Avast Virtualization feature and Prevx SafeOnline

I posted this earlier in the beta forums(because with the 5.1 beta was the first time I used them together.) However I got no reply from an Avast official there and it still happens with 5.1 final and latest build so I’ll copy it here:

[QUOTE]I’m not sure if this is only in the beta, but I’ve only tried it with 5.1.807.

When starting a virtualized browser SafeOnline can still access and protect the browser, Prevx support suspects leaks in the sandbox. Some more details can be found here:
http://www.wilderssecurity.com/showthread.php?t=288579
[/quote]
Original topic:
http://forum.avast.com/index.php?topic=67476.0

Frankly, I don’t quite see any problem here… The sandbox works by virtualizing all interfaces of the host OS. However, if there’s another associated piece of software running “beyond the iron curtain” (i.e. unsandboxed), there are ways these two can communicate.

That is, the avast sandbox may not work as expected in case where there’s already a piece of malware preinstalled on the computer, and another piece of malware, now running inside the sandbox, tries to leverage its capabilities. These two will be able to talk together.

And this is what we see with PrevX - it has some functionality running outside the sandbox (e.g. its drivers etc) and so the sandboxed part (the browser plugin) can use it to do what it needs to do…

Thanks
Vlk

Ok, thanks for your explanation :slight_smile: