![]() |
| SB 3.28 fail to start |
|
tzuk
|
Some other software is preventing Sandboxie from reading the registry. Which system protection tools do you use?
|
||||||||||||
|
_________________ tzuk |
|||||||||||||
|
tepe2
|
Thanks for reply.
Online Armor paid version without AV (2.1.0.131) Avira Classic (free) product version 8.1.0.308 both realtime of course and then SuperAntiSpyware ondemand. As far as I can see within Online Armor nothing related to SBIE is set to block. Edit: I have also done some system hardening with the help from Black Vipers webpage. But this is done long time ago, before I downloaded latest SBIE. |
||||||||||||
|
|
|||||||||||||
|
tepe2
|
I did this:
1. Deactivate HIPS in OA - did not help 2. Activated HIPS in OA, disabled Avira Guard - did not help Scan with Avira and SAS find nothing, (as expected) I have a thread at Wilders which started about OA webguard. I dont know if post #5 would be helpful: http://www.wilderssecurity.com/showthread.php?t=214702 |
||||||||||||
|
|
|||||||||||||
|
tepe2
|
Now this is interesting:
1. I uninstalled SBIE. 2. Downloaded and installed SBIE. 3. With default settings it start up and works. 4. When I edit configuration to what I had before it does not work. I post my configurations here. The only thing I have changed lately is in bold text. I guess this was added around same time I tried to take new version in use. The reason I did add this was because it is suppose to enhance protection against keyloggers. (I read that in a thread at wilderssecurity, but Im no expert so I dont know if it is ok) I think you can ignore the [NB] box settings at the bottom because I dont use that sandbox and will delete it. [GlobalSettings] ProcessGroup=<restricted>,Start.exe,SandboxieDcomLaunch.exe,SandboxieRpcSs.exe,firefox.exe [DefaultBox] ClosedFilePath=!<restricted>,* ClosedIpcPath=!<restricted>,* ConfigLevel=3 AutoRecover=y AutoRecoverIgnore=.jc! AutoRecoverIgnore=.part RecoverFolder=%Personal% RecoverFolder=%Desktop% LingerProcess=wuauclt.exe LingerProcess=devldr32.exe LingerProcess=syncor.exe LingerProcess=jusched.exe LingerProcess=acrord32.exe Enabled=y BoxNameTitle=y NeverDelete=n AutoDelete=y OpenFilePath=seamonkey.exe,%Local AppData%\Mozilla\Profiles\*\Mail* OpenFilePath=seamonkey.exe,%AppData%\Mozilla\Profiles\*\Mail* OpenFilePath=thunderbird.exe,%Local AppData%\Thunderbird OpenFilePath=thunderbird.exe,%AppData%\Thunderbird OpenFilePath=firefox.exe,*\bookmark* OpenFilePath=firefox.exe,D:\Mozilla\Firefox\Profiles\Newprofile\7h1op4by.default\prefs.js OpenFilePath=firefox.exe,*\history.dat OpenFilePath=firefox.exe,*\patterns* ClosedKeyPath=HKEY_CURRENT_CONFIG ClosedKeyPath=HKEY_USERS ClosedKeyPath=HKEY_LOCAL_MACHINE ClosedKeyPath=HKEY_CURRENT_USER ClosedKeyPath=HKEY_CLASSES_ROOT ClosedFilePath=N:\ ClosedFilePath=E:\ ClosedFilePath=D:\Mozilla\Thunderbird\ ClosedFilePath=D:\NTFILE\ ClosedFilePath=%Personal%\ ClosedFilePath=D:\LinDok\ ClosedFilePath=D:\BIOS\ ClosedFilePath=M:\ ClosedFilePath=J: ClosedFilePath=F: ClosedFilePath=G: ClosedFilePath=H: ClosedFilePath=I: ClosedFilePath=!firefox.exe,\Device\RawIp ClosedFilePath=!firefox.exe,\Device\Ip* ClosedFilePath=!firefox.exe,\Device\Tcp* ClosedFilePath=!firefox.exe,\Device\Afd* ReadFilePath=D:\V-75\ OpenKeyPath=seamonkey.exe,HKEY_LOCAL_MACHINE\Software\Wow6432Node\Mozilla\SeaMonkey* OpenKeyPath=seamonkey.exe,HKEY_LOCAL_MACHINE\Software\Mozilla\SeaMonkey* OpenKeyPath=seamonkey.exe,HKEY_CURRENT_USER\Software\Mozilla*\SeaMonkey* OpenKeyPath=thunderbird.exe,HKEY_LOCAL_MACHINE\Software\Wow6432Node\Mozilla Thunderbird OpenKeyPath=thunderbird.exe,HKEY_LOCAL_MACHINE\Software\Mozilla Thunderbird OpenKeyPath=thunderbird.exe,HKEY_CURRENT_USER\Software\Mozilla Thunderbird CopyLimitKb=327680 [UserSettings_0D3E0237] SbieCtrl_UserName=tommy SbieCtrl_ShowWelcome=N SbieCtrl_NextUpdateCheck=1555555555 SbieCtrl_UpdateCheckNotify=Y SbieCtrl_WindowLeft=300 SbieCtrl_WindowTop=417 SbieCtrl_WindowWidth=660 SbieCtrl_WindowHeight=450 SbieCtrl_Hidden=N SbieCtrl_ActiveView=40021 SbieCtrl_AutoApplySettings=Y SbieCtrl_HideWindowNotify=N SbieCtrl_BoxExpandedView_DefaultBox=Y SbieCtrl_SettingChangeNotify=N SbieCtrl_ReloadConfNotify=N SbieCtrl_BoxExpandedView_NB=Y SbieCtrl_EnableLogonStart=Y SbieCtrl_EnableAutoStart=Y SbieCtrl_AddDesktopIcon=Y SbieCtrl_AddQuickLaunchIcon=Y SbieCtrl_AddContextMenu=Y SbieCtrl_AddSendToMenu=Y [NB] Enabled=y ConfigLevel=3 AutoRecover=y AutoRecoverIgnore=.jc! AutoRecoverIgnore=.part LingerProcess=wuauclt.exe LingerProcess=devldr32.exe LingerProcess=syncor.exe LingerProcess=jusched.exe LingerProcess=acrord32.exe AutoDelete=y NeverDelete=n ClosedFilePath=M:\ ClosedFilePath=J: ClosedFilePath=I: ClosedFilePath=H: ClosedFilePath=G: ClosedFilePath=F: ClosedFilePath=D:\ |
||||||||||||
|
|
|||||||||||||
|
tepe2
|
I did some testing. If I remove the text in bold, see my last post above, SBIE still dont work.
I have tried different configurations I have stored in textfiles, and I have to "roll back" to the following settings to make SBIE work: I think you can ignore the [NB] box at the bottom, I dont use it. [GlobalSettings] [DefaultBox] ConfigLevel=2 AutoRecover=y AutoRecoverIgnore=.jc! AutoRecoverIgnore=.part RecoverFolder=%Personal% RecoverFolder=%Desktop% LingerProcess=devldr32.exe LingerProcess=syncor.exe LingerProcess=jusched.exe LingerProcess=acrord32.exe Enabled=y BoxNameTitle=y NeverDelete=n AutoDelete=y OpenFilePath=firefox.exe,*\bookmark* OpenFilePath=firefox.exe,D:\Mozilla\Firefox\Profiles\Newprofile\7h1op4by.default\prefs.js OpenFilePath=firefox.exe,*\history.dat OpenFilePath=firefox.exe,*\patterns* ClosedFilePath=M:\ ClosedFilePath=D:\BIOS\ ClosedFilePath=D:\LinDok\ ClosedFilePath=%Personal%\ ClosedFilePath=D:\NTFILE\ ClosedFilePath=D:\V-75\ ClosedFilePath=D:\Mozilla\Thunderbird\ [UserSettings_0D3E0237] SbieCtrl_UserName=tommy SbieCtrl_ShowWelcome=N SbieCtrl_NextUpdateCheck=1555555555 SbieCtrl_UpdateCheckNotify=Y SbieCtrl_WindowLeft=295 SbieCtrl_WindowTop=301 SbieCtrl_WindowWidth=660 SbieCtrl_WindowHeight=450 SbieCtrl_Hidden=N SbieCtrl_ActiveView=40021 SbieCtrl_AutoApplySettings=Y SbieCtrl_HideWindowNotify=N SbieCtrl_BoxExpandedView_DefaultBox=Y SbieCtrl_SettingChangeNotify=N SbieCtrl_ReloadConfNotify=N SbieCtrl_BoxExpandedView_NB=Y [NB] Enabled=y ConfigLevel=2 AutoRecover=y AutoRecoverIgnore=.jc! AutoRecoverIgnore=.part LingerProcess=devldr32.exe LingerProcess=syncor.exe LingerProcess=jusched.exe LingerProcess=acrord32.exe AutoDelete=y NeverDelete=n ClosedFilePath=M:\ ClosedFilePath=J: ClosedFilePath=I: ClosedFilePath=H: ClosedFilePath=G: ClosedFilePath=F: ClosedFilePath=D:\ |
||||||||||||
|
|
|||||||||||||
|
MitchE323
|
When you did #4, some setting was changed. I notice in one ini file it calls for ConfigLevel=2 and in the other calls for ConfigLevel=3. Well, SandboxIE version 3.28 uses ConfigLevel=4. Whichever ini file you are using, try changing it to '4' and see where that puts you. |
||||||||||||||
|
|
|||||||||||||||
|
tepe2
|
Thanks for your reply. I just tried. It did not help. Must be something else.
|
||||||||||||
|
|
|||||||||||||
|
MitchE323
|
How are you editing the ini file? The best way in through "Edit Configuration" but if you are doing it straight through the file in the Windows folder, then you have to "Reload Configuration".
When you were on step #3, everything was fine and then you wanted to add some things and that messed things up. Maybe post the ini file that works (the one created up to step #3) and then we can add the additional things right here. |
||||||||||||
|
|
|||||||||||||
|
tepe2
|
I save configurations to textfiles and store them in another partition. I edit through "Edit Configuration" by copy/paste the text from the saved textfile. Also I check later to see that configurations have changed.
When downloading and install the default settings work. My latest 2 or 3 saved settings (I have stored in that other partition) does not work, so I tried everyone from newest to oldest until I came to one that works. You can see that one in this thread. It is the second configuration I did post here. The first configuration above is my latest. It worked before I upgraded SBIE. This is the settings I want to use, well except it does not work. |
||||||||||||
|
|
|||||||||||||
|
MitchE323
|
OK so the top file is the one you want to use and you are on version 3.28 and using Firefox 3, right.
2 things; 1. check that this folder is correct (Firefox 3 might have changed it) OpenFilePath=firefox.exe,D:\Mozilla\Firefox\Profiles\Newprofile\7h1op4by.default\prefs.js 2. Why is this a closed file path? ClosedFilePath=D:\Mozilla\Thunderbird\ |
||||||||||||
|
|
|||||||||||||
|
MitchE323
|
Plus; What's up with this?
|
||||||||||||||
|
|
|||||||||||||||
|
tepe2
|
Right.
1. It seems correct. That is my firefox profile which I moved to another partition long time ago. I have C: for windows and programs included Firefox. And D: for data, music, movie etc.... see my link in my third post. 2. I have also move the Thunderbird profile to D-partition. I only use SBIE for firefox so most things in D-partition is closed. Those ClosedKeyPaths in your last post is also something I learned from reading at wilderssecurity forums. Some say they are not needed. Some registry protection I guess. Everything you can see in that config has worked fine uptil now. Late night in my country right now. 4 at night |
||||||||||||||||
|
|
|||||||||||||||||
|
MitchE323
|
Ok, when you start back up again, if I am not here;
Get rid of those registry blocks - you have blocked 100% of the entire registry. |
||||||||||||
|
|
|||||||||||||
|
MitchE323
|
Try this;
[GlobalSettings] ProcessGroup=<Restricted>,Start.exe,SandboxieDcomLaunch.exe,SandboxieRpcSs.exe,firefox.exe ProcessGroup=<Internet>,firefox.exe [DefaultBox] ClosedIpcPath=!<Restricted>,* ClosedFilePath=!<Internet>,\Device\RawIp ClosedFilePath=!<Internet>,\Device\Ip* ClosedFilePath=!<Internet>,\Device\Tcp* ClosedFilePath=!<Internet>,\Device\Afd* RecoverFolder=%Personal% ClosedFilePath=%Personal% ConfigLevel=4 AutoRecover=y AutoRecoverIgnore=.jc! AutoRecoverIgnore=.part RecoverFolder=%Desktop% LingerProcess=trustedinstaller.exe LingerProcess=wuauclt.exe LingerProcess=devldr32.exe LingerProcess=syncor.exe LingerProcess=jusched.exe LingerProcess=acrord32.exe Enabled=y BoxNameTitle=y NeverDelete=n AutoDelete=y OpenFilePath=seamonkey.exe,%Local AppData%\Mozilla\Profiles\*\Mail* OpenFilePath=seamonkey.exe,%AppData%\Mozilla\Profiles\*\Mail* OpenFilePath=thunderbird.exe,%Local AppData%\Thunderbird OpenFilePath=thunderbird.exe,%AppData%\Thunderbird OpenFilePath=firefox.exe,*\bookmark* OpenFilePath=firefox.exe,D:\Mozilla\Firefox\Profiles\Newprofile\7h1op4by.default\prefs.js OpenFilePath=firefox.exe,*\history.dat OpenFilePath=firefox.exe,*\patterns* ClosedFilePath=N:\ ClosedFilePath=E:\ ClosedFilePath=D:\Mozilla\Thunderbird\ ClosedFilePath=D:\NTFILE\ ClosedFilePath=D:\LinDok\ ClosedFilePath=D:\BIOS\ ClosedFilePath=M:\ ClosedFilePath=J:\ ClosedFilePath=F:\ ClosedFilePath=G:\ ClosedFilePath=H:\ ClosedFilePath=I:\ OpenKeyPath=seamonkey.exe,HKEY_LOCAL_MACHINE\Software\Wow6432Node\Mozilla\SeaMonkey* OpenKeyPath=seamonkey.exe,HKEY_LOCAL_MACHINE\Software\Mozilla\SeaMonkey* OpenKeyPath=seamonkey.exe,HKEY_CURRENT_USER\Software\Mozilla*\SeaMonkey* OpenKeyPath=thunderbird.exe,HKEY_LOCAL_MACHINE\Software\Wow6432Node\Mozilla Thunderbird OpenKeyPath=thunderbird.exe,HKEY_LOCAL_MACHINE\Software\Mozilla Thunderbird OpenKeyPath=thunderbird.exe,HKEY_CURRENT_USER\Software\Mozilla Thunderbird CopyLimitKb=327680 [UserSettings_0D3E0237] SbieCtrl_UserName=tommy SbieCtrl_ShowWelcome=N SbieCtrl_NextUpdateCheck=1555555555 SbieCtrl_UpdateCheckNotify=Y SbieCtrl_WindowLeft=300 SbieCtrl_WindowTop=417 SbieCtrl_WindowWidth=660 SbieCtrl_WindowHeight=450 SbieCtrl_Hidden=N SbieCtrl_ActiveView=40021 SbieCtrl_AutoApplySettings=Y SbieCtrl_HideWindowNotify=N SbieCtrl_BoxExpandedView_DefaultBox=Y SbieCtrl_SettingChangeNotify=N SbieCtrl_ReloadConfNotify=N SbieCtrl_BoxExpandedView_NB=Y SbieCtrl_EnableLogonStart=Y SbieCtrl_EnableAutoStart=Y SbieCtrl_AddDesktopIcon=Y SbieCtrl_AddQuickLaunchIcon=Y SbieCtrl_AddContextMenu=Y SbieCtrl_AddSendToMenu=Y [NB] Enabled=y ConfigLevel=4 AutoRecover=y AutoRecoverIgnore=.jc! AutoRecoverIgnore=.part LingerProcess=trustedinstaller.exe LingerProcess=wuauclt.exe LingerProcess=devldr32.exe LingerProcess=syncor.exe LingerProcess=jusched.exe LingerProcess=acrord32.exe AutoDelete=y NeverDelete=n ClosedFilePath=M:\ ClosedFilePath=J:\ ClosedFilePath=I:\ ClosedFilePath=H:\ ClosedFilePath=G:\ ClosedFilePath=F:\ ClosedFilePath=D:\ |
||||||||||||
|
|
|||||||||||||
| SB 3.28 fail to start |
|
||
|


Use the RSS feed to watch this topic for replies