Trust No Program
Reply to topic
[.01] SBIE 3.70 and Kaspersky 2013 conflict
3x0
Guest

Reply with quote
Hi,
there seems to be a minor(?) conflict between KIS 2013 (latest build 13.0.0.3370 Release Candidate) and Sanboxie 3.70 (and previous 3.68 ) on XP SP3 32b.

Launching of applications in Sandboxie results in its components (SandboxieRpcSs.exe and SandboxieDcomLaunch.exe) and the started application itself to start as "dead" processes with absolutely no threads (according to Process explorer). Afterwards, functional instances of said processes are started automatically without problems. Please see image (notice the mem usage of "gray" processes)
http://s14.postimage.org/uy0k7duqp/sbiekis2013.png

Exiting KIS completely from sys tray (service/ui processes terminated) doesn't fix the problem, so it indicates a low level driver conflict.
The culprit is Kaspersky's klif.sys, preventing it from loading fixes the issue with SBIE. I reported the problem to Kaspersky developers a while back and they've assigned a 2nd level priority on the bug, however it doesn't seem like they will actually fix the bug in Release build.

Since they released an RC build it's prudent to contact you at this point since there won't (or shouldn't) be any drastic changes in their release code- which could break any workaround you may implement in SBIE.
You can download the build here: http://devbuilds.kaspersky-labs.com/devbuilds/KIS2013/13.0.0.3370%28RC%29/

Is there anything you can do from your end? Smile
tzuk


Joined: 22 Jun 2004
Posts: 15003
Reply with quote
Thanks for pointing this out! I'll try to take a look in a few days to see what I can do about this.

_________________
tzuk
View user's profileSend private message
tzuk


Joined: 22 Jun 2004
Posts: 15003
Reply with quote
I looked into this but unfortunately I can't address this immediately.

When a program in the sandbox launches a new program, Sandboxie launches the program twice. First it launches an "empty" program that doesn't run, and then on second attempt it really runs the program.

It seems this aspect of Sandboxie is confusing KIS 2013 (RC) and causing it to keep a kind of "reference" or "lock" on the empty program and not release it.

I think it's a bug in KIS 2013 and hopefully they fix it at some point. It's apparently not critical because the leftover "zombie" programs don't interfere with anything.

On the other hand I am considering revising the way Sandboxie works regarding launching programs, so that may be another alternative to fixing the problem. But I can't say when I will do that or if at all.
View user's profileSend private message
tzuk


Joined: 22 Jun 2004
Posts: 15003
Reply with quote
I did want to to look into the way Sandboxie was launching programs at some point so I decided to take this opportunity to look into it now.

Version 3.81.01 implements a change which is a better way to do things, and also fixes the conflict with KIS 2013 on Windows XP.

Related topic:
http://www.sandboxie.com/phpbb/viewtopic.php?t=10147
View user's profileSend private message
[.01] SBIE 3.70 and Kaspersky 2013 conflict
You cannot post new topics in this forum
You can reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
All times are GMT  
Page 1 of 1  

Use the RSS feed to watch this topic for replies
  
  
 Reply to topic  

Sandboxie is Copyright © 2004-2012 by Sandboxie Holdings LLC.  All rights reserved.
Sandboxie.com | Contact Author
This site has been viewed 207,980,983 times since June 2004