| Author |
Message |
| Buster |
Posted: Sun Aug 12, 2012 8:13 am Post subject: |
|
| biscuits wrote: |
| I tried Unlocker. The system process is locking Reghive.Log (PID: 4, handle: 484) and Reghive (PID: 4, handle 584). Unlocker can't unlock them. |
System Process is also the process locking RegHive files on my end and the only way to fix it is rebooting. |
|
 |
| biscuits |
Posted: Sun Aug 12, 2012 8:04 am Post subject: |
|
| I tried Unlocker. The system process is locking Reghive.Log (PID: 4, handle: 484) and Reghive (PID: 4, handle 584). Unlocker can't unlock them. |
|
 |
| Guest10 |
Posted: Thu Aug 09, 2012 5:34 pm Post subject: |
|
It doesn't seem likely that Chrome is causing it, unless maybe there's some extension installed in Chrome that's the cause.
I use the same versions of Chrome and MSE, along with the Zone Alarm firewall program, and have no problem with the Reghive being locked.
You might try installing Unlocker, to see if it can identify a process that's locking the file in the sandbox.
Scroll down to this line:
Download for Windows 2000 / XP / 2003 / Vista / Windows 7 - Unlocker is Freeware
about half-way down the page.
http://www.emptyloop.com/unlocker/
Unlocker is used from the right-click context menu in Windows Explorer.
Right-click on the sandbox name to see if it identifies any locks.
Important!
Make sure some other folder is highlighted (left-clicked) in Explorer's window when you right-click on the sandbox folder.
Otherwise, Windows Explorer will place a lock on whatever folder is highlighted at the time. |
|
 |
| biscuits |
Posted: Thu Aug 09, 2012 1:02 pm Post subject: Could it be chrome? |
|
| Could google chrome be the culprit? I only use sandboxie for chrome. The version that I'm using is 21.0.1180.60m. My other security programs running in realtime is Microsoft Security Essentials v4.0.1526.0 and Windows XP firewall with default settings. |
|
 |
| tzuk |
Posted: Thu Aug 09, 2012 6:59 am Post subject: |
|
| Then you might be using some conflicting third-party software which thinks it's ok to keep that "classes" key locked forever. I ran into such a software once, but I can't remember now which one it was. |
|
 |
| biscuits |
Posted: Wed Aug 08, 2012 10:12 am Post subject: classes key in sandboxie REGHIVE gets locked |
|
| I'm also having problems with unloading the reghive of the Default Sandbox, thus I can't delete the contents of the Default Sandbox. It seems the only reg folder that is locked is the classes key which is located in [HKEY_USERS\Sandbox_(name of user)_DefaultBox\user\current\software]. It seems to be "nonexistent" but regedt doesn't recognized it. |
|
 |
| tzuk |
Posted: Sat May 26, 2012 6:35 pm Post subject: |
|
| I'm not sure what to tell you. If it happens that I have RegEdit open and looking inside the sandbox when the last program in the sandbox ends, then the reghive files remain locked as you describe. At that point I was always able to put RegEdit on the top key of the sandbox registry (the one directly below HKEY_USERS) and use File menu > Unload Hive. And that's basically what I've been suggesting in my earlier post that you should try. |
|
 |
| Buster |
Posted: Thu May 24, 2012 2:12 pm Post subject: |
|
| tzuk wrote: |
The registry hive is unloaded when the last program in the sandbox ends. If you have stuff still access the sandbox registry at the time when the last program in the sandbox ends, then the hive can't be unloaded. If this is a possible scenario, you can work around it yourself:
(1) you can run something trivial which ends immediately, to coax Sandboxie to try unloading the hive again
(2) use Windows API like RegUnloadKey to unmount the hive once you know you're done with the keys below it
(3) use an external command like "%SystemRoot%\system32\reg.exe unload" to do the same. |
I tried solutions 1 and 3 and none worked.
With reg.exe unload I get an error message: access denied |
|
 |
| Buster |
Posted: Mon May 21, 2012 2:58 pm Post subject: |
|
| Next time RegHive gets locked I will try that solutions and I will let you know how it works, thanks! |
|
 |
| tzuk |
Posted: Mon May 21, 2012 2:45 pm Post subject: |
|
The registry hive is unloaded when the last program in the sandbox ends. If you have stuff still access the sandbox registry at the time when the last program in the sandbox ends, then the hive can't be unloaded. If this is a possible scenario, you can work around it yourself:
(1) you can run something trivial which ends immediately, to coax Sandboxie to try unloading the hive again
(2) use Windows API like RegUnloadKey to unmount the hive once you know you're done with the keys below it
(3) use an external command like "%SystemRoot%\system32\reg.exe unload" to do the same. |
|
 |
| Buster |
Posted: Mon May 21, 2012 1:42 pm Post subject: |
|
I still have the problem with RegHive being locked from time to time.
Handle v3.46
Copyright (C) 1997-2011 Mark Russinovich
Sysinternals - www.sysinternals.com
------------------------------------------------------------------------------
System pid: 4 NT AUTHORITY\SYSTEM
17C: File (RW-) C:\
280: File (---) C:\Documents and Settings\LocalService\Configuración local\Datos de programa\Microsoft\Windows\UsrClass.dat.LOG
2A8: File (---) C:\Documents and Settings\LocalService\ntuser.dat.LOG
2AC: File (---) C:\Documents and Settings\LocalService\NTUSER.DAT
2B0: File (---) C:\Documents and Settings\LocalService\Configuración local\Datos de programa\Microsoft\Windows\UsrClass.dat
4D0: File (---) C:\Documents and Settings\Administrador\Configuración local\Datos de programa\Microsoft\Windows\UsrClass.dat.LOG
4DC: File (RW-) \Device\Mup
4E0: File (---) C:\Documents and Settings\Administrador\Configuración local\Datos de programa\Microsoft\Windows\UsrClass.dat
4E4: File (---) C:\Documents and Settings\Administrador\ntuser.dat.LOG
4EC: File (---) C:\Documents and Settings\Administrador\NTUSER.DAT
650: File (-W-) C:\pagefile.sys
660: File (---) C:\Documents and Settings\NetworkService\NTUSER.DAT
974: File (---) C:\WINDOWS\system32\config\system.LOG
978: File (---) C:\WINDOWS\system32\config\default.LOG
988: File (---) C:\WINDOWS\system32\config\SAM.LOG
98C: File (---) C:\WINDOWS\system32\config\software.LOG
994: File (---) C:\WINDOWS\system32\config\software
9A0: File (---) C:\WINDOWS\system32\config\system
9B0: File (---) C:\WINDOWS\system32\config\SECURITY.LOG
9B4: File (---) C:\WINDOWS\system32\config\SECURITY
9B8: File (---) C:\WINDOWS\system32\config\SAM
9BC: File (---) C:\WINDOWS\system32\config\default
A04: File (---) C:\Documents and Settings\NetworkService\Configuración local\Datos de programa\Microsoft\Windows\UsrClass.dat
A18: File (---) C:\Documents and Settings\NetworkService\Configuración local\Datos de programa\Microsoft\Windows\UsrClass.dat.LOG
A3C: File (---) C:\Documents and Settings\NetworkService\ntuser.dat.LOG
B90: File (---) C:\Sandbox\Administrador\AVC3\RegHive
F38: File (---) C:\Sandbox\Administrador\AVC3\RegHive.LOG
|
It is System process who keeps RegHive and RegHive.LOG opened.
tzuk: Is there any way to know why that situation is produced? |
|
 |
| Sunny |
Posted: Fri Feb 18, 2011 7:22 pm Post subject: |
|
| thank you, Guest10. Now I wait till the next time this happens & then I can post an image. Wonder how long it will be. |
|
 |
| Guest10 |
Posted: Fri Feb 18, 2011 1:36 pm Post subject: |
|
| Sunny wrote: |
| is there a way to upload the gif? |
See my post, from another thread:
http://sandboxie.com/phpbb/viewtopic.php?t=9881&start=3
Upload your graphic to a file hosting site then include the link that they give you, in your message in this forum. |
|
 |
| Sunny |
Posted: Thu Feb 17, 2011 11:52 pm Post subject: |
|
afraid i'm not quite as savvy as you are giving me credit for.
1. I'm not deliberately "keeping old versions" I set oa to trust "sandboxie" program & oa does whatever it does...
now that I manually looked to see what it shows, should I make changes --
if I remove the duplicate older entry, will /should oa update to later versions of these same sandboxiefiles? cause I don't show current version of these sandboxie files listed in oa.
2. closed firefox / default sandbox, chose 'terminate all processes', then ran siw process explorer, chose find; 'sandbox' & it shows 16 processes. this is without problems. I saved screen shot gif file for reference. I surely don't understand process explorer's output. is there a way to upload the gif? should it be re-saved in another format? s when i next have the problem, will know how to save the process explorer output and get help. |
|
 |
| tzuk |
Posted: Wed Feb 16, 2011 11:52 pm Post subject: |
|
Ah, I understand. I guess that keeping the details of old versions of Sandboxie in your Online Armor can't hurt but it probably doesn't do anything either.
But as for your problem, I am not sure what to tell you. You might try to terminate all sandboxed processes, and then use the Process Explorer utility to look for SANDBOX . (It has a Find function in the main menu.) This might give you a hint about the cause of the problem. |
|
 |