Trust No Program
This topic is locked: you cannot edit posts or make replies.
Peter2150


Joined: 28 Mar 2007
Posts: 450
Location: Washington DC
Reply with quote
I did some testing in a fully patched Xp Pro Sp3 VM machine. I first put the IE.exe on the desktop and just ran it. It indeed was deleted. Then with the file on the desktop I right clicked it and ran it sandboxed. It still was deleted. Finally I put it in a folder, forced the folder and ran it from that folder. It ran sandboxed and indeed did delete the file.

THen I ran it from Internet Explorer and of course it never got to run due to start restrictions.

Pete
View user's profileSend private message
Buster


Joined: 06 Aug 2007
Posts: 2189
Reply with quote
I just did another test under a VM and I also can reproduce the behaviour. IE.EXE is able to delete itself from the sandbox.
View user's profileSend private message
MitchE323


Joined: 02 Nov 2006
Posts: 2268
Reply with quote
The only way I can get this ie.exe to delete is right click on it > delete. Shocked
View user's profileSend private message
tzuk


Joined: 22 Jun 2004
Posts: 15150
Reply with quote
All versions should see an "unknown executable image", but deletion outside the sandbox should only happen in version 3.43. Thanks for pointing it out raid. It will be fixed in version 3.43.10.

raid wrote:
The "unknown executable" is svchost.exe via LSA, and it's deleted my c:\hold2\ie.exe file


I don't know what you mean about LSA. That svchost.exe process is really another copy of ie.exe with a fake process name. The name-faking is confusing Sandboxie 3.43 and keeping the process in a "partially initialized" state. In this state the program is not fully supervised.

I fixed this in version 3.43. But this name-faking causes Sandboxie to fail to inject SbieDll into the process. So svchost.exe (ie.exe) will not actually work under Sandboxie.

_________________
tzuk
View user's profileSend private message
tzuk


Joined: 22 Jun 2004
Posts: 15150
Reply with quote
Please try version 3.43.10.
View user's profileSend private message
nick s


Joined: 20 Dec 2008
Posts: 331
Reply with quote
tzuk wrote:
Please try version 3.43.10.

The file deletion problem is fixed for me. I do get the following Sandboxie messages:

Quote:
SBIE2313 Could not execute SandboxieRpcSs.exe (2)
SBIE2204 Cannot start sandboxed service RpcSs (2)
SBIE1215 Cannot resolve path to process image [C0000005 / 88]
SBIE1214 Cannot inject SbieDll [C0000005 / 11]

Prior to 3.43.10, I was seeing 2313 & 2204. 1215 and 1214 are new with 3.43.10. I also now get the following Windows XP svchost.exe - Application Error alert:

Quote:
The application failed to initialize properly (0xc000010a). Click on OK to terminate the application.

_________________
Nick
View user's profileSend private message
raid


Joined: 23 Aug 2008
Posts: 58
Location: TN, USA
Reply with quote
tzuk wrote:
Please try version 3.43.10.


That seems to have fixed it for me, thanks!

_________________
Everything is so different, yet I am the same...
View user's profileSend private message
tzuk


Joined: 22 Jun 2004
Posts: 15150
Reply with quote
nick s wrote:
Prior to 3.43.10, I was seeing 2313 & 2204. 1215 and 1214 are new with 3.43.10.


I don't know why you see 2313 and 2204. But 1215 and 1214 are intentional here: The games this malware plays are incompatible with how Sandboxie injects SbieDll.
View user's profileSend private message
nick s


Joined: 20 Dec 2008
Posts: 331
Reply with quote
tzuk wrote:
I don't know why you see 2313 and 2204.

I've seen these messages occasionally when running malware sandboxed. Where malware is concerned, I consider it a Sandboxie feature rather than a problem Very Happy.
View user's profileSend private message
Sandboxed file can delete itself, outside of the sandbox!
You cannot post new topics in this forum
You can reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
All times are GMT  
Page 2 of 2  

Use the RSS feed to watch this topic for replies
  
  
 This topic is locked: you cannot edit posts or make replies.  

Sandboxie is Copyright © 2004-2012 by Sandboxie Holdings LLC.  All rights reserved.
Sandboxie.com | Contact Author
This site has been viewed 212,816,865 times since June 2004