Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

PotPlayerMini64.exe crashes when UseRegDeleteV2=y is used in 1.1.1. #1939

Closed
bastik-1001 opened this issue Jun 10, 2022 · 11 comments
Closed
Labels
Crash Dump Dump file attached for a detailed analysis Status: Fixed in Next Build Fixed in the next Sandboxie version

Comments

@bastik-1001
Copy link
Collaborator

bastik-1001 commented Jun 10, 2022

What happened?

When setting UseRegDeleteV2=y in a sandbox for PotPlayer, PotPlayer crashes.

As the settings are stored in registry, I wanted to test if UseRegDeleteV2=y functions, but just launching PotPlayerMini64.exe makes it crash.

Download link

https://t1.daumcdn.net/potplayer/PotPlayer/Version/Latest/PotPlayerSetup64.exe

To Reproduce

  1. Launch PotPlayerMini64.exe without UseRegDeleteV2=y and see that it works
  2. Close the application, and add UseRegDeleteV2=y to the config
  3. Launch PotPlayerMini64.exe and get the message that the process has crashed.

Expected behavior

PotPlayerMini64.exe not crashing

What is your Windows edition and version?

Windows 7 64bit SP1

In which Windows account you have this problem?

A local or Microsoft account without special changes.

Please mention any installed security software

Windows Defender

What version of Sandboxie are you running?

Sandboxie-Plus 1.1.1 64bit

Is it a regression?

1.1.1 is the first I tried it with.

List of affected browsers

No response

In which sandbox type you have this problem?

In a Hardened sandbox (red sandbox icon).

Where is the program located?

The program is installed only outside the sandbox.

Can you reproduce this problem on an empty sandbox?

I can confirm it also on an empty sandbox.

Did you previously enable some security policy settings outside Sandboxie?

No response

Crash dump

https://github.com/bastik-1001/Crashdump-and-trace/blob/main/PotPlayerMini64.exe.6088.dmp
https://github.com/bastik-1001/Crashdump-and-trace/blob/main/PotPlayerMini64.exe.7236.dmp
https://github.com/bastik-1001/Crashdump-and-trace/blob/main/PotPlayerMini64.exe.7928.dmp

Trace log

https://github.com/bastik-1001/Crashdump-and-trace/raw/main/tracelog%20potplayer%20mini

Sandboxie.ini configuration

[Boxsettings]
Enabled=y
ConfigLevel=9
AutoRecover=y
Template=FileCopy
Template=SkipHook
Template=qWave
Template=BlockPorts
Template=LingerPrograms
Template=Chrome_Phishing_DirectAccess
Template=Firefox_Phishing_DirectAccess
Template=AutoRecoverIgnore
RecoverFolder=%[string]%
RecoverFolder=%Personal%
RecoverFolder=%Favorites%
RecoverFolder=%Desktop%
BorderColor=#00ffff,ttl,2
DropAdminRights=y
BoxNameTitle=n
CopyLimitKb=81920
DontCopy=.mp4
DontCopy=.mp3
DontCopy=.avi
DontCopy=.mkv
ClosePrintSpooler=y
ClosedFilePath=!<InternetAccess>,InternetAccessDevices
ClosedFilePath=<BlockNetDevices>,InternetAccessDevices
ForceProcess=PotPlayerMini64.exe
LeaderProcess=DTDrop64.exe
LeaderProcess=PotPlayerMini64.exe
ProcessGroup=<BlockNetDevices>,dllhost.exe
ProcessGroup=<InternetAccess>,PotPlayerMini64.exe
NotifyInternetAccessDenied=n
BlockNetworkFiles=y
HideOtherBoxes=y
ReadIpcPath=$:explorer.exe
OpenClipboard=n
UseRegDeleteV2=y
@bastik-1001 bastik-1001 added the Confirmation Pending Further confirmation is requested label Jun 10, 2022
@bastik-1001
Copy link
Collaborator Author

While making Potplayer crash to get more than one dump, I left Sandboxie unattended, not addressing the notification about the process in the sandbox having crashed. Then Sandman.exe froze and it got terminated.

There is a dump for that crash as well: https://github.com/bastik-1001/Crashdump-and-trace/blob/main/SandMan.exe.6968.dmp

@isaak654 isaak654 added the Crash Dump Dump file attached for a detailed analysis label Jun 10, 2022
@DavidXanatos
Copy link
Member

i cant reproduce this issue
do you still have it with build 1.1.2?
if yes can you please post new dumps from that build

@DavidXanatos DavidXanatos added the More Info Needed More information is needed to move forward label Jun 16, 2022
@bastik-1001
Copy link
Collaborator Author

bastik-1001 commented Jun 17, 2022

Yes, the problem still exists with 1.1.2. Even when I delete the sandbox folder, since I can't use the function from within Sandman as it crashes. As I saw the bugreport, I did not install 1.1.2 to try if that fixes the UseRegDeleteV2 issue with that application.

Here is the new https://github.com/bastik-1001/Crashdump-and-trace/blob/main/PotPlayerMini64.exe.10860.dmp

It also crashes with a fresh box (Standard Box, only UseRegDeleteV2 is being added.).
Dump for fresh box: https://github.com/bastik-1001/Crashdump-and-trace/blob/main/PotPlayerMini64.exe.8788.dmp

@bastik-1001
Copy link
Collaborator Author

bastik-1001 commented Jun 17, 2022

I have not tried that before, but when I add UseRegDeleteV2=y to any box and try to use Run > Run Program, the window to enter a path opens, when I then browse it open shows "C:\Program Files\Sandboxie-Plus", but upon clicking on "Computer" or anywhere to get to other files Start.exe crashes.

As I said I did not try that with 1.1.1., but I guess that it would behave the same. There's a crash dump for that: https://github.com/bastik-1001/Crashdump-and-trace/blob/main/Start.exe.248.dmp

I'd like to wait for 1.1.3 to be pre-released as this fixes the crash on the box being emptied.

@DavidXanatos
Copy link
Member

could you please send me the RegPaths.dat from the affected box

@bastik-1001
Copy link
Collaborator Author

Since both of them are different, I uploaded both, not sure if it's the file or only the content, which I could have pasted here.

https://github.com/bastik-1001/Crashdump-and-trace/blob/main/RegPaths.dat

https://github.com/bastik-1001/Crashdump-and-trace/blob/main/Test%20Box%20RegPaths.dat

@DavidXanatos
Copy link
Member

hmm... really strange... for me this works fine no crash and the dat file looks fine as well.
So i take it if you clear the box content and try start->browse->... it still crashes?

@bastik-1001
Copy link
Collaborator Author

bastik-1001 commented Jun 18, 2022

Right now all I can do is delete the contents of the folder manually, as Sandman crashes when I try to let it do it.

When I remove the contents and try to Start -> Browse, it just opens Start, but pressing "Browse" does not do anything. Start.exe appears in the sandbox, but then it gets closed. I add a trace for that

09:06:33.254 Start.exe 3012 6552 Ipc (D) Open \KnownDlls\kernel32.dll
09:06:33.264 Start.exe 3012 6552 Ipc (D) Open \KnownDlls\KERNELBASE.dll
09:06:33.264 Start.exe 3012 6552 Ipc (D) Open \Sessions\1\Windows\SharedSection
09:06:33.264 Start.exe 3012 6552 Ipc (D) Open \Sessions\1\Windows\ApiPort
09:06:33.264 Start.exe 3012 6552 Ipc (D) Open \KnownDlls\PSAPI.DLL
09:06:33.264 Start.exe 3012 6552 Ipc (U) (2) \Sessions\1\BaseNamedObjects\SBIE_BOXED_DummyEvent_3012
09:06:33.264 Start.exe 3012 6552 Ipc (U) \GLOBAL??\C:
09:06:33.264 Start.exe 3012 6552 Ipc (U) \Device\HarddiskVolume2
09:06:33.264 Start.exe 3012 6552 Ipc (U) \Device
09:06:33.264 Start.exe 3012 6552 Drive (U) \Device\HarddiskVolume2
09:06:33.264 Start.exe 3012 6552 Ipc (U) \GLOBAL??\D:
09:06:33.264 Start.exe 3012 6552 Ipc (U) \Device\HarddiskVolume3
09:06:33.264 Start.exe 3012 6552 Ipc (U) \Device
09:06:33.264 Start.exe 3012 6552 Drive (U) \Device\HarddiskVolume3
09:06:33.264 Start.exe 3012 6552 Ipc (U) \GLOBAL??\E:
09:06:33.264 Start.exe 3012 6552 Ipc (U) \Device\HarddiskVolume4
09:06:33.264 Start.exe 3012 6552 Ipc (U) \Device
09:06:33.264 Start.exe 3012 6552 Drive (U) \Device\HarddiskVolume4
09:06:33.264 Start.exe 3012 6552 Ipc (U) \GLOBAL??\F:
09:06:33.264 Start.exe 3012 6552 Ipc (U) \Device\HarddiskVolume5
09:06:33.264 Start.exe 3012 6552 Ipc (U) \Device
09:06:33.264 Start.exe 3012 6552 Drive (U) \Device\HarddiskVolume5
09:06:33.264 Start.exe 3012 6552 Ipc (U) \GLOBAL??\G:
09:06:33.264 Start.exe 3012 6552 Ipc (U) \Device\HarddiskVolume7
09:06:33.264 Start.exe 3012 6552 Ipc (U) \Device
09:06:33.264 Start.exe 3012 6552 Drive (U) \Device\HarddiskVolume7
09:06:33.264 Start.exe 3012 6552 Ipc (U) \GLOBAL??\H:
09:06:33.264 Start.exe 3012 6552 Ipc (U) \Device\HarddiskVolume8
09:06:33.264 Start.exe 3012 6552 Ipc (U) \Device
09:06:33.264 Start.exe 3012 6552 Drive (U) \Device\HarddiskVolume8
09:06:33.264 Start.exe 3012 6552 Ipc (U) \GLOBAL??\I:
09:06:33.264 Start.exe 3012 6552 Ipc (U) \Device\HarddiskVolume9
09:06:33.264 Start.exe 3012 6552 Ipc (U) \Device
09:06:33.264 Start.exe 3012 6552 Drive (U) \Device\HarddiskVolume9
09:06:33.264 Start.exe 3012 6552 Ipc (U) \GLOBAL??\J:
09:06:33.264 Start.exe 3012 6552 Ipc (U) \Device\HarddiskVolume10
09:06:33.264 Start.exe 3012 6552 Ipc (U) \Device
09:06:33.264 Start.exe 3012 6552 Drive (U) \Device\HarddiskVolume10
09:06:33.264 Start.exe 3012 6552 Ipc (U) \GLOBAL??\K:
09:06:33.264 Start.exe 3012 6552 Ipc (U) \Device\CdRom1
09:06:33.264 Start.exe 3012 6552 Ipc (U) \Device
09:06:33.264 Start.exe 3012 6552 Drive (U) \Device\CdRom1
09:06:33.264 Start.exe 3012 6552 Ipc (U) \GLOBAL??\M:
09:06:33.264 Start.exe 3012 6552 Ipc (U) \Device\HarddiskVolume6
09:06:33.264 Start.exe 3012 6552 Ipc (U) \Device
09:06:33.264 Start.exe 3012 6552 Drive (U) \Device\HarddiskVolume6
09:06:33.264 Start.exe 3012 6552 Ipc (U) \GLOBAL??\N:
09:06:33.264 Start.exe 3012 6552 Ipc (U) \Device\CdRom0
09:06:33.264 Start.exe 3012 6552 Ipc (U) \Device
09:06:33.264 Start.exe 3012 6552 Drive (U) \Device\CdRom0
09:06:33.264 Start.exe 3012 6552 Ipc (U) \GLOBAL??\P:
09:06:33.264 Start.exe 3012 6552 Ipc (U) \Device\HarddiskVolume12
09:06:33.264 Start.exe 3012 6552 Ipc (U) \Device
09:06:33.264 Start.exe 3012 6552 Drive (U) \Device\HarddiskVolume12
09:06:33.264 Start.exe 3012 6552 Ipc (U) \GLOBAL??\Q:
09:06:33.264 Start.exe 3012 6552 Ipc (U) \Device\HarddiskVolume11
09:06:33.264 Start.exe 3012 6552 Ipc (U) \Device
09:06:33.264 Start.exe 3012 6552 Drive (U) \Device\HarddiskVolume11
09:06:33.264 Start.exe 3012 6552 Ipc (U) (2) \Sessions\1\BaseNamedObjects\SBIE_VCM_Mutex
09:06:33.274 Start.exe 3012 6552 Ipc / ??????????? (U) Open (2) \RPC Control\SbieSvcPort
09:06:33.274 Start.exe 3012 6552 Ipc (U) (2) \Sessions\1\BaseNamedObjects\SBIE_BOXED_RPCSS_SXS_READY
09:06:33.274 Start.exe 3012 6552 Ipc (U) (2) \Sessions\1\BaseNamedObjects\SBIE_BOXED_ServiceInitComplete_RpcSs
09:06:33.274 SandboxieRpcSs.exe 7696 6968 Ipc (D) Open \KnownDlls\kernel32.dll
09:06:33.304 SandboxieRpcSs.exe 7696 6968 Ipc (D) Open \KnownDlls\KERNELBASE.dll
09:06:33.304 SandboxieRpcSs.exe 7696 6968 Ipc (D) Open \Sessions\1\Windows\SharedSection
09:06:33.304 SandboxieRpcSs.exe 7696 6968 Ipc (D) Open \Sessions\1\Windows\ApiPort
09:06:33.304 SandboxieRpcSs.exe 7696 6968 Ipc (D) Open \KnownDlls\PSAPI.DLL
09:06:33.304 SandboxieRpcSs.exe 7696 6968 Ipc (U) (2) \Sessions\1\BaseNamedObjects\SBIE_BOXED_DummyEvent_7696
09:06:33.304 SandboxieRpcSs.exe 7696 6968 Ipc (U) \GLOBAL??\C:
09:06:33.304 SandboxieRpcSs.exe 7696 6968 Ipc (U) \Device\HarddiskVolume2
09:06:33.304 SandboxieRpcSs.exe 7696 6968 Ipc (U) \Device
09:06:33.304 SandboxieRpcSs.exe 7696 6968 Drive (U) \Device\HarddiskVolume2
09:06:33.304 SandboxieRpcSs.exe 7696 6968 Ipc (U) \GLOBAL??\D:
09:06:33.304 SandboxieRpcSs.exe 7696 6968 Ipc (U) \Device\HarddiskVolume3
09:06:33.304 SandboxieRpcSs.exe 7696 6968 Ipc (U) \Device
09:06:33.304 SandboxieRpcSs.exe 7696 6968 Drive (U) \Device\HarddiskVolume3
09:06:33.304 SandboxieRpcSs.exe 7696 6968 Ipc (U) \GLOBAL??\E:
09:06:33.304 SandboxieRpcSs.exe 7696 6968 Ipc (U) \Device\HarddiskVolume4
09:06:33.304 SandboxieRpcSs.exe 7696 6968 Ipc (U) \Device
09:06:33.304 SandboxieRpcSs.exe 7696 6968 Drive (U) \Device\HarddiskVolume4
09:06:33.304 SandboxieRpcSs.exe 7696 6968 Ipc (U) \GLOBAL??\F:
09:06:33.304 SandboxieRpcSs.exe 7696 6968 Ipc (U) \Device\HarddiskVolume5
09:06:33.304 SandboxieRpcSs.exe 7696 6968 Ipc (U) \Device
09:06:33.304 SandboxieRpcSs.exe 7696 6968 Drive (U) \Device\HarddiskVolume5
09:06:33.304 SandboxieRpcSs.exe 7696 6968 Ipc (U) \GLOBAL??\G:
09:06:33.304 SandboxieRpcSs.exe 7696 6968 Ipc (U) \Device\HarddiskVolume7
09:06:33.304 SandboxieRpcSs.exe 7696 6968 Ipc (U) \Device
09:06:33.304 SandboxieRpcSs.exe 7696 6968 Drive (U) \Device\HarddiskVolume7
09:06:33.304 SandboxieRpcSs.exe 7696 6968 Ipc (U) \GLOBAL??\H:
09:06:33.304 SandboxieRpcSs.exe 7696 6968 Ipc (U) \Device\HarddiskVolume8
09:06:33.304 SandboxieRpcSs.exe 7696 6968 Ipc (U) \Device
09:06:33.304 SandboxieRpcSs.exe 7696 6968 Drive (U) \Device\HarddiskVolume8
09:06:33.304 SandboxieRpcSs.exe 7696 6968 Ipc (U) \GLOBAL??\I:
09:06:33.304 SandboxieRpcSs.exe 7696 6968 Ipc (U) \Device\HarddiskVolume9
09:06:33.304 SandboxieRpcSs.exe 7696 6968 Ipc (U) \Device
09:06:33.304 SandboxieRpcSs.exe 7696 6968 Drive (U) \Device\HarddiskVolume9
09:06:33.304 SandboxieRpcSs.exe 7696 6968 Ipc (U) \GLOBAL??\J:
09:06:33.304 SandboxieRpcSs.exe 7696 6968 Ipc (U) \Device\HarddiskVolume10
09:06:33.304 SandboxieRpcSs.exe 7696 6968 Ipc (U) \Device
09:06:33.304 SandboxieRpcSs.exe 7696 6968 Drive (U) \Device\HarddiskVolume10
09:06:33.304 SandboxieRpcSs.exe 7696 6968 Ipc (U) \GLOBAL??\K:
09:06:33.304 SandboxieRpcSs.exe 7696 6968 Ipc (U) \Device\CdRom1
09:06:33.304 SandboxieRpcSs.exe 7696 6968 Ipc (U) \Device
09:06:33.304 SandboxieRpcSs.exe 7696 6968 Drive (U) \Device\CdRom1
09:06:33.304 SandboxieRpcSs.exe 7696 6968 Ipc (U) \GLOBAL??\M:
09:06:33.304 SandboxieRpcSs.exe 7696 6968 Ipc (U) \Device\HarddiskVolume6
09:06:33.304 SandboxieRpcSs.exe 7696 6968 Ipc (U) \Device
09:06:33.304 SandboxieRpcSs.exe 7696 6968 Drive (U) \Device\HarddiskVolume6
09:06:33.304 SandboxieRpcSs.exe 7696 6968 Ipc (U) \GLOBAL??\N:
09:06:33.304 SandboxieRpcSs.exe 7696 6968 Ipc (U) \Device\CdRom0
09:06:33.304 SandboxieRpcSs.exe 7696 6968 Ipc (U) \Device
09:06:33.304 SandboxieRpcSs.exe 7696 6968 Drive (U) \Device\CdRom0
09:06:33.304 SandboxieRpcSs.exe 7696 6968 Ipc (U) \GLOBAL??\P:
09:06:33.304 SandboxieRpcSs.exe 7696 6968 Ipc (U) \Device\HarddiskVolume12
09:06:33.304 SandboxieRpcSs.exe 7696 6968 Ipc (U) \Device
09:06:33.304 SandboxieRpcSs.exe 7696 6968 Drive (U) \Device\HarddiskVolume12
09:06:33.304 SandboxieRpcSs.exe 7696 6968 Ipc (U) \GLOBAL??\Q:
09:06:33.304 SandboxieRpcSs.exe 7696 6968 Ipc (U) \Device\HarddiskVolume11
09:06:33.304 SandboxieRpcSs.exe 7696 6968 Ipc (U) \Device
09:06:33.304 SandboxieRpcSs.exe 7696 6968 Drive (U) \Device\HarddiskVolume11
09:06:33.304 SandboxieRpcSs.exe 7696 6968 Ipc (U) (2) \Sessions\1\BaseNamedObjects\SBIE_VCM_Mutex
09:06:33.304 SandboxieRpcSs.exe 7696 6968 Ipc (D) Open \KnownDlls\WS2_32.dll
09:06:33.304 SandboxieRpcSs.exe 7696 6968 Ipc (D) Open \KnownDlls\MSVCRT.dll
09:06:33.304 SandboxieRpcSs.exe 7696 6968 Ipc (D) Open \KnownDlls\rpcrt4.dll
09:06:33.304 SandboxieRpcSs.exe 7696 6968 Ipc (D) Open \KnownDlls\NSI.dll
09:06:33.304 SandboxieRpcSs.exe 7696 6968 Ipc (D) Open \KnownDlls\advapi32.dll
09:06:33.304 SandboxieRpcSs.exe 7696 6968 Ipc (D) Open \KnownDlls\user32.dll
09:06:33.304 SandboxieRpcSs.exe 7696 6968 Ipc (D) Open \KnownDlls\gdi32.dll
09:06:33.304 SandboxieRpcSs.exe 7696 6968 Ipc (D) Open \KnownDlls\LPK.dll
09:06:33.304 SandboxieRpcSs.exe 7696 6968 Ipc (D) Open \KnownDlls\USP10.dll
09:06:33.304 SandboxieRpcSs.exe 7696 6968 Image (U) *:\program files\sandboxie-plus\sandboxierpcss.exe
09:06:33.304 SandboxieRpcSs.exe 7696 6968 Image (U) c:\windows\system32\ntdll.dll
09:06:33.304 SandboxieRpcSs.exe 7696 6968 Image (U) c:\windows\system32\kernel32.dll
09:06:33.304 SandboxieRpcSs.exe 7696 6968 Image (U) c:\windows\system32\kernelbase.dll
09:06:33.304 SandboxieRpcSs.exe 7696 6968 Image (U) c:\program files\sandboxie-plus\sbiedll.dll
09:06:33.304 SandboxieRpcSs.exe 7696 6968 Image (U) c:\windows\system32\psapi.dll
09:06:33.304 SandboxieRpcSs.exe 7696 6968 Image (U) c:\windows\system32\ws2_32.dll
09:06:33.304 SandboxieRpcSs.exe 7696 6968 Image (U) c:\windows\system32\msvcrt.dll
09:06:33.304 SandboxieRpcSs.exe 7696 6968 Image (U) c:\windows\system32\rpcrt4.dll
09:06:33.304 SandboxieRpcSs.exe 7696 6968 Image (U) c:\windows\system32\nsi.dll
09:06:33.304 SandboxieRpcSs.exe 7696 6968 Image (U) c:\windows\system32\advapi32.dll
09:06:33.304 SandboxieRpcSs.exe 7696 6968 Image (U) c:\windows\system32\sechost.dll
09:06:33.304 SandboxieRpcSs.exe 7696 6968 Image (U) c:\windows\system32\user32.dll
09:06:33.304 SandboxieRpcSs.exe 7696 6968 Ipc / ??????????? (U) \RPC Control\epmapper
09:06:33.304 SandboxieRpcSs.exe 7696 6968 Image (U) c:\windows\system32\gdi32.dll
09:06:33.304 SandboxieRpcSs.exe 7696 6968 Image (U) c:\windows\system32\lpk.dll
09:06:33.304 SandboxieRpcSs.exe 7696 6968 Image (U) c:\windows\system32\usp10.dll
09:06:33.314 SandboxieRpcSs.exe 7696 6968 Ipc (D) Open \KnownDlls\MSCTF.dll
09:06:33.314 SandboxieRpcSs.exe 7696 6968 Image (U) c:\windows\system32\imm32.dll
09:06:33.314 SandboxieRpcSs.exe 7696 6968 Image (U) c:\windows\system32\msctf.dll
09:06:33.314 SandboxieRpcSs.exe 7696 6968 Ipc / ??????????? (U) Open (2) \RPC Control\SbieSvcPort
09:06:33.314 SandboxieRpcSs.exe 7696 6968 Image (U) c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
09:06:33.314 SandboxieRpcSs.exe 7696 6968 Ipc (U) (2) \Sessions\1\BaseNamedObjects\SBIE_BOXED_ServiceInitComplete_Mutex1
09:06:33.314 SandboxieRpcSs.exe 7696 8876 Image (U) c:\windows\system32\sxs.dll
09:06:33.314 SandboxieRpcSs.exe 7696 8876 Ipc (D) Open \KnownDlls\ole32.dll
09:06:33.314 SandboxieRpcSs.exe 7696 8876 Image (U) c:\windows\system32\ole32.dll
09:06:33.314 SandboxieRpcSs.exe 7696 8876 Ipc / ??????????? (U) Open (2) \RPC Control\SbieSvcPort
09:06:33.314 SandboxieRpcSs.exe 7696 8876 Ipc (U) (2) \Sessions\1\BaseNamedObjects\SBIE_BOXED_RPCSS_SXS_READY
09:06:33.324 SandboxieRpcSs.exe 7696 6968 Ipc (U) \Sessions\1\BaseNamedObjects\Global\ComPlusCOMRegTable
09:06:33.324 SandboxieRpcSs.exe 7696 6968 Ipc (D) \Sessions\1\BaseNamedObjects\ComPlusCOMRegTable
09:06:33.324 SandboxieRpcSs.exe 7696 6968 Ipc (U) (2) \Sessions\1\BaseNamedObjects\SBIE_BOXED_ServiceInitComplete_RpcEptMapper
09:06:33.324 SandboxieRpcSs.exe 7696 6968 Image (U) c:\windows\system32\rpcepmap.dll
09:06:33.324 SandboxieRpcSs.exe 7696 10932 Image (U) c:\windows\system32\rpcrtremote.dll
09:06:33.324 SandboxieRpcSs.exe 7696 10932 Ipc (U) \GLOBAL??\NDIS
09:06:33.324 SandboxieRpcSs.exe 7696 10932 Ipc (U) \Device\Ndis
09:06:33.324 SandboxieRpcSs.exe 7696 10932 Ipc (U) \Device
09:06:33.324 SandboxieRpcSs.exe 7696 10932 Pipe / Pipe (U) \Device\Ndis
09:06:33.324 SandboxieRpcSs.exe 7696 10932 Ipc (U) \Device{553EE734-1D14-46DF-BF18-55D241263BAC}
09:06:33.324 SandboxieRpcSs.exe 7696 10932 Ipc (U) \Device\NDMP16
09:06:33.324 SandboxieRpcSs.exe 7696 10932 Ipc (U) \Device
09:06:33.324 SandboxieRpcSs.exe 7696 10932 Pipe / Pipe (U) \Device\NDMP16
09:06:33.324 SandboxieRpcSs.exe 7696 10932 Ipc (U) \Device{71F897D7-EB7C-4D8D-89DB-AC80D9DD2270}
09:06:33.324 SandboxieRpcSs.exe 7696 10932 Ipc (U) \Device\NDMP15
09:06:33.324 SandboxieRpcSs.exe 7696 10932 Ipc (U) \Device
09:06:33.324 SandboxieRpcSs.exe 7696 10932 Pipe / Pipe (U) \Device\NDMP15
09:06:33.324 SandboxieRpcSs.exe 7696 10932 Ipc (U) \Device{DF4A9D2C-8742-4EB1-8703-D395C4183F33}
09:06:33.324 SandboxieRpcSs.exe 7696 10932 Ipc (U) \Device\NDMP14
09:06:33.324 SandboxieRpcSs.exe 7696 10932 Ipc (U) \Device
09:06:33.324 SandboxieRpcSs.exe 7696 10932 Pipe / Pipe (U) \Device\NDMP14
09:06:33.324 SandboxieRpcSs.exe 7696 10932 Ipc (U) \Device{8E301A52-AFFA-4F49-B9CA-C79096A1A056}
09:06:33.324 SandboxieRpcSs.exe 7696 10932 Ipc (U) \Device\NDMP13
09:06:33.324 SandboxieRpcSs.exe 7696 10932 Ipc (U) \Device
09:06:33.324 SandboxieRpcSs.exe 7696 10932 Pipe / Pipe (U) \Device\NDMP13
09:06:33.324 SandboxieRpcSs.exe 7696 10932 Ipc (U) \Device\NdisWanIpv6
09:06:33.324 SandboxieRpcSs.exe 7696 10932 Ipc (U) \Device\NDMP12
09:06:33.324 SandboxieRpcSs.exe 7696 10932 Ipc (U) \Device
09:06:33.324 SandboxieRpcSs.exe 7696 10932 Pipe / Pipe (U) \Device\NDMP12
09:06:33.324 SandboxieRpcSs.exe 7696 10932 Ipc (U) \Device\NdisWanIp
09:06:33.324 SandboxieRpcSs.exe 7696 10932 Ipc (U) \Device\NDMP11
09:06:33.324 SandboxieRpcSs.exe 7696 10932 Ipc (U) \Device
09:06:33.324 SandboxieRpcSs.exe 7696 10932 Pipe / Pipe (U) \Device\NDMP11
09:06:33.324 SandboxieRpcSs.exe 7696 10932 Ipc (U) \Device\NdisWanBh
09:06:33.324 SandboxieRpcSs.exe 7696 10932 Ipc (U) \Device\NDMP10
09:06:33.324 SandboxieRpcSs.exe 7696 10932 Ipc (U) \Device
09:06:33.324 SandboxieRpcSs.exe 7696 10932 Pipe / Pipe (U) \Device\NDMP10
09:06:33.324 SandboxieRpcSs.exe 7696 10932 Ipc (U) \Device{E43D242B-9EAB-4626-A952-46649FBB939A}
09:06:33.324 SandboxieRpcSs.exe 7696 10932 Ipc (U) \Device\NDMP9
09:06:33.324 SandboxieRpcSs.exe 7696 10932 Ipc (U) \Device
09:06:33.324 SandboxieRpcSs.exe 7696 10932 Ipc (U) \Device{3A5D2E7A-BD12-4B41-88B5-0F9D3C80AAF5}
09:06:33.324 SandboxieRpcSs.exe 7696 10932 Ipc (U) \Device\NDMP8
09:06:33.324 SandboxieRpcSs.exe 7696 10932 Ipc (U) \Device
09:06:33.324 SandboxieRpcSs.exe 7696 10932 Pipe / Pipe (U) \Device\NDMP8
09:06:33.324 SandboxieRpcSs.exe 7696 10932 Ipc (U) \Device{3FAC5926-9BC3-4CD2-8632-B60C79479010}
09:06:33.324 SandboxieRpcSs.exe 7696 10932 Ipc (U) \Device\NDMP7
09:06:33.324 SandboxieRpcSs.exe 7696 10932 Ipc (U) \Device
09:06:33.324 SandboxieRpcSs.exe 7696 10932 Pipe / Pipe (U) \Device\NDMP7
09:06:33.324 SandboxieRpcSs.exe 7696 10932 Image (U) c:\windows\system32\secur32.dll
09:06:33.324 SandboxieRpcSs.exe 7696 10932 Image (U) c:\windows\system32\sspicli.dll
09:06:33.324 SandboxieRpcSs.exe 7696 10932 Image (U) c:\windows\system32\cryptsp.dll
09:06:33.324 SandboxieRpcSs.exe 7696 10932 Ipc (U) Open (2) \Security\LSA_AUTHENTICATION_INITIALIZED
09:06:33.324 SandboxieRpcSs.exe 7696 10932 Ipc / ??????????? (U) Open (2) \RPC Control\lsasspirpc
09:06:33.324 SandboxieRpcSs.exe 7696 10932 Image (U) c:\windows\system32\credssp.dll
09:06:33.324 SandboxieRpcSs.exe 7696 10932 Ipc (U) (2) \RPC Control\epmapper
09:06:33.334 SandboxieRpcSs.exe 7696 10932 Ipc (D) \Sessions\1\BaseNamedObjects\SBIE_BOXED_ServiceInitComplete_RpcEptMapper
09:06:33.334 SandboxieRpcSs.exe 7696 6968 Image (U) c:\windows\system32\rpcss.dll
09:06:33.334 SandboxieRpcSs.exe 7696 8400 WinClass (U) Sandboxie_DDE_ProxyClass1
09:06:33.334 SandboxieRpcSs.exe 7696 8400 Ipc / ??????????? (U) Open (2) \RPC Control\SbieSvcPort
09:06:33.334 SandboxieRpcSs.exe 7696 7428 Ipc / ??????????? (U) Open (2) \RPC Control\lsapolicylookup
09:06:33.334 SandboxieRpcSs.exe 7696 9004 Ipc (U) (2) \Sessions\1\BaseNamedObjects\SboxSession
09:06:33.334 SandboxieRpcSs.exe 7696 8400 Image (U) c:\windows\system32\uxtheme.dll
09:06:33.334 SandboxieRpcSs.exe 7696 8400 Ipc / ??????????? (U) Open (2) \ThemeApiPort
09:06:33.334 SandboxieRpcSs.exe 7696 8400 Image (U) c:\windows\system32\dwmapi.dll
09:06:33.334 SandboxieRpcSs.exe 7696 8400 Ipc (D) Open \KnownDlls\SHELL32.dll
09:06:33.334 SandboxieRpcSs.exe 7696 8400 Ipc (D) Open \KnownDlls\SHLWAPI.dll
09:06:33.334 SandboxieRpcSs.exe 7696 8400 Image (U) c:\windows\system32\shell32.dll
09:06:33.334 SandboxieRpcSs.exe 7696 8400 Image (U) c:\windows\system32\shlwapi.dll
09:06:33.334 SandboxieRpcSs.exe 7696 8400 Ipc (U) (4) \Sessions\1\BaseNamedObjects\windows_shell_global_counters
09:06:33.344 SandboxieRpcSs.exe 7696 8400 Ipc (D) Open \KnownDlls\OLEAUT32.dll
09:06:33.344 SandboxieRpcSs.exe 7696 8400 Image (U) c:\windows\system32\propsys.dll
09:06:33.344 SandboxieRpcSs.exe 7696 8400 Image (U) c:\windows\system32\oleaut32.dll
09:06:33.344 SandboxieRpcSs.exe 7696 8400 WinClass (U) Open (4) Shell_TrayWnd
09:06:33.344 SandboxieRpcSs.exe 7696 7428 Image (U) c:\windows\system32\cryptsp.dll
09:06:33.344 SandboxieRpcSs.exe 7696 7428 Image (U) c:\windows\system32\rsaenh.dll
09:06:33.344 SandboxieRpcSs.exe 7696 7428 Image (U) c:\windows\system32\cryptbase.dll
09:06:33.344 SandboxieRpcSs.exe 7696 7428 Ipc (U) \Device\KsecDD
09:06:33.344 SandboxieRpcSs.exe 7696 7428 Ipc (U) \Device
09:06:33.344 SandboxieRpcSs.exe 7696 7428 Pipe / Pipe (U) \Device\KsecDD
09:06:33.354 SandboxieRpcSs.exe 7696 7428 Ipc / ??????????? (U) \RPC Control\actkernel
09:06:33.354 SandboxieRpcSs.exe 7696 7428 Ipc (U) (2) \Sessions\1\BaseNamedObjects\SBIE_BOXED_ServiceInitComplete_DcomLaunch
09:06:33.354 SandboxieRpcSs.exe 7696 7428 File (U) Closed (2) \Device\HarddiskVolume2\Windows\system32\apphelp.dll
09:06:33.354 SandboxieRpcSs.exe 7696 7428 Debug (U) Trace CreateProcess: C:\Program Files\Sandboxie-Plus\SandboxieDcomLaunch.exe ("C:\Program Files\Sandboxie-Plus\SandboxieDcomLaunch.exe"); err=0
09:06:33.354 SandboxieDcomLaunch.exe 9932 11160 Ipc (D) Open \KnownDlls\kernel32.dll
09:06:33.384 SandboxieDcomLaunch.exe 9932 11160 Ipc (D) Open \KnownDlls\KERNELBASE.dll
09:06:33.384 SandboxieDcomLaunch.exe 9932 11160 Ipc (D) Open \Sessions\1\Windows\SharedSection
09:06:33.384 SandboxieDcomLaunch.exe 9932 11160 Ipc (D) Open \Sessions\1\Windows\ApiPort
09:06:33.384 SandboxieDcomLaunch.exe 9932 11160 Ipc (D) Open \KnownDlls\PSAPI.DLL
09:06:33.384 SandboxieDcomLaunch.exe 9932 11160 Ipc (U) (2) \Sessions\1\BaseNamedObjects\SBIE_BOXED_DummyEvent_9932
09:06:33.384 SandboxieDcomLaunch.exe 9932 11160 Ipc (U) \GLOBAL??\C:
09:06:33.384 SandboxieDcomLaunch.exe 9932 11160 Ipc (U) \Device\HarddiskVolume2
09:06:33.384 SandboxieDcomLaunch.exe 9932 11160 Ipc (U) \Device
09:06:33.384 SandboxieDcomLaunch.exe 9932 11160 Drive (U) \Device\HarddiskVolume2
09:06:33.384 SandboxieDcomLaunch.exe 9932 11160 Ipc (U) \GLOBAL??\D:
09:06:33.384 SandboxieDcomLaunch.exe 9932 11160 Ipc (U) \Device\HarddiskVolume3
09:06:33.384 SandboxieDcomLaunch.exe 9932 11160 Ipc (U) \Device
09:06:33.384 SandboxieDcomLaunch.exe 9932 11160 Drive (U) \Device\HarddiskVolume3
09:06:33.384 SandboxieDcomLaunch.exe 9932 11160 Ipc (U) \GLOBAL??\E:
09:06:33.384 SandboxieDcomLaunch.exe 9932 11160 Ipc (U) \Device\HarddiskVolume4
09:06:33.384 SandboxieDcomLaunch.exe 9932 11160 Ipc (U) \Device
09:06:33.384 SandboxieDcomLaunch.exe 9932 11160 Drive (U) \Device\HarddiskVolume4
09:06:33.384 SandboxieDcomLaunch.exe 9932 11160 Ipc (U) \GLOBAL??\F:
09:06:33.384 SandboxieDcomLaunch.exe 9932 11160 Ipc (U) \Device\HarddiskVolume5
09:06:33.384 SandboxieDcomLaunch.exe 9932 11160 Ipc (U) \Device
09:06:33.384 SandboxieDcomLaunch.exe 9932 11160 Drive (U) \Device\HarddiskVolume5
09:06:33.384 SandboxieDcomLaunch.exe 9932 11160 Ipc (U) \GLOBAL??\G:
09:06:33.384 SandboxieDcomLaunch.exe 9932 11160 Ipc (U) \Device\HarddiskVolume7
09:06:33.384 SandboxieDcomLaunch.exe 9932 11160 Ipc (U) \Device
09:06:33.384 SandboxieDcomLaunch.exe 9932 11160 Drive (U) \Device\HarddiskVolume7
09:06:33.384 SandboxieDcomLaunch.exe 9932 11160 Ipc (U) \GLOBAL??\H:
09:06:33.384 SandboxieDcomLaunch.exe 9932 11160 Ipc (U) \Device\HarddiskVolume8
09:06:33.384 SandboxieDcomLaunch.exe 9932 11160 Ipc (U) \Device
09:06:33.384 SandboxieDcomLaunch.exe 9932 11160 Drive (U) \Device\HarddiskVolume8
09:06:33.384 SandboxieDcomLaunch.exe 9932 11160 Ipc (U) \GLOBAL??\I:
09:06:33.384 SandboxieDcomLaunch.exe 9932 11160 Ipc (U) \Device\HarddiskVolume9
09:06:33.384 SandboxieDcomLaunch.exe 9932 11160 Ipc (U) \Device
09:06:33.384 SandboxieDcomLaunch.exe 9932 11160 Drive (U) \Device\HarddiskVolume9
09:06:33.384 SandboxieDcomLaunch.exe 9932 11160 Ipc (U) \GLOBAL??\J:
09:06:33.384 SandboxieDcomLaunch.exe 9932 11160 Ipc (U) \Device\HarddiskVolume10
09:06:33.384 SandboxieDcomLaunch.exe 9932 11160 Ipc (U) \Device
09:06:33.384 SandboxieDcomLaunch.exe 9932 11160 Drive (U) \Device\HarddiskVolume10
09:06:33.384 SandboxieDcomLaunch.exe 9932 11160 Ipc (U) \GLOBAL??\K:
09:06:33.384 SandboxieDcomLaunch.exe 9932 11160 Ipc (U) \Device\CdRom1
09:06:33.384 SandboxieDcomLaunch.exe 9932 11160 Ipc (U) \Device
09:06:33.384 SandboxieDcomLaunch.exe 9932 11160 Drive (U) \Device\CdRom1
09:06:33.384 SandboxieDcomLaunch.exe 9932 11160 Ipc (U) \GLOBAL??\M:
09:06:33.384 SandboxieDcomLaunch.exe 9932 11160 Ipc (U) \Device\HarddiskVolume6
09:06:33.384 SandboxieDcomLaunch.exe 9932 11160 Ipc (U) \Device
09:06:33.384 SandboxieDcomLaunch.exe 9932 11160 Drive (U) \Device\HarddiskVolume6
09:06:33.384 SandboxieDcomLaunch.exe 9932 11160 Ipc (U) \GLOBAL??\N:
09:06:33.384 SandboxieDcomLaunch.exe 9932 11160 Ipc (U) \Device\CdRom0
09:06:33.384 SandboxieDcomLaunch.exe 9932 11160 Ipc (U) \Device
09:06:33.384 SandboxieDcomLaunch.exe 9932 11160 Drive (U) \Device\CdRom0
09:06:33.384 SandboxieDcomLaunch.exe 9932 11160 Ipc (U) \GLOBAL??\P:
09:06:33.384 SandboxieDcomLaunch.exe 9932 11160 Ipc (U) \Device\HarddiskVolume12
09:06:33.384 SandboxieDcomLaunch.exe 9932 11160 Ipc (U) \Device
09:06:33.384 SandboxieDcomLaunch.exe 9932 11160 Drive (U) \Device\HarddiskVolume12
09:06:33.384 SandboxieDcomLaunch.exe 9932 11160 Ipc (U) \GLOBAL??\Q:
09:06:33.384 SandboxieDcomLaunch.exe 9932 11160 Ipc (U) \Device\HarddiskVolume11
09:06:33.384 SandboxieDcomLaunch.exe 9932 11160 Ipc (U) \Device
09:06:33.384 SandboxieDcomLaunch.exe 9932 11160 Drive (U) \Device\HarddiskVolume11
09:06:33.384 SandboxieDcomLaunch.exe 9932 11160 Ipc (U) (2) \Sessions\1\BaseNamedObjects\SBIE_VCM_Mutex
09:06:33.384 SandboxieDcomLaunch.exe 9932 11160 Ipc / ??????????? (U) Open (2) \RPC Control\SbieSvcPort
09:06:33.384 SandboxieDcomLaunch.exe 9932 11160 Ipc (U) (2) \Sessions\1\BaseNamedObjects\SboxSession
09:06:33.384 SandboxieDcomLaunch.exe 9932 11160 Ipc (D) Open \KnownDlls\advapi32.dll
09:06:33.384 SandboxieDcomLaunch.exe 9932 11160 Ipc (D) Open \KnownDlls\MSVCRT.dll
09:06:33.384 SandboxieDcomLaunch.exe 9932 11160 Ipc (D) Open \KnownDlls\rpcrt4.dll
09:06:33.384 SandboxieDcomLaunch.exe 9932 11160 Ipc (D) Open \KnownDlls\user32.dll
09:06:33.384 SandboxieDcomLaunch.exe 9932 11160 Ipc (D) Open \KnownDlls\gdi32.dll
09:06:33.384 SandboxieDcomLaunch.exe 9932 11160 Ipc (D) Open \KnownDlls\LPK.dll
09:06:33.384 SandboxieDcomLaunch.exe 9932 11160 Ipc (D) Open \KnownDlls\USP10.dll
09:06:33.384 SandboxieDcomLaunch.exe 9932 11160 Image (U) *:\program files\sandboxie-plus\sandboxiedcomlaunch.exe
09:06:33.384 SandboxieDcomLaunch.exe 9932 11160 Image (U) c:\windows\system32\ntdll.dll
09:06:33.384 SandboxieDcomLaunch.exe 9932 11160 Image (U) c:\windows\system32\kernel32.dll
09:06:33.384 SandboxieDcomLaunch.exe 9932 11160 Image (U) c:\windows\system32\kernelbase.dll
09:06:33.384 SandboxieDcomLaunch.exe 9932 11160 Image (U) c:\program files\sandboxie-plus\sbiedll.dll
09:06:33.384 SandboxieDcomLaunch.exe 9932 11160 Image (U) c:\windows\system32\psapi.dll
09:06:33.384 SandboxieDcomLaunch.exe 9932 11160 Image (U) c:\windows\system32\advapi32.dll
09:06:33.384 SandboxieDcomLaunch.exe 9932 11160 Image (U) c:\windows\system32\msvcrt.dll
09:06:33.384 SandboxieDcomLaunch.exe 9932 11160 Image (U) c:\windows\system32\sechost.dll
09:06:33.384 SandboxieDcomLaunch.exe 9932 11160 Image (U) c:\windows\system32\rpcrt4.dll
09:06:33.384 SandboxieDcomLaunch.exe 9932 11160 Image (U) c:\windows\system32\user32.dll
09:06:33.384 SandboxieDcomLaunch.exe 9932 11160 Ipc / ??????????? (U) \RPC Control\epmapper
09:06:33.384 SandboxieDcomLaunch.exe 9932 11160 Image (U) c:\windows\system32\gdi32.dll
09:06:33.384 SandboxieDcomLaunch.exe 9932 11160 Image (U) c:\windows\system32\lpk.dll
09:06:33.384 SandboxieDcomLaunch.exe 9932 11160 Image (U) c:\windows\system32\usp10.dll
09:06:33.384 SandboxieDcomLaunch.exe 9932 11160 Ipc (D) Open \KnownDlls\MSCTF.dll
09:06:33.384 SandboxieDcomLaunch.exe 9932 11160 Image (U) c:\windows\system32\imm32.dll
09:06:33.384 SandboxieDcomLaunch.exe 9932 11160 Image (U) c:\windows\system32\msctf.dll
09:06:33.384 SandboxieDcomLaunch.exe 9932 11160 Image (U) c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
09:06:33.394 SandboxieDcomLaunch.exe 9932 11160 Image (U) c:\windows\system32\rpcss.dll
09:06:33.394 SandboxieDcomLaunch.exe 9932 11160 Image (U) c:\windows\system32\sspicli.dll
09:06:33.394 SandboxieDcomLaunch.exe 9932 10396 Ipc / ??????????? (U) Open (2) \RPC Control\lsapolicylookup
09:06:33.394 SandboxieDcomLaunch.exe 9932 10396 Image (U) c:\windows\system32\cryptsp.dll
09:06:33.394 SandboxieDcomLaunch.exe 9932 10396 Ipc (U) Open (2) \Security\LSA_AUTHENTICATION_INITIALIZED
09:06:33.394 SandboxieDcomLaunch.exe 9932 10396 Ipc / ??????????? (U) Open (2) \RPC Control\lsasspirpc
09:06:33.394 SandboxieDcomLaunch.exe 9932 10396 Image (U) c:\windows\system32\credssp.dll
09:06:33.394 SandboxieDcomLaunch.exe 9932 10396 Ipc (U) (2) \RPC Control\actkernel
09:06:33.394 SandboxieDcomLaunch.exe 9932 10396 Ipc (U) \Sessions\1\BaseNamedObjects\Global_ComCatalogCache_
09:06:33.394 SandboxieDcomLaunch.exe 9932 10396 Ipc (D) \Sessions\1\BaseNamedObjects_ComCatalogCache_
09:06:33.394 SandboxieDcomLaunch.exe 9932 10396 Image (U) c:\windows\system32\rpcrtremote.dll
09:06:33.394 SandboxieDcomLaunch.exe 9932 10396 Ipc / ??????????? (U) (2) \RPC Control\epmapper
09:06:33.394 SandboxieDcomLaunch.exe 9932 10396 Ipc (D) \Sessions\1\BaseNamedObjects\SBIE_BOXED_ServiceInitComplete_DcomLaunch
09:06:33.404 SandboxieRpcSs.exe 7696 7428 Ipc (D) \RPC Control\actkernel
09:06:33.404 SandboxieRpcSs.exe 7696 7428 Ipc (U) (2) \Sessions\1\BaseNamedObjects\ScmCreatedEvent
09:06:33.404 SandboxieRpcSs.exe 7696 7428 Ipc (D) \Sessions\1\BaseNamedObjects\SBIE_BOXED_ServiceInitComplete_RpcSs
09:06:33.404 Start.exe 3012 6552 Ipc / ??????????? (U) \RPC Control\epmapper
09:06:33.404 Start.exe 3012 6552 Ipc (D) \Sessions\1\BaseNamedObjects\SBIE_BOXED_ServiceInitComplete_DcomLaunch
09:06:33.404 SandboxieDcomLaunch.exe 9932 2768 Ipc (U) \Sessions\1\BaseNamedObjects\Global\RotHintTable
09:06:33.404 SandboxieDcomLaunch.exe 9932 2768 Ipc (D) \Sessions\1\BaseNamedObjects\RotHintTable
09:06:33.404 SandboxieDcomLaunch.exe 9932 2768 Ipc (U) \Sessions\1\BaseNamedObjects\Global{A3BD3259-3E4F-428a-84C8-F0463A9D3EB5}
09:06:33.404 SandboxieDcomLaunch.exe 9932 2768 Ipc (D) \Sessions\1\BaseNamedObjects{A3BD3259-3E4F-428a-84C8-F0463A9D3EB5}
09:06:33.404 SandboxieDcomLaunch.exe 9932 2768 Ipc (U) \Sessions\1\BaseNamedObjects\Global{A64C7F33-DA35-459b-96CA-63B51FB0CDB9}
09:06:33.404 SandboxieDcomLaunch.exe 9932 2768 Ipc (D) \Sessions\1\BaseNamedObjects{A64C7F33-DA35-459b-96CA-63B51FB0CDB9}
09:06:33.404 Start.exe 3012 6552 Ipc (U) (2) \Sessions\1\BaseNamedObjects\SboxSession
09:06:33.414 Start.exe 3012 6552 Ipc (D) Open \KnownDlls\user32.dll
09:06:33.414 Start.exe 3012 6552 Ipc (D) Open \KnownDlls\gdi32.dll
09:06:33.414 Start.exe 3012 6552 Ipc (D) Open \KnownDlls\LPK.dll
09:06:33.414 Start.exe 3012 6552 Ipc (D) Open \KnownDlls\USP10.dll
09:06:33.414 Start.exe 3012 6552 Ipc (D) Open \KnownDlls\MSVCRT.dll
09:06:33.414 Start.exe 3012 6552 Ipc (D) Open \KnownDlls\SHELL32.dll
09:06:33.414 Start.exe 3012 6552 Ipc (D) Open \KnownDlls\SHLWAPI.dll
09:06:33.414 Start.exe 3012 6552 Ipc (D) Open \KnownDlls\ole32.dll
09:06:33.414 Start.exe 3012 6552 Ipc (D) Open \KnownDlls\rpcrt4.dll
09:06:33.414 Start.exe 3012 6552 Ipc (D) Open \KnownDlls\advapi32.dll
09:06:33.414 Start.exe 3012 6552 Ipc (D) Open \KnownDlls\COMDLG32.dll
09:06:33.414 Start.exe 3012 6552 Image (U) *:\program files\sandboxie-plus\start.exe
09:06:33.414 Start.exe 3012 6552 Image (U) c:\windows\system32\ntdll.dll
09:06:33.414 Start.exe 3012 6552 Image (U) c:\windows\system32\kernel32.dll
09:06:33.414 Start.exe 3012 6552 Image (U) c:\windows\system32\kernelbase.dll
09:06:33.414 Start.exe 3012 6552 Image (U) c:\program files\sandboxie-plus\sbiedll.dll
09:06:33.414 Start.exe 3012 6552 Image (U) c:\windows\system32\psapi.dll
09:06:33.414 Start.exe 3012 6552 Image (U) c:\windows\system32\user32.dll
09:06:33.414 Start.exe 3012 6552 Image (U) c:\windows\system32\gdi32.dll
09:06:33.414 Start.exe 3012 6552 Image (U) c:\windows\system32\lpk.dll
09:06:33.414 Start.exe 3012 6552 Image (U) c:\windows\system32\usp10.dll
09:06:33.414 Start.exe 3012 6552 Image (U) c:\windows\system32\msvcrt.dll
09:06:33.414 Start.exe 3012 6552 Image (U) c:\windows\system32\shell32.dll
09:06:33.414 Start.exe 3012 6552 Image (U) c:\windows\system32\shlwapi.dll
09:06:33.414 Start.exe 3012 6552 Image (U) c:\windows\system32\ole32.dll
09:06:33.414 Start.exe 3012 6552 Image (U) c:\windows\system32\rpcrt4.dll
09:06:33.414 Start.exe 3012 6552 Image (U) c:\windows\system32\advapi32.dll
09:06:33.414 Start.exe 3012 6552 Image (U) c:\windows\system32\sechost.dll
09:06:33.424 Start.exe 3012 6552 Image (U) c:\windows\winsxs\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.24483_none_e372d88f30fbb845\comctl32.dll
09:06:33.424 Start.exe 3012 6552 Image (U) c:\windows\system32\comdlg32.dll
09:06:33.424 Start.exe 3012 6552 Ipc (D) Open \KnownDlls\MSCTF.dll
09:06:33.424 Start.exe 3012 6552 Image (U) c:\windows\system32\imm32.dll
09:06:33.424 Start.exe 3012 6552 Image (U) c:\windows\system32\msctf.dll
09:06:33.434 Start.exe 3012 6552 Ipc (U) (2) \Sessions\1\BaseNamedObjects\SBIE_BOXED_ServiceInitComplete_RpcSs
09:06:33.434 Start.exe 3012 7612 Ipc (D) \Sessions\1\BaseNamedObjects\SBIE_BOXED_ServiceInitComplete_DcomLaunch
09:06:33.434 Start.exe 3012 6552 Image (U) c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
09:06:33.434 Start.exe 3012 6552 Image (U) c:\windows\system32\cryptbase.dll
09:06:33.434 Start.exe 3012 6552 Ipc (U) \Device\KsecDD
09:06:33.434 Start.exe 3012 6552 Ipc (U) \Device
09:06:33.434 Start.exe 3012 6552 Pipe / Pipe (U) \Device\KsecDD
09:06:33.434 Start.exe 3012 6552 Ipc (U) (2) \Sessions\1\BaseNamedObjects\windows_shell_global_counters
09:06:33.434 Start.exe 3012 6552 Image (U) c:\windows\system32\uxtheme.dll
09:06:33.434 Start.exe 3012 6552 Ipc / ??????????? (U) Open (2) \ThemeApiPort
09:06:33.444 Start.exe 3012 6552 Image (U) c:\tools\rbtray\rbhook.dll
09:06:33.444 Start.exe 3012 6552 Image (U) c:\windows\system32\pstorec.dll
09:06:33.444 Start.exe 3012 6552 Image (U) c:\windows\system32\atl.dll
09:06:33.444 Start.exe 3012 6552 Ipc (U) (2) \Sessions\1\BaseNamedObjects\SBIE_ProtectedStorage_Mutex
09:06:33.444 Start.exe 3012 6552 Ipc (U) (2) \Sessions\1\BaseNamedObjects\SBIE_ProtectedStorage_Section
09:06:33.444 Start.exe 3012 6552 Image (U) c:\windows\system32\dwmapi.dll
09:06:33.444 Start.exe 3012 6552 Ipc (D) Open \KnownDlls\OLEAUT32.dll
09:06:33.444 Start.exe 3012 6552 Image (U) c:\windows\system32\propsys.dll
09:06:33.444 Start.exe 3012 6552 Image (U) c:\windows\system32\oleaut32.dll
09:06:33.444 Start.exe 3012 6552 WinClass (U) Open (4) Shell_TrayWnd
09:06:33.454 Start.exe 3012 6552 Ipc (U) Open (2) \Sessions\1\BaseNamedObjects\MSCTF.CtfActivated.Default1
09:06:33.454 Start.exe 3012 6552 Ipc / ??????????? (U) Open (2) \BaseNamedObjects\msctf.serverDefault1
09:06:33.454 Start.exe 3012 6552 Ipc (D) $:taskhost.exe
09:06:33.454 Start.exe 3012 6552 Ipc (U) Open (2) \Sessions\1\BaseNamedObjects\MSCTF.Asm.MutexDefault1
09:06:33.454 Start.exe 3012 6552 Ipc (U) Open (2) \Sessions\1\BaseNamedObjects\MSCTF.AsmCacheReady.Default1
09:06:33.454 Start.exe 3012 6552 Ipc (U) Open (4) \Sessions\1\BaseNamedObjects\CTF.AsmListCache.FMPDefault1
09:06:33.484 Start.exe 3012 6552 Ipc (U) \BaseNamedObjects_ComCatalogCache_
09:06:33.484 Start.exe 3012 6552 Ipc (D) \Sessions\1\BaseNamedObjects_ComCatalogCache_
09:06:33.484 Start.exe 3012 6552 Ipc (D) Open \KnownDlls\clbcatq.dll
09:06:33.484 Start.exe 3012 6552 Ipc (U) Open (2) \KernelObjects\MaximumCommitCondition
09:06:33.484 Start.exe 3012 6552 Image (U) c:\windows\system32\clbcatq.dll
09:06:33.484 Start.exe 3012 6552 Ipc (U) \BaseNamedObjects_ComCatalogCache_
09:06:33.484 Start.exe 3012 6552 Ipc (D) \Sessions\1\BaseNamedObjects_ComCatalogCache_
09:06:33.514 Start.exe 3012 6552 WinClass (U) (4) Auto-Suggest Dropdown
09:06:33.514 Start.exe 3012 6552 WinClass (U) Open (6) RBTrayHook
09:06:33.514 Start.exe 3012 6552 WinClass (U) Open (4) Shell_TrayWnd
09:06:33.514 Start.exe 3012 6552 WinClass (U) #32769
09:06:33.514 Start.exe 3012 6552 WinClass (U) Open (3) RBTrayHook
09:06:33.514 Start.exe 3012 6552 WinClass (U) (8) #32769
09:06:35.574 Start.exe 3012 6552 WinClass (U) (10) #32769
09:06:38.824 Start.exe 3012 6552 Ipc (U) (4) \Sessions\1\BaseNamedObjects\SBIE_VCM_Mutex
09:06:38.824 SandboxieRpcSs.exe 7696 8876 Ipc (U) (4) \Sessions\1\BaseNamedObjects\SBIE_VCM_Mutex
09:06:38.824 Start.exe 3012 6552 WinClass (U) Open (4) Shell_TrayWnd
09:06:38.824 Start.exe 3012 6552 WinClass (U) (2) Progman
09:06:38.824 Start.exe 3012 6552 RtClass (U) (2) $:explorer.exe
09:06:38.824 Start.exe 3012 6552 WinClass (U) Closed Progman
09:06:38.824 Start.exe 3012 2716 Ipc / ??????????? (U) Open (2) \RPC Control\SbieSvcPort
09:06:38.824 Start.exe 3012 2716 WinClass (U) Open (4) Shell_TrayWnd
09:06:38.824 Start.exe 3012 2716 Ipc / ??????????? (U) Open (2) \RPC Control\lsapolicylookup
09:06:38.824 Start.exe 3012 2716 Ipc / ??????????? (U) \RPC Control\epmapper
09:06:38.824 Start.exe 3012 2716 Ipc (U) (2) \Sessions\1\BaseNamedObjects\SBIE_BOXED_ServiceInitComplete_RpcSs
09:06:38.824 Start.exe 3012 2716 Ipc (D) \Sessions\1\BaseNamedObjects\SBIE_BOXED_ServiceInitComplete_DcomLaunch
09:06:38.824 Start.exe 3012 2716 Ipc (D) \RPC Control\epmapper
09:06:38.824 Start.exe 3012 2716 Ipc (U) (2) \RPC Control\OLEC853B72A88B5478FB8B4A9DFBA0E
09:06:38.834 Start.exe 3012 2716 Image (U) c:\windows\system32\cryptsp.dll
09:06:38.834 Start.exe 3012 2716 Image (U) c:\windows\system32\rsaenh.dll
09:06:38.834 Start.exe 3012 6552 ComClass (U) (2) {53BD6B4E-3780-4693-AFC3-7161C2F3EE9C} MruLongList
09:06:38.844 Start.exe 3012 2716 Image (U) c:\windows\system32\rpcrtremote.dll
09:06:38.844 SandboxieRpcSs.exe 7696 3024 Ipc (D) \RPC Control\OLEC853B72A88B5478FB8B4A9DFBA0E
09:06:38.844 SandboxieRpcSs.exe 7696 3024 Ipc (U) \BaseNamedObjects_ComCatalogCache_
09:06:38.844 SandboxieRpcSs.exe 7696 3024 Ipc (D) \Sessions\1\BaseNamedObjects_ComCatalogCache_
09:06:38.844 SandboxieRpcSs.exe 7696 3024 Ipc (D) Open \KnownDlls\clbcatq.dll
09:06:38.844 SandboxieRpcSs.exe 7696 3024 Ipc (U) Open (2) \KernelObjects\MaximumCommitCondition
09:06:38.844 SandboxieRpcSs.exe 7696 3024 Image (U) c:\windows\system32\clbcatq.dll
09:06:38.844 SandboxieRpcSs.exe 7696 3024 Ipc (U) \BaseNamedObjects_ComCatalogCache_
09:06:38.844 SandboxieRpcSs.exe 7696 3024 Ipc (D) \Sessions\1\BaseNamedObjects_ComCatalogCache_
09:06:38.844 SandboxieRpcSs.exe 7696 3024 Ipc / ??????????? (U) Open (2) \RPC Control\SbieSvcPort
09:06:38.844 Start.exe 3012 6552 WinClass (U) Open (3) RBTrayHook
09:06:38.854 Start.exe 3012 6552 WinClass (U) (2) Auto-Suggest Dropdown
09:06:38.854 Start.exe 3012 6552 WinClass (U) Open (6) RBTrayHook
09:06:38.854 Start.exe 3012 6552 WinClass (U) Open (4) Shell_TrayWnd
09:06:38.884 Start.exe 3012 6552 Image (U) c:\windows\system32\explorerframe.dll
09:06:38.884 Start.exe 3012 6552 Image (U) c:\windows\system32\duser.dll
09:06:38.884 Start.exe 3012 6552 Image (U) c:\windows\system32\dui70.dll
09:06:38.884 Start.exe 3012 6552 WinClass (U) ReaderModeCtl
09:06:38.894 Start.exe 3012 6552 WinClass (U) (4) TravelBand
09:06:38.894 Start.exe 3012 6552 WinClass (U) (4) Breadcrumb Parent
09:06:38.894 Start.exe 3012 6552 WinClass (U) (4) Address Band Root
09:06:38.894 Start.exe 3012 6552 WinClass (U) (2) Breadcrumb Parent
09:06:38.894 Start.exe 3012 6552 Image (U) c:\windows\system32\windowscodecs.dll
09:06:38.894 Start.exe 3012 6552 Image (U) c:\windows\system32\apphelp.dll
09:06:38.894 Start.exe 3012 6552 Ipc (D) Open \KnownDlls\Setupapi.dll
09:06:38.904 Start.exe 3012 6552 Ipc (D) Open \KnownDlls\CFGMGR32.dll
09:06:38.904 Start.exe 3012 6552 Ipc (D) Open \KnownDlls\DEVOBJ.dll
09:06:38.904 Start.exe 3012 6552 Image (U) c:\windows\system32\ehstorshell.dll
09:06:38.904 Start.exe 3012 6552 Image (U) c:\windows\system32\setupapi.dll
09:06:38.904 Start.exe 3012 6552 Image (U) c:\windows\system32\cfgmgr32.dll
09:06:38.904 Start.exe 3012 6552 Image (U) c:\windows\system32\devobj.dll
09:06:38.934 Start.exe 3012 6552 Image (U) c:\program files\linkshellextension\hardlinkshellext.dll
09:06:38.934 Start.exe 3012 6552 Image (U) c:\windows\system32\mpr.dll
09:06:38.934 Start.exe 3012 6552 Image (U) c:\windows\system32\netapi32.dll
09:06:38.934 Start.exe 3012 6552 Image (U) c:\windows\system32\netutils.dll
09:06:38.934 Start.exe 3012 6552 Image (U) c:\windows\system32\srvcli.dll
09:06:38.934 Start.exe 3012 6552 Image (U) c:\windows\system32\wkscli.dll
09:06:38.934 Start.exe 3012 6552 Image (U) c:\windows\system32\msvcp140.dll
09:06:38.934 Start.exe 3012 6552 Image (U) c:\windows\system32\vcruntime140.dll
09:06:38.934 Start.exe 3012 6552 Image (U) c:\windows\system32\api-ms-win-crt-runtime-l1-1-0.dll
09:06:38.934 Start.exe 3012 6552 Image (U) c:\windows\system32\ucrtbase.dll
09:06:38.934 Start.exe 3012 6552 Image (U) c:\windows\system32\api-ms-win-core-timezone-l1-1-0.dll
09:06:38.934 Start.exe 3012 6552 Image (U) c:\windows\system32\api-ms-win-core-file-l2-1-0.dll
09:06:38.934 Start.exe 3012 6552 Image (U) c:\windows\system32\api-ms-win-core-localization-l1-2-0.dll
09:06:38.934 Start.exe 3012 6552 Image (U) c:\windows\system32\api-ms-win-core-processthreads-l1-1-1.dll
09:06:38.934 Start.exe 3012 6552 Image (U) c:\windows\system32\api-ms-win-core-file-l1-2-0.dll
09:06:38.934 Start.exe 3012 6552 Image (U) c:\windows\system32\api-ms-win-crt-heap-l1-1-0.dll
09:06:38.934 Start.exe 3012 6552 Image (U) c:\windows\system32\api-ms-win-crt-string-l1-1-0.dll
09:06:38.934 Start.exe 3012 6552 Image (U) c:\windows\system32\api-ms-win-crt-stdio-l1-1-0.dll
09:06:38.934 Start.exe 3012 6552 Image (U) c:\windows\system32\api-ms-win-crt-convert-l1-1-0.dll
09:06:38.934 Start.exe 3012 6552 Image (U) c:\windows\system32\vcruntime140_1.dll
09:06:38.934 Start.exe 3012 6552 Image (U) c:\windows\system32\api-ms-win-crt-locale-l1-1-0.dll
09:06:38.934 Start.exe 3012 6552 Image (U) c:\windows\system32\api-ms-win-crt-filesystem-l1-1-0.dll
09:06:38.934 Start.exe 3012 6552 Image (U) c:\windows\system32\api-ms-win-crt-time-l1-1-0.dll
09:06:38.934 Start.exe 3012 6552 Image (U) c:\windows\system32\api-ms-win-crt-environment-l1-1-0.dll
09:06:38.934 Start.exe 3012 6552 Image (U) c:\windows\system32\api-ms-win-crt-math-l1-1-0.dll
09:06:38.934 Start.exe 3012 6552 Image (U) c:\windows\system32\api-ms-win-crt-utility-l1-1-0.dll
09:06:38.934 Start.exe 3012 6552 Ipc / ??????????? (U) Open (2) \RPC Control\LSARPC_ENDPOINT
09:06:38.944 Start.exe 3012 6552 Image (U) c:\windows\system32\ntshrui.dll
09:06:38.944 Start.exe 3012 6552 Ipc (U) Open ??\PIPE\srvsvc
09:06:38.944 Start.exe 3012 6552 Ipc (U) Open \GLOBAL??\PIPE
09:06:38.944 Start.exe 3012 6552 Pipe (U) (2) \Device\NamedPipe\srvsvc
09:06:38.944 Start.exe 3012 6552 Image (U) c:\windows\system32\cscapi.dll
09:06:38.944 Start.exe 3012 6552 Image (U) c:\windows\system32\slc.dll
09:06:38.954 Start.exe 3012 6552 WinClass (U) (4) UniversalSearchBand
09:06:38.954 Start.exe 3012 6552 WinClass (U) (4) Search Box
09:06:38.954 Start.exe 3012 6552 WinClass (U) (4) SearchEditBoxWrapperClass
09:06:38.954 Start.exe 3012 6552 WinClass (U) (3) DirectUIHWND
09:06:38.964 Start.exe 3012 6552 Image (U) c:\windows\system32\xmllite.dll
09:06:38.964 Start.exe 3012 6552 WinClass (U) RICHEDIT50W
09:06:38.964 Start.exe 3012 6552 Image (U) c:\windows\system32\msftedit.dll
09:06:38.974 Start.exe 3012 6552 Image (U) c:\windows\system32\msls31.dll
09:06:38.974 Start.exe 3012 6552 WinClass (U) (3) _SearchEditBoxFakeWindow
09:06:38.974 Start.exe 3012 6552 Ipc / ??????????? (U) Open (2) \UxSmsApiPort
09:06:38.974 Start.exe 3012 6552 Ipc / ??????????? (U) Open (2) \Sessions\1\BaseNamedObjects\Dwm-426C-ApiPort-114B
09:06:38.974 Start.exe 3012 6552 Ipc (U) (2) \Sessions\1\BaseNamedObjects\SBIE_VCM_Mutex

Edit: When I remove UseRegDeleteV2=y and just do Start-> Browse, I can browse, the folder selction appears and I can go to other locations. (I don't launch anything.) Once I add UseRegDeleteV2=y again and I do Start->Browse Start.exe crashes, once I try to naviage elsewhere.

@DavidXanatos
Copy link
Member

could oyu please try a clean install with no custom settings in the sandboxie.ini
this crash is very strange

@DavidXanatos
Copy link
Member

please try this sbiedll's: xanasoft.com/Downloads/SbieDll.1.1.3.1.zip

@bastik-1001
Copy link
Collaborator Author

Those dlls fix the issue.

I came back to see you having posted two attempts to fix this and as replacing the dlls was the easier one, I replaced those before attempting the clean install. I omitted installing it from scratch as both issues are no longer present.

Now it is possible for me to use UseRegDeleteV2 and use Potplayer, and using the start function does not make Start.exe crash anymore. For me it seems like this issue can be closed.

@DavidXanatos DavidXanatos added Status: Fixed in Next Build Fixed in the next Sandboxie version and removed More Info Needed More information is needed to move forward labels Jun 18, 2022
@offhub offhub removed the Confirmation Pending Further confirmation is requested label Jul 25, 2023
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Crash Dump Dump file attached for a detailed analysis Status: Fixed in Next Build Fixed in the next Sandboxie version
Projects
None yet
Development

No branches or pull requests

4 participants