sandboxie-plus / Sandboxie

Sandboxie Plus & Classic
https://Sandboxie-Plus.com
GNU General Public License v3.0
13.46k stars 1.5k forks source link

SbieDll.dll failure #1620

Closed isaak654 closed 1 year ago

isaak654 commented 2 years ago

Originally posted by @GLoren1 on February 13, 2022

> When I try to run certain MSI files to install programs in sandbox, I get the error message: > > "Initialization of the dynamic link library "C:\Program Files\Sandboxie-Plus\SbieDll.dll failed. The process is terminating abnormally.". > > I've uninstalled and re-installed Sandboxie Plus, but it hasn't solved the problem. > > Any help would be appreciated

Originally posted by @DavidXanatos

> thats strange msi files should not install a sbiedll, can you point me to a download to soem of the problematic msi's please
GLoren1 commented 2 years ago

David,

Here's one that I just tried and that failed.

https://www.finaldraft.com/downloads/finaldraft1203Win.zip

Thanks

DavidXanatos commented 2 years ago

for me it installs just fine t ry witha fresh config, or disable other antimalware prpducts.

GLoren1 commented 2 years ago

Turning off antimalware didn't help. When I delete the current config, will I lose everything in my current sandbox?

isaak654 commented 2 years ago

When I delete the current config, will I lose everything in my current sandbox?

Of course not, just make sure to save a copy of C:\Windows\Sandboxie.ini and C:\Users\%Username%\AppData\Local\Sandboxie-Plus\Sandboxie-Plus.ini elsewhere for a settings comparison.

Please mention your security software, there are different tweaks available for different products: https://github.com/sandboxie-plus/Sandboxie/issues/1545#issuecomment-1019023949 (ESET Internet Security) https://github.com/sandboxie-plus/Sandboxie/issues/1427#issuecomment-1001273168 (Comodo Internet Security)

The recommendation to disable other security products doesn't work at 100%.

You may want to create another sandbox and test if the same behavior applies there too.

isaak654 commented 2 years ago

Also make sure to verify if you applied additional security policy settings outside Sandboxie.

For example in gpedit.msc, secpol.msc, Windows Defender Exploit protection settings, or other management tools like parental controls.

GLoren1 commented 2 years ago

I'm using Bitdefender for virus and spyware protection. I looked at gpedit and secpol.msc, but I don't know how to determine whether the settings are default or customized. I don't recall ever changing anything with these utilities.

I deleted both sandbox .ini files, but I still get the same error message when trying to install msi files.

isaak654 commented 2 years ago

I can start the .msi file attached before just fine with the use of a new standard sandbox.

As explained earlier, you may want to create another sandbox and test if the same behavior applies there too. That would help to confirm a third-party issue or a sandbox-related issue regarding its content.

About Bitdefender, I remember a few recommendations that could work in combination with Sandboxie: https://github.com/sandboxie-plus/Sandboxie/issues/651#issuecomment-798783873

You may also want to share a log by using the steps described here, with the suggestion to paste as few lines as possible.

GLoren1 commented 2 years ago

I did create another sandbox, and the msi failed for the same reason.

To try to eliminate the possibility of anti-malware interference, I disabled it when running sandbox, but that hasn't helped.

Here are a few lines of the log file:

Start.exe (1316, 6344) - 12:33:34.061                   Debug (U)      Trace       CreateProcess: C:\Windows\System32\msiexec.exe ("C:\Windows\System32\msiexec.exe" /i "C:\Users\owner\AppData\Local\Temp\Rar$DRa5096.6557\FinalDraftSetup.msi" ); err=0   
Start.exe (1316, 7308) - 12:33:34.061                   Ipc (U)                    \Sessions\1\BaseNamedObjects\SBIE_BOXED_ServiceInitComplete_RpcSs                                                                                                        
Start.exe (1316, 7308) - 12:33:34.061                   Ipc (D)                    \Sessions\1\BaseNamedObjects\SBIE_BOXED_ServiceInitComplete_DcomLaunch                                                                                                   
msiexec.exe (7412, 11660) - 12:33:34.061                Ipc (D)        Open        \KnownDlls\kernel32.dll                                                                                                                                                  
msiexec.exe (7412, 11660) - 12:33:34.061                Ipc (D)        Open        \KnownDlls\kernelbase.dll  

Thanks

isaak654 commented 2 years ago

The log seems too short to find a possible cause, maybe the full log version could help to find any external DLL.

Disabling the protection provided by third-party security software is not always effective in my experience, unless you do a lot of attempts to disable specific options in the third-party software settings... as last resort, you can also consider to export your Bitdefender settings, uninstall it to see what happens and install it again with the imported settings.

GLoren1 commented 2 years ago

I removed bitdefender and replaced it with Kaspersky to see if that made a difference. It did not fix the problem.

Below is the log file:

|Process|                                               |Type|         |Status|    |Value|                                                                                                                                                                    

Start.exe (12648, 14588) - 20:09:50.090                 Ipc (D)        Open        \KnownDlls\kernel32.dll                                                                                                                                                    
Start.exe (12648, 14588) - 20:09:50.090                 Ipc (D)        Open        \KnownDlls\kernelbase.dll                                                                                                                                                  
Start.exe (12648, 14588) - 20:09:50.090                 Ipc (D)        Open        \Sessions\1\Windows\SharedSection                                                                                                                                          
Start.exe (12648, 14588) - 20:09:50.090                 Ipc (D)        Open        \Sessions\1\Windows\ApiPort                                                                                                                                                
Start.exe (12648, 14588) - 20:09:50.090                 Ipc (D)        Open        \KnownDlls\PSAPI.DLL                                                                                                                                                       
Start.exe (12648, 14588) - 20:09:50.090                 Drive (U)                  \Device\HarddiskVolume5                                                                                                                                                    
Start.exe (12648, 14588) - 20:09:50.090                 Drive (U)                  \Device\HarddiskVolume4                                                                                                                                                    
Start.exe (12648, 14588) - 20:09:50.090                 Drive (U)                  \Device\HarddiskVolume2                                                                                                                                                    
Start.exe (12648, 14588) - 20:09:50.090                 Drive (U)                  \Device\CdRom0                                                                                                                                                             
Start.exe (12648, 14588) - 20:09:50.090                 Drive (U)                  \Device\SCDEmu\SCDEmuCd0                                                                                                                                                   
Start.exe (12648, 14588) - 20:09:50.090                 Drive (U)                  \Device\CdRom1                                                                                                                                                             
Start.exe (12648, 14588) - 20:09:50.090                 Drive (U)                  \Device\HarddiskVolume6                                                                                                                                                    
Start.exe (12648, 14588) - 20:09:50.090                 Ipc (U)                    \Sessions\1\BaseNamedObjects\SBIE_BOXED_DummyEvent_12648                                                                                                                   
Start.exe (12648, 14588) - 20:09:50.090                 Ipc (U)        Open        \RPC Control\SbieSvcPort                                                                                                                                                   
Start.exe (12648, 14588) - 20:09:50.090                 Ipc (U)                    \Sessions\1\BaseNamedObjects\SBIE_BOXED_RPCSS_SXS_READY                                                                                                                    
Start.exe (12648, 14588) - 20:09:50.090                 Ipc (U)                    \Sessions\1\BaseNamedObjects\SBIE_BOXED_ServiceInitComplete_RpcSs                                                                                                          
SandboxieRpcSs.exe (15428, 13892) - 20:09:50.100        Ipc (D)        Open        \KnownDlls\kernel32.dll                                                                                                                                                    
SandboxieRpcSs.exe (15428, 13892) - 20:09:50.100        Ipc (D)        Open        \KnownDlls\kernelbase.dll                                                                                                                                                  
SandboxieRpcSs.exe (15428, 13892) - 20:09:50.100        Ipc (D)        Open        \Sessions\1\Windows\SharedSection                                                                                                                                          
SandboxieRpcSs.exe (15428, 13892) - 20:09:50.100        Ipc (D)        Open        \Sessions\1\Windows\ApiPort                                                                                                                                                
SandboxieRpcSs.exe (15428, 13892) - 20:09:50.100        Ipc (D)        Open        \KnownDlls\PSAPI.DLL                                                                                                                                                       
SandboxieRpcSs.exe (15428, 13892) - 20:09:50.100        Drive (U)                  \Device\HarddiskVolume5                                                                                                                                                    
SandboxieRpcSs.exe (15428, 13892) - 20:09:50.100        Drive (U)                  \Device\HarddiskVolume4                                                                                                                                                    
SandboxieRpcSs.exe (15428, 13892) - 20:09:50.100        Drive (U)                  \Device\HarddiskVolume2                                                                                                                                                    
SandboxieRpcSs.exe (15428, 13892) - 20:09:50.100        Drive (U)                  \Device\CdRom0                                                                                                                                                             
SandboxieRpcSs.exe (15428, 13892) - 20:09:50.100        Drive (U)                  \Device\SCDEmu\SCDEmuCd0                                                                                                                                                   
SandboxieRpcSs.exe (15428, 13892) - 20:09:50.100        Drive (U)                  \Device\CdRom1                                                                                                                                                             
SandboxieRpcSs.exe (15428, 13892) - 20:09:50.100        Drive (U)                  \Device\HarddiskVolume6                                                                                                                                                    
SandboxieRpcSs.exe (15428, 13892) - 20:09:50.110        Ipc (U)                    \Sessions\1\BaseNamedObjects\SBIE_BOXED_DummyEvent_15428                                                                                                                   
SandboxieRpcSs.exe (15428, 13892) - 20:09:50.110        Ipc (D)        Open        \KnownDlls\WS2_32.dll                                                                                                                                                      
SandboxieRpcSs.exe (15428, 13892) - 20:09:50.110        Ipc (D)        Open        \KnownDlls\MSVCRT.dll                                                                                                                                                      
SandboxieRpcSs.exe (15428, 13892) - 20:09:50.110        Ipc (D)        Open        \KnownDlls\rpcrt4.dll                                                                                                                                                      
SandboxieRpcSs.exe (15428, 13892) - 20:09:50.110        Ipc (D)        Open        \KnownDlls\NSI.dll                                                                                                                                                         
SandboxieRpcSs.exe (15428, 13892) - 20:09:50.110        Ipc (D)        Open        \KnownDlls\advapi32.dll                                                                                                                                                    
SandboxieRpcSs.exe (15428, 13892) - 20:09:50.110        Ipc (D)        Open        \KnownDlls\user32.dll                                                                                                                                                      
SandboxieRpcSs.exe (15428, 13892) - 20:09:50.110        Ipc (D)        Open        \KnownDlls\gdi32.dll                                                                                                                                                       
SandboxieRpcSs.exe (15428, 13892) - 20:09:50.110        Ipc (D)        Open        \KnownDlls\LPK.dll                                                                                                                                                         
SandboxieRpcSs.exe (15428, 13892) - 20:09:50.110        Ipc (D)        Open        \KnownDlls\USP10.dll                                                                                                                                                       
SandboxieRpcSs.exe (15428, 13892) - 20:09:50.110        Image (U)                  *:\program files\sandboxie-plus\sandboxierpcss.exe                                                                                                                         
SandboxieRpcSs.exe (15428, 13892) - 20:09:50.110        Image (U)                  c:\windows\system32\ntdll.dll                                                                                                                                              
SandboxieRpcSs.exe (15428, 13892) - 20:09:50.110        Image (U)                  c:\windows\system32\kernel32.dll                                                                                                                                           
SandboxieRpcSs.exe (15428, 13892) - 20:09:50.110        Image (U)                  c:\windows\system32\kernelbase.dll                                                                                                                                         
SandboxieRpcSs.exe (15428, 13892) - 20:09:50.110        Image (U)                  c:\program files\sandboxie-plus\sbiedll.dll                                                                                                                                
SandboxieRpcSs.exe (15428, 13892) - 20:09:50.110        Image (U)                  c:\windows\system32\psapi.dll                                                                                                                                              
SandboxieRpcSs.exe (15428, 13892) - 20:09:50.110        Image (U)                  c:\windows\system32\ws2_32.dll                                                                                                                                             
SandboxieRpcSs.exe (15428, 13892) - 20:09:50.110        Image (U)                  c:\windows\system32\msvcrt.dll                                                                                                                                             
SandboxieRpcSs.exe (15428, 13892) - 20:09:50.110        Image (U)                  c:\windows\system32\rpcrt4.dll                                                                                                                                             
SandboxieRpcSs.exe (15428, 13892) - 20:09:50.110        Image (U)                  c:\windows\system32\nsi.dll                                                                                                                                                
SandboxieRpcSs.exe (15428, 13892) - 20:09:50.110        Image (U)                  c:\windows\system32\advapi32.dll                                                                                                                                           
SandboxieRpcSs.exe (15428, 13892) - 20:09:50.110        Image (U)                  c:\windows\system32\sechost.dll                                                                                                                                            
SandboxieRpcSs.exe (15428, 13892) - 20:09:50.110        Image (U)                  c:\windows\system32\user32.dll                                                                                                                                             
SandboxieRpcSs.exe (15428, 13892) - 20:09:50.110        Ipc (U)                    \RPC Control\epmapper                                                                                                                                                      
SandboxieRpcSs.exe (15428, 13892) - 20:09:50.110        Image (U)                  c:\windows\system32\gdi32.dll                                                                                                                                              
SandboxieRpcSs.exe (15428, 13892) - 20:09:50.110        Image (U)                  c:\windows\system32\lpk.dll                                                                                                                                                
SandboxieRpcSs.exe (15428, 13892) - 20:09:50.110        Image (U)                  c:\windows\system32\usp10.dll                                                                                                                                              
SandboxieRpcSs.exe (15428, 13892) - 20:09:50.110        Ipc (D)        Open        \KnownDlls\MSCTF.dll                                                                                                                                                       
SandboxieRpcSs.exe (15428, 13892) - 20:09:50.110        Image (U)                  c:\windows\system32\imm32.dll                                                                                                                                              
SandboxieRpcSs.exe (15428, 13892) - 20:09:50.110        Image (U)                  c:\windows\system32\msctf.dll                                                                                                                                              
SandboxieRpcSs.exe (15428, 13892) - 20:09:50.110        Ipc (U)        Open        \RPC Control\SbieSvcPort                                                                                                                                                   
SandboxieRpcSs.exe (15428, 13892) - 20:09:50.120        Image (U)                  c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll                                                                                                                       
SandboxieRpcSs.exe (15428, 13892) - 20:09:50.120        Ipc (U)                    \Sessions\1\BaseNamedObjects\SBIE_BOXED_ServiceInitComplete_Mutex1                                                                                                         
SandboxieRpcSs.exe (15428, 15652) - 20:09:50.120        Image (U)                  c:\windows\system32\sxs.dll                                                                                                                                                
SandboxieRpcSs.exe (15428, 15652) - 20:09:50.120        Ipc (D)        Open        \KnownDlls\ole32.dll                                                                                                                                                       
SandboxieRpcSs.exe (15428, 15652) - 20:09:50.120        Image (U)                  c:\windows\system32\ole32.dll                                                                                                                                              
SandboxieRpcSs.exe (15428, 15652) - 20:09:50.120        Ipc (U)        Open        \RPC Control\SbieSvcPort                                                                                                                                                   
SandboxieRpcSs.exe (15428, 15652) - 20:09:50.120        Ipc (U)                    \Sessions\1\BaseNamedObjects\SBIE_BOXED_RPCSS_SXS_READY                                                                                                                    
SandboxieRpcSs.exe (15428, 13892) - 20:09:50.120        Ipc (U)                    \Sessions\1\BaseNamedObjects\Global\ComPlusCOMRegTable                                                                                                                     
SandboxieRpcSs.exe (15428, 13892) - 20:09:50.120        Ipc (D)                    \Sessions\1\BaseNamedObjects\ComPlusCOMRegTable                                                                                                                            
SandboxieRpcSs.exe (15428, 13892) - 20:09:50.120        Ipc (U)                    \Sessions\1\BaseNamedObjects\SBIE_BOXED_ServiceInitComplete_RpcEptMapper                                                                                                   
SandboxieRpcSs.exe (15428, 13892) - 20:09:50.120        Image (U)                  c:\windows\system32\rpcepmap.dll                                                                                                                                           
SandboxieRpcSs.exe (15428, 7756) - 20:09:50.120         Image (U)                  c:\windows\system32\rpcrtremote.dll                                                                                                                                        
SandboxieRpcSs.exe (15428, 7756) - 20:09:50.120         Pipe (U)                   \Device\Ndis                                                                                                                                                               
SandboxieRpcSs.exe (15428, 7756) - 20:09:50.120         Pipe (U)                   \Device\NDMP14                                                                                                                                                             
SandboxieRpcSs.exe (15428, 7756) - 20:09:50.120         Pipe (U)                   \Device\NDMP13                                                                                                                                                             
SandboxieRpcSs.exe (15428, 7756) - 20:09:50.120         Pipe (U)                   \Device\NDMP12                                                                                                                                                             
SandboxieRpcSs.exe (15428, 7756) - 20:09:50.120         Pipe (U)                   \Device\NDMP11                                                                                                                                                             
SandboxieRpcSs.exe (15428, 7756) - 20:09:50.120         Pipe (U)                   \Device\NDMP10                                                                                                                                                             
SandboxieRpcSs.exe (15428, 7756) - 20:09:50.120         Pipe (U)                   \Device\NDMP9                                                                                                                                                              
SandboxieRpcSs.exe (15428, 7756) - 20:09:50.120         Pipe (U)                   \Device\NDMP8                                                                                                                                                              
SandboxieRpcSs.exe (15428, 7756) - 20:09:50.120         Pipe (U)                   \Device\NDMP6                                                                                                                                                              
SandboxieRpcSs.exe (15428, 7756) - 20:09:50.120         Pipe (U)                   \Device\NDMP5                                                                                                                                                              
SandboxieRpcSs.exe (15428, 7756) - 20:09:50.130         Image (U)                  c:\windows\system32\secur32.dll                                                                                                                                            
SandboxieRpcSs.exe (15428, 7756) - 20:09:50.130         Image (U)                  c:\windows\system32\sspicli.dll                                                                                                                                            
SandboxieRpcSs.exe (15428, 7756) - 20:09:50.130         Image (U)                  c:\windows\system32\cryptsp.dll                                                                                                                                            
SandboxieRpcSs.exe (15428, 7756) - 20:09:50.130         Ipc (U)        Open        \Security\LSA_AUTHENTICATION_INITIALIZED                                                                                                                                   
SandboxieRpcSs.exe (15428, 7756) - 20:09:50.130         Ipc (U)        Open        \RPC Control\lsasspirpc                                                                                                                                                    
SandboxieRpcSs.exe (15428, 7756) - 20:09:50.130         Image (U)                  c:\windows\system32\credssp.dll                                                                                                                                            
SandboxieRpcSs.exe (15428, 7756) - 20:09:50.130         Ipc (U)                    \RPC Control\epmapper                                                                                                                                                      
SandboxieRpcSs.exe (15428, 7756) - 20:09:50.130         Ipc (D)                    \Sessions\1\BaseNamedObjects\SBIE_BOXED_ServiceInitComplete_RpcEptMapper                                                                                                   
SandboxieRpcSs.exe (15428, 13892) - 20:09:50.130        Image (U)                  c:\windows\system32\rpcss.dll                                                                                                                                              
SandboxieRpcSs.exe (15428, 10756) - 20:09:50.130        WinClass (U)               Sandboxie_DDE_ProxyClass1                                                                                                                                                  
SandboxieRpcSs.exe (15428, 10756) - 20:09:50.130        Ipc (U)        Open        \RPC Control\SbieSvcPort                                                                                                                                                   
SandboxieRpcSs.exe (15428, 14272) - 20:09:50.130        Ipc (U)        Open        \RPC Control\lsapolicylookup                                                                                                                                               
SandboxieRpcSs.exe (15428, 10756) - 20:09:50.130        Ipc (D)        Open        \KnownDlls\SHELL32.dll                                                                                                                                                     
SandboxieRpcSs.exe (15428, 10756) - 20:09:50.130        Ipc (D)        Open        \KnownDlls\SHLWAPI.dll                                                                                                                                                     
SandboxieRpcSs.exe (15428, 10756) - 20:09:50.130        Image (U)                  c:\windows\system32\shell32.dll                                                                                                                                            
SandboxieRpcSs.exe (15428, 10756) - 20:09:50.130        Image (U)                  c:\windows\system32\shlwapi.dll                                                                                                                                            
SandboxieRpcSs.exe (15428, 10756) - 20:09:50.130        Ipc (U)                    \Sessions\1\BaseNamedObjects\windows_shell_global_counters                                                                                                                 
SandboxieRpcSs.exe (15428, 13824) - 20:09:50.130        Ipc (U)                    \Sessions\1\BaseNamedObjects\SboxSession                                                                                                                                   
SandboxieRpcSs.exe (15428, 10756) - 20:09:50.130        Ipc (U)        (2)         \Sessions\1\BaseNamedObjects\windows_shell_global_counters                                                                                                                 
SandboxieRpcSs.exe (15428, 10756) - 20:09:50.130        Image (U)                  c:\windows\system32\uxtheme.dll                                                                                                                                            
SandboxieRpcSs.exe (15428, 10756) - 20:09:50.130        Ipc (U)        Open        \ThemeApiPort                                                                                                                                                              
SandboxieRpcSs.exe (15428, 14272) - 20:09:50.130        Image (U)                  c:\windows\system32\cryptsp.dll                                                                                                                                            
SandboxieRpcSs.exe (15428, 10756) - 20:09:50.140        Image (U)                  c:\windows\system32\dwmapi.dll                                                                                                                                             
SandboxieRpcSs.exe (15428, 10756) - 20:09:50.140        Ipc (D)        Open        \KnownDlls\OLEAUT32.dll                                                                                                                                                    
SandboxieRpcSs.exe (15428, 10756) - 20:09:50.140        Image (U)                  c:\windows\system32\propsys.dll                                                                                                                                            
SandboxieRpcSs.exe (15428, 10756) - 20:09:50.140        Image (U)                  c:\windows\system32\oleaut32.dll                                                                                                                                           
SandboxieRpcSs.exe (15428, 10756) - 20:09:50.140        WinClass (U)   Open (3)    Shell_TrayWnd                                                                                                                                                              
SandboxieRpcSs.exe (15428, 10756) - 20:09:50.140        Image (U)                  c:\windows\system32\version.dll                                                                                                                                            
SandboxieRpcSs.exe (15428, 14272) - 20:09:50.140        Image (U)                  c:\windows\system32\rsaenh.dll                                                                                                                                             
SandboxieRpcSs.exe (15428, 14272) - 20:09:50.140        Image (U)                  c:\windows\system32\cryptbase.dll                                                                                                                                          
SandboxieRpcSs.exe (15428, 14272) - 20:09:50.140        Pipe (U)                   \Device\KsecDD                                                                                                                                                             
SandboxieRpcSs.exe (15428, 14272) - 20:09:50.140        Ipc (U)                    \RPC Control\actkernel                                                                                                                                                     
SandboxieRpcSs.exe (15428, 14272) - 20:09:50.140        Ipc (U)                    \Sessions\1\BaseNamedObjects\SBIE_BOXED_ServiceInitComplete_DcomLaunch                                                                                                     
SandboxieRpcSs.exe (15428, 14272) - 20:09:50.150        File (U)       Closed      \Device\HarddiskVolume5\Windows\system32\apphelp.dll                                                                                                                       
SandboxieRpcSs.exe (15428, 14272) - 20:09:50.150        Debug (U)      Trace       CreateProcess: C:\Program Files\Sandboxie-Plus\SandboxieDcomLaunch.exe ("C:\Program Files\Sandboxie-Plus\SandboxieDcomLaunch.exe"); err=0                                  
SandboxieDcomLaunch.exe (14428, 17240) - 20:09:50.160   Ipc (D)        Open        \KnownDlls\kernel32.dll                                                                                                                                                    
SandboxieDcomLaunch.exe (14428, 17240) - 20:09:50.160   Ipc (D)        Open        \KnownDlls\kernelbase.dll                                                                                                                                                  
SandboxieDcomLaunch.exe (14428, 17240) - 20:09:50.160   Ipc (D)        Open        \Sessions\1\Windows\SharedSection                                                                                                                                          
SandboxieDcomLaunch.exe (14428, 17240) - 20:09:50.160   Ipc (D)        Open        \Sessions\1\Windows\ApiPort                                                                                                                                                
SandboxieDcomLaunch.exe (14428, 17240) - 20:09:50.160   Ipc (D)        Open        \KnownDlls\PSAPI.DLL                                                                                                                                                       
SandboxieDcomLaunch.exe (14428, 17240) - 20:09:50.160   Drive (U)                  \Device\HarddiskVolume5                                                                                                                                                    
SandboxieDcomLaunch.exe (14428, 17240) - 20:09:50.160   Drive (U)                  \Device\HarddiskVolume4                                                                                                                                                    
SandboxieDcomLaunch.exe (14428, 17240) - 20:09:50.160   Drive (U)                  \Device\HarddiskVolume2                                                                                                                                                    
SandboxieDcomLaunch.exe (14428, 17240) - 20:09:50.160   Drive (U)                  \Device\CdRom0                                                                                                                                                             
SandboxieDcomLaunch.exe (14428, 17240) - 20:09:50.160   Drive (U)                  \Device\SCDEmu\SCDEmuCd0                                                                                                                                                   
SandboxieDcomLaunch.exe (14428, 17240) - 20:09:50.160   Drive (U)                  \Device\CdRom1                                                                                                                                                             
SandboxieDcomLaunch.exe (14428, 17240) - 20:09:50.160   Drive (U)                  \Device\HarddiskVolume6                                                                                                                                                    
SandboxieDcomLaunch.exe (14428, 17240) - 20:09:50.160   Ipc (U)                    \Sessions\1\BaseNamedObjects\SBIE_BOXED_DummyEvent_14428                                                                                                                   
SandboxieDcomLaunch.exe (14428, 17240) - 20:09:50.160   Ipc (U)        Open        \RPC Control\SbieSvcPort                                                                                                                                                   
SandboxieDcomLaunch.exe (14428, 17240) - 20:09:50.160   Ipc (U)                    \Sessions\1\BaseNamedObjects\SboxSession                                                                                                                                   
SandboxieDcomLaunch.exe (14428, 17240) - 20:09:50.160   Ipc (D)        Open        \KnownDlls\advapi32.dll                                                                                                                                                    
SandboxieDcomLaunch.exe (14428, 17240) - 20:09:50.160   Ipc (D)        Open        \KnownDlls\MSVCRT.dll                                                                                                                                                      
SandboxieDcomLaunch.exe (14428, 17240) - 20:09:50.160   Ipc (D)        Open        \KnownDlls\rpcrt4.dll                                                                                                                                                      
SandboxieDcomLaunch.exe (14428, 17240) - 20:09:50.160   Ipc (D)        Open        \KnownDlls\user32.dll                                                                                                                                                      
SandboxieDcomLaunch.exe (14428, 17240) - 20:09:50.160   Ipc (D)        Open        \KnownDlls\gdi32.dll                                                                                                                                                       
SandboxieDcomLaunch.exe (14428, 17240) - 20:09:50.160   Ipc (D)        Open        \KnownDlls\LPK.dll                                                                                                                                                         
SandboxieDcomLaunch.exe (14428, 17240) - 20:09:50.170   Ipc (D)        Open        \KnownDlls\USP10.dll                                                                                                                                                       
SandboxieDcomLaunch.exe (14428, 17240) - 20:09:50.170   Image (U)                  *:\program files\sandboxie-plus\sandboxiedcomlaunch.exe                                                                                                                    
SandboxieDcomLaunch.exe (14428, 17240) - 20:09:50.170   Image (U)                  c:\windows\system32\ntdll.dll                                                                                                                                              
SandboxieDcomLaunch.exe (14428, 17240) - 20:09:50.170   Image (U)                  c:\windows\system32\kernel32.dll                                                                                                                                           
SandboxieDcomLaunch.exe (14428, 17240) - 20:09:50.170   Image (U)                  c:\windows\system32\kernelbase.dll                                                                                                                                         
SandboxieDcomLaunch.exe (14428, 17240) - 20:09:50.170   Image (U)                  c:\program files\sandboxie-plus\sbiedll.dll                                                                                                                                
SandboxieDcomLaunch.exe (14428, 17240) - 20:09:50.170   Image (U)                  c:\windows\system32\psapi.dll                                                                                                                                              
SandboxieDcomLaunch.exe (14428, 17240) - 20:09:50.170   Image (U)                  c:\windows\system32\advapi32.dll                                                                                                                                           
SandboxieDcomLaunch.exe (14428, 17240) - 20:09:50.170   Image (U)                  c:\windows\system32\msvcrt.dll                                                                                                                                             
SandboxieDcomLaunch.exe (14428, 17240) - 20:09:50.170   Image (U)                  c:\windows\system32\sechost.dll                                                                                                                                            
SandboxieDcomLaunch.exe (14428, 17240) - 20:09:50.170   Image (U)                  c:\windows\system32\rpcrt4.dll                                                                                                                                             
SandboxieDcomLaunch.exe (14428, 17240) - 20:09:50.170   Image (U)                  c:\windows\system32\user32.dll                                                                                                                                             
SandboxieDcomLaunch.exe (14428, 17240) - 20:09:50.170   Ipc (U)                    \RPC Control\epmapper                                                                                                                                                      
SandboxieDcomLaunch.exe (14428, 17240) - 20:09:50.170   Image (U)                  c:\windows\system32\gdi32.dll                                                                                                                                              
SandboxieDcomLaunch.exe (14428, 17240) - 20:09:50.170   Image (U)                  c:\windows\system32\lpk.dll                                                                                                                                                
SandboxieDcomLaunch.exe (14428, 17240) - 20:09:50.170   Image (U)                  c:\windows\system32\usp10.dll                                                                                                                                              
SandboxieDcomLaunch.exe (14428, 17240) - 20:09:50.170   Ipc (D)        Open        \KnownDlls\MSCTF.dll                                                                                                                                                       
SandboxieDcomLaunch.exe (14428, 17240) - 20:09:50.170   Image (U)                  c:\windows\system32\imm32.dll                                                                                                                                              
SandboxieDcomLaunch.exe (14428, 17240) - 20:09:50.170   Image (U)                  c:\windows\system32\msctf.dll                                                                                                                                              
SandboxieDcomLaunch.exe (14428, 17240) - 20:09:50.170   Image (U)                  c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll                                                                                                                       
SandboxieDcomLaunch.exe (14428, 17240) - 20:09:50.180   Image (U)                  c:\windows\system32\rpcss.dll                                                                                                                                              
SandboxieDcomLaunch.exe (14428, 17240) - 20:09:50.180   Image (U)                  c:\windows\system32\sspicli.dll                                                                                                                                            
SandboxieDcomLaunch.exe (14428, 14968) - 20:09:50.180   Ipc (U)        Open        \RPC Control\lsapolicylookup                                                                                                                                               
SandboxieDcomLaunch.exe (14428, 14968) - 20:09:50.180   Image (U)                  c:\windows\system32\cryptsp.dll                                                                                                                                            
SandboxieDcomLaunch.exe (14428, 14968) - 20:09:50.180   Ipc (U)        Open        \Security\LSA_AUTHENTICATION_INITIALIZED                                                                                                                                   
SandboxieDcomLaunch.exe (14428, 14968) - 20:09:50.180   Ipc (U)        Open        \RPC Control\lsasspirpc                                                                                                                                                    
SandboxieDcomLaunch.exe (14428, 14968) - 20:09:50.180   Image (U)                  c:\windows\system32\credssp.dll                                                                                                                                            
SandboxieDcomLaunch.exe (14428, 14968) - 20:09:50.180   Ipc (U)                    \RPC Control\actkernel                                                                                                                                                     
SandboxieDcomLaunch.exe (14428, 14968) - 20:09:50.180   Ipc (U)                    \Sessions\1\BaseNamedObjects\Global\__ComCatalogCache__                                                                                                                    
SandboxieDcomLaunch.exe (14428, 14968) - 20:09:50.180   Ipc (D)                    \Sessions\1\BaseNamedObjects\__ComCatalogCache__                                                                                                                           
SandboxieDcomLaunch.exe (14428, 14968) - 20:09:50.180   Image (U)                  c:\windows\system32\rpcrtremote.dll                                                                                                                                        
SandboxieDcomLaunch.exe (14428, 14968) - 20:09:50.180   Ipc (U)                    \RPC Control\epmapper                                                                                                                                                      
SandboxieDcomLaunch.exe (14428, 14968) - 20:09:50.180   Ipc (D)                    \Sessions\1\BaseNamedObjects\SBIE_BOXED_ServiceInitComplete_DcomLaunch                                                                                                     
SandboxieRpcSs.exe (15428, 14272) - 20:09:50.180        Ipc (U)                    \RPC Control\actkernel                                                                                                                                                     
SandboxieRpcSs.exe (15428, 14272) - 20:09:50.180        Ipc (U)                    \Sessions\1\BaseNamedObjects\SBIE_BOXED_ServiceInitComplete_DcomLaunch                                                                                                     
SandboxieRpcSs.exe (15428, 14272) - 20:09:50.180        Ipc (D)                    \RPC Control\actkernel                                                                                                                                                     
SandboxieRpcSs.exe (15428, 14272) - 20:09:50.190        Ipc (U)                    \Sessions\1\BaseNamedObjects\ScmCreatedEvent                                                                                                                               
SandboxieRpcSs.exe (15428, 14272) - 20:09:50.190        Ipc (D)                    \Sessions\1\BaseNamedObjects\SBIE_BOXED_ServiceInitComplete_RpcSs                                                                                                          
Start.exe (12648, 14588) - 20:09:50.190                 Ipc (U)                    \RPC Control\epmapper                                                                                                                                                      
Start.exe (12648, 14588) - 20:09:50.190                 Ipc (D)                    \Sessions\1\BaseNamedObjects\SBIE_BOXED_ServiceInitComplete_DcomLaunch                                                                                                     
SandboxieDcomLaunch.exe (14428, 6704) - 20:09:50.190    Ipc (U)                    \Sessions\1\BaseNamedObjects\Global\RotHintTable                                                                                                                           
SandboxieDcomLaunch.exe (14428, 6704) - 20:09:50.190    Ipc (D)                    \Sessions\1\BaseNamedObjects\RotHintTable                                                                                                                                  
SandboxieDcomLaunch.exe (14428, 6704) - 20:09:50.190    Ipc (U)                    \Sessions\1\BaseNamedObjects\Global\{A3BD3259-3E4F-428a-84C8-F0463A9D3EB5}                                                                                                 
SandboxieDcomLaunch.exe (14428, 6704) - 20:09:50.190    Ipc (D)                    \Sessions\1\BaseNamedObjects\{A3BD3259-3E4F-428a-84C8-F0463A9D3EB5}                                                                                                        
SandboxieDcomLaunch.exe (14428, 6704) - 20:09:50.190    Ipc (U)                    \Sessions\1\BaseNamedObjects\Global\{A64C7F33-DA35-459b-96CA-63B51FB0CDB9}                                                                                                 
SandboxieDcomLaunch.exe (14428, 6704) - 20:09:50.190    Ipc (D)                    \Sessions\1\BaseNamedObjects\{A64C7F33-DA35-459b-96CA-63B51FB0CDB9}                                                                                                        
Start.exe (12648, 14588) - 20:09:50.190                 Ipc (U)                    \Sessions\1\BaseNamedObjects\SboxSession                                                                                                                                   
Start.exe (12648, 14588) - 20:09:50.190                 Ipc (D)        Open        \KnownDlls\user32.dll                                                                                                                                                      
Start.exe (12648, 14588) - 20:09:50.190                 Ipc (D)        Open        \KnownDlls\gdi32.dll                                                                                                                                                       
Start.exe (12648, 14588) - 20:09:50.190                 Ipc (D)        Open        \KnownDlls\LPK.dll                                                                                                                                                         
Start.exe (12648, 14588) - 20:09:50.190                 Ipc (D)        Open        \KnownDlls\USP10.dll                                                                                                                                                       
Start.exe (12648, 14588) - 20:09:50.190                 Ipc (D)        Open        \KnownDlls\MSVCRT.dll                                                                                                                                                      
Start.exe (12648, 14588) - 20:09:50.190                 Ipc (D)        Open        \KnownDlls\SHELL32.dll                                                                                                                                                     
Start.exe (12648, 14588) - 20:09:50.190                 Ipc (D)        Open        \KnownDlls\SHLWAPI.dll                                                                                                                                                     
Start.exe (12648, 14588) - 20:09:50.190                 Ipc (D)        Open        \KnownDlls\ole32.dll                                                                                                                                                       
Start.exe (12648, 14588) - 20:09:50.200                 Ipc (D)        Open        \KnownDlls\rpcrt4.dll                                                                                                                                                      
Start.exe (12648, 14588) - 20:09:50.200                 Ipc (D)        Open        \KnownDlls\advapi32.dll                                                                                                                                                    
Start.exe (12648, 14588) - 20:09:50.200                 Ipc (D)        Open        \KnownDlls\COMDLG32.dll                                                                                                                                                    
Start.exe (12648, 14588) - 20:09:50.200                 Image (U)                  *:\program files\sandboxie-plus\start.exe                                                                                                                                  
Start.exe (12648, 14588) - 20:09:50.200                 Image (U)                  c:\windows\system32\ntdll.dll                                                                                                                                              
Start.exe (12648, 14588) - 20:09:50.200                 Image (U)                  c:\windows\system32\kernel32.dll                                                                                                                                           
Start.exe (12648, 14588) - 20:09:50.200                 Image (U)                  c:\windows\system32\kernelbase.dll                                                                                                                                         
Start.exe (12648, 14588) - 20:09:50.200                 Image (U)                  c:\program files\sandboxie-plus\sbiedll.dll                                                                                                                                
Start.exe (12648, 14588) - 20:09:50.200                 Image (U)                  c:\windows\system32\psapi.dll                                                                                                                                              
Start.exe (12648, 14588) - 20:09:50.200                 Image (U)                  c:\windows\system32\user32.dll                                                                                                                                             
Start.exe (12648, 14588) - 20:09:50.200                 Image (U)                  c:\windows\system32\gdi32.dll                                                                                                                                              
Start.exe (12648, 14588) - 20:09:50.200                 Image (U)                  c:\windows\system32\lpk.dll                                                                                                                                                
Start.exe (12648, 14588) - 20:09:50.200                 Image (U)                  c:\windows\system32\usp10.dll                                                                                                                                              
Start.exe (12648, 14588) - 20:09:50.200                 Image (U)                  c:\windows\system32\msvcrt.dll                                                                                                                                             
Start.exe (12648, 14588) - 20:09:50.200                 Image (U)                  c:\windows\system32\shell32.dll                                                                                                                                            
Start.exe (12648, 14588) - 20:09:50.200                 Image (U)                  c:\windows\system32\shlwapi.dll                                                                                                                                            
Start.exe (12648, 14588) - 20:09:50.200                 Image (U)                  c:\windows\system32\ole32.dll                                                                                                                                              
Start.exe (12648, 14588) - 20:09:50.200                 Image (U)                  c:\windows\system32\rpcrt4.dll                                                                                                                                             
Start.exe (12648, 14588) - 20:09:50.200                 Image (U)                  c:\windows\system32\advapi32.dll                                                                                                                                           
Start.exe (12648, 14588) - 20:09:50.200                 Image (U)                  c:\windows\system32\sechost.dll                                                                                                                                            
Start.exe (12648, 14588) - 20:09:50.200                 Image (U)                  c:\windows\winsxs\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.24483_none_e372d88f30fbb845\comctl32.dll                                               
Start.exe (12648, 14588) - 20:09:50.200                 Image (U)                  c:\windows\system32\comdlg32.dll                                                                                                                                           
Start.exe (12648, 14588) - 20:09:50.200                 Ipc (D)        Open        \KnownDlls\MSCTF.dll                                                                                                                                                       
Start.exe (12648, 14588) - 20:09:50.200                 Image (U)                  c:\windows\system32\imm32.dll                                                                                                                                              
Start.exe (12648, 14588) - 20:09:50.200                 Image (U)                  c:\windows\system32\msctf.dll                                                                                                                                              
Start.exe (12648, 14588) - 20:09:50.210                 Ipc (U)                    \Sessions\1\BaseNamedObjects\SBIE_BOXED_ServiceInitComplete_RpcSs                                                                                                          
Start.exe (12648, 16276) - 20:09:50.210                 Ipc (D)                    \Sessions\1\BaseNamedObjects\SBIE_BOXED_ServiceInitComplete_DcomLaunch                                                                                                     
Start.exe (12648, 14588) - 20:09:50.210                 Image (U)                  c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll                                                                                                                       
Start.exe (12648, 14588) - 20:09:50.220                 Ipc (U)                    \Sessions\1\BaseNamedObjects\windows_shell_global_counters                                                                                                                 
Start.exe (12648, 3840) - 20:09:50.220                  Image (U)                  c:\windows\system32\cryptbase.dll                                                                                                                                          
Start.exe (12648, 3840) - 20:09:50.220                  Pipe (U)                   \Device\KsecDD                                                                                                                                                             
Start.exe (12648, 3840) - 20:09:50.220                  Ipc (U)        Open        \RPC Control\SbieSvcPort                                                                                                                                                   
Start.exe (12648, 3840) - 20:09:50.220                  Image (U)                  c:\windows\system32\uxtheme.dll                                                                                                                                            
Start.exe (12648, 3840) - 20:09:50.220                  Ipc (U)        Open        \ThemeApiPort                                                                                                                                                              
Start.exe (12648, 3840) - 20:09:50.220                  Ipc (D)        Open        \KnownDlls\OLEAUT32.dll                                                                                                                                                    
Start.exe (12648, 3840) - 20:09:50.220                  Image (U)                  c:\windows\system32\propsys.dll                                                                                                                                            
Start.exe (12648, 3840) - 20:09:50.220                  Image (U)                  c:\windows\system32\oleaut32.dll                                                                                                                                           
Start.exe (12648, 3840) - 20:09:50.230                  Ipc (U)                    \BaseNamedObjects\__ComCatalogCache__                                                                                                                                      
Start.exe (12648, 3840) - 20:09:50.230                  Ipc (D)                    \Sessions\1\BaseNamedObjects\__ComCatalogCache__                                                                                                                           
Start.exe (12648, 3840) - 20:09:50.240                  Ipc (D)        Open        \KnownDlls\clbcatq.dll                                                                                                                                                     
Start.exe (12648, 3840) - 20:09:50.240                  Ipc (U)        Open        \KernelObjects\MaximumCommitCondition                                                                                                                                      
Start.exe (12648, 3840) - 20:09:50.240                  Image (U)                  c:\windows\system32\clbcatq.dll                                                                                                                                            
Start.exe (12648, 3840) - 20:09:50.240                  Ipc (U)                    \BaseNamedObjects\__ComCatalogCache__                                                                                                                                      
Start.exe (12648, 3840) - 20:09:50.240                  Ipc (D)                    \Sessions\1\BaseNamedObjects\__ComCatalogCache__                                                                                                                           
Start.exe (12648, 3840) - 20:09:50.240                  Ipc (D)        Open        \KnownDlls\WLDAP32.dll                                                                                                                                                     
Start.exe (12648, 3840) - 20:09:50.240                  Image (U)                  c:\windows\system32\ntmarta.dll                                                                                                                                            
Start.exe (12648, 3840) - 20:09:50.240                  Image (U)                  c:\windows\system32\wldap32.dll                                                                                                                                            
Start.exe (12648, 3840) - 20:09:50.240                  Ipc (U)                    \Sessions\1\BaseNamedObjects\Local\C:*Users"me*AppData*Local*Microsoft*Windows*Caches*cversions.1.ro                                                                    
Start.exe (12648, 3840) - 20:09:50.240                  Ipc (D)                    \Sessions\1\BaseNamedObjects\C:*Users*me*AppData*Local*Microsoft*Windows*Caches*cversions.1.ro                                                                          
Start.exe (12648, 3840) - 20:09:50.240                  Ipc (U)                    \Sessions\1\BaseNamedObjects\Local\C:*Users*me*AppData*Local*Microsoft*Windows*Caches*{AFBF9F1A-8EE8-4C77-AF34-C647E37CA0D9}.1.ver0x0000000000000025.db                 
Start.exe (12648, 3840) - 20:09:50.240                  Ipc (D)                    \Sessions\1\BaseNamedObjects\C:*Users*me*AppData*Local*Microsoft*Windows*Caches*{AFBF9F1A-8EE8-4C77-AF34-C647E37CA0D9}.1.ver0x0000000000000025.db                       
Start.exe (12648, 3840) - 20:09:50.240                  Ipc (U)                    \BaseNamedObjects\windows_shell_global_counters                                                                                                                            
Start.exe (12648, 3840) - 20:09:50.240                  Ipc (D)                    \Sessions\1\BaseNamedObjects\windows_shell_global_counters                                                                                                                 
Start.exe (12648, 3840) - 20:09:50.240                  Ipc (D)        Open        \KnownDlls\profapi.dll                                                                                                                                                     
Start.exe (12648, 3840) - 20:09:50.240                  Image (U)                  c:\windows\system32\profapi.dll                                                                                                                                            
Start.exe (12648, 3840) - 20:09:50.240                  Ipc (U)                    \BaseNamedObjects\C:*ProgramData*Microsoft*Windows*Caches*cversions.2.ro                                                                                                   
Start.exe (12648, 3840) - 20:09:50.240                  Ipc (U)                    \Sessions\1\BaseNamedObjects\C:*ProgramData*Microsoft*Windows*Caches*cversions.2.ro                                                                                        
Start.exe (12648, 3840) - 20:09:50.250                  Ipc (U)                    \Sessions\1\BaseNamedObjects\Global\C:*ProgramData*Microsoft*Windows*Caches*cversions.2.ro                                                                                 
Start.exe (12648, 3840) - 20:09:50.250                  Ipc (D)                    \Sessions\1\BaseNamedObjects\C:*ProgramData*Microsoft*Windows*Caches*cversions.2.ro                                                                                        
Start.exe (12648, 3840) - 20:09:50.250                  Ipc (U)                    \BaseNamedObjects\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000012.db                                                
Start.exe (12648, 3840) - 20:09:50.250                  Ipc (U)                    \Sessions\1\BaseNamedObjects\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000012.db                                     
Start.exe (12648, 3840) - 20:09:50.250                  Ipc (U)                    \Sessions\1\BaseNamedObjects\Global\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000012.db                              
Start.exe (12648, 3840) - 20:09:50.250                  Ipc (D)                    \Sessions\1\BaseNamedObjects\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000012.db                                     
Start.exe (12648, 3840) - 20:09:50.250                  Ipc (U)                    \BaseNamedObjects\C:*ProgramData*Microsoft*Windows*Caches*cversions.2.ro                                                                                                   
Start.exe (12648, 3840) - 20:09:50.250                  Ipc (D)                    \Sessions\1\BaseNamedObjects\C:*ProgramData*Microsoft*Windows*Caches*cversions.2.ro                                                                                        
Start.exe (12648, 3840) - 20:09:50.250                  Ipc (U)                    \BaseNamedObjects\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000002.db                                                
Start.exe (12648, 3840) - 20:09:50.250                  Ipc (U)                    \Sessions\1\BaseNamedObjects\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000002.db                                     
Start.exe (12648, 3840) - 20:09:50.250                  Ipc (U)                    \Sessions\1\BaseNamedObjects\Global\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000002.db                              
Start.exe (12648, 3840) - 20:09:50.250                  Ipc (D)                    \Sessions\1\BaseNamedObjects\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000002.db                                     
Start.exe (12648, 3840) - 20:09:50.280                  Image (U)                  c:\windows\system32\apphelp.dll                                                                                                                                            
Start.exe (12648, 3840) - 20:09:50.280                  Image (U)                  c:\windows\system32\shdocvw.dll                                                                                                                                            
Start.exe (12648, 3840) - 20:09:50.280                  Pipe (U)                   \Device\HarddiskVolume5                                                                                                                                                    
Start.exe (12648, 3840) - 20:09:50.280                  Pipe (U)                   \Device\MountPointManager                                                                                                                                                  
Start.exe (12648, 16852) - 20:09:50.280                 Ipc (D)        Open        \KnownDlls\Setupapi.dll                                                                                                                                                    
Start.exe (12648, 16852) - 20:09:50.280                 Ipc (D)        Open        \KnownDlls\CFGMGR32.dll                                                                                                                                                    
Start.exe (12648, 16852) - 20:09:50.280                 Ipc (D)        Open        \KnownDlls\DEVOBJ.dll                                                                                                                                                      
Start.exe (12648, 16852) - 20:09:50.280                 Image (U)                  c:\windows\system32\setupapi.dll                                                                                                                                           
Start.exe (12648, 16852) - 20:09:50.280                 Image (U)                  c:\windows\system32\cfgmgr32.dll                                                                                                                                           
Start.exe (12648, 16852) - 20:09:50.280                 Image (U)                  c:\windows\system32\devobj.dll                                                                                                                                             
Start.exe (12648, 16852) - 20:09:50.280                 Ipc (U)                    \RPC Control\plugplay                                                                                                                                                      
Start.exe (12648, 16852) - 20:09:50.280                 Ipc (U)        Open        \RPC Control\SbieSvcPort                                                                                                                                                   
Start.exe (12648, 3840) - 20:09:50.290                  Pipe (U)                   \Device\HarddiskVolume5                                                                                                                                                    
Start.exe (12648, 3840) - 20:09:50.290                  Pipe (U)                   \Device\MountPointManager                                                                                                                                                  
Start.exe (12648, 15300) - 20:09:50.290                 Pipe (U)                   \Device\Ide\IdeDeviceP1T0L0-1                                                                                                                                              
Start.exe (12648, 15300) - 20:09:50.290                 Pipe (U)                   \Device\MountPointManager                                                                                                                                                  
Start.exe (12648, 15300) - 20:09:50.290                 Pipe (U)                   \Device\HarddiskVolume1                                                                                                                                                    
Start.exe (12648, 15300) - 20:09:50.290                 Pipe (U)                   \Device\MountPointManager                                                                                                                                                  
Start.exe (12648, 15300) - 20:09:50.290                 Pipe (U)                   \Device\HarddiskVolume2                                                                                                                                                    
Start.exe (12648, 15300) - 20:09:50.290                 Pipe (U)                   \Device\MountPointManager                                                                                                                                                  
Start.exe (12648, 15300) - 20:09:50.290                 Pipe (U)                   \Device\HarddiskVolume3                                                                                                                                                    
Start.exe (12648, 15300) - 20:09:50.290                 Pipe (U)                   \Device\MountPointManager                                                                                                                                                  
Start.exe (12648, 15300) - 20:09:50.290                 Pipe (U)                   \Device\HarddiskVolume4                                                                                                                                                    
Start.exe (12648, 15300) - 20:09:50.290                 Pipe (U)                   \Device\MountPointManager                                                                                                                                                  
Start.exe (12648, 15300) - 20:09:50.290                 Pipe (U)                   \Device\HarddiskVolume5                                                                                                                                                    
Start.exe (12648, 15300) - 20:09:50.290                 Pipe (U)                   \Device\MountPointManager                                                                                                                                                  
Start.exe (12648, 15300) - 20:09:50.290                 Pipe (U)                   \Device\HarddiskVolume6                                                                                                                                                    
Start.exe (12648, 15300) - 20:09:50.290                 Pipe (U)                   \Device\MountPointManager                                                                                                                                                  
Start.exe (12648, 15300) - 20:09:50.290                 Pipe (U)                   \Device\000000bb                                                                                                                                                           
Start.exe (12648, 15300) - 20:09:50.290                 Pipe (U)                   \Device\MountPointManager                                                                                                                                                  
Start.exe (12648, 16852) - 20:09:50.290                 Pipe (U)       (17)        \Device\MountPointManager                                                                                                                                                  
Start.exe (12648, 3840) - 20:09:50.300                  Debug (U)      Trace       CreateProcess: C:\Windows\System32\msiexec.exe ("C:\Windows\System32\msiexec.exe" /i "C:\Users\me\AppData\Local\Temp\Rar$DRa15656.44292\FinalDraftSetup.msi" ); err=0   
Start.exe (12648, 14588) - 20:09:50.300                 Ipc (U)                    \Sessions\1\BaseNamedObjects\SBIE_BOXED_ServiceInitComplete_RpcSs                                                                                                          
Start.exe (12648, 14588) - 20:09:50.300                 Ipc (D)                    \Sessions\1\BaseNamedObjects\SBIE_BOXED_ServiceInitComplete_DcomLaunch                                                                                                     
msiexec.exe (15952, 15148) - 20:09:50.310               Ipc (D)        Open        \KnownDlls\kernel32.dll                                                                                                                                                    
msiexec.exe (15952, 15148) - 20:09:50.310               Ipc (D)        Open        \KnownDlls\kernelbase.dll
isaak654 commented 2 years ago

If you are on the main Sandboxie Plus window and you've closed any running program in the sandbox:

Second attempt: add also these lines:

UnrestrictedToken=y
MsiInstallerExemptions=y

If nothing of these attempts changed the behavior, remove all added lines and wait the main dev for further steps.

isaak654 commented 2 years ago

Another thing is that the oldest Plus versions didn't uninstall correctly some entries, so make sure to run the latest Plus v1.0.11.

GLoren1 commented 2 years ago

I was running v1.0.10. I tried to uninstall and reinstall v1.0.11, but the install failed because SbieDrv.sys already existed. I tried to manually uninstall SbieDrv.sys, but notified that I need to be administrator despite being the administrator. I tried to change permissions of the file and could not.

So, I re-installed v1.0.11 by skipping SbieDrv.sys. Now, when I start Sandboxie Plus it errors with "Failed to connect to driver"

isaak654 commented 2 years ago

Driver connection issues can be fixed from Sandbox menu -> Maintenance on the Plus interface. There is a note about it on the README.md file:

Maintenance mode - it allows to uninstall/install/start/stop Sandboxie driver and service when needed

GLoren1 commented 2 years ago

I was able to correctly install the latest version with the help of your suggestions, and I added your suggested lines in the .ini file. Now, when I try an msi file in sandbox, it fails with several messages appearing. I've pasted those below:

PID 11716: SBIE2336 Error in GUI server: [11 / C0000021] PID 11716: SBIE2335 Initialization failed for process SandboxieDcomLaunch.exe [88 / 87] SandboxieRpcSs.exe (7252): SBIE2313 Could not execute SandboxieDcomLaunch.exe (5) SandboxieRpcSs.exe (7252): SBIE2204 Cannot start sandboxed service DcomLaunch (5) PID 11716: SBIE2336 Error in GUI server: [11 / C0000021] PID 11716: SBIE2335 Initialization failed for process SandboxieDcomLaunch.exe [88 / 87] SandboxieRpcSs.exe (7252): SBIE2313 Could not execute SandboxieDcomLaunch.exe (5) SandboxieRpcSs.exe (7252): SBIE2204 Cannot start sandboxed service DcomLaunch (5) PID 11716: SBIE2336 Error in GUI server: [11 / C0000021] PID 11716: SBIE2335 Initialization failed for process SandboxieDcomLaunch.exe [88 / 87] Start.exe (14424): SBIE2204 Cannot start sandboxed service RpcSs (-1) SandboxieRpcSs.exe (7252): SBIE2313 Could not execute SandboxieDcomLaunch.exe (5) SandboxieRpcSs.exe (7252): SBIE2204 Cannot start sandboxed service DcomLaunch (5) PID 11716: SBIE2336 Error in GUI server: [11 / C0000021] PID 11716: SBIE2335 Initialization failed for process SandboxieDcomLaunch.exe [88 / 87] SandboxieRpcSs.exe (7252): SBIE2313 Could not execute SandboxieDcomLaunch.exe (5) SandboxieRpcSs.exe (7252): SBIE2204 Cannot start sandboxed service DcomLaunch (5)

isaak654 commented 2 years ago

The only interesting thing I found about SBIE2336 Error in GUI server: [11 / C0000021] is an old fix released on 22 May 2014 in Sandboxie v4.10 that is compatible until Windows 8.1.

Fixed the following startup errors on the Dell Venue and other Win 8.1 tablets. SBIE2336 Error in GUI server: 11 / C0000021. SBIE2335 Initialization failed for process Start.exe 88/0 Source 1: https://malwaretips.com/threads/sandboxie-version-4-12-released.27355 Source 2: https://github.com/sandboxie-plus/sandboxie-old/tree/main/4.x

Just out of curiosity, what is your Windows version?

GLoren1 commented 2 years ago

Windows 7 with all of the latest updates.

GLoren1 commented 2 years ago

If nothing of these attempts changed the behavior, remove all added lines and wait the main dev for further steps.

Update: I installed Sandboxie on another machine and got similar errors. Is anyone still looking at this issue?

DavidXanatos commented 2 years ago

In my windows 7 test VM the msi installs just fine, also known msi issues do not include troubles loading the sbiedll.dll Final Draft.exe fails to start though not sure why sbiedll.dll loads fien but before th files entry point is invoked it fails. not sure whats up with that other 32 bit .net apps work just fine may be some obfuscater is breaking it or something app specific

hendrikreimers commented 2 years ago

Same issue since update to 1.1.3 (x64). Downgrade keeps the issue.

wilders-soccerfan commented 2 years ago

I am on Win7 Home, SP1, 64bit, build 7601. FinalDraftSetup.msi (in the linked zip) installs just fine in sbie plus v1.1.3. I tried in a new security hardened box with MsiInstallerExemptions=y FinalDraft1

GLoren1 commented 2 years ago

I still get the same errors with sbie plus v1.1.3. The errors occur on both of my machines running Windows 7.

isaak654 commented 2 years ago

If that persists, you could export (with the consent of @DavidXanatos) one of your mentioned machines as a virtual one (you'll need to use disk2vhd to obtain a .vhd image) and sent through a hosting service after compressing the file as .7z with the most high compression ratio.

If privacy is a concern, you could remove any program and data contained in the .vhd image before the upload.

For more info, a developer's contact is provided here or in his contact page.

I shared privately 3 virtual machines for some past issues that have been solved, so I know what I mean.

Uj947nXmRqV2nRaWshKtHzTvckUUpD commented 2 years ago

trying to run Hyper.exe (https://github.com/vercel/hyper) sandboxed and getting same error. ~Note that in the initial issue's description, it is mistakenly written "Installation" instead of "Initialization":~

image

Update: same happens with latest version 1.2.5

isaak654 commented 2 years ago

trying to run Hyper.exe (https://github.com/vercel/hyper) sandboxed and getting same error.

Update: same happens with latest version 1.2.5

@fusionneur Hyper.exe runs fine for me in the stardard isolation sandbox, same Plus version (x64). I think the only game changer for this issue is explained here, alternatively it's a matter of providing more accurate steps.

chocobopie commented 1 year ago

image Having same issue, tried reinstall many times but didnt work

isaak654 commented 1 year ago

Please check your folder permissions: #2563

the one with the shorter SID makes the problems the other one at the top can stay

This is also quite similar to https://forum.xanasoft.com/threads/windows-11-install-sandboxie-on-another-drive.500/

DavidXanatos commented 1 year ago

does the folder permissions check helped?

Uj947nXmRqV2nRaWshKtHzTvckUUpD commented 1 year ago

I tried running hyper in latest sandboxie, and i am not getting error anymore. I did not do anything else, other than updating sandboxie and Windows 11 OS in these months

EngrMubasharAli commented 1 year ago

i get problem with chrome browser, what is the solution ?

Gloryandel commented 1 year ago

I also encountered Sandboxie-Plus\SbieDll.dll initialization failure when installing Stack Browser. The process terminated abnormally. Is there a solution now?

isaak654 commented 1 year ago

There is no definitive solution yet.

For the time being, please look at the suggestions provided in the previous comments: https://github.com/sandboxie-plus/Sandboxie/issues/1620#issuecomment-1189913792 https://github.com/sandboxie-plus/Sandboxie/issues/1620#issuecomment-1383439323 You may also want to check all issues under the label https://github.com/sandboxie-plus/Sandboxie/labels/SbieDll in order to find workarounds like this.

It is also recommended to install the latest version of Sandboxie and provide a proper amount of technical details.

EngrMubasharAli commented 1 year ago

installed newer version of Sandboxie-plus v1.7.2, not a clean install but overwrite from old version the problem is same image

isaak654 commented 1 year ago

@EngrMubasharAli I don't see a specific SbieDll initialization failure... in your case, I would suggest to install v1.8.1 through a clean install and possibly open a new issue if that is still present.

DavidXanatos commented 1 year ago

I also encountered Sandboxie-Plus\SbieDll.dll initialization failure when installing Stack Browser. The process terminated abnormally. Is there a solution now?

since you mention browser, that may be AppContainer related, please try out build 1.8.3 once its out, that should improve on that.

github-actions[bot] commented 1 year ago

As it has been 3 months since the last activity, we are automatically closing this issue in 14 days. If it is still present, please respond to help us investigate on newer Sandboxie versions. Thank you for your contribution!