Welcome to City-Data.com Forum!
U.S. CitiesCity-Data Forum Index
Go Back   City-Data Forum > General Forums > Science and Technology > Computers
 [Register]
Please register to participate in our discussions with 2 million other members - it's free and quick! Some forums can only be seen by registered members. After you create your account, you'll be able to customize options and access all our 15,000 new posts/day with fewer ads.
View detailed profile (Advanced) or search
site with Google Custom Search

Search Forums  (Advanced)
 
 
Old 12-24-2022, 07:10 PM
 
157 posts, read 105,320 times
Reputation: 107

Advertisements

Quote:
Originally Posted by TurcoLoco View Post
But, what if you are running Sandboxie within Windows Sandbox which is running in VBox which is running on Lindows, then what?



jk.





Merry Xmas to all the geeks everywhere!
It'd still see the DLL on most malware analyst-detection since it is running in Sandboxie... Regardless of the layers of VM Sandboxie is running within... Same with all major virtualization and subsystem-isolation solutions, though... Malware just blacklists shared libraries and memory mapping behavior, and 99.9% of the solutions do little to nothing to hide...

Years back there was a third-party plugin for Sandboxie that did okay hiding it from IAT, LoadLibrary, and memory scan, but that stopped being updated...

Sandboxie is second to none for zero and nth day exploit infection containment, though... Combine it with Chromium rendering sandboxing and telementry opsec and you'll make the NSA annoyed...

Last edited by 24gf424g; 12-24-2022 at 07:22 PM..
Quick reply to this message

 
Old 12-25-2022, 01:16 PM
 
Location: Wartrace,TN
8,051 posts, read 12,767,329 times
Reputation: 16479
Just a report back. I tried all the suggestions (uninstalling Malewarebytes and the windows tools posted). It still wouldn't update. I also did a little research on the KB ending in 1234 and there were reported problems. I decided to go ahead and do the iso image update keeping all apps and personal files.

It went smoothly and no data was lost. Today it updated a security update and it says I am up to date.
I guess I will see if it does any cumulative update in the future.

THANKS ALL for the suggestions and help!
Quick reply to this message
 
Old 12-28-2022, 11:49 AM
 
Location: SCW, AZ
8,307 posts, read 13,439,396 times
Reputation: 7980
Quote:
Originally Posted by 24gf424g View Post
It'd still see the DLL on most malware analyst-detection since it is running in Sandboxie... Regardless of the layers of VM Sandboxie is running within... Same with all major virtualization and subsystem-isolation solutions, though... Malware just blacklists shared libraries and memory mapping behavior, and 99.9% of the solutions do little to nothing to hide...

Years back there was a third-party plugin for Sandboxie that did okay hiding it from IAT, LoadLibrary, and memory scan, but that stopped being updated...

Sandboxie is second to none for zero and nth day exploit infection containment, though... Combine it with Chromium rendering sandboxing and telementry opsec and you'll make the NSA annoyed...
I was being funny with my post, didn't think you'd take it this serious.
Since it got a bit more serious, and given that I don't know anything about Sandboxie, allow me to ask:

If a malware could tell it was running in a virtual environment, why would that even matter, especially if clipboard or file sharing was not enabled between the Guest and the Host machines?


Quote:
Originally Posted by Wartrace View Post
Just a report back. I tried all the suggestions (uninstalling Malewarebytes and the windows tools posted). It still wouldn't update. I also did a little research on the KB ending in 1234 and there were reported problems. I decided to go ahead and do the iso image update keeping all apps and personal files.

It went smoothly and no data was lost. Today it updated a security update and it says I am up to date.
I guess I will see if it does any cumulative update in the future.

THANKS ALL for the suggestions and help!
Thank you for reporting back with the good news!

Cheers!
Quick reply to this message
Please register to post and access all features of our very popular forum. It is free and quick. Over $68,000 in prizes has already been given out to active posters on our forum. Additional giveaways are planned.

Detailed information about all U.S. cities, counties, and zip codes on our site: City-data.com.


 
Please update this thread with any new information or opinions. This open thread is still read by thousands of people, so we encourage all additional points of view.

Quick Reply
Message:
Over $104,000 in prizes was already given out to active posters on our forum and additional giveaways are planned!

Go Back   City-Data Forum > General Forums > Science and Technology > Computers

All times are GMT -6.

© 2005-2024, Advameg, Inc. · Please obey Forum Rules · Terms of Use and Privacy Policy · Bug Bounty

City-Data.com - Contact Us - Archive 1, 2, 3, 4, 5, 6, 7, 8, 9, 10, 11, 12, 13, 14, 15, 16, 17, 18, 19, 20, 21, 22, 23, 24, 25, 26, 27, 28, 29, 30, 31, 32, 33, 34, 35, 36, 37 - Top