sandboxie Created 14 years ago2010-08-01 21:42:29 UTC by Captain Terror Captain Terror

Created 14 years ago2010-08-01 21:42:29 UTC by Captain Terror Captain Terror

Posted 14 years ago2010-08-01 21:52:14 UTC Post #283753
Anyone have experience with this or other programs like it?

I'm using Sandboxie to test a file to see if it's actually a trojan or if it's a false positive.

The file is an executable in a .rar file. I can run winrar sandboxed to extract the files, but i'm not sure how to "move" the file in question to a place where i can test it out, without infecting my files.

In other words, if i simply extract the questionable file to my desktop, will the act of extracting it possibly infect me with a virus, or does it have to be opened first?

Once i have it on my desktop, i can simply run it using sandboxie safely. I'm sure there is a way to do this in sandboxie without extracting the file to my machine, i just don't know how..

Anyone have any ideas? If you'd like more information about the file in question, you'll have to pm me..
:badass:

Edit: I think i've got it but i'm not sure. What i did:
1. created new folder
2. copy/paste winrar file with suspicious file to new folder
3. right-click on folder and click "run sandboxed"

Now, if i look in the sandboxie control window, the new folder and the winrar file are in a new sandbox. Hopefully this is ok?
Captain Terror Captain Terrorwhen a man loves a woman
Posted 14 years ago2010-08-01 23:09:21 UTC Post #283754
Why am I imagining Boxxy sitting in a sandbox? >_>
Posted 14 years ago2010-08-01 23:18:59 UTC Post #283756
Don't go there...

Also, i believe if you actually extract the file in the quarantined sandboxie folder it should keep you safe, that's where all the sandboxie'd programs store their files and registry entries anyways.
Crollo CrolloTrollo
Posted 14 years ago2010-08-01 23:28:02 UTC Post #283758
Ever heard of a zip bomb? If that doesn't concern you, I guess you could try, but I'm no expert in the subject. Don't take my advice.
Posted 14 years ago2010-08-02 00:21:41 UTC Post #283761
I tried rezipping a file multiple times over, and it doesnt get smaller, in that case, zip bombs shouldn't exist, how exactly do you make them? (just out of pure curiosity.)
Posted 14 years ago2010-08-02 00:28:26 UTC Post #283763
Hint: Not with standard compression software. They're probably written manually in Notepad or something like that.
Posted 14 years ago2010-08-02 02:10:55 UTC Post #283770
crollo: so, you mean the sandboxie folder i.e., c:\sandboxie? (inside that folder, there's a text file labeled: "DONT-USE.txt")

)

Captain Terror Captain Terrorwhen a man loves a woman
Posted 14 years ago2010-08-02 08:58:35 UTC Post #283774
No there's a hidden folder that sandboxie uses for quarantining and you'll be able to find it easier if you actually install and run safe programs sanboxied, so you can tell which folder the files where actually saved to.
Crollo CrolloTrollo
You must be logged in to post a response.