SandboxDiff - Registry/Files changes

Utilities designed for use with Sandboxie
Shield
Posts: 29
Joined: Wed Dec 10, 2008 5:45 am

Post by Shield » Fri Dec 12, 2008 8:43 pm

Thanks majoMo, this will be quite handy!

Happy holidays!

majoMo
Posts: 14
Joined: Mon Jun 30, 2008 6:18 pm

SandboxDiff Updated

Post by majoMo » Fri Jan 23, 2009 1:43 pm

SandboxDiff updated.

Changes:

- Added Registry changes in .reg format (Windows Registry Editor Version 5.00)

Thus the Registry and Files changes are avaliable in text, .reg (registry) and .html (here you can see all files and registry entries created by sandbox'process).


* Download and info in first post. *

MFS
Posts: 0
Joined: Sat Dec 06, 2008 10:09 am

Post by MFS » Sat Jan 24, 2009 8:18 pm

Thank you. I'll test it. :D

~tmp

Post by ~tmp » Tue Jan 27, 2009 8:21 am

Some antivirs don't like the techniques you use in the subj.
Comodo, NOD32, AViRA... say something like:
TrojWare.Win32.Qhost.~AR@1639959
and possible dangerous packer-cruncher blah-blah-blah.

Take it easy, even Kaspersky says SBie is a really very dangerous thing too.
Just make a note saying the program analyzes both real and virtual registry plus both real and virtual filesystem then compares the results. It is intended for this.

raid
Posts: 58
Joined: Sat Aug 23, 2008 12:17 am
Location: TN, USA
Contact:

Post by raid » Sat Jan 31, 2009 11:28 pm

Thanks for the update regarding this program.

Another program I've found useful is the Mitec Windows Registry Recovery Tool. You can mount the reghive after you run your sandboxed application and see exactly what it's added to the "registry" as far as it knows. :)

So if it's added policies, you will know. Any entries in the sandboxed registry can be viewed with ease using this tool.

http://www.mitec.cz/wrr.html
Everything is so different, yet I am the same...

tzuk
Sandboxie Founder
Sandboxie Founder
Posts: 16076
Joined: Tue Jun 22, 2004 12:57 pm

Post by tzuk » Mon Feb 02, 2009 5:40 pm

majoMo, I can add this utility here if you want:

http://www.sandboxie.com/index.php?ContributedUtilities
tzuk

majoMo
Posts: 14
Joined: Mon Jun 30, 2008 6:18 pm

Post by majoMo » Wed Feb 04, 2009 10:23 pm

@ tzuk, very interesting the "Contributed Utilities page". It seems useful for SandboxIE'users really. Like requested, the answer is affirmative: I want. Thanks for your kindly information.

tzuk
Sandboxie Founder
Sandboxie Founder
Posts: 16076
Joined: Tue Jun 22, 2004 12:57 pm

Post by tzuk » Thu Feb 05, 2009 9:00 am

My pleasure. Let me know if you don't me to host the file on this server. Or if you're ok with it, let me know when I should update the copy that I host here.

http://www.sandboxie.com/index.php?ContributedUtilities
tzuk

majoMo
Posts: 14
Joined: Mon Jun 30, 2008 6:18 pm

Post by majoMo » Mon Feb 09, 2009 2:39 pm

@ tzuk, to host in that server it's well. When any update comes out I'll inform you firstly.

Regards.

MrZ
Posts: 1
Joined: Mon Feb 23, 2009 5:42 pm

How do I safely uninstall this?

Post by MrZ » Fri Feb 27, 2009 4:02 pm

The program after install in Vista seems to put files in different places, for example I found "wait.exe" and "regdiff.exe" in my c:\users\myname\appdata\local folder. Later they disappeared from that folder! I know they were there at one time, then they disappeared.

Can you explain where these various executables are? Where else would your program put them?

majoMo
Posts: 14
Joined: Mon Jun 30, 2008 6:18 pm

Post by majoMo » Sun Mar 01, 2009 6:59 pm

The files used by SandboxDiff in that folder (temporarily) are listed in help file.

t-max

regdump.exe error

Post by t-max » Fri Apr 17, 2009 10:24 am

Hi,
I get an error with regdump.exe, after making an installation of MS Office 2003.

Does anybody know what can be causing it?

majoMo
Posts: 14
Joined: Mon Jun 30, 2008 6:18 pm

Post by majoMo » Wed Apr 22, 2009 2:41 pm

Hi t-max, thanks for your reporting.

I was able to reproduce that error with same app.. In fact the file "regdump.exe", used by SandboxDiff, crashed when loading the hive file; there is a bug in that executable indeed (it's an unusual bug with it).

It seems that when loading some hive files "regdump.exe" crashes.

Consequences? The registries changes in "Comp-Reg.txt" file isn't complete; it record the changes until the crash time. Tip: when "regdump.exe" crashes the reliable and accurate registry changes are in the file "Comp-Reg.REG.txt" (in .reg format).

In the next release I'll reenforce SandboxDiff to check the reliableness in "Comp-Reg.REG.txt" record. At least we can have one trusty registry changes file if occur a crash in that file.

majoMo
Posts: 14
Joined: Mon Jun 30, 2008 6:18 pm

Post by majoMo » Sat Apr 25, 2009 9:05 am

SandboxDiff updated.

Changes:

- Analyzing/Comparing process far faster now.


Download in: Contributed Utilities page.

gyp
Posts: 0
Joined: Sat May 23, 2009 11:30 pm

comp-reg error

Post by gyp » Sat May 23, 2009 11:34 pm

In comp-reg.txt I am getting

1d0
< hive path err
\ No newline at end of file

Otherwise seems to be functioning very easy

Post Reply

Who is online

Users browsing this forum: No registered users and 1 guest