Block Process Access
Can u please check if there is anything wrong with my config.
i cannot use the Google toolbar for searching (in Firefox).
Need to click Home and search from www.google.com
And yes, there is a quite small lag when i typed the words especially in search box of forum (like wbb,tvfl)
Next, I'll try
When i add[GlobalSettings]
Template=ShortKeys
Template=KeyScrambler
FileRootPath=D:\Sandbox\%SANDBOX%
[UserSettings_0BD401EF]
SbieCtrl_UserName=asm@m
SbieCtrl_ReSyncContextMenu=N
SbieCtrl_NextUpdateCheck=1256186976
SbieCtrl_UpdateCheckNotify=Y
SbieCtrl_ShowWelcome=N
SbieCtrl_BoxExpandedView_DefaultBox=Y
SbieCtrl_HideWindowNotify=N
SbieCtrl_BoxExpandedView_TestBox=Y
SbieCtrl_BoxExpandedView_TestingBox=Y
SbieCtrl_WindowLeft=169
SbieCtrl_WindowTop=151
SbieCtrl_WindowWidth=660
SbieCtrl_WindowHeight=450
SbieCtrl_Hidden=Y
SbieCtrl_ActiveView=40021
SbieCtrl_AutoApplySettings=N
SbieCtrl_SettingChangeNotify=Y
SbieCtrl_BoxExpandedView_InstallBox=Y
SbieCtrl_ExplorerWarn=N
SbieCtrl_BoxExpandedView_Apps=Y
SbieCtrl_TerminateNotify=Y
SbieCtrl_TerminateWarn=Y
SbieCtrl_ExplorerNotify=Y
SbieCtrl_EditConfNotify=Y
SbieCtrl_ReloadConfNotify=Y
SbieCtrl_ProcSettingsNotify=Y
SbieCtrl_ShortcutNotify=Y
SbieCtrl_ShouldDeleteNotify=Y
SbieCtrl_ColWidthProcName=250
SbieCtrl_ColWidthProcId=70
SbieCtrl_ColWidthProcTitle=310
[DefaultBox]
ConfigLevel=6
AutoRecover=y
Template=AutoRecoverIgnore
Template=Firefox_Phishing_DirectAccess
Template=LingerPrograms
Template=InternetDownloadManager
Template=ShortKeys
Template=Kaspersky
Template=KeyScrambler
Template=IExplore_Force
Template=IExplore_Favorites_RecoverFolder
Template=Firefox_Force
RecoverFolder=%Favorites%
RecoverFolder=%Desktop%
RecoverFolder=%Personal%
RecoverFolder=%{374DE290-123F-4565-9164-39C4925E467B}%
Enabled=y
LingerProcess=klwtblfs.exe
LingerProcess=RealSched.exe
LingerProcess=RunDll32.exe
LingerProcess=GoogleToolbarNotifier.exe
LingerProcess=GoogleUpdate.exe
LingerProcess=SynCor.exe
LingerProcess=JUSched.exe
LingerProcess=Adobe_Updater.exe
LingerProcess=AcroRd32.exe
AutoRecoverIgnore=.dtapart
AutoRecoverIgnore=.download
AutoRecoverIgnore=.tmp
AutoRecoverIgnore=.dlm
AutoRecoverIgnore=.leechget
AutoRecoverIgnore=.jc!
AutoRecoverIgnore=.part
OpenIpcPath=*\BaseNamedObjects*\__hex30-90__
OpenIpcPath=*\BaseNamedObjects*\KLObj_mt_KLSCRIPTCHECKER_PR_*
OpenIpcPath=*\BaseNamedObjects*\PRObjects*
OpenIpcPath=*\BaseNamedObjects*\PREvent*
OpenIpcPath=*\BaseNamedObjects*\PRCustomProps*
OpenIpcPath=\RPC Control\PRRemote:*
OpenIpcPath=*\BaseNamedObjects*\KSEncStatusEvent
OpenIpcPath=*\BaseNamedObjects*\KSProcEvent*
OpenIpcPath=*\BaseNamedObjects*\KSEncryptionEvent*
OpenIpcPath=*\BaseNamedObjects*\KeyScrambler*
OpenIpcPath=\Device\KeyScrambler
OpenPipePath=\Device\NamedPipe\KSTIPipe*
ForceProcess=iexplore.exe
ForceProcess=firefox.exe
OpenClsid={AC746233-E9D3-49CD-862F-068F7B7CCCA4}
OpenFilePath=firefox.exe,*\urlclassifier*.sqlite*
to the last row,InjectDll=C:\Program Files\Sandboxie\AntiDel\antidel.dll
i cannot use the Google toolbar for searching (in Firefox).
Need to click Home and search from www.google.com
And yes, there is a quite small lag when i typed the words especially in search box of forum (like wbb,tvfl)
Next, I'll try
InjectDll=C:\some\path\to\sbieinj.dll
AntiDel, as you may know, it´s a library I wrote to don´t allow file deletion.
The effects of not allowing a program to delete files may have are unknown. Sometimes it will not have any effect and others... a lag typing.
If you don´t like the effects AntiDel produces in a program I suggest you don´t use AntiDel with that program.
The effects of not allowing a program to delete files may have are unknown. Sometimes it will not have any effect and others... a lag typing.
If you don´t like the effects AntiDel produces in a program I suggest you don´t use AntiDel with that program.
After your questions are addressed, concerning the use of InjectDll and AntiDel, would you like to discuss the rest of your configuration for DefaultBox?bugmenot wrote:Can u please check if there is anything wrong with my config.
No, I'm not saying that there's anything wrong with it.
It's just that you have a great many duplicated settings.
To name just a couple of them:
Template=IExplore_Force
Template=Firefox_Force
Those lines are fine, so you really don't need these lines:
ForceProcess=iexplore.exe
ForceProcess=firefox.exe
Your configuration file could be greatly simplified, by removing duplicated settings - settings that are added by Templates, but are also listed in the other lines in your configuration file.
We could do it via private messages, if you don't want to take up space in this thread.
Paul
Win 10 Home 64-bit (w/admin rights) - Zone Alarm Pro Firewall, MalwareBytes Premium A/V, Cyberfox, Thunderbird
Sandboxie user since March 2007
Win 10 Home 64-bit (w/admin rights) - Zone Alarm Pro Firewall, MalwareBytes Premium A/V, Cyberfox, Thunderbird
Sandboxie user since March 2007
Maybe u can teach me somethingGuest10 wrote:After your questions are addressed, concerning the use of InjectDll and AntiDel, would you like to discuss the rest of your configuration for DefaultBox?bugmenot wrote:Can u please check if there is anything wrong with my config.
No, I'm not saying that there's anything wrong with it.
It's just that you have a great many duplicated settings.
To name just a couple of them:
Template=IExplore_Force
Template=Firefox_Force
Those lines are fine, so you really don't need these lines:
ForceProcess=iexplore.exe
ForceProcess=firefox.exe
Your configuration file could be greatly simplified, by removing duplicated settings - settings that are added by Templates, but are also listed in the other lines in your configuration file.
We could do it via private messages, if you don't want to take up space in this thread.
And how to do that?Buster wrote:Do you mean AntiDel has a bug?bugmenot wrote:Its sure is AntiDel bugs.
About how to exclude Firefox. You could modify source code and allow FireFox.exe process to delete.
Wraithdu described the sandiff tool as a way to block sandboxed processes frm readin unsandboxed process memories and from EXECUTING unsandboxed processes...(at least thats what I read on the first page) So is Sandiff for more security or just for more privacy. If security, can Tzuk incorporate the code in a new release of SB itself? That would make it easier for users to activate and customize.
Read again because you are wrong. It´s wraithdu´s Block Read Access DLL who block sandboxed processed from reading unsanboxed process memories, not Sandiff.Anonymous wrote:Wraithdu described the sandiff tool as a way to block sandboxed processes frm readin unsandboxed process memories and from EXECUTING unsandboxed processes...(at least thats what I read on the first page) So is Sandiff for more security or just for more privacy. If security, can Tzuk incorporate the code in a new release of SB itself? That would make it easier for users to activate and customize.
Who is online
Users browsing this forum: No registered users and 1 guest