2. SBIE 5.14 (latest)
3. Earthdesk (any version) - http://www.xericdesign.com/earthdesk-win.php
4. NOT running AV software of ANY kind. Windows defender disabled via group policy.
STEPS to reproduce:
1. Download Earthdesk for windows: http://www.xericdesign.com/earthdesk-win.php
2. Install in Sandboxie
3. Launch and see the desktop picture does not show up on the desktop
I have not tested this in the past, so I am not sure what's going on. I played with a bunch of SBIE's settings, but couldn't get it to work
Should be very easy to reproduce.. This is what it should look like:
Running under Sandboxie, no image is displayed.
Here's the resource access log:
Code: Select all
(Drive) \Device\CdRom0
(Drive) \Device\HarddiskVolume4
(Drive) \Device\HarddiskVolume5
(Drive) \Device\HarddiskVolume6
(Drive) \Device\HarddiskVolume8
(Drive) \Device\HarddiskVolume9
(Drive) \Device\Mup\;LanmanRedirector\;N:0000000000026cad\Magneto\d
Clsid -------------------------------
Clsid O {8BC3F05E-D86B-11D0-A075-00C04FB68820} Windows Management and Instrumentation
File/Key -------------------------------
File/Key X \REGISTRY\MACHINE
File/Key X \REGISTRY\MACHINE\SOFTWARE\Classes
File/Key X \REGISTRY\Machine\Software\Classes\Directory
File/Key X \REGISTRY\Machine\Software\Classes\Folder
File/Key X \REGISTRY\MACHINE\SOFTWARE\Microsoft\COM3
File/Key X \REGISTRY\MACHINE\SOFTWARE\Microsoft\Ole
File/Key X \REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SyncRootManager
File/Key X \REGISTRY\MACHINE\SOFTWARE\Policies
File/Key X \REGISTRY\MACHINE\Software\WOW6432Node
File/Key X \REGISTRY\MACHINE\Software\WOW6432Node\Microsoft\WBEM\CIMOM
File/Key X \REGISTRY\MACHINE\System
File/Key X \REGISTRY\MACHINE\SYSTEM\ControlSet001\Services\WinSock2\Parameters\NameSpace_Catalog5
File/Key X \REGISTRY\MACHINE\SYSTEM\ControlSet001\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries
File/Key X \REGISTRY\MACHINE\SYSTEM\ControlSet001\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries64
File/Key X \REGISTRY\MACHINE\SYSTEM\ControlSet001\Services\WinSock2\Parameters\Protocol_Catalog9
File/Key X \REGISTRY\MACHINE\SYSTEM\ControlSet001\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries
File/Key X \REGISTRY\MACHINE\SYSTEM\ControlSet001\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries64
File/Key X \REGISTRY\MACHINE\System\CurrentControlSet\Control\SafeBoot\Option
File/Key X \REGISTRY\MACHINE\System\CurrentControlSet\Services\Tcpip\Parameters
File/Key X \REGISTRY\MACHINE\System\CurrentControlSet\Services\WinSock2\Parameters
File/Key X \REGISTRY\machine\system\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5
File/Key X \REGISTRY\machine\system\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9
File/Key X \REGISTRY\USER
File/Key X \REGISTRY\USER\S-1-5-21-2058250888-4282892043-3876035344-1001
File/Key X \REGISTRY\USER\S-1-5-21-2058250888-4282892043-3876035344-1001\Control Panel
File/Key X \REGISTRY\USER\S-1-5-21-2058250888-4282892043-3876035344-1001\Control Panel\Desktop
File/Key X \REGISTRY\user\S-1-5-21-2058250888-4282892043-3876035344-1001\software\classes
File/Key X \REGISTRY\User\S-1-5-21-2058250888-4282892043-3876035344-1001_Classes
File/Key X \REGISTRY\USER\S-1-5-21-2058250888-4282892043-3876035344-1001_Classes
File/Key X \REGISTRY\User\S-1-5-21-2058250888-4282892043-3876035344-1001_Classes
File/Key X \REGISTRY\USER\S-1-5-21-2058250888-4282892043-3876035344-1001_Classes
File/Key X \REGISTRY\USER\S-1-5-21-2058250888-4282892043-3876035344-1001_Classes\.exe
File/Key X \REGISTRY\USER\S-1-5-21-2058250888-4282892043-3876035344-1001_Classes\AllFilesystemObjects
File/Key X \REGISTRY\USER\S-1-5-21-2058250888-4282892043-3876035344-1001_Classes\CLSID\{0E5AAE11-A475-4c5b-AB00-C66DE400274E}
File/Key X \REGISTRY\USER\S-1-5-21-2058250888-4282892043-3876035344-1001_Classes\CLSID\{0E5AAE11-A475-4c5b-AB00-C66DE400274E}\InProcServer32
File/Key X \REGISTRY\USER\S-1-5-21-2058250888-4282892043-3876035344-1001_Classes\CLSID\{1f486a52-3cb1-48fd-8f50-b8dc300d9f9d}
File/Key X \REGISTRY\USER\S-1-5-21-2058250888-4282892043-3876035344-1001_Classes\CLSID\{1f486a52-3cb1-48fd-8f50-b8dc300d9f9d}\InProcServer32
File/Key X \REGISTRY\USER\S-1-5-21-2058250888-4282892043-3876035344-1001_Classes\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder
File/Key X \REGISTRY\USER\S-1-5-21-2058250888-4282892043-3876035344-1001_Classes\CLSID\{66742402-F9B9-11D1-A202-0000F81FEDEE}
File/Key X \REGISTRY\USER\S-1-5-21-2058250888-4282892043-3876035344-1001_Classes\CLSID\{76765b11-3f95-4af2-ac9d-ea55d8994f1a}
File/Key X \REGISTRY\USER\S-1-5-21-2058250888-4282892043-3876035344-1001_Classes\CLSID\{76765b11-3f95-4af2-ac9d-ea55d8994f1a}\InProcServer32
File/Key X \REGISTRY\USER\S-1-5-21-2058250888-4282892043-3876035344-1001_Classes\CLSID\{9ac9fbe1-e0a2-4ad6-b4ee-e212013ea917}
File/Key X \REGISTRY\USER\S-1-5-21-2058250888-4282892043-3876035344-1001_Classes\CLSID\{9ac9fbe1-e0a2-4ad6-b4ee-e212013ea917}\InProcServer32
File/Key X \REGISTRY\USER\S-1-5-21-2058250888-4282892043-3876035344-1001_Classes\CLSID\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}
File/Key X \REGISTRY\USER\S-1-5-21-2058250888-4282892043-3876035344-1001_Classes\CLSID\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\Instance
File/Key X \REGISTRY\USER\S-1-5-21-2058250888-4282892043-3876035344-1001_Classes\CLSID\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\Instance\InitPropertyBag
File/Key X \REGISTRY\USER\S-1-5-21-2058250888-4282892043-3876035344-1001_Classes\CLSID\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\ShellFolder
File/Key X \REGISTRY\USER\S-1-5-21-2058250888-4282892043-3876035344-1001_Classes\CLSID\{CDC82860-468D-4d4e-B7E7-C298FF23AB2C}
File/Key X \REGISTRY\USER\S-1-5-21-2058250888-4282892043-3876035344-1001_Classes\CLSID\{CDC82860-468D-4d4e-B7E7-C298FF23AB2C}\InProcServer32
File/Key X \REGISTRY\USER\S-1-5-21-2058250888-4282892043-3876035344-1001_Classes\Drive\shellex\FolderExtensions
File/Key X \REGISTRY\USER\S-1-5-21-2058250888-4282892043-3876035344-1001_Classes\Drive\shellex\FolderExtensions\{fbeb8a05-beee-4442-804e-409d6c4515e9}
File/Key X \REGISTRY\USER\S-1-5-21-2058250888-4282892043-3876035344-1001_Classes\exefile
File/Key X \REGISTRY\USER\S-1-5-21-2058250888-4282892043-3876035344-1001_Classes\exefile\shell
File/Key X \REGISTRY\USER\S-1-5-21-2058250888-4282892043-3876035344-1001_Classes\exefile\shell\open
File/Key X \REGISTRY\USER\S-1-5-21-2058250888-4282892043-3876035344-1001_Classes\exefile\shell\open\command
File/Key X \REGISTRY\USER\S-1-5-21-2058250888-4282892043-3876035344-1001_Classes\Interface\{00000134-0000-0000-C000-000000000046}\ProxyStubClsid32
File/Key X \REGISTRY\USER\S-1-5-21-2058250888-4282892043-3876035344-1001_Classes\SystemFileAssociations\.exe
File/Key X \REGISTRY\USER\S-1-5-21-2058250888-4282892043-3876035344-1001_Classes\WOW6432Node\CLSID\{4590F811-1D3A-11D0-891F-00AA004B2E24}
File/Key X \REGISTRY\USER\S-1-5-21-2058250888-4282892043-3876035344-1001_Classes\WOW6432Node\CLSID\{4590F811-1D3A-11D0-891F-00AA004B2E24}\InprocServer32
File/Key X \REGISTRY\USER\S-1-5-21-2058250888-4282892043-3876035344-1001_Classes\WOW6432Node\CLSID\{674B6698-EE92-11D0-AD71-00C04FD8FDFF}
File/Key X \REGISTRY\USER\S-1-5-21-2058250888-4282892043-3876035344-1001_Classes\WOW6432Node\CLSID\{674B6698-EE92-11D0-AD71-00C04FD8FDFF}\InprocServer32
File/Key X \REGISTRY\USER\S-1-5-21-2058250888-4282892043-3876035344-1001_Classes\WOW6432Node\CLSID\{75048700-EF1F-11D0-9888-006097DEACF9}
File/Key X \REGISTRY\USER\S-1-5-21-2058250888-4282892043-3876035344-1001_Classes\WOW6432Node\CLSID\{75048700-EF1F-11D0-9888-006097DEACF9}\InProcServer32
File/Key X \REGISTRY\USER\S-1-5-21-2058250888-4282892043-3876035344-1001_Classes\WOW6432Node\CLSID\{E7D35CFA-348B-485E-B524-252725D697CA}
File/Key X \REGISTRY\USER\S-1-5-21-2058250888-4282892043-3876035344-1001_Classes\WOW6432Node\CLSID\{E7D35CFA-348B-485E-B524-252725D697CA}\InProcServer32
File/Key X \REGISTRY\USER\S-1-5-21-2058250888-4282892043-3876035344-1001_Classes\WOW6432Node\Interface\{00000134-0000-0000-C000-000000000046}\ProxyStubClsid32
File/Key X \REGISTRY\USER\S-1-5-21-2058250888-4282892043-3876035344-1001_Classes\WOW6432Node\Interface\{027947E1-D731-11CE-A357-000000000001}\ProxyStubClsid32
File/Key X \REGISTRY\USER\S-1-5-21-2058250888-4282892043-3876035344-1001_Classes\WOW6432Node\Interface\{1C1C45EE-4395-11D2-B60B-00104B703EFD}\ProxyStubClsid32
File/Key X \REGISTRY\USER\S-1-5-21-2058250888-4282892043-3876035344-1001_Classes\WOW6432Node\Interface\{423EC01E-2E35-11D2-B604-00104B703EFD}\ProxyStubClsid32
File/Key X \REGISTRY\USER\S-1-5-21-2058250888-4282892043-3876035344-1001_Classes\WOW6432Node\Interface\{9556DC99-828C-11CF-A37E-00AA003240C7}\ProxyStubClsid32
File/Key X \REGISTRY\USER\S-1-5-21-2058250888-4282892043-3876035344-1001_Classes\WOW6432Node\Interface\{D4781CD6-E5D3-44DF-AD94-930EFE48A887}\ProxyStubClsid32
File/Key X \REGISTRY\USER\S-1-5-21-2058250888-4282892043-3876035344-1001_Classes\WOW6432Node\Interface\{F309AD18-D86A-11D0-A075-00C04FB68820}\ProxyStubClsid32
Image -------------------------------
Ipc -------------------------------
Ipc \BaseNamedObjects\__ComCatalogCache__
Ipc \BaseNamedObjects\{A3BD3259-3E4F-428a-84C8-F0463A9D3EB5}
Ipc \BaseNamedObjects\{A64C7F33-DA35-459b-96CA-63B51FB0CDB9}
Ipc \BaseNamedObjects\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000022.db
Ipc \BaseNamedObjects\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000001.db
Ipc \BaseNamedObjects\C:*ProgramData*Microsoft*Windows*Caches*cversions.2.ro
Ipc \BaseNamedObjects\FontCachePort
Ipc \BaseNamedObjects\RotHintTable
Ipc \BaseNamedObjects\SC_AutoStartComplete
Ipc \BaseNamedObjects\windows_shell_global_counters
Ipc \RPC Control\actkernel
Ipc \RPC Control\epmapper
Ipc \RPC Control\OLE2311F2EF719990CEEEE70671D05D
Ipc \RPC Control\OLE74829BFC6D743F2DC7A5ED1509E7
Ipc \Sessions\1\BaseNamedObjects\__ComCatalogCache__
Ipc \Sessions\1\BaseNamedObjects\{A3BD3259-3E4F-428a-84C8-F0463A9D3EB5}
Ipc \Sessions\1\BaseNamedObjects\{A64C7F33-DA35-459b-96CA-63B51FB0CDB9}
Ipc \Sessions\1\BaseNamedObjects\b17c9753-6440-41a1-96c2-1e1e6053fc34
Ipc \Sessions\1\BaseNamedObjects\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000022.db
Ipc \Sessions\1\BaseNamedObjects\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000001.db
Ipc \Sessions\1\BaseNamedObjects\C:*ProgramData*Microsoft*Windows*Caches*cversions.2.ro
Ipc \Sessions\1\BaseNamedObjects\C:*Users**************AppData*Local*Microsoft*Windows*Caches*{AFBF9F1A-8EE8-4C77-AF34-C647E37CA0D9}.1.ver0x0000000000000022.db
Ipc \Sessions\1\BaseNamedObjects\C:*Users**************AppData*Local*Microsoft*Windows*Caches*cversions.1.ro
Ipc \Sessions\1\BaseNamedObjects\com.xericdesign.earthdesk.signal.running
Ipc \Sessions\1\BaseNamedObjects\ComPlusCOMRegTable
Ipc \Sessions\1\BaseNamedObjects\CrashRptEvent_b17c9753-6440-41a1-96c2-1e1e6053fc34
Ipc \Sessions\1\BaseNamedObjects\RotHintTable
Ipc \Sessions\1\BaseNamedObjects\SBIE_BOXED_DummyEvent_3664
Ipc \Sessions\1\BaseNamedObjects\SBIE_BOXED_DummyEvent_4588
Ipc \Sessions\1\BaseNamedObjects\SBIE_BOXED_DummyEvent_6044
Ipc \Sessions\1\BaseNamedObjects\SBIE_BOXED_DummyEvent_6832
Ipc \Sessions\1\BaseNamedObjects\SBIE_BOXED_RPCSS_SXS_READY
Ipc \Sessions\1\BaseNamedObjects\SBIE_BOXED_ServiceInitComplete_DcomLaunch
Ipc \Sessions\1\BaseNamedObjects\SBIE_BOXED_ServiceInitComplete_Mutex1
Ipc \Sessions\1\BaseNamedObjects\SBIE_BOXED_ServiceInitComplete_RpcEptMapper
Ipc \Sessions\1\BaseNamedObjects\SBIE_BOXED_ServiceInitComplete_RpcSs
Ipc \Sessions\1\BaseNamedObjects\SboxSession
Ipc \Sessions\1\BaseNamedObjects\SC_AutoStartComplete
Ipc \Sessions\1\BaseNamedObjects\ScmCreatedEvent
Ipc \Sessions\1\BaseNamedObjects\SessionImmersiveColorMutex
Ipc \Sessions\1\BaseNamedObjects\SessionImmersiveColorPreference
Ipc \Sessions\1\BaseNamedObjects\SM0:3664:120:WilError_01
Ipc \Sessions\1\BaseNamedObjects\SM0:3664:120:WilError_01_p0
Ipc \Sessions\1\BaseNamedObjects\SM0:3664:120:WilError_01_p0h
Ipc \Sessions\1\BaseNamedObjects\SM0:6832:64:WilError_01
Ipc \Sessions\1\BaseNamedObjects\SM0:6832:64:WilError_01_p0
Ipc \Sessions\1\BaseNamedObjects\SyncRootManager
Ipc \Sessions\1\BaseNamedObjects\windows_shell_global_counters
Ipc O \BaseNamedObjects\msctf.serverDefault1
Ipc O \KernelObjects\MaximumCommitCondition
Ipc O \KnownDlls\advapi32.dll
Ipc O \KnownDlls\bcryptPrimitives.dll
Ipc O \KnownDlls\cfgmgr32.dll
Ipc O \KnownDlls\clbcatq.dll
Ipc O \KnownDlls\combase.dll
Ipc O \KnownDlls\COMDLG32.dll
Ipc O \KnownDlls\gdi32.dll
Ipc O \KnownDlls\gdi32full.dll
Ipc O \KnownDlls\IMM32.dll
Ipc O \KnownDlls\kernel.appcore.dll
Ipc O \KnownDlls\kernel32.dll
Ipc O \KnownDlls\kernelbase.dll
Ipc O \KnownDlls\msvcp_win.dll
Ipc O \KnownDlls\MSVCRT.dll
Ipc O \KnownDlls\ole32.dll
Ipc O \KnownDlls\OLEAUT32.dll
Ipc O \KnownDlls\powrprof.dll
Ipc O \KnownDlls\profapi.dll
Ipc O \KnownDlls\PSAPI.DLL
Ipc O \KnownDlls\rpcrt4.dll
Ipc O \KnownDlls\sechost.dll
Ipc O \KnownDlls\shcore.dll
Ipc O \KnownDlls\SHELL32.dll
Ipc O \KnownDlls\SHLWAPI.dll
Ipc O \KnownDlls\ucrtbase.dll
Ipc O \KnownDlls\user32.dll
Ipc O \KnownDlls\win32u.dll
Ipc O \KnownDlls\windows.storage.dll
Ipc O \KnownDlls\Wow64.dll
Ipc O \KnownDlls\Wow64cpu.dll
Ipc O \KnownDlls\Wow64win.dll
Ipc O \KnownDlls\WS2_32.dll
Ipc O \KnownDlls32\advapi32.dll
Ipc O \KnownDlls32\bcryptPrimitives.dll
Ipc O \KnownDlls32\cfgmgr32.dll
Ipc O \KnownDlls32\clbcatq.dll
Ipc O \KnownDlls32\combase.dll
Ipc O \KnownDlls32\COMDLG32.dll
Ipc O \KnownDlls32\CRYPTBASE.dll
Ipc O \KnownDlls32\gdi32.dll
Ipc O \KnownDlls32\gdi32full.dll
Ipc O \KnownDlls32\IMM32.dll
Ipc O \KnownDlls32\kernel.appcore.dll
Ipc O \KnownDlls32\kernel32.dll
Ipc O \KnownDlls32\kernelbase.dll
Ipc O \KnownDlls32\MSCTF.dll
Ipc O \KnownDlls32\msvcp_win.dll
Ipc O \KnownDlls32\MSVCRT.dll
Ipc O \KnownDlls32\NSI.dll
Ipc O \KnownDlls32\ole32.dll
Ipc O \KnownDlls32\OLEAUT32.dll
Ipc O \KnownDlls32\powrprof.dll
Ipc O \KnownDlls32\profapi.dll
Ipc O \KnownDlls32\PSAPI.DLL
Ipc O \KnownDlls32\rpcrt4.dll
Ipc O \KnownDlls32\sechost.dll
Ipc O \KnownDlls32\shcore.dll
Ipc O \KnownDlls32\SHELL32.dll
Ipc O \KnownDlls32\SHLWAPI.dll
Ipc O \KnownDlls32\SspiCli.dll
Ipc O \KnownDlls32\ucrtbase.dll
Ipc O \KnownDlls32\user32.dll
Ipc O \KnownDlls32\win32u.dll
Ipc O \KnownDlls32\windows.storage.dll
Ipc O \KnownDlls32\WS2_32.dll
Ipc O \RPC Control\lsapolicylookup
Ipc O \RPC Control\LSARPC_ENDPOINT
Ipc O \RPC Control\lsasspirpc
Ipc O \RPC Control\SbieSvcPort
Ipc O \Security\LSA_AUTHENTICATION_INITIALIZED
Ipc O \Sessions\1\BaseNamedObjects\AMIPC_34121_HookDLL_Event_SendReply
Ipc O \Sessions\1\BaseNamedObjects\AMIPC_34121_HookDLL_Event_SendRequest
Ipc O \Sessions\1\BaseNamedObjects\AMIPC_34121_HookDLL_FileMapping
Ipc O \Sessions\1\BaseNamedObjects\AMIPC_34121_HookDLL_Mutex_Client
Ipc O \Sessions\1\BaseNamedObjects\AMIPC_34121_HookDLL_Mutex_Server
Ipc O \Sessions\1\BaseNamedObjects\CicLoadWinStaWinSta0
Ipc O \Sessions\1\BaseNamedObjects\CTF.AsmListCache.FMPDefault1S-1-5-21-2058250888-4282892043-3876035344-1001
Ipc O \Sessions\1\BaseNamedObjects\MSCTF.Asm.MutexDefault1S-1-5-21-2058250888-4282892043-3876035344-1001
Ipc O \Sessions\1\BaseNamedObjects\MSCTF.CtfMonitorInstMutexDefault1
Ipc O \Sessions\1\Windows\ApiPort
Ipc O \Sessions\1\Windows\SharedSection
Ipc O \Sessions\1\Windows\Theme1686223837
Ipc O \Sessions\1\Windows\ThemeSection
Ipc O \ThemeApiPort
Ipc O \Windows\Theme2393393972
Pipe -------------------------------
Pipe O ?
Pipe O \Device\0000006f
Pipe O \Device\CNG
Pipe O \Device\HarddiskVolume1
Pipe O \Device\HarddiskVolume4
Pipe O \Device\HarddiskVolume5
Pipe O \Device\HarddiskVolume6
Pipe O \Device\HarddiskVolume8
Pipe O \Device\HarddiskVolume9
Pipe O \Device\KsecDD
Pipe O \Device\MountPointManager
Pipe O \Device\Ndis
Pipe O \Device\NDMP2
Pipe O \Device\NDMP3
Pipe O \Device\NDMP4
Pipe O \Device\NetBT_Tcpip_{2B954DBD-257F-406D-93CE-613AC6785D72}
Pipe O \Device\NetBT_Tcpip_{FD24A1E9-8AAE-481F-BF7A-19E9E66C1242}
Pipe O \Device\Nsi
WinCls -------------------------------