Deleted files/regkeys info?

If it's not about a problem in the program
Post Reply
DocMAX
Posts: 28
Joined: Tue Oct 29, 2013 4:07 am
Location: Deutschland

Deleted files/regkeys info?

Post by DocMAX » Mon Nov 11, 2013 3:54 pm

Hi,
where does Sandboxie store deleted files information?
Recently i deleted some registry entries but need the original entries from host system back.
U know what i mean?

Thx,
DocMAX

Guest10
Posts: 5124
Joined: Sun Apr 27, 2008 5:24 pm
Location: Ohio, USA

Re: Deleted files/regkeys info?

Post by Guest10 » Tue Nov 12, 2013 1:24 pm

DocMAX wrote:where does Sandboxie store deleted files information?
Recently i deleted some registry entries but need the original entries from host system back.
Files that are deleted from sandboxes, using "Delete Contents", bypass the Windows Recycle Bin and should be considered as unrecoverable.
It's true that there are some undelete utilities out there, that might be used to recover deleted files, but you need to have one of them installed in advance because it's possible that installing the utility might overwrite the very files that you are trying to recover.
My install of Recuva says that I have 36,000 + deleted files, and only a few of those look like they might have been deleted from one of my C:\Sandbox folders:
TempWmicBatchFile.bat ........ C:\?\drive\C\Program Files\Java\jre7\
Many, many other deleted files from sandboxes have apparently been overwritten.

System Restore says backups of some files that are deleted from the hard drive, but by no means all of them.
Paul
Win 10 Home 64-bit (w/admin rights) - Zone Alarm Pro Firewall, MalwareBytes Premium A/V, Cyberfox, Thunderbird
Sandboxie user since March 2007

DocMAX
Posts: 28
Joined: Tue Oct 29, 2013 4:07 am
Location: Deutschland

Post by DocMAX » Tue Nov 12, 2013 2:34 pm

Hi you didn't understand.

Sandboxie does NOT delete files outside the sandbox (else sandboxing wouldn't make any sense).
My question is, how does Sandbox "mark" files deleted.

I did some research and found out, if a file is in the same location INSIDE the sandbox and also exists OUTSIDE the sandbox same location the file INSIDE the sandbox is not there (thus, as if its deleted).

But how does it work in the registry?

tzuk?

BR,
DocMAX

doktornotor
Posts: 205
Joined: Mon Apr 05, 2010 8:40 am

Post by doktornotor » Tue Nov 12, 2013 3:31 pm

DocMAX wrote:My question is, how does Sandbox "mark" files deleted.
It doesn't mark anything, deleted is deleted.
DocMAX wrote: I did some research and found out, if a file is in the same location INSIDE the sandbox and also exists OUTSIDE the sandbox same location the file INSIDE the sandbox is not there (thus, as if its deleted).
Pretty annoying bug.

Windows 7/8/8.1 x64
Windows Firewall (behind pfSense router), Avast Free 2014
Sandboxie, AppLocker, EMET 4.1

DocMAX
Posts: 28
Joined: Tue Oct 29, 2013 4:07 am
Location: Deutschland

Post by DocMAX » Tue Nov 12, 2013 3:40 pm

The files i delete in sandbox are not deleted outside the box!!!

Guest10
Posts: 5124
Joined: Sun Apr 27, 2008 5:24 pm
Location: Ohio, USA

Post by Guest10 » Wed Nov 13, 2013 11:11 am

First of all, files in the sandbox that DO NOT exist in the corresponding folder that's outside of the sandbox, are truly deleted.

Files in the sandbox, that DO exist in the corresponding folder that's outside of the sandbox, are normally set to 0 bytes and are given an illegal date/time stamp. The date that is used is prior to the introduction of DOS, and therefore it is treated by Windows as an invalid file.

This is what I have recorded. I think this is still correct:
"Deleted files in the sandbox:
The file creation date is changed to a special magic number for deleted files. In a file properties dialogs, it shows Friday, May 23, 1986, 15:47:02."

Run Windows Explorer sandboxed, and if you find a file like that it will have the effect of hiding a file by the same name that's outside of the sandbox, as far as sandboxed programs are concerned.
If it's a Registry change, you can look at the contents of the Reghive file while it's mounted (while the sandbox is *in use*), and possibly delete or modify a key. You can use the UNsandboxed Registry Editor program and look under the "HKEY_USERS\Sandbox_...." key.
Paul
Win 10 Home 64-bit (w/admin rights) - Zone Alarm Pro Firewall, MalwareBytes Premium A/V, Cyberfox, Thunderbird
Sandboxie user since March 2007

DR_LaRRY_PEpPeR
Posts: 291
Joined: Wed Jul 04, 2012 6:40 pm
Location: St. Louis area

Post by DR_LaRRY_PEpPeR » Fri Nov 15, 2013 9:25 am

There's no such thing as an illegal/invalid timestamp, AFAIK. (They can go back to 1600 I think.)

Files are marked as "deleted" in the sandbox with an empty file, as Guest 10 said, as well as the time that Sandboxie treats as "special." (Probably just some Unix timestamp like 0x123456789, etc. -- arbitrary, something unique to check for.)

Same thing with registry keys -- an empty key with a "special" creation (??) and/or last write time. You have to use some other program to see the registry timestamp stuff (available with Registry API, but not shown in Regedit, etc.).

There was some other topic I saw about this once, and then I saw the registry timestamps with one of the registry "diff" programs...
XP Home-as-Pro SP3 (Admin) w/ continued updates (Embedded/POSReady 2009)
> Permissions + "2-level" SRP, latest Sandboxie (Pro/registered), EMET 4, no anti-anything (ever)
Did I make tzuk crazed... in his last days? :o

Guest10
Posts: 5124
Joined: Sun Apr 27, 2008 5:24 pm
Location: Ohio, USA

Post by Guest10 » Fri Nov 15, 2013 1:45 pm

Paul
Win 10 Home 64-bit (w/admin rights) - Zone Alarm Pro Firewall, MalwareBytes Premium A/V, Cyberfox, Thunderbird
Sandboxie user since March 2007

Post Reply

Who is online

Users browsing this forum: No registered users and 0 guests