![]() |
| Kaspersky link filter |
|
Guest
|
I had a really quick look at KIS 2010 and when I started Firefox Sandboxie poped up a message saying it was blocking klwtblfs.exe from starting. Maybe if you have the start/run access enable and dont have the issue message box ticked when access is denied that could be the problem. I didn't try the addon as I use Opera as my main browser so I have no idea if adding klwtblfs.exe helps. I cant test anymore as I went back to 2009 since 2010 didnt want to accept my key for some reason.
|
||||||||||||
|
|
|||||||||||||
|
Tony
|
Hi, yes i have already added klwtblfs.exe or firefox would not start.
I have tried adding everything i could find in program files and application data also. Thanks for trying to help though |
||||||||||||
|
|
|||||||||||||
|
tzuk
|
I tested and included support for this in version 3.37.19.
http://www.sandboxie.com/phpbb/viewtopic.php?t=5525 As usual this is just a matter of telling Sandboxie to which Kaspersky program resources it has to allow access. But one of those resources has a strange name that is a sequence of seemingly random letters and numbers. If that sequence is unique to my system then it will not work for you. But hopefully it is the same sequence for everyone. I'd like to hear your results. |
||||||||||||
|
_________________ tzuk |
|||||||||||||
|
Tony
|
Hi tzuk and thanks for taking the time to test this.
Before i installed 3.37.19 i deleted all settings that i had applied myself whilst trying to get it to work. After installation of 3.37.19, Firefox failed to start and an error box came up saying klwtblfs.exe would not initialise. I then added klwtblfs.exe to "Restrictions/Start Run Access" and firefox loaded okay but when i click the Kaspersky link filter "K Icon" it still says urls check is disabled. I should add that i am using the kaspersky antivirus only and not the Kaspersky internet security, although i would assume that the process for this part of Kaspersky would be the same for the AV and the Suite. |
||||||||||||
|
|
|||||||||||||
|
tzuk
|
At first I installed KIS on Windows Vista.
Now I also installed KAV on Windows XP. Both variations work with the same configuration set. Did you enable (or accept) the support for "Kaspersky Internet Security" in Software Compatibility? |
||||||||||||
|
|
|||||||||||||
|
Tony
|
Hi, yes i did enable (or accept) the support for "Kaspersky Internet Security" in Software Compatibility.
I have also tried a re-install. I also then disabled then re-enabled from the "Configure/ Software Compatability menu. I have KAV installed on Windows XP. EDIT: one thing to add, the virtual keyboard works just fine when selected from firefox toolbar. And i have exactly the same situation with Internet Explorer 8. |
||||||||||||
|
|
|||||||||||||
|
tzuk
|
Try invoking the Resource Access Monitor before starting your Web browser.
Then close the monitor and paste here. For more information: http://www.sandboxie.com/index.php?ResourceAccessMonitor |
||||||||||||
|
|
|||||||||||||
|
Tony
|
Here you are
(Drive) \Device\CdRom0 (Drive) \Device\Harddisk1\DP(1)0-0+8 (Drive) \Device\Harddisk2\DP(1)0-0+9 (Drive) \Device\Harddisk3\DP(1)0-0+a (Drive) \Device\Harddisk4\DP(1)0-0+b (Drive) \Device\Harddisk5\DP(1)0-0+c (Drive) \Device\HarddiskVolume1 (Drive) \Device\HarddiskVolume2 (Unk) 00000022 \Device\SandboxieDriverApi (Unk) 00000022 \Device\WMIDataDevice (Unk) 00000035 \Dfs (Unk) 00000039 \Device\KsecDD (Unk) 000000F1 \Device\RasAcd Clsid ------------------------------- Clsid {41C8D38D-3B56-4AF4-8BC2-361BC6ADED23} LinkFilterSyncObj Class Clsid {60407493-502E-4CCB-AC8C-0F6F9D2F5AC9} LinkHighlightFilter Class Clsid {CD9B4C01-9803-46B0-91B6-2136920C33E5} LinkFilter Class Clsid {E0CED967-3BAF-4693-8F2F-522AF524B318} LinkFilterThreadDep Class Ipc ------------------------------- Ipc \BaseNamedObjects\!IETld!Mutex Ipc \BaseNamedObjects\{A3BD3259-3E4F-428a-84C8-F0463A9D3EB5} Ipc \BaseNamedObjects\{A64C7F33-DA35-459b-96CA-63B51FB0CDB9} Ipc \BaseNamedObjects\ComPlusCOMRegTable Ipc \BaseNamedObjects\crypt32LogoffEvent Ipc \BaseNamedObjects\FirefoxStartupMutex Ipc \BaseNamedObjects\Ipc2Cnt$100 Ipc \BaseNamedObjects\KLWTBLFS.EXE" Ipc \BaseNamedObjects\RotHintTable Ipc \BaseNamedObjects\RPCSS_REGEVENT:{41C8D38D-3B56-4AF4-8BC2-361BC6ADED23} Ipc \BaseNamedObjects\SbieDllDummyEvent_1412 Ipc \BaseNamedObjects\SbieDllDummyEvent_1804 Ipc \BaseNamedObjects\SbieDllDummyEvent_1960 Ipc \BaseNamedObjects\SbieDllDummyEvent_256 Ipc \BaseNamedObjects\SbieDllDummyEvent_3648 Ipc \BaseNamedObjects\SbieServiceInitComplete_DcomLaunch Ipc \BaseNamedObjects\SbieServiceInitComplete_RpcSs Ipc \BaseNamedObjects\SbieWindowsInstallerInUse Ipc \BaseNamedObjects\ScmCreatedEvent Ipc \BaseNamedObjects\shell.{210A4BA0-3AEA-1069-A2D9-08002B30309D} Ipc \BaseNamedObjects\shell.{7CB834F0-527B-11D2-9D1F-0000F805CA57} Ipc \BaseNamedObjects\shell.{A48F1A32-A340-11D1-BC6B-00A0C90312E1} Ipc \BaseNamedObjects\UrlZonesSM_Dad Ipc \BaseNamedObjects\userenv: User Profile setup event Ipc \BaseNamedObjects\ZoneAttributeCacheCounterMutex Ipc \BaseNamedObjects\ZonesCacheCounterMutex Ipc \BaseNamedObjects\ZonesCounterMutex Ipc \BaseNamedObjects\ZonesLockedCacheCounterMutex Ipc \RPC Control\actkernel Ipc \RPC Control\epmapper Ipc \RPC Control\OLE295B63BB12DA4F8F86909A4BE147 Ipc \RPC Control\OLE49FAB202F0C94CD5A20C126FB08F Ipc O \BaseNamedObjects\{45DB34C3-955C-11D3-ABEF-444553540000} Hook Ipc O \BaseNamedObjects\{45DB34C3-955C-11D3-ABEF-444553540000} Interprocess Ipc O \BaseNamedObjects\{45DB34C3-955C-11D3-ABEF-444553540000} PrintList Ipc O \BaseNamedObjects\{45DB34C3-955C-11D3-ABEF-444553540000} SharedData Ipc O \BaseNamedObjects\{45DB34C3-955C-11D3-ABEF-444553540000} ShellWindowsWatcher Ipc O \BaseNamedObjects\{45DB34C3-955C-11D3-ABEF-444553540000}U3 Ipc O \BaseNamedObjects\{50EA3133-3D0D-44C2-8131-8A1BD21A5B99}AnswerBuf20$100Event1 Ipc O \BaseNamedObjects\{50EA3133-3D0D-44C2-8131-8A1BD21A5B99}AnswerBuf20$100Event2 Ipc O \BaseNamedObjects\{50EA3133-3D0D-44C2-8131-8A1BD21A5B99}AnswerBuf20$100Map Ipc O \BaseNamedObjects\CiceroSharedMemDefaultS-1-5-21-1728975953-2134157595-2106790746-1005 Ipc O \BaseNamedObjects\CTF.Asm.MutexDefaultS-1-5-21-1728975953-2134157595-2106790746-1005 Ipc O \BaseNamedObjects\CTF.AsmListCache.FMPDefaultS-1-5-21-1728975953-2134157595-2106790746-1005 Ipc O \BaseNamedObjects\CTF.Compart.MutexDefaultS-1-5-21-1728975953-2134157595-2106790746-1005 Ipc O \BaseNamedObjects\CTF.Layouts.MutexDefaultS-1-5-21-1728975953-2134157595-2106790746-1005 Ipc O \BaseNamedObjects\CTF.LBES.MutexDefaultS-1-5-21-1728975953-2134157595-2106790746-1005 Ipc O \BaseNamedObjects\CTF.ThreadMarshalInterfaceEvent.00000BC8.00000000.0000003E Ipc O \BaseNamedObjects\CTF.ThreadMIConnectionEvent.00000BC8.00000000.0000003E Ipc O \BaseNamedObjects\CTF.TimListCache.FMPDefaultS-1-5-21-1728975953-2134157595-2106790746-1005MUTEX.DefaultS-1-5-21-1728975953-2134157595-2106790746-1005 Ipc O \BaseNamedObjects\CTF.TimListCache.FMPDefaultS-1-5-21-1728975953-2134157595-2106790746-1005SFM.DefaultS-1-5-21-1728975953-2134157595-2106790746-1005 Ipc O \BaseNamedObjects\CTF.TMD.MutexDefaultS-1-5-21-1728975953-2134157595-2106790746-1005 Ipc O \BaseNamedObjects\DBWinMutex Ipc O \BaseNamedObjects\MSCTF.CheckThreadInptIdle.Event.ILH.GLCFLL Ipc O \BaseNamedObjects\MSCTF.CheckThreadInptIdle.Event.ILH.HOPELL Ipc O \BaseNamedObjects\MSCTF.MarshalInterface.FileMap.ILH..GLCFLL Ipc O \BaseNamedObjects\MSCTF.MarshalInterface.FileMap.ILH.B.FNCFLL Ipc O \BaseNamedObjects\MSCTF.MarshalInterface.FileMap.ILH.C.FNCFLL Ipc O \BaseNamedObjects\MSCTF.MarshalInterface.FileMap.ILH.D.FNCFLL Ipc O \BaseNamedObjects\MSCTF.MarshalInterface.FileMap.ILH.E.FNCFLL Ipc O \BaseNamedObjects\MSCTF.MarshalInterface.FileMap.ILH.F.FNCFLL Ipc O \BaseNamedObjects\MSCTF.MarshalInterface.FileMap.ILH.G.FNCFLL Ipc O \BaseNamedObjects\MSCTF.MarshalInterface.FileMap.IML.LB.FNCFLL Ipc O \BaseNamedObjects\MSCTF.MarshalInterface.FileMap.IML.MB.FNCFLL Ipc O \BaseNamedObjects\MSCTF.MarshalInterface.FileMap.IML.NB.FNCFLL Ipc O \BaseNamedObjects\MSCTF.SendReceive.Event.IML.IC Ipc O \BaseNamedObjects\MSCTF.SendReceiveConection.Event.IML.IC Ipc O \BaseNamedObjects\MSCTF.Shared.MUTEX.IML Ipc O \BaseNamedObjects\MSCTF.Shared.SFM.IML Ipc O \BaseNamedObjects\PRCustomProps#1cb Ipc O \BaseNamedObjects\PRCustomProps#1cb:sync_obj Ipc O \BaseNamedObjects\PREvent1960#1cb Ipc O \BaseNamedObjects\PRObjects#1cb Ipc O \BaseNamedObjects\PRObjects#1cb:sync_obj Ipc O \BaseNamedObjects\Sandboxie_DeviceIdList Ipc O \BaseNamedObjects\Sandboxie_DeviceSetupClasses Ipc O \BaseNamedObjects\ShimCacheMutex Ipc O \BaseNamedObjects\ShimSharedMemory Ipc O \KnownDlls\advapi32.dll Ipc O \KnownDlls\appHelp.dll Ipc O \KnownDlls\comdlg32.dll Ipc O \KnownDlls\gdi32.dll Ipc O \KnownDlls\iertutil.dll Ipc O \KnownDlls\imagehlp.dll Ipc O \KnownDlls\kernel32.dll Ipc O \KnownDlls\MPR.dll Ipc O \KnownDlls\msvcrt.dll Ipc O \KnownDlls\Normaliz.dll Ipc O \KnownDlls\ole32.dll Ipc O \KnownDlls\oleaut32.dll Ipc O \KnownDlls\rpcrt4.dll Ipc O \KnownDlls\Secur32.dll Ipc O \KnownDlls\shell32.dll Ipc O \KnownDlls\SHLWAPI.dll Ipc O \KnownDlls\urlmon.dll Ipc O \KnownDlls\user32.dll Ipc O \KnownDlls\USERENV.dll Ipc O \KnownDlls\version.dll Ipc O \KnownDlls\wininet.dll Ipc O \KnownDlls\wldap32.dll Ipc O \LsaAuthenticationPort Ipc O \NLS\NlsSectionCType Ipc O \NLS\NlsSectionLocale Ipc O \NLS\NlsSectionSortkey Ipc O \NLS\NlsSectionSortTbls Ipc O \NLS\NlsSectionUnicode Ipc O \RPC Control\DNSResolver Ipc O \RPC Control\PRRemote:1556 Ipc O \RPC Control\PRRemote:1960 Ipc O \RPC Control\SbieSvcPort Ipc O \Security\LSA_AUTHENTICATION_INITIALIZED Ipc O \ThemeApiPort Ipc O \Windows\ApiPort Ipc X \BaseNamedObjects\!IETld!Mutex Ipc X \BaseNamedObjects\3f282e5033ba1b650351fde1bcd1575e3f10a17532817cbd503c32 Ipc X \BaseNamedObjects\mc2SWDIJ1 Pipe ------------------------------- Pipe O \Device\Afd Pipe O \Device\Afd\AsyncConnectHlp Pipe O \Device\Afd\Endpoint Pipe X \Device\NamedPipe\lsarpc Pipe X \Device\NamedPipe\wkssvc WinCls ------------------------------- WinCls O Shell_TrayWnd WinCls X DDEMLMom WinCls X FirefoxMessageWindow WinCls X Progman WinCls X SUPERANTISPYWARE |
||||||||||||
|
|
|||||||||||||
|
tzuk
|
Thanks.
That's what I was talking about earlier. Go to Sandbox Settings > IPC Access > Direct Access, click Add and enter:
I'm pretty sure it will work after this. That's the random-looking resource name that I mentioned earlier. It's not even the same length (i.e. number of characters) as it was for me. |
||||||||||||||||
|
|
|||||||||||||||||
|
Tony
|
Hi.
Yes its working fine now I only wish i could understand how to figure it out myself as i do not understand how you came to the conclusion from my post lol. Thanks tzuk. |
||||||||||||
|
|
|||||||||||||
|
Tony
|
There would appear to be another problem.
If i browse with Sandboxie disabled forced programs then only one Kaspersky url advisor process "klwtblfs.exe" runs. Once Sandboxie forced programs is enabled then klwtblfs.exe starts a new process for every web page that loads. Uncheck the "check all urls" box does not make any difference. Disable the browser add on stops this process from running. I am running 3.38 version now. |
||||||||||||
|
|
|||||||||||||
|
Tony
|
Here is the results from resourse monitor.
firefox browser was already opened before i started logging the events and i browsed just a few pages. (Drive) \Device\CdRom0 (Drive) \Device\Harddisk1\DP(1)0-0+8 (Drive) \Device\Harddisk2\DP(1)0-0+9 (Drive) \Device\Harddisk3\DP(1)0-0+a (Drive) \Device\Harddisk4\DP(1)0-0+b (Drive) \Device\Harddisk5\DP(1)0-0+c (Drive) \Device\HarddiskVolume1 (Drive) \Device\HarddiskVolume2 (Unk) 00000022 \Device\SandboxieDriverApi (Unk) 00000039 \Device\KsecDD (Unk) 000000F1 \Device\RasAcd Clsid ------------------------------- Clsid {41C8D38D-3B56-4AF4-8BC2-361BC6ADED23} LinkFilterSyncObj Class Clsid {45C5B34D-0F78-4AE5-BCC9-AD0E0953DDF6} Link Class Clsid {5F5F6D79-C4A3-4740-8284-0631F402B642} Collection Class Clsid {926869E0-1C7C-408C-B130-D674467E9B55} FilteredLink Class Ipc ------------------------------- Ipc \BaseNamedObjects\_!MSFTHISTORY!_ Ipc \BaseNamedObjects\c:!documents and settings!dad!cookies! Ipc \BaseNamedObjects\c:!documents and settings!dad!local settings!history!history.ie5! Ipc \BaseNamedObjects\c:!documents and settings!dad!local settings!temporary internet files!content.ie5! Ipc \BaseNamedObjects\C:_Documents and Settings_Dad_Cookies_index.dat_49152 Ipc \BaseNamedObjects\C:_Documents and Settings_Dad_Local Settings_History_History.IE5_index.dat_114688 Ipc \BaseNamedObjects\C:_Documents and Settings_Dad_Local Settings_Temporary Internet Files_Content.IE5_index.dat_507904 Ipc \BaseNamedObjects\KLWTBLFS.EXE" Ipc \BaseNamedObjects\RPCSS_REGEVENT:{41C8D38D-3B56-4AF4-8BC2-361BC6ADED23} Ipc \BaseNamedObjects\SbieDllDummyEvent_1848 Ipc \BaseNamedObjects\SbieDllDummyEvent_1916 Ipc \BaseNamedObjects\SbieDllDummyEvent_2420 Ipc \BaseNamedObjects\SbieDllDummyEvent_3872 Ipc \BaseNamedObjects\SbieServiceInitComplete_RpcSs Ipc \RPC Control\epmapper Ipc \RPC Control\OLE4BD64D6410A344D6A49D918DD1CD Ipc \RPC Control\OLE798649579FF34B1085E44DB344BC Ipc \RPC Control\OLE7F2DB31BC605437A93A180296909 Ipc \RPC Control\OLEA500AD53E34740B5B5404322DBCA Ipc O \BaseNamedObjects\CiceroSharedMemDefaultS-1-5-21-1728975953-2134157595-2106790746-1005 Ipc O \BaseNamedObjects\CTF.Asm.MutexDefaultS-1-5-21-1728975953-2134157595-2106790746-1005 Ipc O \BaseNamedObjects\CTF.Compart.MutexDefaultS-1-5-21-1728975953-2134157595-2106790746-1005 Ipc O \BaseNamedObjects\CTF.Layouts.MutexDefaultS-1-5-21-1728975953-2134157595-2106790746-1005 Ipc O \BaseNamedObjects\CTF.LBES.MutexDefaultS-1-5-21-1728975953-2134157595-2106790746-1005 Ipc O \BaseNamedObjects\CTF.TimListCache.FMPDefaultS-1-5-21-1728975953-2134157595-2106790746-1005MUTEX.DefaultS-1-5-21-1728975953-2134157595-2106790746-1005 Ipc O \BaseNamedObjects\CTF.TimListCache.FMPDefaultS-1-5-21-1728975953-2134157595-2106790746-1005SFM.DefaultS-1-5-21-1728975953-2134157595-2106790746-1005 Ipc O \BaseNamedObjects\CTF.TMD.MutexDefaultS-1-5-21-1728975953-2134157595-2106790746-1005 Ipc O \BaseNamedObjects\MSCTF.SendReceive.Event.ABP.IC Ipc O \BaseNamedObjects\MSCTF.SendReceive.Event.MMI.IC Ipc O \BaseNamedObjects\MSCTF.SendReceiveConection.Event.ABP.IC Ipc O \BaseNamedObjects\MSCTF.SendReceiveConection.Event.MMI.IC Ipc O \BaseNamedObjects\MSCTF.Shared.MUTEX.MMI Ipc O \BaseNamedObjects\MSCTF.Shared.SFM.MMI Ipc O \BaseNamedObjects\WininetConnectionMutex Ipc O \BaseNamedObjects\WininetProxyRegistryMutex Ipc O \BaseNamedObjects\WininetStartupMutex Ipc O \KnownDlls\advapi32.dll Ipc O \KnownDlls\gdi32.dll Ipc O \KnownDlls\kernel32.dll Ipc O \KnownDlls\msvcrt.dll Ipc O \KnownDlls\ole32.dll Ipc O \KnownDlls\oleaut32.dll Ipc O \KnownDlls\rpcrt4.dll Ipc O \KnownDlls\Secur32.dll Ipc O \KnownDlls\user32.dll Ipc O \KnownDlls\version.dll Ipc O \LsaAuthenticationPort Ipc O \NLS\NlsSectionCType Ipc O \NLS\NlsSectionLocale Ipc O \NLS\NlsSectionSortkey Ipc O \NLS\NlsSectionSortTbls Ipc O \NLS\NlsSectionUnicode Ipc O \RPC Control\SbieSvcPort Ipc O \Security\LSA_AUTHENTICATION_INITIALIZED Ipc O \ThemeApiPort Ipc O \Windows\ApiPort Ipc X \BaseNamedObjects\_!MSFTHISTORY!_ Ipc X \BaseNamedObjects\c:!documents and settings!dad!cookies! Ipc X \BaseNamedObjects\c:!documents and settings!dad!local settings!history!history.ie5! Ipc X \BaseNamedObjects\c:!documents and settings!dad!local settings!temporary internet files!content.ie5! Ipc X \BaseNamedObjects\C:_Documents and Settings_Dad_Cookies_index.dat_49152 Ipc X \BaseNamedObjects\C:_Documents and Settings_Dad_Local Settings_History_History.IE5_index.dat_114688 Ipc X \BaseNamedObjects\C:_Documents and Settings_Dad_Local Settings_Temporary Internet Files_Content.IE5_index.dat_507904 Ipc X \BaseNamedObjects\mc2SWDIJ1 Pipe ------------------------------- Pipe O \Device\Afd Pipe O \Device\Afd\Endpoint Pipe X \Device\NamedPipe\lsarpc WinCls ------------------------------- WinCls O CicLoaderWndClass WinCls O CicMarshalWndClass |
||||||||||||
|
|
|||||||||||||
|
Tony
|
I also use Online Armor paid.
I have been running Firefox as "Run Safer" in Online Armor settings, and disabled drop my rights in Sandboxie settings. Now that i have set Firefox to "Run Normal" there would appear to be only one instance of KLWTBLFS.EXE running. So i would assume that there is some slight conflict somewhere between Online Armor "run safer" mode and Sandboxie. |
||||||||||||
|
|
|||||||||||||
|
tzuk
|
More precisely, it is the combination of Online Armor "Run Safer", the Kaspersky URL checker, and Sandboxie, right?
This behavior happens with IE8 or Firefox? I'm asking because IE8 starts a new process for every web page (or almost every page) so perhaps that has something to do with multiple klwtblfs.exe. But Firefox has just one process for everything. |
||||||||||||||
|
|
|||||||||||||||
| Kaspersky link filter |
|
||
|


Use the RSS feed to watch this topic for replies