 |
 | Sandboxed programs fail to start |  |
|
Unknown_User_784
| Joined: 01 Jan 1970 |
| Posts: 0 |
|
|
 |
Posted: Sun May 13, 2007 9:13 pm |
|
 |
 |
 |
 |
I've been running Sandboxie 2.86 for over a month now. Initially, sandboxed programs ran just fine... but as of recently, everything has failed to "start". The processes are launched, but fail to initiate any GUI or console.
I've also noticed that they have very little allocated memory when launched .Take Internet Explorer 7 for example: When launched sandboxed, IEXPLORE.EXE gets 52,788KB (Virtual) 3,948KB (Working Set) and 15,028KB (Page File) and hangs. When running it normally, IEXPLORE.EXE gets 145,184KB (Virtual) 30,076KB (Working Set) and 21,036 (Page File). [Acquired via TaskInfo]
The same story applies to any other application I try to run. When accessing my sandbox (%APPDATA%\Sandbox), I get the following:
Directory of: %APPDATA%\Sandbox\*.*
05/13/2007 2:03pm Sorted by Long Name
Levels: All Date: Modified
%APPDATA%\Sandbox
0 files; 0 bytes
%APPDATA%\Sandbox\DefaultBox
RegHive 262,144 05/13/2007 1:57pm A
RegHive.LOG 1,024 05/13/2007 1:59pm HA
2 files; 263,168 bytes
%APPDATA%\Sandbox\DefaultBox\drive
0 files; 0 bytes
%APPDATA%\Sandbox\DefaultBox\drive\C
0 files; 0 bytes
%APPDATA%\Sandbox\DefaultBox\drive\C\WINDOWS
0 files; 0 bytes
%APPDATA%\Sandbox\DefaultBox\drive\C\WINDOWS\AppPatch
AppLoc.tmp 4 05/12/2007 11:39pm A
1 file; 4 bytes
Total: 6 directories; 3 files; 263,172 bytes
|
Emptying the sandbox and running another sandboxed application yields the same sandbox contents. In case you don't happen to know, the %WINDIR%\AppPatch directory is used my Microsoft AppLocale. I'm pretty sure that there's nothing wrong with AppLocale as I've ran applications through AppLocale inside a sandbox successfully in the past.
I am running Windows XP Media Center Edition 2005, all updates applied.
System specs: AMD Athlon 64 X2 5200+, 2GB RAM, with 44GB free on the OS and Sandbox HD. I do not recall making any drastic system changes before Sandboxie stopped functioning. (Even the Start.exe, etc. components stopped working)
Contents of the configuration file:
# Sandboxie Configuration File
# Automatically generated whenever the configuration changes.
# Set ConfigLevel to 99 to prevent the overwriting of this file.
[GlobalSettings]
ConfigLevel=1
BoxRootFolder=%APPDATA%
ForceDisableSeconds=10
FileTrace=.
PipeTrace=.
KeyTrace=.
IpcTrace=.
[DefaultBox]
Enabled=yes
CopyLimitKb=32768
OpenFilePath=msimn.exe,%AppData%\Identities
OpenFilePath=msimn.exe,%Local AppData%\Identities
OpenFilePath=msimn.exe,%AppData%\Microsoft\Address Book
OpenFilePath=msimn.exe,*.eml
OpenFilePath=outlook.exe,%AppData%\Microsoft\Outlook
OpenFilePath=outlook.exe,%Local AppData%\Microsoft\Outlook
OpenFilePath=outlook.exe,*.eml
OpenKeyPath=msimn.exe,HKEY_CURRENT_USER\Identities
OpenKeyPath=msimn.exe,HKEY_CURRENT_USER\Software\Microsoft\Outlook Express
OpenKeyPath=msimn.exe,HKEY_CURRENT_USER\Software\Microsoft\Internet Account Manager
OpenKeyPath=msimn.exe,HKEY_LOCAL_MACHINE\Software\Microsoft\Outlook Express
OpenKeyPath=msimn.exe,HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Outlook Express
OpenKeyPath=outlook.exe,HKEY_CURRENT_USER\Software\Microsoft\Office
OpenKeyPath=outlook.exe,HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook
LingerProcess=acrord32.exe
LingerProcess=jusched.exe
LingerProcess=syncor.exe
RecoverFolder=%Favorites%
RecoverFolder=%Personal%
RecoverFolder=%Desktop%
BlockDrivers=y
BlockFakeInput=y
|
I'd really like to be able to use Sandboxie again, so any help would be appreciated.
|
|
|
 |
 | |  |
|
martinr
| Joined: 15 Apr 2007 |
| Posts: 76 |
|
|
 |
Posted: Mon May 14, 2007 3:47 pm |
|
 |
 |
 |
 |
I wonder if you're seeing similar symptoms to the problem one or 2 others are having? I'm no expert on Sandboxie at all, but can you confirm what happens if you give Internet Explorer at least 1.5 minutes to load i.e. is it really failling to start or just taking a long time (>1.5 mins)? I ask because I have had that snag. It also affected Outlook Express but not, for example, the Firefox browser. So could you also confirm you have this problem with all applications or is it just I.E. and one or 2 others e.g. O.E.?
Thanks.
|
|
|
 |
 | |  |
|
Unknown_User_784
| Joined: 01 Jan 1970 |
| Posts: 0 |
|
|
 |
Posted: Mon May 14, 2007 9:52 pm |
|
 |
 |
 |
 |
To my knowledge, it affects all programs that I try to run, even if I give it 10+ hours to try and start. (Basically overnight) I've let Firefox, IE, Thunderbird, and the Sandboxie browser (The Function>Run Sandboxed>Any Program\From Start Menu thing) try to run sandboxed overnight a few times with no success.
I do know what issue you're talking about though.. it's happened to me on an older computer in which there was a <30 sec delay in launching programs. I've never quite resolved that issue either.
|
|
|
 |
 | |  |
|
Unknown_User_784
| Joined: 01 Jan 1970 |
| Posts: 0 |
|
|
 |
Posted: Tue May 15, 2007 4:14 am |
|
 |
 |
 |
 |
In case this further helps to solve my issue, here's a Sandboxie trace (IpcTrace=ad + PipeTrace=ad) Note: I'm using Internet Explorer 7 to acquire these since it's a widespread program. I have the same issue with all programs I try to run sandboxed.
(003928) SBIE (IA) 00000001 \KnownDlls\kernel32.dll
(003928) SBIE (IA) 00000000 \Sandbox\Administrator\DefaultBox\Session_0\BaseNamedObjects\SbieDllDummyEvent_3928
(003928) SBIE (IA) 00000004 \BaseNamedObjects\Sandboxie_Services
(003928) SBIE (IA) 00120001 \BaseNamedObjects\ShimCacheMutex
(003928) SBIE (IA) 00000002 \BaseNamedObjects\ShimSharedMemory
(001904) SBIE (IA) 0000000E \KnownDlls\kernel32.dll
(001904) SBIE (IA) 001F0001 \Windows\ApiPort
(001904) SBIE (IA) 00000004 \NLS\NlsSectionUnicode
(001904) SBIE (IA) 00000004 \NLS\NlsSectionLocale
(001904) SBIE (IA) 00000005 \NLS\NlsSectionSortkey
(001904) SBIE (IA) 00000004 \NLS\NlsSectionSortTbls
(001904) SBIE (IA) 0000000E \KnownDlls\advapi32.dll
(001904) SBIE (IA) 0000000E \KnownDlls\rpcrt4.dll
(001904) SBIE (IA) 0000000E \KnownDlls\gdi32.dll
(001904) SBIE (IA) 0000000E \KnownDlls\user32.dll
(001904) SBIE (IA) 0000000E \KnownDlls\msvcrt.dll
(001904) SBIE (IA) 0000000E \KnownDlls\SHLWAPI.dll
(001904) SBIE (IA) 0000000E \KnownDlls\shell32.dll
(001904) SBIE (IA) 0000000E \KnownDlls\ole32.dll
(001904) SBIE (IA) 0000000E \KnownDlls\urlmon.dll
(001904) SBIE (IA) 0000000E \KnownDlls\oleaut32.dll
(001904) SBIE (IA) 0000000E \KnownDlls\iertutil.dll
(001904) SBIE (IA) 0000000E \KnownDlls\version.dll
(001904) SBIE (IA) 00000001 \KnownDlls\kernel32.dll
(001904) SBIE (IA) 00000000 \Sandbox\Administrator\DefaultBox\Session_0\BaseNamedObjects\SbieDllDummyEvent_1904
(001904) SBIE (IA) 00000004 \BaseNamedObjects\Sandboxie_Services
(001904) SBIE (IA) 00000004 \NLS\NlsSectionCType
(001904) SBIE (IA) 00000000 \Sandbox\Administrator\DefaultBox\Session_0\BaseNamedObjects\shell.{A48F1A32-A340-11D1-BC6B-00A0C90312E1}
(001904) SBIE (IA) 0000000E \KnownDlls\COMCTL32.dll
(001904) SBIE (PA) 00000400 001904
(001904) SBIE (IA) 00000000 \Sandbox\Administrator\DefaultBox\Session_0\BaseNamedObjects\ZonesCounterMutex
(001904) SBIE (IA) 00000000 \Sandbox\Administrator\DefaultBox\Session_0\BaseNamedObjects\ZonesCacheCounterMutex
(001904) SBIE (IA) 00000000 \Sandbox\Administrator\DefaultBox\Session_0\BaseNamedObjects\ZonesLockedCacheCounterMutex
(001904) SBIE (IA) 001F0001 \ThemeApiPort
(001904) SBIE (PA) 00000000 001904
(001904) SBIE (IA) 00000000 \Sandbox\Administrator\DefaultBox\Session_0\BaseNamedObjects\KAV_INPROCESS_DLL_LOADED
(001904) SBIE (ID) 00000006 \BaseNamedObjects\windows_shell_global_counters
(001904) SBIE (TA) 00000000 001904
(001904) SBIE (FA) 00000001.0F.FFFFFFFF \Device\NamedPipe\lsarpc
(001904) SBIE (FA) C0100080.01.00000040 \Device\NamedPipe\lsarpc
(001904) SBIE (IA) 00000000 \Sandbox\Administrator\DefaultBox\Session_0\BaseNamedObjects\windows_shell_global_counters
(001904) SBIE (IA) 00000000 \Sandbox\Administrator\DefaultBox\Session_0\BaseNamedObjects\windows_shell_global_counters
(001904) SBIE (IA) 00000000 \Sandbox\Administrator\DefaultBox\Session_0\BaseNamedObjects\shell.{210A4BA0-3AEA-1069-A2D9-08002B30309D}
(001904) SBIE (IA) 000F0007 \BaseNamedObjects\CiceroSharedMemDefaultS-1-5-21-448539723-507921405-725345543-1003
(001904) SBIE (IA) 001F0001 \BaseNamedObjects\CTF.LBES.MutexDefaultS-1-5-21-448539723-507921405-725345543-1003
(001904) SBIE (IA) 001F0001 \BaseNamedObjects\CTF.Compart.MutexDefaultS-1-5-21-448539723-507921405-725345543-1003
(001904) SBIE (IA) 001F0001 \BaseNamedObjects\CTF.Asm.MutexDefaultS-1-5-21-448539723-507921405-725345543-1003
(001904) SBIE (IA) 001F0001 \BaseNamedObjects\CTF.Layouts.MutexDefaultS-1-5-21-448539723-507921405-725345543-1003
(001904) SBIE (IA) 001F0001 \BaseNamedObjects\CTF.TMD.MutexDefaultS-1-5-21-448539723-507921405-725345543-1003
(001904) SBIE (IA) 001F0001 \BaseNamedObjects\CTF.TimListCache.FMPDefaultS-1-5-21-448539723-507921405-725345543-1003MUTEX.DefaultS-1-5-21-448539723-507921405-725345543-1003
(001904) SBIE (IA) 000F001F \BaseNamedObjects\CTF.TimListCache.FMPDefaultS-1-5-21-448539723-507921405-725345543-1003SFM.DefaultS-1-5-21-448539723-507921405-725345543-1003
(001904) SBIE (IA) 0000000E \KnownDlls\USERENV.dll
|
Also, technical information on the two threads of IEXPLORE.EXE when loaded that I screencapped. This is after letting it sit for 10 minutes+ (See the Uptime column). The two thread states explain why they're not launching, but I can't see why not. (Wait Execution Delay/Wait User Request)
http://img515.imageshack.us/img515/3022/sandboxie01hh1.png
http://img515.imageshack.us/img515/4610/sandboxie02qb1.png
As a side note: Yes, I've disabled Kaspersky AV and tried it. I've also unloaded everything else and tried it to no avail. This leaves me quite stumped...
[edit]
I think the following might help:
Summary of some processes that are running... some might seem out of place since most of these are usually run on my file server, which hasn't worked for over two months.
avp.exe - Kaspersky AV
perl.exe - MRTG (Multi Router Traffic Grapher)
mDNSResponder - Something that appeared after I installed Photoshop CS3
tos*.exe - Toshiba Bluetooth stack
spd.exe / cFosSpeed.exe - cFosSpeed
mailserver.exe - Kerio Mail Server
spamserver.exe - Anti-spam component of mail server
lighttpd.exe - LightTPD (HTTP server)
ooccag.exe - O&O CleverCache
StarWindService.exe - Alcohol 120%
IWM.exe - logging
TrueCrypt.exe - HD encryption
Blackbox.exe - xoblite (Windows shell replacement) |
As you can see... Sandboxie is very useful in an environment such as this.
|
|
|
 |
 | |  |
|
tzuk
| Joined: 22 Jun 2004 |
| Posts: 15159 |
|
|
 |
Posted: Tue May 15, 2007 5:12 pm |
|
 |
 |
 |
 |
I saw this in your trace:
| Quote: |
| \Sandbox\Administrator\DefaultBox\Session_0\BaseNamedObjects\KAV_INPROCESS_DLL_LOADED |
This is probably a Kaspersky-related resource, and it is being sandboxed. I am just guessing here... But let's say Kaspersky is waiting for the app to connect to the resource:
\BaseNamedObjects\KAV_INPROCESS_DLL_LOADED
But because of Sandboxie, the app actually tries to connect to:
\Sandbox\Administrator\DefaultBox\Session_0\BaseNamedObjects\KAV_INPROCESS_DLL_LOADED
So as a first step, I suggest, you add to your Sandboxie.ini:
| OpenIpcPath=*\BaseNamedObjects*\KAV_INPROCESS_DLL_LOADED |
(Note the stars.)
Then relod configuration and retry.
|
|
_________________ tzuk
|
 |
 | |  |
|
Unknown_User_784
| Joined: 01 Jan 1970 |
| Posts: 0 |
|
|
 |
Posted: Tue May 15, 2007 9:41 pm |
|
 |
 |
 |
 |
I added:
| OpenIpcPath=*\BaseNamedObjects*\KAV_INPROCESS_DLL_LOADED |
to the config, reloaded it... and still nothing.
Here's another trace with that config modification.
(005152) SBIE (IA) 00000001 \KnownDlls\kernel32.dll
(005152) SBIE (IA) 00000000 \Sandbox\Administrator\DefaultBox\Session_0\BaseNamedObjects\SbieDllDummyEvent_5152
(005152) SBIE (IA) 00000004 \BaseNamedObjects\Sandboxie_Services
(005152) SBIE (IA) 00120001 \BaseNamedObjects\ShimCacheMutex
(005152) SBIE (IA) 00000002 \BaseNamedObjects\ShimSharedMemory
(002656) SBIE (IA) 0000000E \KnownDlls\kernel32.dll
(002656) SBIE (IA) 001F0001 \Windows\ApiPort
(002656) SBIE (IA) 00000004 \NLS\NlsSectionUnicode
(002656) SBIE (IA) 00000004 \NLS\NlsSectionLocale
(002656) SBIE (IA) 00000005 \NLS\NlsSectionSortkey
(002656) SBIE (IA) 00000004 \NLS\NlsSectionSortTbls
(002656) SBIE (IA) 0000000E \KnownDlls\advapi32.dll
(002656) SBIE (IA) 0000000E \KnownDlls\rpcrt4.dll
(002656) SBIE (IA) 0000000E \KnownDlls\gdi32.dll
(002656) SBIE (IA) 0000000E \KnownDlls\user32.dll
(002656) SBIE (IA) 0000000E \KnownDlls\msvcrt.dll
(002656) SBIE (IA) 0000000E \KnownDlls\SHLWAPI.dll
(002656) SBIE (IA) 0000000E \KnownDlls\shell32.dll
(002656) SBIE (IA) 0000000E \KnownDlls\ole32.dll
(002656) SBIE (IA) 0000000E \KnownDlls\urlmon.dll
(002656) SBIE (IA) 0000000E \KnownDlls\oleaut32.dll
(002656) SBIE (IA) 0000000E \KnownDlls\iertutil.dll
(002656) SBIE (IA) 0000000E \KnownDlls\version.dll
(002656) SBIE (IA) 00000001 \KnownDlls\kernel32.dll
(002656) SBIE (IA) 00000000 \Sandbox\Administrator\DefaultBox\Session_0\BaseNamedObjects\SbieDllDummyEvent_2656
(002656) SBIE (IA) 00000004 \BaseNamedObjects\Sandboxie_Services
(002656) SBIE (IA) 00000004 \NLS\NlsSectionCType
(002656) SBIE (IA) 00000000 \Sandbox\Administrator\DefaultBox\Session_0\BaseNamedObjects\shell.{A48F1A32-A340-11D1-BC6B-00A0C90312E1}
(002656) SBIE (IA) 0000000E \KnownDlls\COMCTL32.dll
(002656) SBIE (PA) 00000400 002656
(002656) SBIE (IA) 00000000 \Sandbox\Administrator\DefaultBox\Session_0\BaseNamedObjects\ZonesCounterMutex
(002656) SBIE (IA) 00000000 \Sandbox\Administrator\DefaultBox\Session_0\BaseNamedObjects\ZonesCacheCounterMutex
(002656) SBIE (IA) 00000000 \Sandbox\Administrator\DefaultBox\Session_0\BaseNamedObjects\ZonesLockedCacheCounterMutex
(002656) SBIE (IA) 001F0001 \ThemeApiPort
(002656) SBIE (PA) 00000000 002656
(002656) SBIE (ID) 00000006 \BaseNamedObjects\windows_shell_global_counters
(002656) SBIE (TA) 00000000 002656
(002656) SBIE (FA) 00000001.0F.FFFFFFFF \Device\NamedPipe\lsarpc
(002656) SBIE (FA) C0100080.01.00000040 \Device\NamedPipe\lsarpc
(002656) SBIE (IA) 00000000 \Sandbox\Administrator\DefaultBox\Session_0\BaseNamedObjects\windows_shell_global_counters
(002656) SBIE (IA) 00000000 \Sandbox\Administrator\DefaultBox\Session_0\BaseNamedObjects\windows_shell_global_counters
(002656) SBIE (IA) 00000000 \Sandbox\Administrator\DefaultBox\Session_0\BaseNamedObjects\shell.{210A4BA0-3AEA-1069-A2D9-08002B30309D}
(002656) SBIE (IA) 000F0007 \BaseNamedObjects\CiceroSharedMemDefaultS-1-5-21-448539723-507921405-725345543-1003
(002656) SBIE (IA) 001F0001 \BaseNamedObjects\CTF.LBES.MutexDefaultS-1-5-21-448539723-507921405-725345543-1003
(002656) SBIE (IA) 001F0001 \BaseNamedObjects\CTF.Compart.MutexDefaultS-1-5-21-448539723-507921405-725345543-1003
(002656) SBIE (IA) 001F0001 \BaseNamedObjects\CTF.Asm.MutexDefaultS-1-5-21-448539723-507921405-725345543-1003
(002656) SBIE (IA) 001F0001 \BaseNamedObjects\CTF.Layouts.MutexDefaultS-1-5-21-448539723-507921405-725345543-1003
(002656) SBIE (IA) 001F0001 \BaseNamedObjects\CTF.TMD.MutexDefaultS-1-5-21-448539723-507921405-725345543-1003
(002656) SBIE (IA) 001F0001 \BaseNamedObjects\CTF.TimListCache.FMPDefaultS-1-5-21-448539723-507921405-725345543-1003MUTEX.DefaultS-1-5-21-448539723-507921405-725345543-1003
(002656) SBIE (IA) 000F001F \BaseNamedObjects\CTF.TimListCache.FMPDefaultS-1-5-21-448539723-507921405-725345543-1003SFM.DefaultS-1-5-21-448539723-507921405-725345543-1003
(002656) SBIE (IA) 0000000E \KnownDlls\USERENV.dll |
|
|
|
 |
 | |  |
|
tzuk
| Joined: 22 Jun 2004 |
| Posts: 15159 |
|
|
 |
Posted: Tue May 15, 2007 11:26 pm |
|
 |
 |
 |
 |
The new trace shows no mention of KAV_INPROCESS_DLL_LOADED. Why is that?
But since this hasn't helped, do you remember which, if any, of the programs you listed, you have installed in the last month, around the time Sandboxie stopped working?
|
|
|
 |
 | |  |
|
Unknown_User_784
| Joined: 01 Jan 1970 |
| Posts: 0 |
|
|
 |
Posted: Wed May 16, 2007 1:22 am |
|
 |
 |
 |
 |
Well.. I'm not sure why it didn't show up in the trace, but I followed your advice to add that one line to the configuration. Adding that one line resulted in "KAV_INPROCESS_DLL_LOADED" disappearing from the trace.
Removing that one line from the configuration adds "KAV_INPROCESS_DLL_LOADED" back.
(003008) SBIE (IA) 00000001 \KnownDlls\kernel32.dll
(003008) SBIE (IA) 00000000 \Sandbox\Administrator\DefaultBox\Session_0\BaseNamedObjects\SbieDllDummyEvent_3008
(003008) SBIE (IA) 00000004 \BaseNamedObjects\Sandboxie_Services
(003008) SBIE (IA) 00120001 \BaseNamedObjects\ShimCacheMutex
(003008) SBIE (IA) 00000002 \BaseNamedObjects\ShimSharedMemory
(003952) SBIE (IA) 0000000E \KnownDlls\kernel32.dll
(003952) SBIE (IA) 001F0001 \Windows\ApiPort
(003952) SBIE (IA) 00000004 \NLS\NlsSectionUnicode
(003952) SBIE (IA) 00000004 \NLS\NlsSectionLocale
(003952) SBIE (IA) 00000005 \NLS\NlsSectionSortkey
(003952) SBIE (IA) 00000004 \NLS\NlsSectionSortTbls
(003952) SBIE (IA) 0000000E \KnownDlls\advapi32.dll
(003952) SBIE (IA) 0000000E \KnownDlls\rpcrt4.dll
(003952) SBIE (IA) 0000000E \KnownDlls\gdi32.dll
(003952) SBIE (IA) 0000000E \KnownDlls\user32.dll
(003952) SBIE (IA) 0000000E \KnownDlls\msvcrt.dll
(003952) SBIE (IA) 0000000E \KnownDlls\SHLWAPI.dll
(003952) SBIE (IA) 0000000E \KnownDlls\shell32.dll
(003952) SBIE (IA) 0000000E \KnownDlls\ole32.dll
(003952) SBIE (IA) 0000000E \KnownDlls\urlmon.dll
(003952) SBIE (IA) 0000000E \KnownDlls\oleaut32.dll
(003952) SBIE (IA) 0000000E \KnownDlls\iertutil.dll
(003952) SBIE (IA) 0000000E \KnownDlls\version.dll
(003952) SBIE (IA) 00000001 \KnownDlls\kernel32.dll
(003952) SBIE (IA) 00000000 \Sandbox\Administrator\DefaultBox\Session_0\BaseNamedObjects\SbieDllDummyEvent_3952
(003952) SBIE (IA) 00000004 \BaseNamedObjects\Sandboxie_Services
(003952) SBIE (IA) 00000004 \NLS\NlsSectionCType
(003952) SBIE (IA) 00000000 \Sandbox\Administrator\DefaultBox\Session_0\BaseNamedObjects\shell.{A48F1A32-A340-11D1-BC6B-00A0C90312E1}
(003952) SBIE (IA) 0000000E \KnownDlls\COMCTL32.dll
(003952) SBIE (PA) 00000400 003952
(003952) SBIE (IA) 00000000 \Sandbox\Administrator\DefaultBox\Session_0\BaseNamedObjects\ZonesCounterMutex
(003952) SBIE (IA) 00000000 \Sandbox\Administrator\DefaultBox\Session_0\BaseNamedObjects\ZonesCacheCounterMutex
(003952) SBIE (IA) 00000000 \Sandbox\Administrator\DefaultBox\Session_0\BaseNamedObjects\ZonesLockedCacheCounterMutex
(003952) SBIE (IA) 001F0001 \ThemeApiPort
(003952) SBIE (PA) 00000000 003952
(003952) SBIE (IA) 00000000 \Sandbox\Administrator\DefaultBox\Session_0\BaseNamedObjects\KAV_INPROCESS_DLL_LOADED
(003952) SBIE (TA) 00000000 003952
(003952) SBIE (FA) 00000001.0F.FFFFFFFF \Device\NamedPipe\lsarpc
(003952) SBIE (FA) C0100080.01.00000040 \Device\NamedPipe\lsarpc
(003952) SBIE (IA) 00000000 \Sandbox\Administrator\DefaultBox\Session_0\BaseNamedObjects\windows_shell_global_counters
(003952) SBIE (IA) 00000000 \Sandbox\Administrator\DefaultBox\Session_0\BaseNamedObjects\windows_shell_global_counters
(003952) SBIE (IA) 00000000 \Sandbox\Administrator\DefaultBox\Session_0\BaseNamedObjects\shell.{210A4BA0-3AEA-1069-A2D9-08002B30309D}
(003952) SBIE (IA) 000F0007 \BaseNamedObjects\CiceroSharedMemDefaultS-1-5-21-448539723-507921405-725345543-1003
(003952) SBIE (IA) 001F0001 \BaseNamedObjects\CTF.LBES.MutexDefaultS-1-5-21-448539723-507921405-725345543-1003
(003952) SBIE (IA) 001F0001 \BaseNamedObjects\CTF.Compart.MutexDefaultS-1-5-21-448539723-507921405-725345543-1003
(003952) SBIE (IA) 001F0001 \BaseNamedObjects\CTF.Asm.MutexDefaultS-1-5-21-448539723-507921405-725345543-1003
(003952) SBIE (IA) 001F0001 \BaseNamedObjects\CTF.Layouts.MutexDefaultS-1-5-21-448539723-507921405-725345543-1003
(003952) SBIE (IA) 001F0001 \BaseNamedObjects\CTF.TMD.MutexDefaultS-1-5-21-448539723-507921405-725345543-1003
(003952) SBIE (IA) 001F0001 \BaseNamedObjects\CTF.TimListCache.FMPDefaultS-1-5-21-448539723-507921405-725345543-1003MUTEX.DefaultS-1-5-21-448539723-507921405-725345543-1003
(003952) SBIE (IA) 000F001F \BaseNamedObjects\CTF.TimListCache.FMPDefaultS-1-5-21-448539723-507921405-725345543-1003SFM.DefaultS-1-5-21-448539723-507921405-725345543-1003
(003952) SBIE (IA) 0000000E \KnownDlls\USERENV.dll
|
According to the "Created on" info in my program directory... Sandboxie was installed on April 28th, 2007 (So it was actually half a month ago.. seemed longer.)
Here's the list of programs installed after that date that have a system-wide effect or run constantly.
Cisco Systems VPN Client
Raxco PerfectDisk
IndieVolume
KatMouse
Kerio Mailserver
MDNSResponder.exe (Bonjour/Photoshop CS3 component)
O&O CleverCache
FreeSSHd |
I disabled them all via services.msc or their respective administrative consoles... but it's still a no-go.
The only other thing that could contribute to this issue is Windows Update. I've been keeping up with recent patches/hotfixes. At the moment, I'm updating the Windows Update software to be able to access my update history. I'll post back right after.
[edit]
Here ya go:
The ones that might've affected Sandboxie are the bottom two in the nested quote-code thing below. I am certain that this issue started way before May 12th.
| Quote: |
Windows XP Windows Malicious Software Removal Tool - May 2007 (KB890830) Saturday, May 12, 2007 Windows Update
Windows XP Cumulative Security Update for Internet Explorer 7 for Windows XP (KB931768) Saturday, May 12, 2007 Windows Update
Windows XP Update for Windows XP (KB930916) Saturday, May 12, 2007 Windows Update
Windows XP Update for Microsoft Core XML Services (MSXML) 6.0 Service Pack 1 (KB934268) Sunday, April 29, 2007 Windows Update
Windows XP Update for Windows XP (KB934238) Thursday, April 26, 2007 Automatic Updates |
Windows XP Windows Malicious Software Removal Tool - April 2007 (KB890830) Thursday, April 12, 2007 Windows Update
Windows XP MSXML 4.0 SP2 Security Update (KB927978) Thursday, April 12, 2007 Windows Update
Windows XP Update for Windows Media Format 11 SDK for Windows XP (KB929399) Wednesday, April 11, 2007 Windows Update
Windows XP Windows Media Player 11 (for Windows Media Center Edition 2005) Wednesday, April 11, 2007 Windows Update
Windows XP Security Update for Windows XP (KB923689) Wednesday, April 11, 2007 Windows Update
Windows XP Update Rollup for Windows XP Media Center Edition 2005 (KB925766) Wednesday, April 11, 2007 Windows Update
Windows XP Update for Windows XP Media Center Edition 2005 (KB913800) Wednesday, April 11, 2007 Windows Update
Windows XP Update for Windows XP Media Center Edition 2005 (KB912024) Wednesday, April 11, 2007 Windows Update
Windows XP Update Rollup 2 for Windows XP Media Center Edition 2005 (KB900325) Wednesday, April 11, 2007 Windows Update
Windows XP Security Update for Microsoft .NET Framework, Version 1.1 Service Pack 1 (KB886903) Wednesday, April 11, 2007 Windows Update
Windows XP Security Update for Windows XP (KB932168) Wednesday, April 11, 2007 Windows Update
Windows XP Security Update for Windows XP (KB931261) Wednesday, April 11, 2007 Windows Update
Windows XP Security Update for Windows XP (KB930178) Wednesday, April 11, 2007 Windows Update
Windows XP Security Update for Windows XP (KB931784) Wednesday, April 11, 2007 Windows Update
Windows XP Security Update for Windows XP (KB901190) Wednesday, April 11, 2007 Windows Update
... (etc)
|
|
|
|
 |
 | |  |
|
SnDPhoenix
| Joined: 26 Dec 2006 |
| Posts: 2694 |
| Location: West Florida |
|
 |
Posted: Wed May 16, 2007 1:42 am |
|
 |
 |
 |
 |
Dumb question, but have you tried uninstalling and then re-installing Sandboxie? Also you keep doing a IpcTrace=ad & PipeTrace=ad trace, but have you tried a FileTrace instead, im starting to think this might be a problem with some file(s).
|
|
_________________ Windows 7 SP1 x64, Sandboxie v3.70 x64 with Experimental Protection, GnuPG, OTR (Off-The-Record), Sticky Password, My Brain.
|
 |
 | |  |
|
Unknown_User_784
| Joined: 01 Jan 1970 |
| Posts: 0 |
|
|
 |
Posted: Wed May 16, 2007 2:23 am |
|
 |
 |
 |
 |
Whoops... seems I failed to mentioned that, but I re-installed Sandboxie again anyhow with no positive results. (I set the option to delete the config files)
Upon re-installing Sandboxie, I applied the following changes to the configuration:
FileTrace=ad
PipeTrace=ad
IpcTrace=ad
OpenIpcPath=*\BaseNamedObjects*\KAV_INPROCESS_DLL_LOADED |
and I did another trace... but this one happens to be 1931 lines long and 235.25KB worth of text. Since it's rather unreasonable to post it here...
I've uploaded it externally and linked it here.
|
|
|
|
tzuk
| Joined: 22 Jun 2004 |
| Posts: 15159 |
|
|
 |
Posted: Thu May 17, 2007 9:45 pm |
|
 |
 |
 |
 |
It still shows a bunch of third-party DLLs (other than Microsoft DLLs and the Sandboxie SbieDll) being loaded into Internet Explorer.
Can you try getting your IE to load without any such DLLs? For example I've seen PowerMenuHook, Kaspersky DLLs, sizer (?) and IWM (?), and mySQL and GTK+ stuff.
|
|
|
 |
 | |  |
|
Unknown_User_784
| Joined: 01 Jan 1970 |
| Posts: 0 |
|
|
 |
Posted: Fri May 18, 2007 12:35 am |
|
 |
 |
 |
 |
Issue resolved.. sort of.
After I closed every unnecessary program, service, and whatever... Sandboxie started working again. So, I loaded up program by program, service by service, until I found the problem.
It happens to be that a global hook in which I use to log my actions causes the applications to hang. (It's basically in effect a keylogger that I've had running since I've installed the operating system) What's strange though, is that if I stop the unload the hook and restart the Sandboxie service, and then re-load the hook... everything works again. My actions are still logged, the Sandboxed programs run fine, et cetera.
I can't quite figure out why Sandboxie didn't work since the start. The global hook is installed as a system service that's been running since I've installed the OS. Sandboxie worked for the first one or two weeks and then stopped working. What I can't figure out is *why* it stopped working. If this doesn't make sense, it's because I'm in a confused state at the moment.
Albeit unlikely, I'll report back if I find out anything new. I hope this helps other people. :)
[edit]In case you're wondering, it's the "IWM" dll/exe that are run by the service[/edit]
|
|
|
 |
 | |  |
|
SnDPhoenix
| Joined: 26 Dec 2006 |
| Posts: 2694 |
| Location: West Florida |
|
 |
Posted: Fri May 18, 2007 7:38 pm |
|
 |
 |
 |
 |
cant you give services higher priority? if so, then try giving sandboxie service a high(er) priority.
|
|
|
You can post new topics in this forum You can reply to topics in this forum You cannot edit your posts in this forum You cannot delete your posts in this forum You cannot vote in polls in this forum
|
All times are GMT
Page 1 of 1
Use the RSS feed to watch this topic for replies
|
|
|
|
|  |