The method of malware scanning for sandboxed files mentioned above is the one I've been using. However, I noticed when you click "Explore Contents" in the Sandbox menu that you get a message recommending running windows explorer sandboxed before manipulating files. Is there a security risk in using the method of scanning via unsandboxed windows explorer?

If there is, then I've run into a snag, because neither of my on-demand malware scanners are allowed access when using sandboxed Windows explorer and I'm not sure how to change settings accordingly.

I'd appreciate any clarification on this subject! :)

Guest10
Posts: 5124
Joined: Sun Apr 27, 2008 5:24 pm
Location: Ohio, USA

Post by Guest10 » Mon Jul 16, 2012 4:22 pm

FYT wrote:Is there a security risk in using the method of scanning via unsandboxed windows explorer?
No, there's no risk.
Just right-click either the sandbox folder and perform a scan of the entire folder, or browse though the contents of the folder and right-click scan whatever you want, using an unsandboxed Windows Explorer.
Even if you made a mistake and ran a .exe file that's in the sandbox, it will start and run sandboxed anyway - just because it's located inside of the sandbox.
Paul
Win 10 Home 64-bit (w/admin rights) - Zone Alarm Pro Firewall, MalwareBytes Premium A/V, Cyberfox, Thunderbird
Sandboxie user since March 2007

FYT

Post by FYT » Mon Jul 16, 2012 7:20 pm

Ah, ok - I'm glad I sort of understood what I was doing. :wink: [Though I am curious about the reason for that automatic SB recommendation that one use a sandboxed windows explorer: when is that useful?]

Anyway, thanks for clearing things up, Paul -- much appreciated!!

bo.elam
Sandboxie Guru
Sandboxie Guru
Posts: 2809
Joined: Wed Apr 22, 2009 9:17 pm

Post by bo.elam » Mon Jul 16, 2012 9:12 pm

FYT wrote:[Though I am curious about the reason for that automatic SB recommendation that one use a sandboxed windows explorer: when is that useful?]
You can use a sandboxed Windows Explorer to navigate to files you download from the internet, when you click on the file, it will open sandboxed.

Bo

fyt

Post by fyt » Wed Jul 18, 2012 12:26 am

bo.elam wrote:You can use a sandboxed Windows Explorer to navigate to files you download from the internet, when you click on the file, it will open sandboxed.
Thanks very much for the explanation!

Post Reply

Who is online

Users browsing this forum: No registered users and 0 guests