[.06] Causes sandboxes to not delete
Posted: Thu Apr 11, 2013 6:33 pm
I have found (using 4.01.05) that I can cause "System" to have locks on the 2 Reghive files in a sandbox just by sandboxing a program that is not listed in the Start/Run Restrictions list.
With these programs in the list:
ProcessGroup=<StartRunAccess>,firefox.exe,plugin-container.exe,flashgot.exe
Sandboxing Notepad gives:
2013-04-11 18:09:18 SBIE1308 Program cannot start due to restrictions - notepad.exe [Test_Start_Run]
2013-04-11 18:09:18 SBIE2314 Canceling process notepad.exe
Double-clicking the SBIE2222 line to allow Notepad to run gives:
ProcessGroup=<StartRunAccess>,firefox.exe,plugin-container.exe,flashgot.exe,notepad.exe
With no programs running at this time, and the sandbox set to auto-delete, delete contents fails (not renamed).
Manual Delete Contents is unable to delete contents due to "System" locks.
Notepad will run the next time it's tried, but when the program ends the sandbox still cannot be renamed or deleted.
So far, I've had to reboot to delete the contents of the 3 sandboxes that I've tried this with.
-----
[Test_Start_Run]
Enabled=y
ConfigLevel=7
AutoRecover=y
Template=BlockPorts
Template=LingerPrograms
Template=Firefox_Phishing_DirectAccess
Template=AutoRecoverIgnore
RecoverFolder=%Personal%
RecoverFolder=%Favorites%
RecoverFolder=%Desktop%
BorderColor=#00FFFF,ttl
NotifyStartRunAccessDenied=y
AutoDelete=y
ProcessGroup=<StartRunAccess>,firefox.exe,plugin-container.exe,flashgot.exe
ClosedIpcPath=!<StartRunAccess>,*
With these programs in the list:
ProcessGroup=<StartRunAccess>,firefox.exe,plugin-container.exe,flashgot.exe
Sandboxing Notepad gives:
2013-04-11 18:09:18 SBIE1308 Program cannot start due to restrictions - notepad.exe [Test_Start_Run]
2013-04-11 18:09:18 SBIE2314 Canceling process notepad.exe
Double-clicking the SBIE2222 line to allow Notepad to run gives:
ProcessGroup=<StartRunAccess>,firefox.exe,plugin-container.exe,flashgot.exe,notepad.exe
With no programs running at this time, and the sandbox set to auto-delete, delete contents fails (not renamed).
Manual Delete Contents is unable to delete contents due to "System" locks.
Notepad will run the next time it's tried, but when the program ends the sandbox still cannot be renamed or deleted.
So far, I've had to reboot to delete the contents of the 3 sandboxes that I've tried this with.
-----
[Test_Start_Run]
Enabled=y
ConfigLevel=7
AutoRecover=y
Template=BlockPorts
Template=LingerPrograms
Template=Firefox_Phishing_DirectAccess
Template=AutoRecoverIgnore
RecoverFolder=%Personal%
RecoverFolder=%Favorites%
RecoverFolder=%Desktop%
BorderColor=#00FFFF,ttl
NotifyStartRunAccessDenied=y
AutoDelete=y
ProcessGroup=<StartRunAccess>,firefox.exe,plugin-container.exe,flashgot.exe
ClosedIpcPath=!<StartRunAccess>,*