Open bjm234 opened 1 year ago
Okay, auto delete works in my Default Auto Delete sbox by adding msedge.exe, mbam.exe, MbamBgNativeMsg.exe, cmd.exe to Lingering Programs.
I thought if leader processes are defined, all others are treated as lingering processes. I had added msedge.exe, mbam.exe, MbamBgNativeMsg.exe, cmd.exe to Leader Programs. That did not work, for me.
I have to see if my Edge sbox Enhanced Isolation Auto Delete will auto delete.
Does Leader/Lingering see MbamBgNativeMsg.exe the same as mbambgnativemsg.exe My Edge sbox Leader/Lingering will not hold uppercase...reverts to all lower case.
To test it, try setting ConfidentialBox to N.
ConfidentialBox=n
It doesn't matter whether the letters are uppercase or lowercase.
Disable Malwarebytes Browser Guard extension or use ClosedFilePath=%ProgramFiles%\Malwarebytes\Anti-Malware\MbamBgNativeMsg.exe
to block it from running in the sandbox.
When you try to terminate MbamBgNativeMsg.exe manually (or with Sandboxie), you get an "Access Denied" error. This is why it seems to be stuck, because it won't terminate itself. In such cases it may be better to use a more forceful termination technique. @DavidXanatos
Okay, auto delete works in my Default Auto Delete sbox by adding msedge.exe, mbam.exe, MbamBgNativeMsg.exe, cmd.exe to Lingering Programs.
Edge sbox Enhanced Isolation Box Protection Auto Delete will not auto delete.
I'm not married to MBG. I'm curious why MBG does not play well in my Edge sbox.
My bookmarks extension + uBO play well in my Edge sbox.
@offhub Thanks for your interest.
@offhub
ClosedFilePath=%ProgramFiles%\Malwarebytes\Anti-Malware\MbamBgNativeMsg.exe is definitive fix...if I want to run Malwarebytes Brower Guard extension in my Edge sbox.
No Leader/Lingering Programs needed.
Edge sbox - Auto-delete works.
Regards w Respect
Having this same issue but with Firefox. What is strange is I am able to manually terminate MbamBgNativeMsg.exe with task manager and then the sandbox will finally end and delete. Even more confusing, if you right click MbamBgNativeMsg.exe in the Sandboxie Control window and click "Terminate Program" it fails to terminate with no error message, BUT if I right click the sandbox itself and click "Terminate Programs" it will terminate everything including MbamBgNativeMsg.exe. Why does one method work but not the other? 🤔
Describe what you noticed and did
Just curious any users run Malwarebytes Browser Guard extension in Edge sbox. Edge sbox upon close does not terminate when Malwarebytes Browser Guard is enabled. Edge sbox auto delete enabled does not auto delete. Terminate Programs sorts. Just curious any users experience similar in Edge sbox. I've tried new default sbox with auto delete enabled. I've tried direct/full access to AppData\Local\Microsoft\Edge\User Data\Default\Extensions\ihcjic..... I've tried direct access to entire Edge profile. I've tried Leader Programs > msedge.exe + default LingerPrograms enabled. I've tried Leader Programs > MbamBgNativeMsg.exe No joy.
Just curious what's holding Edge from terminating. With bookmarks extension and uBlock Origin. Edge sbox auto delete is okay. With bookmarks, uBO and MBG. Edge sbox auto delete is not okay.
Chrome sbox (same extensions) has same issue as Edge sbox. Firefox sbox (same extensions) seems to auto delete okay. Just curious. Thanks
How often did you encounter it so far?
reproducible
Affected program
Edge
Download link
Not relevant
Where is the program located?
Edge is installed only outside the sandbox.
Expected behavior
expect to see auto delete okay
What is your Windows edition and version?
W10 22H2
In which Windows account you have this problem?
A local account (Administrator).
Please mention any installed security software
Norton 360, OSArmor
What version of Sandboxie are you running?
1.11.4
Is it a new installation of Sandboxie?
I just updated Sandboxie from a previous version (I remember which one it is).
Is it a regression?
1.11.3 same MBG issue
In which sandbox type you have this problem?
Enhanced Isolation or Default Auto Delete
Can you reproduce this problem on a new empty sandbox?
I can confirm it also on a new empty default sandbox with auto delete enabled.
Did you previously enable some security policy settings outside Sandboxie?
No response
Crash dump
No response
Trace log
No response
Sandboxie.ini configuration
Maybe, Malwarebytes Browser Guard is talking to Malwarebytes even though my Malwarebytes is not running real-time protection.
Does Leader/Lingering see MbamBgNativeMsg.exe the same as mbambgnativemsg.exe