Trust No Program
Reply to topic
TheBat, Avast and Sandboxie
atomheart
Guest

Reply with quote
Sandboxie 3.74 64-bit
Windows 7 64-bit
Avast free 7.0.1473
TheBAT E-mail client

Hello,

I use TheBat as e-mail client and have configured Sandboxie that TheBat can write e-mail data (including attachment files) outside the sandbox. I use Avast free as my antivirus software. When I recveive mails with file attachments these files will be stored in a separate folder called "Attach". These folder is within the folder path which I have specified in Sandboxie as the folder for "theBat". When I get mails with malware attachments (for example a pdf file with a trojan inside) these files will be stored in the Attach folder as well. The problem is that Avast cannot detect this file as malware in the moment when it was stored first time in that folder. Only when I for example move or copy the file into another folder or when I let Avast check the file Avast will detect the file as malware. May it be possible that Sandboxie prevents Avast from scanning the files?
tzuk


Joined: 22 Jun 2004
Posts: 15004
Reply with quote
And you are sure that if Sandboxie is not the mix, then avast detects the malware as soon the file is placed in the Attach folder?

_________________
tzuk
View user's profileSend private message
Guest10


Joined: 27 Apr 2008
Posts: 4355
Location: Ohio, USA
Reply with quote
If you can exclude some folder from Avast scanning, you can probably use Notepad to create a .txt file in that folder that contains the EICAR test file.

See the one-line test string listed under "Design":
https://en.wikipedia.org/wiki/EICAR_test_file
(Don't include the [1] footnote symbol)

You need to create the file in a folder that Avast isn't scanning. Otherwise, Avast will "clean" the file right away.
Then, see if you can attach that file to two emails to yourself.
Open one when sandboxed and one when not sandboxed, to compare the two.

_________________
Paul
XP Pro SP3 (Admin rights), Zone Alarm Pro Firewall, Malwarebytes Pro, Firefox 21, Thunderbird 17
View user's profileSend private message
atomheart
Guest

Reply with quote
it was not Sandboxie, it was Avast who was not fast enough with updates for virus signatures. That was the reason why Avast did not detect it when it was written first time on the harddisk. Later (few hours) I checked the file again and it was detected. Amazing how fast malware distributes these days.
TheBat, Avast and Sandboxie
You can post new topics in this forum
You can reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
All times are GMT  
Page 1 of 1  

Use the RSS feed to watch this topic for replies
  
  
 Reply to topic  

Sandboxie is Copyright © 2004-2012 by Sandboxie Holdings LLC.  All rights reserved.
Sandboxie.com | Contact Author
This site has been viewed 208,553,045 times since June 2004