Hi!
Does Sandboxie protect MBR and BIOS (UEFI) from any changes? (Because some malware can do bad things with these locations).
Hi!
Does Sandboxie protect MBR and BIOS (UEFI) from any changes? (Because some malware can do bad things with these locations).
Hi B B2,
Sandboxie protects you by not allowing Sandboxed applications modify your host. It runs along with Windows. Please see these entries for more info:
https://www.sandboxie.com/HowItWorks
https://www.sandboxie.com/FrequentlyAskedQuestions#HowItWorks
If you accidentally run malware in the Sandbox, you should be protected. However, please keep in mind that nothing 100% bullet proof, and that an antivirus is recommended along with Sandboxie: https://www.sandboxie.com/FrequentlyAskedQuestions#HowSafe
Sandboxed applications will also prevent you from installing drivers and services, thus minimizing the chances of making changes to the computer (as sometimes users may allow direct access to files/folders from the Sandbox. See here: https://www.sandboxie.com/ResourceAccessSettings#file )
If you make changes inside a sandbox that may potentially contain malware, those changes will not replicate to your host. However, Sandboxie will not work before the OS is loaded, so if you are already affected by a program trying to make changes to your BIOS (or anything happens before the OS loads) Sandboxie won't protect you at that stage.
Regards,
Barb@Sophos
Community Support Engineer | Sophos Technical Support
Knowledge Base | @SophosSupport | Sign up for SMS Alerts
If a post solves your question use the 'This helped me' link.
Barb@Sophos said:Hi B B2,
Sandboxie protects you by not allowing Sandboxed applications modify your host. It runs along with Windows. Please see these entries for more info:
https://www.sandboxie.com/HowItWorks
https://www.sandboxie.com/FrequentlyAskedQuestions#HowItWorks
I readed that, but MBR and BIOS are not mentioned in list of objects supervised by Sandboxie. So, what will happen if malware (running in sandbox) tries to write to MBR, for example? Will Sandboxie create sandboxed copy of MBR and prevent writing to host's MBR?
Why no answer? :(