Results 1 to 9 of 9

Thread: Where is the sandbox for Avast?

Hybrid View

Previous Post Previous Post   Next Post Next Post
  1. #1
    Join Date
    Mar 2010
    Posts
    2,442

    Lightbulb

    Finally found the answer:

    What exactly is isolated?

    All file-system changes done by a sandboxed application are virtualized (these modified files are stored in the hidden folder in root: "\## aswSnx private storage"). The folder can be visible if you set HideTarget=0 in "%avast data folder%\snx_lconfig.xml" file. File changes are cached in memory, so any unapproved file modifications in this hidden folder may lead to "undefined" state. I think these attempts are also blocked by our driver (not sure right now). All registry changes are also virtualized (see "HKEY_CURRENT_USERS\__aswSnx private storage" hive), all named objects (events, sections, ...) are virtualized (download winobj.zip to see Windows Object Manager namespaces), in-process communication (LPC/ALPC) is virtualized. Process/Thread/... modifications are blocked or limited. Windows names/classes/SCM/WinHooks will be virtualized in next version.

    Avast sandbox uses pre-defined exceptions for the most browsers (see snx_gconfig.xml), i.e. bookmarks/cookies/history are excluded automatically from the virtualization and everything you'll download (by standard way, e.g. by using SaveAs dialogs, ...) are also excluded. However, every file which would be saved by malware is virtualized. We plan to add more options into expert settings in upcoming versions.
    Quoted from

    Tried to edit snx_lconfig.xml, but no luck.

  2. #2
    Join Date
    Sep 2011
    Location
    FRANCE
    Posts
    1
    First, I am sorry to reup this topic today.
    The thing is that I only find here what I wanted to know about the avast sandbox.
    Concerning the edition of the snx_lconfig.xml file, I modified & saved it under the safe mode. Then when it restarts normally you can see the '\## aswSnx private storage' folder !
    Your post is the hopeful result of a very long research on the Internet. So, BIG, BIG, BIG thanks

Tags for this Thread

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •