sandboxie-plus / Sandboxie

Sandboxie Plus & Classic
https://Sandboxie-Plus.com
GNU General Public License v3.0
13.99k stars 1.56k forks source link

Word won't open in Sandboxie (Click-to-Run installations) #428

Closed Seeadler1 closed 3 years ago

Seeadler1 commented 3 years ago

Hi,

since version 5.46.0, Word can no longer be opened in the sandbox. A system error message appears: "% 1 is not a valid Win32 application (193)"

But Wordpad works

Regards

DavidXanatos commented 3 years ago

And with 5.45.2 it was working fine?

Seeadler1 commented 3 years ago

I think so but I am not sure... With 5.45.0 is working fine

DavidXanatos commented 3 years ago

Hmm.. that is strange as on my test VM i just installed office and it starts ok. There comes an other error when you forget to enable the click to run template, but with it it starts well.

could you please test which version exactly breaks it for you as that helps me a lot narrowing down what may have caused the issue.

Seeadler1 commented 3 years ago

Thanks! Where can I enable the click to run template?

Damnatus commented 3 years ago

in Sandboxie Classic it is called Software Compatibility and is in the Configure menu. But the app compatibility for Office Click-to-Run is likely not there and has to be added via Sandboxie.ini Just add Template=OfficeLicensing Template=OfficeClickToRun under the Sandbox brackets of [YourOfficeSandboxName].

Otherwise use Sandboxie Plus with the new SandMan UI Screenshot 2021-01-22 013539

bjm234 commented 3 years ago

image image

Seeadler1 commented 3 years ago

Thank you all!!! I will test it...

Seeadler1 commented 3 years ago

Global Settings in the ini looks like this. It seems correct but Word doesn't work. But WordPad is working...

Image 3

Seeadler1 commented 3 years ago

Now I tested Word with the old version 5.33.6 without any changes. But the same error. Office/Word definitely worked with the old 5.33.6.

Microsoft must have changed something fundamentally. So it has nothing to do with your classic version, David.

APMichael commented 3 years ago

I assume you have Word from Microsoft Office 365 or 2016, right?

Unfortunately, Microsoft seems to have really changed something here.

https://github.com/sandboxie-plus/Sandboxie/issues/376 or https://www.wilderssecurity.com/threads/ms-office-365-2016-c2r-click-to-run-no-longer-works-with-sandboxie.435875/

Seeadler1 commented 3 years ago

Right Michael! Office 2016

NewKidOnTheBlock commented 3 years ago

Can't confirm. Tried to open a random .docx in Sandboxie and it worked fine. (Word 2016 64bit)

APMichael commented 3 years ago

Can't confirm. Tried to open a random .docx in Sandboxie and it worked fine. (Word 2016 64bit)

Click-To-Run (C2R) or MSI version?

NewKidOnTheBlock commented 3 years ago

InstantGif_2021 01 25-14 43

APMichael commented 3 years ago

@NewKidOnTheBlock: Ok, thanks, but that doesn't answer the version question...

Edit: With the changed installation path, it looks to me more like a MSI version and that works fine. The issue currently only applies to the C2R version of Microsoft Office 365 and 2016.

NewKidOnTheBlock commented 3 years ago

@Seeadler1 I noted you got a ton of outdated templates in your Sandoxie.ini: You might wanna clean that up manually: https://github.com/sandboxie-plus/Sandboxie/issues/413#issuecomment-763141546

Seeadler1 commented 3 years ago

I am not shure bit I think it is the MSI Version. And as I said: some time ago, Word was still running without any problems in Sandboxie. This templates I clean up: Template=Windows10CoreUI Template= WindowsFontCache Template=FireFix_For_Win7 But it doesn't help

isaak654 commented 3 years ago

I was able to reproduce the issue between Office 2016 "Click to Run" and Sandboxie-Plus 0.6.7:

1) Download C2R from here 2) Run the downloaded file and select the folder where you want to extract the setup files 3) Run cmd in admin mode and use the same path where you extracted the files before. 4) Run setup.exe /download configuration-Office365-x64.xml (it could take one hour to finish) 5) Run setup.exe /configure configuration-Office365-x64.xml (this will install office 2016 click to run) 6) Now apply the compatibility template "Microsoft Office Click-to-run" in your sandbox. 7) Run Word or Excel as sandboxed (you will find the shortcut in C:\ProgramData\Microsoft\Windows\Start Menu\Programs). 8) Instant crash, same error like this one.

Resource log of the crash: https://git.io/JtzJu

APMichael commented 3 years ago

@DavidXanatos: Are there any new findings on this yet? Can the issue be solved soon?

isaak654 commented 3 years ago

With SB+ 0.7.2, it seems partially fixed for me. I can run Word or Excel as sandboxed by following my previous installation steps (two posts above). The only problem I have is with sandboxed Access, the window opens but it shakes so badly that I can't interact with it.

A workaround to solve the issue is by setting 'Sandbox Indicator in Title' option to 'Don't Alter the window title' in Sandboxie Plus. The line appeared in the sandbox is: BoxNameTitle=-

I would like to hear some additional confirmation.

My initial sandboxie.ini settings ``` [GlobalSettings] FileRootPath=\??\%SystemDrive%\Sandbox\%USER%\%SANDBOX% SeparateUserFolders=n KeyRootPath=\REGISTRY\USER\Sandbox_%USER%_%SANDBOX% IpcRootPath=\Sandbox\%USER%\%SANDBOX%\Session_%SESSION% EditAdminOnly=n ForceDisableAdminOnly=n ForgetPassword=n Template=OfficeClickToRun Template=WindowsRasMan Template=WindowsLive Template=OfficeLicensing StartRunAlertDenied=n NotifyStartRunAccessDenied=y TemplateReject=BitDefenderInternetSecurity TemplateReject=HitmanProAlert [New_Box_to_use] Enabled=y ConfigLevel=8 AutoRecover=n BlockNetworkFiles=y RecoverFolder=%{374DE290-123F-4565-9164-39C4925E467B}% RecoverFolder=%Personal% RecoverFolder=%Desktop% BorderColor=#00FFFF,ttl Template=SkipHook Template=FileCopy Template=qWave Template=BlockPorts Template=LingerPrograms Template=Chrome_Phishing_DirectAccess Template=Firefox_Phishing_DirectAccess Template=AutoRecoverIgnore ```
My trace log (without the workaround) ``` |Process| |Type| |Status| |Value| MSACCESS.EXE (3756) _ Thread 4920 __ 00:56:56.142 Ipc \Sessions\1\BaseNamedObjects\AirDrop::3756 __ 00:56:56.130 Pipe \Device\DeviceApi __ 00:56:56.130 Ipc Open \KnownDlls\cfgmgr32.dll __ 00:56:56.066 Ipc \Sessions\1\BaseNamedObjects\SM0:3756:304:WilStaging_02_p0h __ 00:56:56.066 Ipc \Sessions\1\BaseNamedObjects\SM0:3756:304:WilStaging_02_p0 __ 00:56:56.066 Ipc \Sessions\1\BaseNamedObjects\SM0:3756:304:WilStaging_02 __ 00:56:56.066 Ipc \Sessions\1\BaseNamedObjects\SM0:3756:304:WilStaging_02_p0h __ 00:56:56.066 Ipc \Sessions\1\BaseNamedObjects\SM0:3756:304:WilStaging_02_p0 __ 00:56:56.066 Ipc \Sessions\1\BaseNamedObjects\SM0:3756:304:WilStaging_02 __ 00:56:55.980 Ipc \RPC Control\LRPC-3a7f3cb977eb87ecc4 __ 00:56:55.915 Ipc Open \RPC Control\SbieSvcPort __ 00:56:55.869 Ipc open \RPC Control\SbieSvcPort __ 00:56:55.857 Ipc \Sessions\1\BaseNamedObjects\SM0:3756:304:WilStaging_02_p0h __ 00:56:55.857 Ipc \Sessions\1\BaseNamedObjects\SM0:3756:304:WilStaging_02_p0 __ 00:56:55.857 Ipc \Sessions\1\BaseNamedObjects\SM0:3756:304:WilStaging_02 _ Thread 4820 __ 00:56:57.726 ComClass Windows.System.Profile.SharedModeSettings __ 00:56:57.628 Ipc \Sessions\1\BaseNamedObjects\SM0:3756:304:WilStaging_02_p0h __ 00:56:57.628 Ipc \Sessions\1\BaseNamedObjects\SM0:3756:304:WilStaging_02_p0 __ 00:56:57.628 Ipc \Sessions\1\BaseNamedObjects\SM0:3756:304:WilStaging_02 __ 00:56:57.628 Ipc open \BaseNamedObjects\msctf.serverDefault1 __ 00:56:57.628 Ipc open \Sessions\1\BaseNamedObjects\CTF.AsmListCache.FMPDefault1 __ 00:56:57.628 Ipc open \Sessions\1\BaseNamedObjects\MSCTF.Asm.MutexDefault1 __ 00:56:57.498 WinClass closed ApplicationManager_DesktopShellWindow __ 00:56:57.498 WinClass $:explorer.exe __ 00:56:57.465 WinClass ApplicationManager_DesktopShellWindow __ 00:56:57.465 Ipc (2) \Sessions\1\BaseNamedObjects\eacHWNDInterface:40062 __ 00:56:57.453 ComClass Windows.UI.ViewManagement.UIViewSettings __ 00:56:57.349 Ipc open \BaseNamedObjects\FontCachePort __ 00:56:57.015 Ipc \Sessions\1\BaseNamedObjects\552FFA80-3393-423d-8671-7BA046BB5906 __ 00:56:56.951 Ipc \Sessions\1\BaseNamedObjects\FLOODGATE.ACCESS.CAMPAIGNSTATES.JSON __ 00:56:56.951 Ipc \Sessions\1\BaseNamedObjects\FLOODGATE.ACCESS.SURVEYHISTORYSTATS.JSON __ 00:56:56.887 Ipc \Sessions\1\BaseNamedObjects\FLOODGATE.ACCESS.GOVERNEDCHANNELSTATES.JSON __ 00:56:56.854 Ipc (3) \Sessions\1\BaseNamedObjects\SessionImmersiveColorPreference __ 00:56:56.854 Ipc \Sessions\1\BaseNamedObjects\SessionImmersiveColorMutex __ 00:56:56.704 ComClass Windows.ApplicationModel.Core.CoreApplication __ 00:56:56.595 ComClass ApplicationTheme.AppThemeAPI __ 00:56:56.460 Ipc (3) \RPC Control\eventlog __ 00:56:56.130 Pipe \Device\MountPointManager __ 00:56:55.947 Ipc \Sessions\1\BaseNamedObjects\{D2E68709-534D-4786-A9B7-D2364CACDA8F}16.0 __ 00:56:55.903 Ipc \Sessions\1\BaseNamedObjects\SM0:3756:120:WilError_03_p0h __ 00:56:55.903 Ipc \Sessions\1\BaseNamedObjects\SM0:3756:120:WilError_03_p0 __ 00:56:55.903 Ipc \Sessions\1\BaseNamedObjects\SM0:3756:120:WilError_03 __ 00:56:55.903 Ipc \Sessions\1\BaseNamedObjects\SM0:3756:304:WilStaging_02_p0h __ 00:56:55.903 Ipc \Sessions\1\BaseNamedObjects\SM0:3756:304:WilStaging_02_p0 __ 00:56:55.903 Ipc \Sessions\1\BaseNamedObjects\SM0:3756:304:WilStaging_02 __ 00:56:55.882 Ipc (3) \Sessions\1\BaseNamedObjects\windows_shell_global_counters __ 00:56:55.869 Pipe \Device\KsecDD __ 00:56:55.654 Ipc open \RPC Control\lsasspirpc __ 00:56:55.654 Ipc open \Security\LSA_AUTHENTICATION_INITIALIZED __ 00:56:55.608 Ipc Open \KnownDlls\SHCORE.dll __ 00:56:55.597 Ipc \Sessions\1\BaseNamedObjects\SM0:3756:304:WilStaging_02_p0h __ 00:56:55.597 Ipc \Sessions\1\BaseNamedObjects\SM0:3756:304:WilStaging_02_p0 __ 00:56:55.597 Ipc \Sessions\1\BaseNamedObjects\SM0:3756:304:WilStaging_02 __ 00:56:55.597 Ipc open \Sessions\1\Windows\Theme4176104281 __ 00:56:55.597 Ipc open \Windows\Theme1799100494 __ 00:56:55.597 Ipc open \Sessions\1\Windows\ThemeSection __ 00:56:55.565 Ipc \Sessions\1\BaseNamedObjects\AccHeapTrackingSemaphore __ 00:56:55.408 Ipc Open \KnownDlls\MSCTF.dll __ 00:56:55.408 Ipc open \ThemeApiPort __ 00:56:55.345 Ipc \Sessions\1\BaseNamedObjects\SBIE_WindowsInstallerInUse __ 00:56:54.970 Pipe \Device\KsecDD __ 00:56:54.970 Ipc Open \KnownDlls\SHLWAPI.dll __ 00:56:54.958 Ipc Open \KnownDlls\CRYPT32.dll __ 00:56:54.958 Ipc Open \KnownDlls\bcrypt.dll __ 00:56:54.889 Ipc \Sessions\1\BaseNamedObjects\SBIE_BOXED_ServiceInitComplete_DcomLaunch __ 00:56:54.889 Ipc \Sessions\1\BaseNamedObjects\SBIE_BOXED_ServiceInitComplete_RpcSs __ 00:56:54.889 Pipe \Device\CNG __ 00:56:54.877 Ipc Open \KnownDlls\bcryptPrimitives.dll __ 00:56:54.866 Ipc open \RPC Control\AppV-ISV-03a8adc6-f826-4b82-8ce0-fe506a17f3c3SFT-venv_server __ 00:56:54.866 Ipc open \RPC Control\AppV-ISV-03a8adc6-f826-4b82-8ce0-fe506a17f3c3SFT-vobjects_server __ 00:56:54.831 WinClass open OleMainThreadWndClass __ 00:56:54.831 WinClass $:SandMan.exe __ 00:56:54.831 WinClass OleMainThreadWndClass __ 00:56:54.831 Ipc open \RPC Control\AppV-ISV-03a8adc6-f826-4b82-8ce0-fe506a17f3c3AppvEnterprise_vcom_subsystem __ 00:56:54.831 WinClass open OleMainThreadWndClass __ 00:56:54.831 WinClass $:SandMan.exe __ 00:56:54.831 WinClass OleMainThreadWndClass __ 00:56:54.831 Ipc open \RPC Control\AppV-ISV-03a8adc6-f826-4b82-8ce0-fe506a17f3c3vfs_subsystem __ 00:56:54.831 Ipc open \RPC Control\AppV-ISV-03a8adc6-f826-4b82-8ce0-fe506a17f3c3APPV-VREG_SERVER __ 00:56:54.831 Ipc open \RPC Control\AppV-ISV-03a8adc6-f826-4b82-8ce0-fe506a17f3c3APPV-RSOD_SERVER __ 00:56:54.831 Ipc open \RPC Control\AppV-ISV-03a8adc6-f826-4b82-8ce0-fe506a17f3c3APPV-jitv_server __ 00:56:54.766 Ipc open \RPC Control\AppV-ISV-03a8adc6-f826-4b82-8ce0-fe506a17f3c3APPV-VIRTMAN-NOTIFICATIONS __ 00:56:54.766 Ipc open \RPC Control\lsapolicylookup __ 00:56:54.755 Ipc open \RPC Control\C2RClientAPI_Server_System16 __ 00:56:54.755 Ipc open \RPC Control\LSARPC_ENDPOINT __ 00:56:54.743 Ipc Open \KnownDlls\IMM32.dll __ 00:56:54.711 Ipc \RPC Control\epmapper __ 00:56:54.711 Ipc Open \KnownDlls\OLEAUT32.dll __ 00:56:54.607 Ipc Open \KnownDlls\SHELL32.dll __ 00:56:54.607 Ipc Open \KnownDlls\combase.dll __ 00:56:54.607 Ipc Open \KnownDlls\ole32.dll __ 00:56:54.597 Ipc Open \KnownDlls\WS2_32.dll __ 00:56:54.597 Ipc Open \KnownDlls\rpcrt4.dll __ 00:56:54.597 Ipc Open \KnownDlls\sechost.dll __ 00:56:54.597 Ipc Open \KnownDlls\MSVCRT.dll __ 00:56:54.597 Ipc Open \KnownDlls\advapi32.dll __ 00:56:54.597 Ipc Open \KnownDlls\user32.dll __ 00:56:54.597 Ipc Open \KnownDlls\ucrtbase.dll __ 00:56:54.585 Ipc Open \KnownDlls\msvcp_win.dll __ 00:56:54.585 Ipc Open \KnownDlls\gdi32full.dll __ 00:56:54.585 Ipc Open \KnownDlls\win32u.dll __ 00:56:54.585 Ipc Open \KnownDlls\gdi32.dll __ 00:56:54.585 Ipc \Sessions\1\BaseNamedObjects\SboxSession __ 00:56:54.478 Ipc open \RPC Control\SbieSvcPort __ 00:56:54.478 Ipc \Sessions\1\BaseNamedObjects\SBIE_BOXED_DummyEvent_3756 __ 00:56:54.478 Drive \Device\Mup\;VBoxMiniRdr\;Z:\VBoxSvr\linguist_5.15.2 __ 00:56:54.478 Drive \Device\CdRom0 __ 00:56:54.478 Drive \Device\HarddiskVolume2 __ 00:56:54.478 Ipc Open \KnownDlls\PSAPI.DLL __ 00:56:54.478 Ipc Open \Sessions\1\Windows\ApiPort __ 00:56:54.478 Ipc Open \Sessions\1\Windows\SharedSection __ 00:56:54.478 Ipc Open \KnownDlls\kernelbase.dll __ 00:56:54.478 Ipc Open \KnownDlls\kernel32.dll _ Thread 4428 __ 00:56:58.005 Ipc open \Sessions\1\Windows\DwmApiPort _ Thread 4384 __ 00:56:55.915 Ipc open \KernelObjects\HighMemoryCondition __ 00:56:55.915 Ipc open \KernelObjects\LowMemoryCondition __ 00:56:55.915 Ipc Open \RPC Control\SbieSvcPort __ 00:56:55.869 Ipc open \RPC Control\SbieSvcPort _ Thread 4244 __ 00:56:56.777 ComClass Windows.Internal.Security.Authentication.Web.WamProviderRegistration __ 00:56:56.777 ComClass Windows.Foundation.Uri __ 00:56:56.777 ComClass Windows.Internal.Security.Authentication.Web.TokenBrokerInternal __ 00:56:56.777 ComClass Windows.Foundation.Uri __ 00:56:56.744 ComClass Windows.Internal.Security.Authentication.Web.WamProviderRegistration __ 00:56:56.744 ComClass Windows.Foundation.Uri __ 00:56:56.732 Ipc \Sessions\1\BaseNamedObjects\SM0:3756:120:WilError_03_p0h __ 00:56:56.732 Ipc \Sessions\1\BaseNamedObjects\SM0:3756:120:WilError_03_p0 __ 00:56:56.732 Ipc \Sessions\1\BaseNamedObjects\SM0:3756:120:WilError_03 __ 00:56:56.722 Ipc open \RPC Control\SbieSvcPort __ 00:56:56.704 ComClass Windows.Internal.Security.Authentication.Web.TokenBrokerInternal __ 00:56:56.704 ComClass Windows.Foundation.Uri _ Thread 4100 __ 00:56:57.939 ComClass open {A47979D2-C419-11D9-A5B4-001185AD2B89} Network List Manager __ 00:56:57.834 ComClass {DCB00C01-570F-4A9B-8D69-199FDBA5723B} NetworkListManager __ 00:56:57.834 Ipc open \RPC Control\SbieSvcPort _ Thread 3864 __ 00:56:57.604 Ipc open \RPC Control\SPPCTransportEndpoint-00001 __ 00:56:57.247 Debug StartService: sppsvc __ 00:56:57.233 Ipc \Sessions\1\BaseNamedObjects\SM0:3756:304:WilStaging_02_p0h __ 00:56:57.233 Ipc \Sessions\1\BaseNamedObjects\SM0:3756:304:WilStaging_02_p0 __ 00:56:57.233 Ipc \Sessions\1\BaseNamedObjects\SM0:3756:304:WilStaging_02 __ 00:56:57.233 ComClass Windows.Security.Isolation.IsolatedWindowsEnvironmentHost __ 00:56:56.347 ComClass open {A47979D2-C419-11D9-A5B4-001185AD2B89} Network List Manager __ 00:56:56.314 Ipc \RPC Control\OLE6A0E1640D38D18C8E8BB7105B0A5 __ 00:56:56.314 Ipc \RPC Control\epmapper __ 00:56:56.314 Ipc \Sessions\1\BaseNamedObjects\SBIE_BOXED_ServiceInitComplete_DcomLaunch __ 00:56:56.314 Ipc \Sessions\1\BaseNamedObjects\SBIE_BOXED_ServiceInitComplete_RpcSs __ 00:56:56.314 Ipc \RPC Control\epmapper __ 00:56:55.980 ComClass {DCB00C01-570F-4A9B-8D69-199FDBA5723B} NetworkListManager __ 00:56:55.847 Ipc open \RPC Control\SbieSvcPort __ 00:56:55.721 Ipc \Sessions\1\BaseNamedObjects\__ComCatalogCache__ __ 00:56:55.721 Ipc \BaseNamedObjects\__ComCatalogCache__ __ 00:56:55.721 Ipc open \KernelObjects\MaximumCommitCondition __ 00:56:55.721 Ipc Open \KnownDlls\clbcatq.dll __ 00:56:55.721 Ipc \Sessions\1\BaseNamedObjects\__ComCatalogCache__ __ 00:56:55.721 Ipc \BaseNamedObjects\__ComCatalogCache__ __ 00:56:55.721 Ipc \Sessions\1\BaseNamedObjects\SM0:3756:304:WilStaging_02_p0h __ 00:56:55.721 Ipc \Sessions\1\BaseNamedObjects\SM0:3756:304:WilStaging_02_p0 __ 00:56:55.721 Ipc \Sessions\1\BaseNamedObjects\SM0:3756:304:WilStaging_02 _ Thread 3584 __ 00:56:58.937 Pipe \Device\HarddiskVolume2 __ 00:56:56.522 Ipc \Sessions\1\BaseNamedObjects\SM0:3756:304:WilStaging_02_p0h __ 00:56:56.522 Ipc \Sessions\1\BaseNamedObjects\SM0:3756:304:WilStaging_02_p0 __ 00:56:56.522 Ipc \Sessions\1\BaseNamedObjects\SM0:3756:304:WilStaging_02 __ 00:56:56.460 Ipc \Sessions\1\BaseNamedObjects\SM0:3756:120:WilError_03_p0h __ 00:56:56.460 Ipc \Sessions\1\BaseNamedObjects\SM0:3756:120:WilError_03_p0 __ 00:56:56.460 Ipc \Sessions\1\BaseNamedObjects\SM0:3756:120:WilError_03 __ 00:56:56.347 ComClass open {8BC3F05E-D86B-11D0-A075-00C04FB68820} Windows Management and Instrumentation __ 00:56:56.130 Ipc open \RPC Control\SbieSvcPort _ Thread 3512 __ 00:56:57.760 Ipc \Sessions\1\BaseNamedObjects\F99C425F-9135-43ed-BD7D-396DE488DC53_Office16 __ 00:56:57.693 Ipc \Sessions\1\BaseNamedObjects\69545831-0931-4328-8676-335423887A86-Office16013801_S-1-5-21-958572366-666666666-3141863981-1001 __ 00:56:57.660 Ipc \Sessions\1\BaseNamedObjects\EF46F207-682E-44D0-B511-33F2BD9D52DB-VER16 __ 00:56:57.660 Ipc \Sessions\1\BaseNamedObjects\5CAC3FAB-87F0-4750-984D-D50144543427Office-VER16 _ Thread 3088 __ 00:56:57.726 ComClass open {A47979D2-C419-11D9-A5B4-001185AD2B89} Network List Manager __ 00:56:57.169 Ipc open \RPC Control\SbieSvcPort _ Thread 1092 __ 00:56:56.744 Ipc Open \RPC Control\SbieSvcPort __ 00:56:56.732 Ipc open \RPC Control\SbieSvcPort _ Thread 740 __ 00:56:58.937 Pipe open \Device\Nsi __ 00:56:58.937 Ipc Open \KnownDlls\NSI.dll __ 00:56:57.015 Pipe \Device\NamedPipe\wkssvc __ 00:56:56.777 ComClass Windows.Security.Authentication.Web.Core.WebAuthenticationCoreManager __ 00:56:56.777 ComClass Windows.Security.Authentication.Web.Core.WebAuthenticationCoreManager __ 00:56:56.744 ComClass Windows.Security.Authentication.Web.Core.WebAuthenticationCoreManager __ 00:56:56.704 ComClass Windows.Foundation.Diagnostics.AsyncCausalityTracer __ 00:56:56.522 ComClass Windows.Security.Authentication.Web.Core.WebAuthenticationCoreManager __ 00:56:55.903 ComClass Windows.Security.Authentication.Web.Core.WebAuthenticationCoreManager __ 00:56:55.847 Ipc open \RPC Control\SbieSvcPort __ 00:56:55.847 Ipc \Sessions\1\BaseNamedObjects\SBIE_ProtectedStorage_Section __ 00:56:55.847 Ipc \Sessions\1\BaseNamedObjects\SBIE_ProtectedStorage_Mutex __ 00:56:55.847 Ipc \Sessions\1\BaseNamedObjects\Office16.B1E641B5-F92B-4B82-83B7-10DC868435E8 _ Thread 192 __ 00:56:55.620 Ipc open \RPC Control\SbieSvcPort SandboxieDcomLaunch.exe (3620) _ Thread 4588 __ 00:56:54.225 Ipc open \KernelObjects\MaximumCommitCondition __ 00:56:54.225 Ipc Open \KnownDlls\clbcatq.dll __ 00:56:54.225 Ipc \Sessions\1\BaseNamedObjects\__ComCatalogCache__ __ 00:56:54.225 Ipc \BaseNamedObjects\__ComCatalogCache__ __ 00:56:54.225 Ipc \Sessions\1\BaseNamedObjects\SM0:3620:304:WilStaging_02_p0h __ 00:56:54.225 Ipc \Sessions\1\BaseNamedObjects\SM0:3620:304:WilStaging_02_p0 __ 00:56:54.225 Ipc \Sessions\1\BaseNamedObjects\SM0:3620:304:WilStaging_02 __ 00:56:54.211 Pipe \Device\KsecDD __ 00:56:54.211 Ipc Open \KnownDlls\bcrypt.dll __ 00:56:54.211 Ipc Open \KnownDlls\OLEAUT32.dll __ 00:56:54.211 Ipc \Sessions\1\BaseNamedObjects\SM0:3620:120:WilError_03_p0h __ 00:56:54.211 Ipc \Sessions\1\BaseNamedObjects\SM0:3620:120:WilError_03_p0 __ 00:56:54.211 Ipc \Sessions\1\BaseNamedObjects\SM0:3620:120:WilError_03 __ 00:56:54.194 Ipc open \RPC Control\SbieSvcPort __ 00:56:53.753 Ipc \Sessions\1\BaseNamedObjects\{A64C7F33-DA35-459b-96CA-63B51FB0CDB9} __ 00:56:53.753 Ipc \BaseNamedObjects\{A64C7F33-DA35-459b-96CA-63B51FB0CDB9} __ 00:56:53.753 Ipc \Sessions\1\BaseNamedObjects\{A3BD3259-3E4F-428a-84C8-F0463A9D3EB5} __ 00:56:53.753 Ipc \BaseNamedObjects\{A3BD3259-3E4F-428a-84C8-F0463A9D3EB5} __ 00:56:53.753 Ipc \Sessions\1\BaseNamedObjects\RotHintTable __ 00:56:53.753 Ipc \BaseNamedObjects\RotHintTable _ Thread 3632 __ 00:56:53.753 Ipc \Sessions\1\BaseNamedObjects\SBIE_BOXED_ServiceInitComplete_DcomLaunch __ 00:56:53.753 Ipc \Sessions\1\BaseNamedObjects\__ComCatalogCache__ __ 00:56:53.753 Ipc \BaseNamedObjects\__ComCatalogCache__ __ 00:56:53.753 Ipc \RPC Control\actkernel __ 00:56:53.753 Ipc open \RPC Control\lsasspirpc __ 00:56:53.753 Ipc open \Security\LSA_AUTHENTICATION_INITIALIZED __ 00:56:53.753 Ipc open \RPC Control\lsapolicylookup _ Thread 2768 __ 00:56:53.753 Pipe \Device\CNG __ 00:56:53.753 Ipc Open \KnownDlls\combase.dll __ 00:56:53.753 Ipc Open \KnownDlls\bcryptPrimitives.dll __ 00:56:53.310 Ipc Open \KnownDlls\IMM32.dll __ 00:56:53.310 Ipc \RPC Control\epmapper __ 00:56:53.310 Ipc Open \KnownDlls\ucrtbase.dll __ 00:56:53.310 Ipc Open \KnownDlls\msvcp_win.dll __ 00:56:53.310 Ipc Open \KnownDlls\gdi32full.dll __ 00:56:53.310 Ipc Open \KnownDlls\gdi32.dll __ 00:56:53.310 Ipc Open \KnownDlls\win32u.dll __ 00:56:53.310 Ipc Open \KnownDlls\user32.dll __ 00:56:53.310 Ipc Open \KnownDlls\rpcrt4.dll __ 00:56:53.310 Ipc Open \KnownDlls\sechost.dll __ 00:56:53.310 Ipc Open \KnownDlls\MSVCRT.dll __ 00:56:53.310 Ipc Open \KnownDlls\advapi32.dll __ 00:56:53.310 Ipc \Sessions\1\BaseNamedObjects\SboxSession __ 00:56:53.310 Ipc Open \RPC Control\SbieSvcPort __ 00:56:53.225 Ipc open \RPC Control\SbieSvcPort __ 00:56:53.225 Ipc \Sessions\1\BaseNamedObjects\SBIE_BOXED_DummyEvent_3620 __ 00:56:53.225 Drive \Device\Mup\;VBoxMiniRdr\;Z:\VBoxSvr\linguist_5.15.2 __ 00:56:53.225 Drive \Device\CdRom0 __ 00:56:53.225 Drive \Device\HarddiskVolume2 __ 00:56:53.225 Ipc Open \KnownDlls\PSAPI.DLL __ 00:56:53.225 Ipc Open \Sessions\1\Windows\ApiPort __ 00:56:53.225 Ipc Open \Sessions\1\Windows\SharedSection __ 00:56:53.225 Ipc Open \KnownDlls\kernelbase.dll __ 00:56:53.225 Ipc Open \KnownDlls\kernel32.dll SandboxieRpcSs.exe (3040) _ Thread 5116 __ 00:56:53.225 Ipc open \RPC Control\SbieSvcPort __ 00:56:53.225 Ipc \Sessions\1\BaseNamedObjects\SM0:3040:304:WilStaging_02_p0h __ 00:56:53.225 Ipc \Sessions\1\BaseNamedObjects\SM0:3040:304:WilStaging_02_p0 __ 00:56:53.225 Ipc \Sessions\1\BaseNamedObjects\SM0:3040:304:WilStaging_02 __ 00:56:53.225 Ipc open \Sessions\1\Windows\Theme4176104281 __ 00:56:53.225 Ipc open \Windows\Theme1799100494 __ 00:56:53.225 Ipc open \Sessions\1\Windows\ThemeSection __ 00:56:53.225 Ipc Open \KnownDlls\OLEAUT32.dll __ 00:56:53.225 Ipc Open \KnownDlls\MSCTF.dll __ 00:56:53.179 Ipc open \ThemeApiPort _ Thread 4316 __ 00:56:53.179 Pipe \Device\CNG __ 00:56:53.178 Ipc Open \KnownDlls\bcryptPrimitives.dll __ 00:56:53.150 Ipc \Sessions\1\BaseNamedObjects\SBIE_BOXED_ServiceInitComplete_RpcEptMapper __ 00:56:53.150 Ipc \Sessions\1\BaseNamedObjects\SC_AutoStartComplete __ 00:56:53.150 Ipc \BaseNamedObjects\SC_AutoStartComplete __ 00:56:53.150 Ipc \Sessions\1\BaseNamedObjects\ComPlusCOMRegTable __ 00:56:53.150 Ipc \Sessions\1\BaseNamedObjects\SBIE_BOXED_ServiceInitComplete_Mutex1 __ 00:56:53.150 Ipc open \RPC Control\SbieSvcPort __ 00:56:53.065 Ipc Open \KnownDlls\IMM32.dll __ 00:56:53.065 Ipc \RPC Control\epmapper __ 00:56:53.065 Ipc Open \KnownDlls\ucrtbase.dll __ 00:56:53.065 Ipc Open \KnownDlls\msvcp_win.dll __ 00:56:53.065 Ipc Open \KnownDlls\gdi32full.dll __ 00:56:53.065 Ipc Open \KnownDlls\gdi32.dll __ 00:56:53.065 Ipc Open \KnownDlls\win32u.dll __ 00:56:53.065 Ipc Open \KnownDlls\user32.dll __ 00:56:53.065 Ipc Open \KnownDlls\sechost.dll __ 00:56:53.065 Ipc Open \KnownDlls\MSVCRT.dll __ 00:56:53.065 Ipc Open \KnownDlls\advapi32.dll __ 00:56:53.065 Ipc Open \KnownDlls\rpcrt4.dll __ 00:56:53.065 Ipc Open \KnownDlls\WS2_32.dll __ 00:56:53.065 Ipc \Sessions\1\BaseNamedObjects\SBIE_BOXED_DummyEvent_3040 __ 00:56:53.065 Drive \Device\Mup\;VBoxMiniRdr\;Z:\VBoxSvr\linguist_5.15.2 __ 00:56:53.065 Drive \Device\CdRom0 __ 00:56:53.065 Drive \Device\HarddiskVolume2 __ 00:56:53.065 Ipc Open \KnownDlls\PSAPI.DLL __ 00:56:53.065 Ipc Open \Sessions\1\Windows\ApiPort __ 00:56:53.065 Ipc Open \Sessions\1\Windows\SharedSection __ 00:56:53.065 Ipc Open \KnownDlls\kernelbase.dll __ 00:56:53.065 Ipc Open \KnownDlls\kernel32.dll _ Thread 4108 __ 00:56:53.178 Ipc \Sessions\1\BaseNamedObjects\SBIE_BOXED_ServiceInitComplete_RpcEptMapper __ 00:56:53.178 Ipc \RPC Control\epmapper __ 00:56:53.178 Ipc open \RPC Control\lsasspirpc __ 00:56:53.178 Ipc open \Security\LSA_AUTHENTICATION_INITIALIZED __ 00:56:53.178 Pipe \Device\NDMP1 __ 00:56:53.178 Pipe \Device\NDMP2 __ 00:56:53.178 Pipe \Device\NDMP3 __ 00:56:53.178 Pipe \Device\NDMP4 __ 00:56:53.178 Pipe \Device\NDMP5 __ 00:56:53.178 Pipe \Device\NDMP6 __ 00:56:53.178 Pipe \Device\NDMP7 __ 00:56:53.178 Pipe \Device\NDMP8 __ 00:56:53.178 Pipe \Device\NDMP9 __ 00:56:53.178 Pipe \Device\Ndis __ 00:56:53.178 Ipc \Sessions\1\BaseNamedObjects\SC_AutoStartComplete __ 00:56:53.178 Ipc \BaseNamedObjects\SC_AutoStartComplete _ Thread 3952 __ 00:56:53.310 Ipc \Sessions\1\BaseNamedObjects\SboxSession _ Thread 3824 __ 00:56:53.179 Ipc \Sessions\1\BaseNamedObjects\SBIE_BOXED_RPCSS_SXS_READY __ 00:56:53.150 Ipc open \RPC Control\SbieSvcPort __ 00:56:53.150 Ipc Open \KnownDlls\combase.dll __ 00:56:53.150 Ipc Open \KnownDlls\ole32.dll _ Thread 3020 __ 00:56:53.753 Ipc \Sessions\1\BaseNamedObjects\SBIE_BOXED_ServiceInitComplete_RpcSs __ 00:56:53.753 Ipc \Sessions\1\BaseNamedObjects\ScmCreatedEvent __ 00:56:53.225 Debug trace CreateProcess: C:\Program Files\Sandboxie-Plus\SandboxieDcomLaunch.exe ("C:\Program Files\Sandboxie-Plus\SandboxieDcomLaunch.exe"); err=0 __ 00:56:53.192 Ipc \Sessions\1\BaseNamedObjects\SBIE_BOXED_ServiceInitComplete_DcomLaunch __ 00:56:53.192 Ipc \RPC Control\actkernel __ 00:56:53.192 Ipc open \RPC Control\lsapolicylookup _ Thread 2072 __ 00:56:54.429 Ipc open \RPC Control\SbieSvcPort __ 00:56:54.418 Ipc \Sessions\1\BaseNamedObjects\__ComCatalogCache__ __ 00:56:54.418 Ipc \BaseNamedObjects\__ComCatalogCache__ __ 00:56:54.225 Pipe \Device\KsecDD __ 00:56:54.225 Ipc Open \KnownDlls\bcrypt.dll __ 00:56:54.211 Ipc \Sessions\1\BaseNamedObjects\SM0:3040:120:WilError_03_p0h __ 00:56:54.211 Ipc \Sessions\1\BaseNamedObjects\SM0:3040:120:WilError_03_p0 __ 00:56:54.211 Ipc \Sessions\1\BaseNamedObjects\SM0:3040:120:WilError_03 __ 00:56:54.194 Ipc open \KernelObjects\MaximumCommitCondition __ 00:56:54.194 Ipc Open \KnownDlls\clbcatq.dll __ 00:56:54.194 Ipc \Sessions\1\BaseNamedObjects\__ComCatalogCache__ __ 00:56:54.194 Ipc \BaseNamedObjects\__ComCatalogCache__ __ 00:56:54.194 Ipc \Sessions\1\BaseNamedObjects\SM0:3040:304:WilStaging_02_p0h __ 00:56:54.194 Ipc \Sessions\1\BaseNamedObjects\SM0:3040:304:WilStaging_02_p0 __ 00:56:54.194 Ipc \Sessions\1\BaseNamedObjects\SM0:3040:304:WilStaging_02 Start.exe (2316) _ Thread 4748 __ 00:56:54.211 Pipe \Device\MountPointManager __ 00:56:54.211 Pipe \Device\0000001a __ 00:56:54.211 Pipe \Device\MountPointManager __ 00:56:54.211 Pipe \Device\HarddiskVolume3 __ 00:56:54.211 Pipe \Device\MountPointManager __ 00:56:54.211 Pipe \Device\HarddiskVolume2 __ 00:56:54.194 Pipe \Device\MountPointManager __ 00:56:54.194 Pipe \Device\HarddiskVolume1 _ Thread 4684 __ 00:56:54.211 Pipe (7) \Device\MountPointManager __ 00:56:54.149 Pipe \Device\DeviceApi __ 00:56:54.149 Ipc Open \KnownDlls\cfgmgr32.dll _ Thread 1616 __ 00:56:54.429 ComClass {C2F03A33-21F5-47FA-B4BB-156362A2F239} Immersive Shell __ 00:56:54.236 Ipc \Sessions\1\BaseNamedObjects\SM0:2316:120:WilError_03_p0h __ 00:56:54.236 Ipc \Sessions\1\BaseNamedObjects\SM0:2316:120:WilError_03_p0 __ 00:56:54.236 Ipc \Sessions\1\BaseNamedObjects\SM0:2316:120:WilError_03 __ 00:56:54.183 ComClass Windows.Internal.StateRepository.FileTypeAssociation _ Thread 1100 __ 00:56:54.511 Ipc \Sessions\1\BaseNamedObjects\SBIE_BOXED_ServiceInitComplete_DcomLaunch __ 00:56:54.511 Ipc \Sessions\1\BaseNamedObjects\SBIE_BOXED_ServiceInitComplete_RpcSs __ 00:56:54.440 Debug trace CreateProcess: C:\Program Files\Microsoft Office\root\Office16\MSACCESS.EXE ("C:\Program Files\Microsoft Office\root\Office16\MSACCESS.EXE" ); err=0 __ 00:56:54.440 File closed \Device\HarddiskVolume2\Windows\system32\apphelp.dll __ 00:56:54.440 File closed \Device\HarddiskVolume2\Windows\System32\apphelp.dll __ 00:56:54.418 Ipc \Sessions\1\BaseNamedObjects\C:*Users*Test*AppData*Local*Microsoft*Windows*Caches*cversions.3.ro __ 00:56:54.418 Ipc (2) \Sessions\1\BaseNamedObjects\C:*Users*Test*AppData*Local*Microsoft*Windows*Caches*{3DA71D5A-20CC-432F-A115-DFE92379E91F}.3.ver0x0000000000000115.db __ 00:56:54.418 Ipc (2) \Sessions\1\BaseNamedObjects\C:*Users*Test*AppData*Local*Microsoft*Windows*Caches*cversions.3.ro __ 00:56:54.353 ComClass Windows.Foundation.PropertyValue __ 00:56:54.183 Ipc \Sessions\1\BaseNamedObjects\SM0:2316:120:WilError_03_p0h __ 00:56:54.183 Ipc \Sessions\1\BaseNamedObjects\SM0:2316:120:WilError_03_p0 __ 00:56:54.183 Ipc \Sessions\1\BaseNamedObjects\SM0:2316:120:WilError_03 __ 00:56:54.183 Ipc \Sessions\1\BaseNamedObjects\SM0:2316:120:WilError_03_p0h __ 00:56:54.183 Ipc \Sessions\1\BaseNamedObjects\SM0:2316:120:WilError_03_p0 __ 00:56:54.183 Ipc \Sessions\1\BaseNamedObjects\SM0:2316:120:WilError_03 __ 00:56:54.183 Ipc \RPC Control\OLE6C469B03740638B5DD59A303F7DD __ 00:56:54.183 Ipc \RPC Control\epmapper __ 00:56:54.183 Ipc \Sessions\1\BaseNamedObjects\SBIE_BOXED_ServiceInitComplete_DcomLaunch __ 00:56:54.183 Ipc \Sessions\1\BaseNamedObjects\SBIE_BOXED_ServiceInitComplete_RpcSs __ 00:56:54.183 Ipc \RPC Control\epmapper __ 00:56:54.149 Pipe \Device\MountPointManager __ 00:56:54.149 Pipe \Device\HarddiskVolume2 __ 00:56:54.086 Ipc \Sessions\1\BaseNamedObjects\windows_shell_global_counters __ 00:56:54.086 Ipc \BaseNamedObjects\windows_shell_global_counters __ 00:56:54.086 Ipc \Sessions\1\BaseNamedObjects\C:*Users*Test*AppData*Local*Microsoft*Windows*Caches*{AFBF9F1A-8EE8-4C77-AF34-C647E37CA0D9}.1.ver0x0000000000000038.db __ 00:56:54.086 Ipc \Sessions\1\BaseNamedObjects\C:*Users*Test*AppData*Local*Microsoft*Windows*Caches*cversions.1.ro __ 00:56:54.054 Ipc \Sessions\1\BaseNamedObjects\SM0:2316:304:WilStaging_02_p0h __ 00:56:54.054 Ipc \Sessions\1\BaseNamedObjects\SM0:2316:304:WilStaging_02_p0 __ 00:56:54.054 Ipc \Sessions\1\BaseNamedObjects\SM0:2316:304:WilStaging_02 __ 00:56:54.054 Ipc \Sessions\1\BaseNamedObjects\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000004.db __ 00:56:54.054 Ipc \BaseNamedObjects\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000004.db __ 00:56:54.043 Ipc \Sessions\1\BaseNamedObjects\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000004.db __ 00:56:54.043 Ipc \BaseNamedObjects\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000004.db __ 00:56:54.043 Ipc \Sessions\1\BaseNamedObjects\C:*ProgramData*Microsoft*Windows*Caches*cversions.2.ro __ 00:56:54.043 Ipc \BaseNamedObjects\C:*ProgramData*Microsoft*Windows*Caches*cversions.2.ro __ 00:56:54.043 Ipc \Sessions\1\BaseNamedObjects\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000010.db __ 00:56:54.043 Ipc \BaseNamedObjects\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000010.db __ 00:56:54.043 Ipc \Sessions\1\BaseNamedObjects\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000010.db __ 00:56:54.043 Ipc \BaseNamedObjects\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000010.db __ 00:56:54.043 Ipc \Sessions\1\BaseNamedObjects\C:*ProgramData*Microsoft*Windows*Caches*cversions.2.ro __ 00:56:54.043 Ipc \BaseNamedObjects\C:*ProgramData*Microsoft*Windows*Caches*cversions.2.ro __ 00:56:54.017 Ipc \Sessions\1\BaseNamedObjects\SM0:2316:304:WilStaging_02_p0h __ 00:56:54.017 Ipc \Sessions\1\BaseNamedObjects\SM0:2316:304:WilStaging_02_p0 __ 00:56:54.017 Ipc \Sessions\1\BaseNamedObjects\SM0:2316:304:WilStaging_02 __ 00:56:54.017 Ipc \Sessions\1\BaseNamedObjects\C:*ProgramData*Microsoft*Windows*Caches*cversions.2.ro __ 00:56:54.017 Ipc \BaseNamedObjects\C:*ProgramData*Microsoft*Windows*Caches*cversions.2.ro __ 00:56:54.005 Ipc \Sessions\1\BaseNamedObjects\__ComCatalogCache__ __ 00:56:54.005 Ipc \BaseNamedObjects\__ComCatalogCache__ __ 00:56:54.005 Ipc open \KernelObjects\MaximumCommitCondition __ 00:56:54.005 Ipc Open \KnownDlls\clbcatq.dll __ 00:56:54.005 Ipc \Sessions\1\BaseNamedObjects\__ComCatalogCache__ __ 00:56:54.005 Ipc \BaseNamedObjects\__ComCatalogCache__ __ 00:56:54.005 Ipc \Sessions\1\BaseNamedObjects\SM0:2316:304:WilStaging_02_p0h __ 00:56:54.005 Ipc \Sessions\1\BaseNamedObjects\SM0:2316:304:WilStaging_02_p0 __ 00:56:54.005 Ipc \Sessions\1\BaseNamedObjects\SM0:2316:304:WilStaging_02 __ 00:56:53.971 Ipc \Sessions\1\BaseNamedObjects\SM0:2316:120:WilError_03_p0h __ 00:56:53.971 Ipc \Sessions\1\BaseNamedObjects\SM0:2316:120:WilError_03_p0 __ 00:56:53.971 Ipc \Sessions\1\BaseNamedObjects\SM0:2316:120:WilError_03 __ 00:56:53.971 Ipc \Sessions\1\BaseNamedObjects\SM0:2316:304:WilStaging_02_p0h __ 00:56:53.971 Ipc \Sessions\1\BaseNamedObjects\SM0:2316:304:WilStaging_02_p0 __ 00:56:53.971 Ipc \Sessions\1\BaseNamedObjects\SM0:2316:304:WilStaging_02 __ 00:56:53.971 Pipe \Device\CNG __ 00:56:53.971 Ipc Open \KnownDlls\bcryptPrimitives.dll __ 00:56:53.971 File closed \Device\HarddiskVolume2\Windows\system32\apphelp.dll __ 00:56:53.971 File closed \Device\HarddiskVolume2\Windows\SYSTEM32\apphelp.dll __ 00:56:53.971 File closed \Device\HarddiskVolume2\Windows\System32\apphelp.dll __ 00:56:53.971 Ipc (2) \Sessions\1\BaseNamedObjects\windows_shell_global_counters __ 00:56:53.971 Ipc open \RPC Control\lsapolicylookup __ 00:56:53.971 Ipc \Sessions\1\BaseNamedObjects\windows_shell_global_counters __ 00:56:53.971 Ipc \Sessions\1\BaseNamedObjects\SM0:2316:304:WilStaging_02_p0h __ 00:56:53.971 Ipc \Sessions\1\BaseNamedObjects\SM0:2316:304:WilStaging_02_p0 __ 00:56:53.971 Ipc \Sessions\1\BaseNamedObjects\SM0:2316:304:WilStaging_02 __ 00:56:53.971 Ipc open \Sessions\1\Windows\Theme4176104281 __ 00:56:53.971 Ipc open \Windows\Theme1799100494 __ 00:56:53.971 Ipc open \Sessions\1\Windows\ThemeSection __ 00:56:53.971 Ipc open \ThemeApiPort __ 00:56:53.971 Ipc \Sessions\1\BaseNamedObjects\SBIE_BOXED_ServiceInitComplete_DcomLaunch __ 00:56:53.971 Ipc \Sessions\1\BaseNamedObjects\SBIE_BOXED_ServiceInitComplete_RpcSs __ 00:56:53.753 Ipc Open \KnownDlls\IMM32.dll __ 00:56:53.753 Ipc Open \KnownDlls\OLEAUT32.dll __ 00:56:53.753 Ipc Open \KnownDlls\SHCORE.dll __ 00:56:53.753 Ipc Open \KnownDlls\COMDLG32.dll __ 00:56:53.753 Ipc Open \KnownDlls\sechost.dll __ 00:56:53.753 Ipc Open \KnownDlls\advapi32.dll __ 00:56:53.753 Ipc Open \KnownDlls\combase.dll __ 00:56:53.753 Ipc Open \KnownDlls\rpcrt4.dll __ 00:56:53.753 Ipc Open \KnownDlls\ole32.dll __ 00:56:53.753 Ipc Open \KnownDlls\MSVCRT.dll __ 00:56:53.753 Ipc Open \KnownDlls\SHLWAPI.dll __ 00:56:53.753 Ipc Open \KnownDlls\SHELL32.dll __ 00:56:53.753 Ipc Open \KnownDlls\ucrtbase.dll __ 00:56:53.753 Ipc Open \KnownDlls\msvcp_win.dll __ 00:56:53.753 Ipc Open \KnownDlls\gdi32full.dll __ 00:56:53.753 Ipc Open \KnownDlls\gdi32.dll __ 00:56:53.753 Ipc Open \KnownDlls\win32u.dll __ 00:56:53.753 Ipc Open \KnownDlls\user32.dll __ 00:56:53.753 Ipc \Sessions\1\BaseNamedObjects\SboxSession __ 00:56:53.753 Ipc \Sessions\1\BaseNamedObjects\SBIE_BOXED_ServiceInitComplete_DcomLaunch __ 00:56:53.753 Ipc \RPC Control\epmapper __ 00:56:52.950 Ipc \Sessions\1\BaseNamedObjects\SBIE_BOXED_ServiceInitComplete_RpcSs __ 00:56:52.950 Ipc \Sessions\1\BaseNamedObjects\SBIE_BOXED_RPCSS_SXS_READY __ 00:56:52.950 Ipc open \RPC Control\SbieSvcPort __ 00:56:52.902 Ipc \Sessions\1\BaseNamedObjects\SBIE_BOXED_DummyEvent_2316 __ 00:56:52.902 Drive \Device\Mup\;VBoxMiniRdr\;Z:\VBoxSvr\linguist_5.15.2 __ 00:56:52.902 Drive \Device\CdRom0 __ 00:56:52.902 Drive \Device\HarddiskVolume2 __ 00:56:52.902 Ipc Open \KnownDlls\PSAPI.DLL __ 00:56:52.902 Ipc Open \Sessions\1\Windows\ApiPort __ 00:56:52.902 Ipc Open \Sessions\1\Windows\SharedSection __ 00:56:52.902 Ipc Open \KnownDlls\kernelbase.dll __ 00:56:52.902 Ipc Open \KnownDlls\kernel32.dll ```
My trace log (after the workaround) ``` |Process| |Type| |Status| |Value| Start.exe (4932) _ Thread 1772 __ 09:38:32.746 ComClass {C2F03A33-21F5-47FA-B4BB-156362A2F239} Immersive Shell __ 09:38:32.530 Ipc \Sessions\1\BaseNamedObjects\SM0:4932:120:WilError_03_p0h __ 09:38:32.530 Ipc \Sessions\1\BaseNamedObjects\SM0:4932:120:WilError_03_p0 __ 09:38:32.530 Ipc \Sessions\1\BaseNamedObjects\SM0:4932:120:WilError_03 __ 09:38:32.489 ComClass Windows.Internal.StateRepository.FileTypeAssociation _ Thread 1420 __ 09:38:32.489 Pipe \Device\MountPointManager __ 09:38:32.489 Pipe \Device\0000001a __ 09:38:32.478 Pipe \Device\MountPointManager __ 09:38:32.478 Pipe \Device\HarddiskVolume3 __ 09:38:32.478 Pipe \Device\MountPointManager __ 09:38:32.478 Pipe \Device\HarddiskVolume2 __ 09:38:32.478 Pipe \Device\MountPointManager __ 09:38:32.478 Pipe \Device\HarddiskVolume1 _ Thread 1180 __ 09:38:32.489 Pipe (7) \Device\MountPointManager __ 09:38:32.454 Pipe \Device\DeviceApi __ 09:38:32.454 Ipc Open \KnownDlls\cfgmgr32.dll _ Thread 1128 __ 09:38:32.897 Ipc \Sessions\1\BaseNamedObjects\SBIE_BOXED_ServiceInitComplete_DcomLaunch __ 09:38:32.897 Ipc \Sessions\1\BaseNamedObjects\SBIE_BOXED_ServiceInitComplete_RpcSs __ 09:38:32.779 Debug trace CreateProcess: C:\Program Files\Microsoft Office\root\Office16\MSACCESS.EXE ("C:\Program Files\Microsoft Office\root\Office16\MSACCESS.EXE" ); err=0 __ 09:38:32.779 File closed \Device\HarddiskVolume2\Windows\system32\apphelp.dll __ 09:38:32.779 File closed \Device\HarddiskVolume2\Windows\System32\apphelp.dll __ 09:38:32.714 Ipc \Sessions\1\BaseNamedObjects\C:*Users*Test*AppData*Local*Microsoft*Windows*Caches*cversions.3.ro __ 09:38:32.714 Ipc (2) \Sessions\1\BaseNamedObjects\C:*Users*Test*AppData*Local*Microsoft*Windows*Caches*{3DA71D5A-20CC-432F-A115-DFE92379E91F}.3.ver0x000000000000014f.db __ 09:38:32.714 Ipc (2) \Sessions\1\BaseNamedObjects\C:*Users*Test*AppData*Local*Microsoft*Windows*Caches*cversions.3.ro __ 09:38:32.650 ComClass Windows.Foundation.PropertyValue __ 09:38:32.489 Ipc \Sessions\1\BaseNamedObjects\SM0:4932:120:WilError_03_p0h __ 09:38:32.489 Ipc \Sessions\1\BaseNamedObjects\SM0:4932:120:WilError_03_p0 __ 09:38:32.489 Ipc \Sessions\1\BaseNamedObjects\SM0:4932:120:WilError_03 __ 09:38:32.489 Ipc \Sessions\1\BaseNamedObjects\SM0:4932:120:WilError_03_p0h __ 09:38:32.489 Ipc \Sessions\1\BaseNamedObjects\SM0:4932:120:WilError_03_p0 __ 09:38:32.489 Ipc \Sessions\1\BaseNamedObjects\SM0:4932:120:WilError_03 __ 09:38:32.478 Ipc \RPC Control\OLE2A3B783F72945441FC1838496508 __ 09:38:32.466 Ipc \RPC Control\epmapper __ 09:38:32.454 Ipc \Sessions\1\BaseNamedObjects\SBIE_BOXED_ServiceInitComplete_DcomLaunch __ 09:38:32.454 Ipc \Sessions\1\BaseNamedObjects\SBIE_BOXED_ServiceInitComplete_RpcSs __ 09:38:32.454 Ipc \RPC Control\epmapper __ 09:38:32.386 Pipe \Device\MountPointManager __ 09:38:32.386 Pipe \Device\HarddiskVolume2 __ 09:38:32.229 Ipc (3) \Sessions\1\BaseNamedObjects\windows_shell_global_counters __ 09:38:32.229 Ipc \BaseNamedObjects\windows_shell_global_counters __ 09:38:32.229 Ipc \Sessions\1\BaseNamedObjects\windows_shell_global_counters __ 09:38:32.229 Ipc \Sessions\1\BaseNamedObjects\C:*Users*Test*AppData*Local*Microsoft*Windows*Caches*{AFBF9F1A-8EE8-4C77-AF34-C647E37CA0D9}.1.ver0x000000000000003d.db __ 09:38:32.229 Ipc \Sessions\1\BaseNamedObjects\C:*Users*Test*AppData*Local*Microsoft*Windows*Caches*cversions.1.ro __ 09:38:32.151 Ipc (52) \Sessions\1\BaseNamedObjects\windows_shell_global_counters __ 09:38:32.151 Ipc \Sessions\1\BaseNamedObjects\SM0:4932:304:WilStaging_02_p0h __ 09:38:32.151 Ipc \Sessions\1\BaseNamedObjects\SM0:4932:304:WilStaging_02_p0 __ 09:38:32.151 Ipc \Sessions\1\BaseNamedObjects\SM0:4932:304:WilStaging_02 __ 09:38:32.151 Ipc \Sessions\1\BaseNamedObjects\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000004.db __ 09:38:32.151 Ipc \BaseNamedObjects\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000004.db __ 09:38:32.151 Ipc \Sessions\1\BaseNamedObjects\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000004.db __ 09:38:32.151 Ipc \BaseNamedObjects\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000004.db __ 09:38:32.151 Ipc \Sessions\1\BaseNamedObjects\C:*ProgramData*Microsoft*Windows*Caches*cversions.2.ro __ 09:38:32.151 Ipc \BaseNamedObjects\C:*ProgramData*Microsoft*Windows*Caches*cversions.2.ro __ 09:38:32.151 Ipc \Sessions\1\BaseNamedObjects\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000010.db __ 09:38:32.151 Ipc \BaseNamedObjects\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000010.db __ 09:38:32.151 Ipc \Sessions\1\BaseNamedObjects\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000010.db __ 09:38:32.141 Ipc \BaseNamedObjects\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000010.db __ 09:38:32.141 Ipc \Sessions\1\BaseNamedObjects\C:*ProgramData*Microsoft*Windows*Caches*cversions.2.ro __ 09:38:32.141 Ipc \BaseNamedObjects\C:*ProgramData*Microsoft*Windows*Caches*cversions.2.ro __ 09:38:32.141 Ipc open \RPC Control\lsapolicylookup __ 09:38:32.109 Ipc \Sessions\1\BaseNamedObjects\SM0:4932:304:WilStaging_02_p0h __ 09:38:32.109 Ipc \Sessions\1\BaseNamedObjects\SM0:4932:304:WilStaging_02_p0 __ 09:38:32.109 Ipc \Sessions\1\BaseNamedObjects\SM0:4932:304:WilStaging_02 __ 09:38:32.109 Ipc \Sessions\1\BaseNamedObjects\C:*ProgramData*Microsoft*Windows*Caches*cversions.2.ro __ 09:38:32.109 Ipc \BaseNamedObjects\C:*ProgramData*Microsoft*Windows*Caches*cversions.2.ro __ 09:38:32.077 Ipc \Sessions\1\BaseNamedObjects\__ComCatalogCache__ __ 09:38:32.077 Ipc \BaseNamedObjects\__ComCatalogCache__ __ 09:38:32.077 Ipc open \KernelObjects\MaximumCommitCondition __ 09:38:32.077 Ipc Open \KnownDlls\clbcatq.dll __ 09:38:32.077 Ipc \Sessions\1\BaseNamedObjects\__ComCatalogCache__ __ 09:38:32.077 Ipc \BaseNamedObjects\__ComCatalogCache__ __ 09:38:32.077 Ipc \Sessions\1\BaseNamedObjects\SM0:4932:304:WilStaging_02_p0h __ 09:38:32.077 Ipc \Sessions\1\BaseNamedObjects\SM0:4932:304:WilStaging_02_p0 __ 09:38:32.077 Ipc \Sessions\1\BaseNamedObjects\SM0:4932:304:WilStaging_02 __ 09:38:32.002 Ipc (35) \Sessions\1\BaseNamedObjects\windows_shell_global_counters __ 09:38:29.236 Ipc (2) \Sessions\1\BaseNamedObjects\windows_shell_global_counters __ 09:38:29.236 Ipc \Sessions\1\BaseNamedObjects\SM0:4932:120:WilError_03_p0h __ 09:38:29.236 Ipc \Sessions\1\BaseNamedObjects\SM0:4932:120:WilError_03_p0 __ 09:38:29.236 Ipc \Sessions\1\BaseNamedObjects\SM0:4932:120:WilError_03 __ 09:38:29.236 Ipc \Sessions\1\BaseNamedObjects\SM0:4932:304:WilStaging_02_p0h __ 09:38:29.236 Ipc \Sessions\1\BaseNamedObjects\SM0:4932:304:WilStaging_02_p0 __ 09:38:29.236 Ipc \Sessions\1\BaseNamedObjects\SM0:4932:304:WilStaging_02 __ 09:38:29.236 Pipe \Device\CNG __ 09:38:29.225 Ipc Open \KnownDlls\bcryptPrimitives.dll __ 09:38:29.225 File closed \Device\HarddiskVolume2\Windows\system32\apphelp.dll __ 09:38:29.225 File closed \Device\HarddiskVolume2\Windows\SYSTEM32\apphelp.dll __ 09:38:29.225 File closed \Device\HarddiskVolume2\Windows\System32\apphelp.dll __ 09:38:29.213 Ipc (2) \Sessions\1\BaseNamedObjects\windows_shell_global_counters __ 09:38:29.213 Ipc \Sessions\1\BaseNamedObjects\SM0:4932:304:WilStaging_02_p0h __ 09:38:29.213 Ipc \Sessions\1\BaseNamedObjects\SM0:4932:304:WilStaging_02_p0 __ 09:38:29.213 Ipc \Sessions\1\BaseNamedObjects\SM0:4932:304:WilStaging_02 __ 09:38:29.213 Ipc open \Sessions\1\Windows\Theme3651103575 __ 09:38:29.213 Ipc open \Windows\Theme3338626119 __ 09:38:29.213 Ipc open \Sessions\1\Windows\ThemeSection __ 09:38:29.150 Ipc open \ThemeApiPort __ 09:38:29.150 Ipc \Sessions\1\BaseNamedObjects\SBIE_BOXED_ServiceInitComplete_DcomLaunch __ 09:38:29.150 Ipc \Sessions\1\BaseNamedObjects\SBIE_BOXED_ServiceInitComplete_RpcSs __ 09:38:28.843 Ipc Open \KnownDlls\IMM32.dll __ 09:38:28.831 Ipc Open \KnownDlls\OLEAUT32.dll __ 09:38:28.831 Ipc Open \KnownDlls\SHCORE.dll __ 09:38:28.831 Ipc Open \KnownDlls\COMDLG32.dll __ 09:38:28.831 Ipc Open \KnownDlls\sechost.dll __ 09:38:28.831 Ipc Open \KnownDlls\advapi32.dll __ 09:38:28.831 Ipc Open \KnownDlls\combase.dll __ 09:38:28.831 Ipc Open \KnownDlls\rpcrt4.dll __ 09:38:28.831 Ipc Open \KnownDlls\ole32.dll __ 09:38:28.831 Ipc Open \KnownDlls\MSVCRT.dll __ 09:38:28.831 Ipc Open \KnownDlls\SHLWAPI.dll __ 09:38:28.831 Ipc Open \KnownDlls\SHELL32.dll __ 09:38:28.831 Ipc Open \KnownDlls\ucrtbase.dll __ 09:38:28.831 Ipc Open \KnownDlls\msvcp_win.dll __ 09:38:28.757 Ipc Open \KnownDlls\gdi32full.dll __ 09:38:28.757 Ipc Open \KnownDlls\gdi32.dll __ 09:38:28.757 Ipc Open \KnownDlls\win32u.dll __ 09:38:28.757 Ipc Open \KnownDlls\user32.dll __ 09:38:28.757 Ipc \Sessions\1\BaseNamedObjects\SboxSession __ 09:38:28.746 Ipc \Sessions\1\BaseNamedObjects\SBIE_BOXED_ServiceInitComplete_DcomLaunch __ 09:38:28.746 Ipc \RPC Control\epmapper __ 09:38:27.239 Ipc \Sessions\1\BaseNamedObjects\SBIE_BOXED_ServiceInitComplete_RpcSs __ 09:38:27.239 Ipc \Sessions\1\BaseNamedObjects\SBIE_BOXED_RPCSS_SXS_READY __ 09:38:27.239 Ipc open \RPC Control\SbieSvcPort __ 09:38:27.239 Ipc \Sessions\1\BaseNamedObjects\SBIE_BOXED_DummyEvent_4932 __ 09:38:27.239 Drive \Device\Mup\;VBoxMiniRdr\;Z:\VBoxSvr\linguist_5.15.2 __ 09:38:27.239 Drive \Device\CdRom0 __ 09:38:27.239 Drive \Device\HarddiskVolume2 __ 09:38:27.239 Ipc Open \KnownDlls\PSAPI.DLL __ 09:38:27.239 Ipc Open \Sessions\1\Windows\ApiPort __ 09:38:27.239 Ipc Open \Sessions\1\Windows\SharedSection __ 09:38:27.239 Ipc Open \KnownDlls\kernelbase.dll __ 09:38:27.239 Ipc Open \KnownDlls\kernel32.dll MSACCESS.EXE (4840) _ Thread 4784 __ 09:38:37.716 Ipc open \RPC Control\SbieSvcPort _ Thread 4696 __ 09:38:39.151 Debug trace CreateProcess: C:\Program Files\Sandboxie-Plus\SandboxieCrypto.exe ("C:\Program Files\Sandboxie-Plus\SandboxieCrypto.exe"); err=0 __ 09:38:39.106 Pipe \Device\MountPointManager __ 09:38:39.106 Debug SetServiceStatus; status: <00000002> __ 09:38:39.095 Debug StartBoxedService; name: 'cryptsvc' __ 09:38:39.095 Ipc \Sessions\1\BaseNamedObjects\SBIE_BOXED_ServiceInitComplete_cryptsvc __ 09:38:38.832 Ipc \Sessions\1\BaseNamedObjects\SM0:4840:304:WilStaging_02_p0h __ 09:38:38.832 Ipc \Sessions\1\BaseNamedObjects\SM0:4840:304:WilStaging_02_p0 __ 09:38:38.832 Ipc \Sessions\1\BaseNamedObjects\SM0:4840:304:WilStaging_02 __ 09:38:38.768 Pipe open \Device\Afd __ 09:38:38.036 Ipc \BaseNamedObjects\F932B6C7-3A20-46A0-B8A0-8894AA421973 __ 09:38:37.590 Ipc open \RPC Control\SbieSvcPort _ Thread 4584 __ 09:38:36.462 Ipc (3) \Sessions\1\BaseNamedObjects\windows_shell_global_counters __ 09:38:36.462 Ipc \Sessions\1\BaseNamedObjects\SM0:4840:120:WilError_03_p0h __ 09:38:36.462 Ipc \Sessions\1\BaseNamedObjects\SM0:4840:120:WilError_03_p0 __ 09:38:36.462 Ipc \Sessions\1\BaseNamedObjects\SM0:4840:120:WilError_03 __ 09:38:36.462 Ipc \Sessions\1\BaseNamedObjects\SM0:4840:304:WilStaging_02_p0h __ 09:38:36.462 Ipc \Sessions\1\BaseNamedObjects\SM0:4840:304:WilStaging_02_p0 __ 09:38:36.462 Ipc \Sessions\1\BaseNamedObjects\SM0:4840:304:WilStaging_02 __ 09:38:36.462 Ipc (6) \Sessions\1\BaseNamedObjects\windows_shell_global_counters _ Thread 4324 __ 09:38:36.760 Ipc open \KernelObjects\HighMemoryCondition __ 09:38:36.760 Ipc open \KernelObjects\LowMemoryCondition __ 09:38:36.729 WinClass open (3) Shell_TrayWnd __ 09:38:35.773 Ipc open \RPC Control\SbieSvcPort __ 09:38:35.773 WinClass OfficePowerManagerWindow _ Thread 4280 __ 09:38:38.768 Pipe open \Device\Afd __ 09:38:38.666 Ipc open \RPC Control\DNSResolver __ 09:38:38.624 Pipe open (3) \Device\Afd __ 09:38:38.624 Ipc \BaseNamedObjects\F932B6C7-3A20-46A0-B8A0-8894AA421973 __ 09:38:37.600 Pipe open \Device\Afd _ Thread 4164 __ 09:38:42.663 ComClass open {A47979D2-C419-11D9-A5B4-001185AD2B89} Network List Manager __ 09:38:42.196 ComClass {DCB00C01-570F-4A9B-8D69-199FDBA5723B} NetworkListManager __ 09:38:42.196 Ipc open \RPC Control\SbieSvcPort __ 09:38:42.184 ComClass Windows.Networking.Connectivity.NetworkInformation _ Thread 3696 __ 09:38:45.783 Ipc open \Sessions\1\Windows\DwmApiPort _ Thread 3692 __ 09:38:48.842 WinClass closed Progman __ 09:38:48.842 WinClass $:explorer.exe __ 09:38:48.815 WinClass Progman __ 09:38:48.721 Ipc (12) \Sessions\1\BaseNamedObjects\windows_shell_global_counters __ 09:38:47.886 Ipc open \RPC Control\SbieSvcPort _ Thread 3676 __ 09:38:48.815 Ipc \Sessions\1\BaseNamedObjects\SM0:4840:120:WilError_03_p0h __ 09:38:48.815 Ipc \Sessions\1\BaseNamedObjects\SM0:4840:120:WilError_03_p0 __ 09:38:48.815 Ipc \Sessions\1\BaseNamedObjects\SM0:4840:120:WilError_03 __ 09:38:48.815 ComClass {C2F03A33-21F5-47FA-B4BB-156362A2F239} Immersive Shell __ 09:38:39.511 ComClass Windows.Internal.Security.Authentication.Web.TokenBrokerInternal __ 09:38:39.511 ComClass Windows.Foundation.Uri __ 09:38:36.626 ComClass Windows.Internal.Security.Authentication.Web.WamProviderRegistration __ 09:38:36.626 ComClass Windows.Foundation.Uri __ 09:38:36.613 ComClass Windows.Internal.Security.Authentication.Web.TokenBrokerInternal __ 09:38:36.613 ComClass Windows.Foundation.Uri __ 09:38:36.613 ComClass Windows.Internal.Security.Authentication.Web.WamProviderRegistration __ 09:38:36.613 ComClass Windows.Foundation.Uri __ 09:38:36.536 Ipc \Sessions\1\BaseNamedObjects\SM0:4840:120:WilError_03_p0h __ 09:38:36.536 Ipc \Sessions\1\BaseNamedObjects\SM0:4840:120:WilError_03_p0 __ 09:38:36.536 Ipc \Sessions\1\BaseNamedObjects\SM0:4840:120:WilError_03 __ 09:38:36.536 Ipc open \RPC Control\SbieSvcPort __ 09:38:36.525 ComClass Windows.Internal.Security.Authentication.Web.TokenBrokerInternal __ 09:38:36.493 ComClass Windows.Foundation.Uri _ Thread 3296 __ 09:38:35.918 Ipc \Sessions\1\BaseNamedObjects\AirDrop::4840 __ 09:38:35.918 Pipe \Device\DeviceApi __ 09:38:35.918 Ipc Open \KnownDlls\cfgmgr32.dll __ 09:38:35.887 Ipc \Sessions\1\BaseNamedObjects\SM0:4840:304:WilStaging_02_p0h __ 09:38:35.887 Ipc \Sessions\1\BaseNamedObjects\SM0:4840:304:WilStaging_02_p0 __ 09:38:35.887 Ipc \Sessions\1\BaseNamedObjects\SM0:4840:304:WilStaging_02 __ 09:38:35.873 Ipc \Sessions\1\BaseNamedObjects\SM0:4840:304:WilStaging_02_p0h __ 09:38:35.873 Ipc \Sessions\1\BaseNamedObjects\SM0:4840:304:WilStaging_02_p0 __ 09:38:35.873 Ipc \Sessions\1\BaseNamedObjects\SM0:4840:304:WilStaging_02 __ 09:38:35.862 Ipc \RPC Control\LRPC-f58089625564942c16 __ 09:38:35.773 Ipc open \RPC Control\SbieSvcPort __ 09:38:35.763 Ipc \Sessions\1\BaseNamedObjects\SM0:4840:304:WilStaging_02_p0h __ 09:38:35.763 Ipc \Sessions\1\BaseNamedObjects\SM0:4840:304:WilStaging_02_p0 __ 09:38:35.763 Ipc \Sessions\1\BaseNamedObjects\SM0:4840:304:WilStaging_02 _ Thread 3036 __ 09:38:39.049 ComClass {88D96A05-F192-11D4-A65F-0040963251E5} XML DOM Document 6.0 __ 09:38:38.984 Ipc (3) \Sessions\1\BaseNamedObjects\windows_shell_global_counters __ 09:38:38.984 Ipc \Sessions\1\BaseNamedObjects\552FFA80-3393-423d-8671-7BA046BB5906 __ 09:38:38.382 Ipc \Sessions\1\BaseNamedObjects\552FFA80-3393-423d-8671-7BA046BB5906 __ 09:38:38.190 Ipc open \RPC Control\SPPCTransportEndpoint-00001 __ 09:38:38.103 Debug StartService: sppsvc __ 09:38:38.036 Ipc Open \RPC Control\SbieSvcPort __ 09:38:38.036 Ipc open \RPC Control\SbieSvcPort __ 09:38:38.036 Ipc \Sessions\1\BaseNamedObjects\SM0:4840:304:WilStaging_02_p0h __ 09:38:38.036 Ipc \Sessions\1\BaseNamedObjects\SM0:4840:304:WilStaging_02_p0 __ 09:38:38.036 Ipc \Sessions\1\BaseNamedObjects\SM0:4840:304:WilStaging_02 __ 09:38:38.003 ComClass Windows.Security.Isolation.IsolatedWindowsEnvironmentHost __ 09:38:37.324 Ipc (2) \Sessions\1\BaseNamedObjects\windows_shell_global_counters _ Thread 2900 __ 09:38:45.563 Ipc (14) \Sessions\1\BaseNamedObjects\windows_shell_global_counters __ 09:38:45.000 ComClass open {A47979D2-C419-11D9-A5B4-001185AD2B89} Network List Manager __ 09:38:44.920 ComClass {DCB00C01-570F-4A9B-8D69-199FDBA5723B} NetworkListManager __ 09:38:42.184 Pipe \Device\HarddiskVolume2 __ 09:38:39.511 ComClass Windows.Security.Authentication.Web.Core.WebAuthenticationCoreManager __ 09:38:38.534 Ipc Open \KnownDlls\WINTRUST.dll __ 09:38:38.437 Ipc \Sessions\1\BaseNamedObjects\SM0:4840:304:WilStaging_02_p0h __ 09:38:38.437 Ipc \Sessions\1\BaseNamedObjects\SM0:4840:304:WilStaging_02_p0 __ 09:38:38.437 Ipc \Sessions\1\BaseNamedObjects\SM0:4840:304:WilStaging_02 __ 09:38:37.716 ComClass open {8BC3F05E-D86B-11D0-A075-00C04FB68820} Windows Management and Instrumentation __ 09:38:36.760 Pipe \Device\NamedPipe\wkssvc __ 09:38:36.626 ComClass Windows.Security.Authentication.Web.Core.WebAuthenticationCoreManager __ 09:38:36.613 ComClass Windows.Security.Authentication.Web.Core.WebAuthenticationCoreManager __ 09:38:36.613 ComClass Windows.Security.Authentication.Web.Core.WebAuthenticationCoreManager __ 09:38:36.493 ComClass Windows.Foundation.Diagnostics.AsyncCausalityTracer __ 09:38:36.493 ComClass Windows.Security.Authentication.Web.Core.WebAuthenticationCoreManager __ 09:38:35.763 Ipc open \KernelObjects\MaximumCommitCondition __ 09:38:35.763 Ipc Open \KnownDlls\clbcatq.dll __ 09:38:35.763 Ipc \Sessions\1\BaseNamedObjects\__ComCatalogCache__ __ 09:38:35.763 Ipc \BaseNamedObjects\__ComCatalogCache__ __ 09:38:35.763 Ipc \Sessions\1\BaseNamedObjects\SM0:4840:304:WilStaging_02_p0h __ 09:38:35.763 Ipc \Sessions\1\BaseNamedObjects\SM0:4840:304:WilStaging_02_p0 __ 09:38:35.763 Ipc \Sessions\1\BaseNamedObjects\SM0:4840:304:WilStaging_02 __ 09:38:35.763 ComClass Windows.Security.Authentication.Web.Core.WebAuthenticationCoreManager __ 09:38:35.763 Ipc open \RPC Control\SbieSvcPort __ 09:38:35.763 Ipc \Sessions\1\BaseNamedObjects\SBIE_ProtectedStorage_Section __ 09:38:35.763 Ipc \Sessions\1\BaseNamedObjects\SBIE_ProtectedStorage_Mutex __ 09:38:35.763 Ipc \Sessions\1\BaseNamedObjects\Office16.B1E641B5-F92B-4B82-83B7-10DC868435E8 _ Thread 2756 __ 09:38:47.917 Ipc (35) \Sessions\1\BaseNamedObjects\windows_shell_global_counters __ 09:38:47.886 Ipc \Sessions\1\BaseNamedObjects\SBIE_BOXED_ServiceInitComplete_cryptsvc __ 09:38:47.886 Ipc \BaseNamedObjects\F932B6C7-3A20-46A0-B8A0-8894AA421973 _ Thread 2488 __ 09:38:49.272 WinClass NetUICtrlNotifySink __ 09:38:49.261 ComClass Windows.Globalization.Language __ 09:38:48.946 WinClass RICHEDIT60W __ 09:38:48.298 WinClass NetUICtrlNotifySink __ 09:38:47.765 WinClass NetUIHWND __ 09:38:47.456 WinClass (2) NUIDialog __ 09:38:46.988 WinClass open (3) Shell_TrayWnd __ 09:38:46.762 WinClass MsoStdCompMgr __ 09:38:46.456 WinClass open (3) Shell_TrayWnd __ 09:38:45.900 Ipc (10) \Sessions\1\BaseNamedObjects\windows_shell_global_counters __ 09:38:45.900 WinClass MsoSplash __ 09:38:45.207 WinClass NetUIHWND __ 09:38:44.908 WinClass FullpageUIHost __ 09:38:44.908 ComClass Windows.System.Profile.SharedModeSettings __ 09:38:44.819 Ipc (3) \Sessions\1\BaseNamedObjects\windows_shell_global_counters __ 09:38:44.549 Ipc \Sessions\1\BaseNamedObjects\SM0:4840:304:WilStaging_02_p0h __ 09:38:44.549 Ipc \Sessions\1\BaseNamedObjects\SM0:4840:304:WilStaging_02_p0 __ 09:38:44.549 Ipc \Sessions\1\BaseNamedObjects\SM0:4840:304:WilStaging_02 __ 09:38:44.341 Ipc open \BaseNamedObjects\msctf.serverDefault1 __ 09:38:44.079 Ipc open \Sessions\1\BaseNamedObjects\CTF.AsmListCache.FMPDefault1 __ 09:38:44.079 Ipc open \Sessions\1\BaseNamedObjects\MSCTF.Asm.MutexDefault1 __ 09:38:43.345 WinClass (4) NetUICtrlNotifySink __ 09:38:43.002 WinClass closed ApplicationManager_DesktopShellWindow __ 09:38:43.002 WinClass $:explorer.exe __ 09:38:43.002 WinClass ApplicationManager_DesktopShellWindow __ 09:38:43.002 Ipc (2) \Sessions\1\BaseNamedObjects\12e8HWNDInterface:904c8 __ 09:38:42.991 ComClass Windows.UI.ViewManagement.UIViewSettings __ 09:38:42.556 WinClass NetUIHWND __ 09:38:42.077 WinClass NUIPane __ 09:38:41.871 WinClass MsoWorkPane __ 09:38:41.406 WinClass MsoCommandBar __ 09:38:40.517 WinClass MsoCommandBarDock __ 09:38:40.517 Ipc open \BaseNamedObjects\FontCachePort __ 09:38:40.245 WinClass (2) NetUI_Hidden __ 09:38:40.026 WinClass (2) NetUIHWND __ 09:38:39.769 WinClass (2) NUIPane __ 09:38:39.545 WinClass MsoWorkPane __ 09:38:37.959 Ipc (11) \Sessions\1\BaseNamedObjects\windows_shell_global_counters __ 09:38:37.749 Ipc \Sessions\1\BaseNamedObjects\552FFA80-3393-423d-8671-7BA046BB5906 __ 09:38:37.716 Ipc \Sessions\1\BaseNamedObjects\FLOODGATE.ACCESS.CAMPAIGNSTATES.JSON __ 09:38:37.705 Ipc \Sessions\1\BaseNamedObjects\FLOODGATE.ACCESS.SURVEYHISTORYSTATS.JSON __ 09:38:37.693 Ipc \Sessions\1\BaseNamedObjects\FLOODGATE.ACCESS.GOVERNEDCHANNELSTATES.JSON __ 09:38:37.632 Ipc (3) \Sessions\1\BaseNamedObjects\SessionImmersiveColorPreference __ 09:38:37.632 Ipc \Sessions\1\BaseNamedObjects\SessionImmersiveColorMutex __ 09:38:37.536 ComClass Windows.ApplicationModel.Core.CoreApplication __ 09:38:37.441 ComClass ApplicationTheme.AppThemeAPI __ 09:38:37.275 Ipc (3) \RPC Control\eventlog __ 09:38:37.139 WinClass RichEdit20A __ 09:38:37.139 WinClass RichEditD2DPT __ 09:38:37.139 WinClass RichEditD2D __ 09:38:37.139 WinClass RICHEDIT60W __ 09:38:37.127 Pipe \Device\MountPointManager __ 09:38:37.051 Ipc \Sessions\1\BaseNamedObjects\{D2E68709-534D-4786-A9B7-D2364CACDA8F}16.0 __ 09:38:37.051 Pipe \Device\KsecDD __ 09:38:37.018 WinClass MsoGroupLine __ 09:38:36.572 WinClass HardwareMonitorWindowClass __ 09:38:35.763 WinClass AirSpace::MessageHwndThreadAlarm O16 __ 09:38:35.698 Ipc open \RPC Control\lsasspirpc __ 09:38:35.698 Ipc open \Security\LSA_AUTHENTICATION_INITIALIZED __ 09:38:35.440 WinClass MsoSplash __ 09:38:35.134 WinClass ForegroundDispatcher00007FFCC60B6EF0 __ 09:38:35.111 WinClass open (3) Shell_TrayWnd __ 09:38:35.111 Ipc \Sessions\1\BaseNamedObjects\SM0:4840:304:WilStaging_02_p0h __ 09:38:35.111 Ipc \Sessions\1\BaseNamedObjects\SM0:4840:304:WilStaging_02_p0 __ 09:38:35.111 Ipc \Sessions\1\BaseNamedObjects\SM0:4840:304:WilStaging_02 __ 09:38:35.111 Ipc open \Sessions\1\Windows\Theme3651103575 __ 09:38:35.111 Ipc open \Windows\Theme3338626119 __ 09:38:35.111 Ipc open \Sessions\1\Windows\ThemeSection __ 09:38:34.796 WinClass (2) OMain __ 09:38:34.523 Ipc \Sessions\1\BaseNamedObjects\AccHeapTrackingSemaphore __ 09:38:34.422 WinClass open (3) Shell_TrayWnd __ 09:38:34.165 WinClass ARC Event Window 00 __ 09:38:34.153 Ipc \Sessions\1\BaseNamedObjects\SM0:4840:304:WilStaging_02_p0h __ 09:38:34.153 Ipc \Sessions\1\BaseNamedObjects\SM0:4840:304:WilStaging_02_p0 __ 09:38:34.153 Ipc \Sessions\1\BaseNamedObjects\SM0:4840:304:WilStaging_02 __ 09:38:34.142 WinClass open (3) Shell_TrayWnd __ 09:38:34.132 Ipc Open \KnownDlls\MSCTF.dll __ 09:38:34.132 Ipc open \ThemeApiPort __ 09:38:34.132 Ipc (2) \Sessions\1\BaseNamedObjects\windows_shell_global_counters __ 09:38:34.132 Ipc Open \KnownDlls\SHCORE.dll __ 09:38:33.874 WinClass ARC Event Window 00 __ 09:38:33.843 Ipc \Sessions\1\BaseNamedObjects\SBIE_WindowsInstallerInUse __ 09:38:33.431 Pipe \Device\KsecDD __ 09:38:33.431 Ipc Open \KnownDlls\SHLWAPI.dll __ 09:38:33.420 Ipc Open \KnownDlls\CRYPT32.dll __ 09:38:33.420 Ipc Open \KnownDlls\bcrypt.dll __ 09:38:33.297 Ipc \Sessions\1\BaseNamedObjects\SBIE_BOXED_ServiceInitComplete_DcomLaunch __ 09:38:33.297 Ipc \Sessions\1\BaseNamedObjects\SBIE_BOXED_ServiceInitComplete_RpcSs __ 09:38:33.297 Pipe \Device\CNG __ 09:38:33.286 Ipc Open \KnownDlls\bcryptPrimitives.dll __ 09:38:33.254 Ipc open \RPC Control\AppV-ISV-03a8adc6-f826-4b82-8ce0-fe506a17f3c3SFT-venv_server __ 09:38:33.239 Ipc open \RPC Control\AppV-ISV-03a8adc6-f826-4b82-8ce0-fe506a17f3c3SFT-vobjects_server __ 09:38:33.239 WinClass open OleMainThreadWndClass __ 09:38:33.239 WinClass $:SandMan.exe __ 09:38:33.239 WinClass OleMainThreadWndClass __ 09:38:33.239 Ipc open \RPC Control\AppV-ISV-03a8adc6-f826-4b82-8ce0-fe506a17f3c3AppvEnterprise_vcom_subsystem __ 09:38:33.239 WinClass open OleMainThreadWndClass __ 09:38:33.239 WinClass $:SandMan.exe __ 09:38:33.239 WinClass OleMainThreadWndClass __ 09:38:33.239 Ipc open \RPC Control\AppV-ISV-03a8adc6-f826-4b82-8ce0-fe506a17f3c3vfs_subsystem __ 09:38:33.239 Ipc open \RPC Control\AppV-ISV-03a8adc6-f826-4b82-8ce0-fe506a17f3c3APPV-VREG_SERVER __ 09:38:33.239 Ipc open \RPC Control\AppV-ISV-03a8adc6-f826-4b82-8ce0-fe506a17f3c3APPV-RSOD_SERVER __ 09:38:33.239 Ipc open \RPC Control\AppV-ISV-03a8adc6-f826-4b82-8ce0-fe506a17f3c3APPV-jitv_server __ 09:38:33.177 Ipc open \RPC Control\AppV-ISV-03a8adc6-f826-4b82-8ce0-fe506a17f3c3APPV-VIRTMAN-NOTIFICATIONS __ 09:38:33.177 Ipc open \RPC Control\lsapolicylookup __ 09:38:33.177 Ipc open \RPC Control\C2RClientAPI_Server_System16 __ 09:38:33.177 Ipc open \RPC Control\LSARPC_ENDPOINT __ 09:38:33.142 Ipc Open \KnownDlls\IMM32.dll __ 09:38:33.110 Ipc \RPC Control\epmapper __ 09:38:33.052 Ipc Open \KnownDlls\OLEAUT32.dll __ 09:38:32.988 Ipc Open \KnownDlls\SHELL32.dll __ 09:38:32.988 Ipc Open \KnownDlls\combase.dll __ 09:38:32.988 Ipc Open \KnownDlls\ole32.dll __ 09:38:32.988 Ipc Open \KnownDlls\WS2_32.dll __ 09:38:32.978 Ipc Open \KnownDlls\rpcrt4.dll __ 09:38:32.978 Ipc Open \KnownDlls\sechost.dll __ 09:38:32.978 Ipc Open \KnownDlls\MSVCRT.dll __ 09:38:32.978 Ipc Open \KnownDlls\advapi32.dll __ 09:38:32.978 Ipc Open \KnownDlls\user32.dll __ 09:38:32.978 Ipc Open \KnownDlls\ucrtbase.dll __ 09:38:32.978 Ipc Open \KnownDlls\msvcp_win.dll __ 09:38:32.978 Ipc Open \KnownDlls\gdi32full.dll __ 09:38:32.978 Ipc Open \KnownDlls\win32u.dll __ 09:38:32.978 Ipc Open \KnownDlls\gdi32.dll __ 09:38:32.978 Ipc \Sessions\1\BaseNamedObjects\SboxSession __ 09:38:32.849 Ipc open \RPC Control\SbieSvcPort __ 09:38:32.837 Ipc \Sessions\1\BaseNamedObjects\SBIE_BOXED_DummyEvent_4840 __ 09:38:32.837 Drive \Device\Mup\;VBoxMiniRdr\;Z:\VBoxSvr\linguist_5.15.2 __ 09:38:32.837 Drive \Device\CdRom0 __ 09:38:32.837 Drive \Device\HarddiskVolume2 __ 09:38:32.837 Ipc Open \KnownDlls\PSAPI.DLL __ 09:38:32.837 Ipc Open \Sessions\1\Windows\ApiPort __ 09:38:32.837 Ipc Open \Sessions\1\Windows\SharedSection __ 09:38:32.837 Ipc Open \KnownDlls\kernelbase.dll __ 09:38:32.837 Ipc Open \KnownDlls\kernel32.dll _ Thread 2480 __ 09:38:35.440 Ipc open \RPC Control\SbieSvcPort __ 09:38:35.440 WinClass MsoSplash _ Thread 1964 __ 09:38:44.920 Ipc \Sessions\1\BaseNamedObjects\F99C425F-9135-43ed-BD7D-396DE488DC53_Office16 __ 09:38:44.876 Ipc \Sessions\1\BaseNamedObjects\69545831-0931-4328-8676-335423887A86-Office16013801_S-1-5-21-958572366-666666666-3141863981-1001 __ 09:38:44.865 Ipc \Sessions\1\BaseNamedObjects\EF46F207-682E-44D0-B511-33F2BD9D52DB-VER16 __ 09:38:44.865 Ipc \Sessions\1\BaseNamedObjects\5CAC3FAB-87F0-4750-984D-D50144543427Office-VER16 __ 09:38:43.037 Pipe \Device\HarddiskVolume2 __ 09:38:42.747 ComClass Windows.Foundation.Diagnostics.AsyncCausalityTracer __ 09:38:42.737 ComClass Windows.Security.Authentication.OnlineId.OnlineIdServiceTicketRequest __ 09:38:42.726 ComClass Windows.Security.Authentication.OnlineId.OnlineIdSystemAuthenticator __ 09:38:42.184 Pipe open \Device\NetBT_Tcpip_{11E35F63-D877-484A-8E32-E979F3E5D42A} __ 09:38:38.470 Ipc open \RPC Control\SbieSvcPort _ Thread 1860 __ 09:38:38.425 ComClass open {A47979D2-C419-11D9-A5B4-001185AD2B89} Network List Manager __ 09:38:38.036 Ipc open \RPC Control\SbieSvcPort _ Thread 1648 __ 09:38:38.613 Ipc \BaseNamedObjects\F932B6C7-3A20-46A0-B8A0-8894AA421973 __ 09:38:38.415 Pipe open \Device\Afd __ 09:38:38.415 Ipc \Sessions\1\BaseNamedObjects\SM0:4840:304:WilStaging_02_p0h __ 09:38:38.415 Ipc \Sessions\1\BaseNamedObjects\SM0:4840:304:WilStaging_02_p0 __ 09:38:38.415 Ipc \Sessions\1\BaseNamedObjects\SM0:4840:304:WilStaging_02 __ 09:38:38.202 Ipc (17) \Sessions\1\BaseNamedObjects\windows_shell_global_counters __ 09:38:38.127 Ipc (20) \Sessions\1\BaseNamedObjects\windows_shell_global_counters __ 09:38:38.127 Pipe open \Device\NetBT_Tcpip_{11E35F63-D877-484A-8E32-E979F3E5D42A} __ 09:38:38.116 Ipc open \RPC Control\dhcpcsvc __ 09:38:38.103 Ipc open \RPC Control\dhcpcsvc6 __ 09:38:38.036 Pipe open \Device\Afd __ 09:38:37.895 Ipc \BaseNamedObjects\F932B6C7-3A20-46A0-B8A0-8894AA421973 __ 09:38:37.833 Ipc open \RPC Control\LRPC-c38d8dad0185b25e4a __ 09:38:37.590 Pipe open \Device\Nsi __ 09:38:37.590 Ipc Open \KnownDlls\NSI.dll __ 09:38:37.590 Ipc \BaseNamedObjects\F932B6C7-3A20-46A0-B8A0-8894AA421973 __ 09:38:37.504 Ipc \Sessions\1\BaseNamedObjects\SM0:4840:304:WilStaging_02_p0h __ 09:38:37.504 Ipc \Sessions\1\BaseNamedObjects\SM0:4840:304:WilStaging_02_p0 __ 09:38:37.504 Ipc \Sessions\1\BaseNamedObjects\SM0:4840:304:WilStaging_02 __ 09:38:37.504 Ipc Open \RPC Control\webcache_{031b98cf-4a69-4c31-ab42-fd9b3c199407}_S-1-5-21-958572366-666666666-3141863981-1001 __ 09:38:37.441 Ipc open \RPC Control\webcache_{031b98cf-4a69-4c31-ab42-fd9b3c199407}_S-1-5-21-958572366-666666666-3141863981-1001 __ 09:38:37.441 Ipc (7) \Sessions\1\BaseNamedObjects\windows_shell_global_counters __ 09:38:37.337 Ipc \Sessions\1\BaseNamedObjects\ZonesLockedCacheCounterMutex __ 09:38:37.242 Ipc \Sessions\1\BaseNamedObjects\ZonesCacheCounterMutex __ 09:38:37.242 Ipc \Sessions\1\BaseNamedObjects\UrlZonesSM_Test __ 09:38:37.242 Ipc Open \KnownDlls\NORMALIZ.dll __ 09:38:36.462 Ipc \Sessions\1\BaseNamedObjects\SM0:4840:120:WilError_03_p0h __ 09:38:36.462 Ipc \Sessions\1\BaseNamedObjects\SM0:4840:120:WilError_03_p0 __ 09:38:36.462 Ipc \Sessions\1\BaseNamedObjects\SM0:4840:120:WilError_03 __ 09:38:36.398 ComClass open {A47979D2-C419-11D9-A5B4-001185AD2B89} Network List Manager __ 09:38:36.365 Ipc \RPC Control\OLE9FC95DCB3AAB7ACA40C47E157A67 __ 09:38:36.332 Ipc \RPC Control\epmapper __ 09:38:36.332 Ipc \Sessions\1\BaseNamedObjects\SBIE_BOXED_ServiceInitComplete_DcomLaunch __ 09:38:36.332 Ipc \Sessions\1\BaseNamedObjects\SBIE_BOXED_ServiceInitComplete_RpcSs __ 09:38:36.332 Ipc \RPC Control\epmapper __ 09:38:35.952 ComClass {DCB00C01-570F-4A9B-8D69-199FDBA5723B} NetworkListManager __ 09:38:35.918 Ipc open \RPC Control\SbieSvcPort __ 09:38:35.785 Ipc \Sessions\1\BaseNamedObjects\__ComCatalogCache__ __ 09:38:35.785 Ipc \BaseNamedObjects\__ComCatalogCache__ _ Thread 1084 __ 09:38:48.466 Ipc \RPC Control\keysvc __ 09:38:48.298 Ipc \Sessions\1\BaseNamedObjects\SBIE_BOXED_ServiceInitComplete_cryptsvc __ 09:38:48.145 Pipe open (3) \Device\Afd __ 09:38:48.070 Ipc \BaseNamedObjects\F932B6C7-3A20-46A0-B8A0-8894AA421973 __ 09:38:42.780 Ipc open \RPC Control\SbieSvcPort __ 09:38:42.780 Ipc (3) \RPC Control\protected_storage _ Thread 240 __ 09:38:48.009 Ipc \BaseNamedObjects\F932B6C7-3A20-46A0-B8A0-8894AA421973 SandboxieDcomLaunch.exe (4276) _ Thread 4892 __ 09:38:32.519 Ipc open \KernelObjects\MaximumCommitCondition __ 09:38:32.519 Ipc Open \KnownDlls\clbcatq.dll __ 09:38:32.519 Ipc \Sessions\1\BaseNamedObjects\__ComCatalogCache__ __ 09:38:32.519 Ipc \BaseNamedObjects\__ComCatalogCache__ __ 09:38:32.519 Ipc \Sessions\1\BaseNamedObjects\SM0:4276:304:WilStaging_02_p0h __ 09:38:32.519 Ipc \Sessions\1\BaseNamedObjects\SM0:4276:304:WilStaging_02_p0 __ 09:38:32.519 Ipc \Sessions\1\BaseNamedObjects\SM0:4276:304:WilStaging_02 __ 09:38:32.504 Pipe \Device\KsecDD __ 09:38:32.504 Ipc Open \KnownDlls\bcrypt.dll __ 09:38:32.504 Ipc Open \KnownDlls\OLEAUT32.dll __ 09:38:32.504 Ipc \Sessions\1\BaseNamedObjects\SM0:4276:120:WilError_03_p0h __ 09:38:32.504 Ipc \Sessions\1\BaseNamedObjects\SM0:4276:120:WilError_03_p0 __ 09:38:32.504 Ipc \Sessions\1\BaseNamedObjects\SM0:4276:120:WilError_03 __ 09:38:32.504 Ipc open \RPC Control\SbieSvcPort __ 09:38:28.746 Ipc \Sessions\1\BaseNamedObjects\{A64C7F33-DA35-459b-96CA-63B51FB0CDB9} __ 09:38:28.746 Ipc \BaseNamedObjects\{A64C7F33-DA35-459b-96CA-63B51FB0CDB9} __ 09:38:28.746 Ipc \Sessions\1\BaseNamedObjects\{A3BD3259-3E4F-428a-84C8-F0463A9D3EB5} __ 09:38:28.746 Ipc \BaseNamedObjects\{A3BD3259-3E4F-428a-84C8-F0463A9D3EB5} __ 09:38:28.746 Ipc \Sessions\1\BaseNamedObjects\RotHintTable __ 09:38:28.746 Ipc \BaseNamedObjects\RotHintTable _ Thread 4492 __ 09:38:28.718 Ipc \Sessions\1\BaseNamedObjects\SBIE_BOXED_ServiceInitComplete_DcomLaunch __ 09:38:28.718 Ipc \Sessions\1\BaseNamedObjects\__ComCatalogCache__ __ 09:38:28.718 Ipc \BaseNamedObjects\__ComCatalogCache__ __ 09:38:28.718 Ipc \RPC Control\actkernel __ 09:38:28.706 Ipc open \RPC Control\lsasspirpc __ 09:38:28.706 Ipc open \Security\LSA_AUTHENTICATION_INITIALIZED __ 09:38:28.706 Ipc open \RPC Control\lsapolicylookup _ Thread 2316 __ 09:38:28.693 Pipe \Device\CNG __ 09:38:28.693 Ipc Open \KnownDlls\combase.dll __ 09:38:28.693 Ipc Open \KnownDlls\bcryptPrimitives.dll __ 09:38:28.674 Ipc Open \KnownDlls\IMM32.dll __ 09:38:28.674 Ipc \RPC Control\epmapper __ 09:38:28.674 Ipc Open \KnownDlls\ucrtbase.dll __ 09:38:28.674 Ipc Open \KnownDlls\msvcp_win.dll __ 09:38:28.674 Ipc Open \KnownDlls\gdi32full.dll __ 09:38:28.674 Ipc Open \KnownDlls\gdi32.dll __ 09:38:28.674 Ipc Open \KnownDlls\win32u.dll __ 09:38:28.674 Ipc Open \KnownDlls\user32.dll __ 09:38:28.674 Ipc Open \KnownDlls\rpcrt4.dll __ 09:38:28.674 Ipc Open \KnownDlls\sechost.dll __ 09:38:28.674 Ipc Open \KnownDlls\MSVCRT.dll __ 09:38:28.674 Ipc Open \KnownDlls\advapi32.dll __ 09:38:28.674 Ipc \Sessions\1\BaseNamedObjects\SboxSession __ 09:38:28.530 Ipc open \RPC Control\SbieSvcPort __ 09:38:28.530 Ipc \Sessions\1\BaseNamedObjects\SBIE_BOXED_DummyEvent_4276 __ 09:38:28.530 Drive \Device\Mup\;VBoxMiniRdr\;Z:\VBoxSvr\linguist_5.15.2 __ 09:38:28.530 Drive \Device\CdRom0 __ 09:38:28.530 Drive \Device\HarddiskVolume2 __ 09:38:28.530 Ipc Open \KnownDlls\PSAPI.DLL __ 09:38:28.530 Ipc Open \Sessions\1\Windows\ApiPort __ 09:38:28.530 Ipc Open \Sessions\1\Windows\SharedSection __ 09:38:28.530 Ipc Open \KnownDlls\kernelbase.dll __ 09:38:28.530 Ipc Open \KnownDlls\kernel32.dll SandboxieCrypto.exe (4176) _ Thread 4076 __ 09:38:39.324 ComClass closed unknown __ 09:38:39.303 Ipc \Sessions\1\BaseNamedObjects\__ComCatalogCache__ __ 09:38:39.303 Ipc \BaseNamedObjects\__ComCatalogCache__ __ 09:38:39.303 Ipc open \KernelObjects\MaximumCommitCondition __ 09:38:39.303 Ipc Open \KnownDlls\clbcatq.dll __ 09:38:39.303 Ipc \Sessions\1\BaseNamedObjects\__ComCatalogCache__ __ 09:38:39.303 Ipc \BaseNamedObjects\__ComCatalogCache__ __ 09:38:39.303 Ipc \Sessions\1\BaseNamedObjects\SM0:4176:304:WilStaging_02_p0h __ 09:38:39.303 Ipc \Sessions\1\BaseNamedObjects\SM0:4176:304:WilStaging_02_p0 __ 09:38:39.303 Ipc \Sessions\1\BaseNamedObjects\SM0:4176:304:WilStaging_02 __ 09:38:39.303 Ipc open \RPC Control\samss lpc __ 09:38:39.271 Ipc Open \KnownDlls\WS2_32.dll __ 09:38:39.260 Ipc open \RPC Control\SbieSvcPort _ Thread 3440 __ 09:38:39.260 Debug ServiceMainThread; end __ 09:38:39.260 Ipc \Sessions\1\BaseNamedObjects\SBIE_BOXED_ServiceInitComplete_cryptsvc __ 09:38:39.260 Debug SetServiceStatus; status: <00000004> __ 09:38:39.260 Pipe \Device\CNG __ 09:38:39.260 Ipc Open \KnownDlls\bcryptPrimitives.dll __ 09:38:39.228 Ipc Open \KnownDlls\combase.dll __ 09:38:39.228 Ipc Open \KnownDlls\OLEAUT32.dll __ 09:38:39.217 Ipc \RPC Control\keysvc __ 09:38:39.217 Ipc open \RPC Control\lsapolicylookup __ 09:38:39.217 Debug SetServiceStatus; status: <00000002> __ 09:38:39.217 Debug ServiceMainThread; begin _ Thread 2684 __ 09:38:44.989 Pipe (2) \Device\Harddisk0\DR0 __ 09:38:44.989 Pipe \Device\HarddiskVolume2 __ 09:38:44.989 Pipe \Device\MountPointManager __ 09:38:44.989 Pipe \Device\HarddiskVolume2 __ 09:38:44.989 Pipe \Device\MountPointManager __ 09:38:44.989 Pipe \Device\HarddiskVolume2 __ 09:38:44.989 Ipc open \KernelObjects\LowMemoryCondition _ Thread 1676 __ 09:38:39.207 Debug SetServiceStatus; status: <00000002> __ 09:38:39.207 Debug StartServiceCtrlDispatcher; name: 'CryptSvc' __ 09:38:39.207 Pipe \Device\KsecDD __ 09:38:39.207 Ipc Open \KnownDlls\bcrypt.dll __ 09:38:39.207 Ipc Open \KnownDlls\CRYPT32.dll __ 09:38:39.207 Ipc \Sessions\1\BaseNamedObjects\SBIE_BOXED_ServiceCrypto_Mutex1 __ 09:38:39.207 Ipc \Sessions\1\BaseNamedObjects\SBIE_BOXED_ServiceInitComplete_DcomLaunch __ 09:38:39.207 Ipc \Sessions\1\BaseNamedObjects\SBIE_BOXED_ServiceInitComplete_RpcSs __ 09:38:39.195 Ipc Open \KnownDlls\IMM32.dll __ 09:38:39.195 Ipc \RPC Control\epmapper __ 09:38:39.184 Ipc Open \KnownDlls\ucrtbase.dll __ 09:38:39.184 Ipc Open \KnownDlls\msvcp_win.dll __ 09:38:39.184 Ipc Open \KnownDlls\gdi32full.dll __ 09:38:39.184 Ipc Open \KnownDlls\gdi32.dll __ 09:38:39.184 Ipc Open \KnownDlls\win32u.dll __ 09:38:39.184 Ipc Open \KnownDlls\user32.dll __ 09:38:39.184 Ipc Open \KnownDlls\rpcrt4.dll __ 09:38:39.172 Ipc Open \KnownDlls\sechost.dll __ 09:38:39.172 Ipc Open \KnownDlls\MSVCRT.dll __ 09:38:39.172 Ipc Open \KnownDlls\advapi32.dll __ 09:38:39.172 Ipc \Sessions\1\BaseNamedObjects\SboxSession __ 09:38:39.172 Ipc open \RPC Control\SbieSvcPort __ 09:38:39.172 Ipc \Sessions\1\BaseNamedObjects\SBIE_BOXED_DummyEvent_4176 __ 09:38:39.162 Drive \Device\Mup\;VBoxMiniRdr\;Z:\VBoxSvr\linguist_5.15.2 __ 09:38:39.162 Drive \Device\CdRom0 __ 09:38:39.162 Drive \Device\HarddiskVolume2 __ 09:38:39.162 Ipc Open \KnownDlls\PSAPI.DLL __ 09:38:39.162 Ipc Open \Sessions\1\Windows\ApiPort __ 09:38:39.162 Ipc Open \Sessions\1\Windows\SharedSection __ 09:38:39.162 Ipc Open \KnownDlls\kernelbase.dll __ 09:38:39.162 Ipc Open \KnownDlls\kernel32.dll SandboxieRpcSs.exe (3772) _ Thread 4496 __ 09:38:27.807 Ipc \Sessions\1\BaseNamedObjects\SBIE_BOXED_ServiceInitComplete_RpcEptMapper __ 09:38:27.807 Ipc \RPC Control\epmapper __ 09:38:27.807 Ipc open \RPC Control\lsasspirpc __ 09:38:27.807 Ipc open \Security\LSA_AUTHENTICATION_INITIALIZED __ 09:38:27.807 Pipe \Device\NDMP1 __ 09:38:27.807 Pipe \Device\NDMP2 __ 09:38:27.807 Pipe \Device\NDMP3 __ 09:38:27.807 Pipe \Device\NDMP4 __ 09:38:27.807 Pipe \Device\NDMP5 __ 09:38:27.807 Pipe \Device\NDMP6 __ 09:38:27.807 Pipe \Device\NDMP7 __ 09:38:27.807 Pipe \Device\NDMP8 __ 09:38:27.807 Pipe \Device\NDMP9 __ 09:38:27.807 Pipe \Device\Ndis __ 09:38:27.807 Ipc \Sessions\1\BaseNamedObjects\SC_AutoStartComplete __ 09:38:27.807 Ipc \BaseNamedObjects\SC_AutoStartComplete _ Thread 3324 __ 09:38:27.807 Ipc \Sessions\1\BaseNamedObjects\SBIE_BOXED_RPCSS_SXS_READY __ 09:38:27.744 Ipc open \RPC Control\SbieSvcPort __ 09:38:27.732 Ipc Open \KnownDlls\combase.dll __ 09:38:27.732 Ipc Open \KnownDlls\ole32.dll _ Thread 3224 __ 09:38:30.181 Ipc (138) \Sessions\1\BaseNamedObjects\windows_shell_global_counters __ 09:38:30.181 Ipc \Sessions\1\BaseNamedObjects\SM0:3772:120:WilError_03_p0h __ 09:38:30.181 Ipc \Sessions\1\BaseNamedObjects\SM0:3772:120:WilError_03_p0 __ 09:38:30.181 Ipc \Sessions\1\BaseNamedObjects\SM0:3772:120:WilError_03 __ 09:38:30.181 Ipc \Sessions\1\BaseNamedObjects\SM0:3772:304:WilStaging_02_p0h __ 09:38:30.181 Ipc \Sessions\1\BaseNamedObjects\SM0:3772:304:WilStaging_02_p0 __ 09:38:30.181 Ipc \Sessions\1\BaseNamedObjects\SM0:3772:304:WilStaging_02 __ 09:38:30.181 Ipc (5) \Sessions\1\BaseNamedObjects\windows_shell_global_counters __ 09:38:30.181 Ipc \Sessions\1\BaseNamedObjects\SM0:3772:304:WilStaging_02_p0h __ 09:38:30.181 Ipc \Sessions\1\BaseNamedObjects\SM0:3772:304:WilStaging_02_p0 __ 09:38:30.181 Ipc \Sessions\1\BaseNamedObjects\SM0:3772:304:WilStaging_02 __ 09:38:30.074 WinClass open (3) Shell_TrayWnd __ 09:38:30.074 Ipc \Sessions\1\BaseNamedObjects\SM0:3772:304:WilStaging_02_p0h __ 09:38:30.074 Ipc \Sessions\1\BaseNamedObjects\SM0:3772:304:WilStaging_02_p0 __ 09:38:30.074 Ipc \Sessions\1\BaseNamedObjects\SM0:3772:304:WilStaging_02 __ 09:38:30.074 Ipc open \Sessions\1\Windows\Theme3651103575 __ 09:38:30.074 Ipc open \Windows\Theme3338626119 __ 09:38:30.074 Ipc open \Sessions\1\Windows\ThemeSection __ 09:38:30.074 Ipc Open \KnownDlls\OLEAUT32.dll __ 09:38:30.074 Ipc Open \KnownDlls\MSCTF.dll __ 09:38:29.958 Ipc open \ThemeApiPort __ 09:38:29.958 Ipc Open \KnownDlls\SHLWAPI.dll __ 09:38:29.958 Ipc (2) \Sessions\1\BaseNamedObjects\windows_shell_global_counters __ 09:38:29.958 Ipc Open \KnownDlls\SHCORE.dll __ 09:38:29.958 Ipc Open \KnownDlls\SHELL32.dll __ 09:38:27.807 Ipc Open \RPC Control\SbieSvcPort __ 09:38:27.807 Ipc open \RPC Control\SbieSvcPort __ 09:38:27.807 WinClass Sandboxie_DDE_ProxyClass1 _ Thread 2772 __ 09:38:27.996 Ipc \Sessions\1\BaseNamedObjects\SboxSession _ Thread 2440 __ 09:38:27.807 Pipe \Device\CNG __ 09:38:27.807 Ipc Open \KnownDlls\bcryptPrimitives.dll __ 09:38:27.732 Ipc \Sessions\1\BaseNamedObjects\SBIE_BOXED_ServiceInitComplete_RpcEptMapper __ 09:38:27.732 Ipc \Sessions\1\BaseNamedObjects\SC_AutoStartComplete __ 09:38:27.732 Ipc \BaseNamedObjects\SC_AutoStartComplete __ 09:38:27.732 Ipc \Sessions\1\BaseNamedObjects\ComPlusCOMRegTable __ 09:38:27.698 Ipc \Sessions\1\BaseNamedObjects\SBIE_BOXED_ServiceInitComplete_Mutex1 __ 09:38:27.698 Ipc open \RPC Control\SbieSvcPort __ 09:38:27.698 Ipc Open \KnownDlls\IMM32.dll __ 09:38:27.687 Ipc \RPC Control\epmapper __ 09:38:27.687 Ipc Open \KnownDlls\ucrtbase.dll __ 09:38:27.687 Ipc Open \KnownDlls\msvcp_win.dll __ 09:38:27.659 Ipc Open \KnownDlls\gdi32full.dll __ 09:38:27.659 Ipc Open \KnownDlls\gdi32.dll __ 09:38:27.659 Ipc Open \KnownDlls\win32u.dll __ 09:38:27.659 Ipc Open \KnownDlls\user32.dll __ 09:38:27.659 Ipc Open \KnownDlls\sechost.dll __ 09:38:27.659 Ipc Open \KnownDlls\MSVCRT.dll __ 09:38:27.659 Ipc Open \KnownDlls\advapi32.dll __ 09:38:27.659 Ipc Open \KnownDlls\rpcrt4.dll __ 09:38:27.659 Ipc Open \KnownDlls\WS2_32.dll __ 09:38:27.648 Ipc \Sessions\1\BaseNamedObjects\SBIE_BOXED_DummyEvent_3772 __ 09:38:27.648 Drive \Device\Mup\;VBoxMiniRdr\;Z:\VBoxSvr\linguist_5.15.2 __ 09:38:27.648 Drive \Device\CdRom0 __ 09:38:27.648 Drive \Device\HarddiskVolume2 __ 09:38:27.648 Ipc Open \KnownDlls\PSAPI.DLL __ 09:38:27.648 Ipc Open \Sessions\1\Windows\ApiPort __ 09:38:27.648 Ipc Open \Sessions\1\Windows\SharedSection __ 09:38:27.648 Ipc Open \KnownDlls\kernelbase.dll __ 09:38:27.648 Ipc Open \KnownDlls\kernel32.dll _ Thread 1876 __ 09:38:46.456 Ipc \Sessions\1\BaseNamedObjects\RotHintTable __ 09:38:46.456 Ipc \BaseNamedObjects\RotHintTable _ Thread 844 __ 09:38:32.746 Ipc open \RPC Control\SbieSvcPort __ 09:38:32.714 Ipc \Sessions\1\BaseNamedObjects\__ComCatalogCache__ __ 09:38:32.714 Ipc \BaseNamedObjects\__ComCatalogCache__ __ 09:38:32.519 Pipe \Device\KsecDD __ 09:38:32.519 Ipc Open \KnownDlls\bcrypt.dll __ 09:38:32.504 Ipc \Sessions\1\BaseNamedObjects\SM0:3772:120:WilError_03_p0h __ 09:38:32.504 Ipc \Sessions\1\BaseNamedObjects\SM0:3772:120:WilError_03_p0 __ 09:38:32.504 Ipc \Sessions\1\BaseNamedObjects\SM0:3772:120:WilError_03 __ 09:38:32.504 Ipc open \KernelObjects\MaximumCommitCondition __ 09:38:32.504 Ipc Open \KnownDlls\clbcatq.dll __ 09:38:32.504 Ipc \Sessions\1\BaseNamedObjects\__ComCatalogCache__ __ 09:38:32.504 Ipc \BaseNamedObjects\__ComCatalogCache__ __ 09:38:32.504 Ipc \Sessions\1\BaseNamedObjects\SM0:3772:304:WilStaging_02_p0h __ 09:38:32.504 Ipc \Sessions\1\BaseNamedObjects\SM0:3772:304:WilStaging_02_p0 __ 09:38:32.489 Ipc \Sessions\1\BaseNamedObjects\SM0:3772:304:WilStaging_02 _ Thread 220 __ 09:38:28.746 Ipc \Sessions\1\BaseNamedObjects\SBIE_BOXED_ServiceInitComplete_RpcSs __ 09:38:28.746 Ipc \Sessions\1\BaseNamedObjects\ScmCreatedEvent __ 09:38:28.542 Debug trace CreateProcess: C:\Program Files\Sandboxie-Plus\SandboxieDcomLaunch.exe ("C:\Program Files\Sandboxie-Plus\SandboxieDcomLaunch.exe"); err=0 __ 09:38:27.886 Ipc \Sessions\1\BaseNamedObjects\SBIE_BOXED_ServiceInitComplete_DcomLaunch __ 09:38:27.886 Ipc \RPC Control\actkernel __ 09:38:27.886 Ipc open \RPC Control\lsapolicylookup ```
APMichael commented 3 years ago

Since I checked the Office programs after each update of Sandboxie, it seems that the latest Office updates are responsible for it working again now.

I can confirm everything, including the wobbling Access window.

However, a Sandboxie error message also appears for me: "SBIE2313 Could not run SandboxieCrypto.exe (5)"

Edit: The issue with SandboxieCrypto.exe is not due to Sandboxie. The culprit was Windows Defender. A special attack surface reduction rule has been enabled that prevents all Office applications from creating child processes.

I seem to remember that certain Office windows already had problems with the Sandboxie indicator (#) earlier and therefore it was already recommended in the old forums to disable it for Office.

Seeadler1 commented 3 years ago

Since 5.49.0 Classic Word 2016 has been working without problems and error messages.

Thanks!

APMichael commented 3 years ago

Another user also got Office working again with a repair installation, which normally installs the latest version. Therefore, it seems that Microsoft really was the culprit. Let us hope that Microsoft does not break the compatibility with Sandboxie again with a future Office update.

Edit: Issues #428 and #376 could be closed then, right?

isaak654 commented 3 years ago

Reinstall doesn't solve the issue with the beta version released by MS, according to henryg1. Personally I would wait a bit before closing...

isaak654 commented 3 years ago

@Seeadler1 @APMichael @ewald81375

This is how I passed the error "The server endpoint cannot perform the operation (1752). 102497-f148505953075b4029ea41f1ad15cee7

Create a new default sandbox and add the following lines that will reduce the isolation enough to run MS Office C2R apps:

RpcPortBinding=kernel32.dll,'0497b57d-2e66-424f-a0c6-157cd5d41700@ncalrpc:',TimeOut=n
BoxNameTitle=-
UnrestrictedToken=y
OpenIpcPath=\*

Make sure to not duplicate BoxNameTitle. Suggested version to apply these lines: Sandboxie v0.9.6 / 5.51.6 or later (because of this issue recently fixed)

Tested and working for me by running the following shortcuts: C:\Users\Test\Desktop\SbieTest2\Start.exe /box:New_Box_2 "C:\Program Files\Microsoft Office\root\Office16\MSACCESS.EXE" C:\Users\Test\Desktop\SbieTest2\Start.exe /box:New_Box_2 "C:\Program Files\Microsoft Office\root\Office16\EXCEL.EXE"

APMichael commented 3 years ago

Thanks for sharing. Maybe this will also help @DavidXanatos to fix the problem directly in Sandboxie without weakening the isolation.

DavidXanatos commented 3 years ago

Will be fixed in the next build

you can fix it yourself by adding

RpcPortBinding=kernel32.dll,'0497b57d-2e66-424f-a0c6-157cd5d41700@ncalrpc:',Resolve=AppInfo,TimeOut=y
RpcPortBindingIfId=AppInfo,{0497b57d-2e66-424f-a0c6-157cd5d41700}

to the [Template_RpcPortBindings] section of Templates.ini file or directly to the box you want to run Word in

EDIT: It may require a reboot.

DavidXanatos commented 3 years ago

Or try the 0.9.7 build

APMichael commented 3 years ago

Or try the 0.9.7 build

Works! 😃 Thank you for the now quick fix. And also thanks again to @isaak654 for his help on this.

ewald81375 commented 3 years ago

Hi David,

I tried the new version with Office 2010 on my notebook: Outlook, Word and Powerpoint worked very well . But I had problems with Excel: I startet several excel-sheets with Sandboxie but always no content was shown!!!

Because I´m out off home for a few days I can´t try the new version with Office 2019. After being back I will try with Office 2019 and will send you the result.

Best regards

Ewald

Von: DavidXanatos @.*** Gesendet: Samstag, 2. Oktober 2021 11:45 An: sandboxie-plus/Sandboxie Cc: ewald81375; Mention Betreff: Re: [sandboxie-plus/Sandboxie] Word won't open in Sandboxie (Click-to-Run installations) (#428)

Or try the 0.9.7 build

— You are receiving this because you were mentioned. Reply to this email directly, view it on GitHub https://github.com/sandboxie-plus/Sandboxie/issues/428#issuecomment-932723732 , or unsubscribe https://github.com/notifications/unsubscribe-auth/AUMXODDLUXOZ7P4FBE7NG23UE3ICHANCNFSM4WNI4BNQ . Triage notifications on the go with GitHub Mobile for iOS https://apps.apple.com/app/apple-store/id1477376905?ct=notification-email&mt=8&pt=524675 or Android https://play.google.com/store/apps/details?id=com.github.android&referrer=utm_campaign%3Dnotification-email%26utm_medium%3Demail%26utm_source%3Dgithub . Das Bild wurde vom Absender entfernt.

isaak654 commented 3 years ago

But I had problems with Excel: I startet several excel-sheets with Sandboxie but always no content was shown!!! Because I´m out off home for a few days I can´t try the new version with Office 2019. After being back I will try with Office 2019 and will send you the result.

I ran this Excel spreadsheet on MS Office 365 and it is loaded correctly while sandboxed: https://docs.microsoft.com/en-us/power-bi/create-reports/sample-financial-download

mauriceatkinson commented 3 years ago

I downloaded v0.9.7d as I had an issue with click to run after i downloaded a csv within the sandbox. This version now displayed the downloaded csv but before it did that sandboxie imported my entire OST email file into the sandbox. Strange behaviour I thought and could not see why my ost file is needed??

DavidXanatos commented 3 years ago

because apaprently office wanted to open it for writing and to presetv isoaltion and keep teh original file intact a copy was created on which the sandboxed programs can write without altering the original. You could eider set the file to be read only in which case office may fail or somethign, or you coudl set the file as aopen allowing sandboxed office to alter the original

ewald81375 commented 3 years ago

Hi David,

I now did a complete test with the newest version of Sandboxie 0.9.7 with Office 2019 on my desktop Computer and Office 2010 on my notebook.

Result:

  1. Sandboxie 0.9.7 works very well with Office 2019 (Excel, Word, Outlook, PowerPoint)
  2. Sandboxie 0.9.7 works very well with Word, Outlook, PowerPoint in Office 2010. The problem with Excel is, that Sandboxie starts with the Excel sheet but finally no content is shown. In the attachment you can find a zip-file with the 2 Excels I tried and the result in both cases. This is only fyi and you can close the issue (Word won’t …). Office 2010 is an old version running on my notebook (backup for my Desktop computer) and therefore this problem is not important for me.

Thank you very much for support and best regards

Ewald

Von: DavidXanatos @.> Gesendet: Freitag, 8. Oktober 2021 09:45 An: sandboxie-plus/Sandboxie @.> Cc: ewald81375 @.>; Mention @.> Betreff: Re: [sandboxie-plus/Sandboxie] Word won't open in Sandboxie (Click-to-Run installations) (#428)

because apaprently office wanted to open it for writing and to presetv isoaltion and keep teh original file intact a copy was created on which the sandboxed programs can write without altering the original. You could eider set the file to be read only in which case office may fail or somethign, or you coudl set the file as aopen allowing sandboxed office to alter the original

— You are receiving this because you were mentioned. Reply to this email directly, view it on GitHub https://github.com/sandboxie-plus/Sandboxie/issues/428#issuecomment-938420611 , or unsubscribe https://github.com/notifications/unsubscribe-auth/AUMXODCIP4ZGRQF6OER2HN3UF2OO3ANCNFSM4WNI4BNQ . Triage notifications on the go with GitHub Mobile for iOS https://apps.apple.com/app/apple-store/id1477376905?ct=notification-email&mt=8&pt=524675 or Android https://play.google.com/store/apps/details?id=com.github.android&referrer=utm_campaign%3Dnotification-email%26utm_medium%3Demail%26utm_source%3Dgithub .

dovry commented 2 years ago

@isaak654's comment helped me get OneNote running. https://github.com/sandboxie-plus/Sandboxie/issues/428#issuecomment-931371641 image If you log in, however, it adds your microsoft account to the windows install, so there's really no reason to run it sandboxed if you're using some 3rd party syncing service anyway.