Trust No Program
Reply to topic
Shield


Joined: 10 Dec 2008
Posts: 29
Reply with quote
Thanks majoMo, this will be quite handy!

Happy holidays!
View user's profileSend private message
SandboxDiff Updated
majoMo


Joined: 30 Jun 2008
Posts: 13
Reply with quote
SandboxDiff updated.

Changes:

- Added Registry changes in .reg format (Windows Registry Editor Version 5.00)

Thus the Registry and Files changes are avaliable in text, .reg (registry) and .html (here you can see all files and registry entries created by sandbox'process).


* Download and info in first post. *
View user's profileSend private message
MFS


Joined: 06 Dec 2008
Posts: 0
Reply with quote
Thank you. I'll test it. Very Happy
View user's profileSend private message
~tmp
Guest

Reply with quote
Some antivirs don't like the techniques you use in the subj.
Comodo, NOD32, AViRA... say something like:
TrojWare.Win32.Qhost.~AR@1639959
and possible dangerous packer-cruncher blah-blah-blah.

Take it easy, even Kaspersky says SBie is a really very dangerous thing too.
Just make a note saying the program analyzes both real and virtual registry plus both real and virtual filesystem then compares the results. It is intended for this.
raid


Joined: 23 Aug 2008
Posts: 58
Location: TN, USA
Reply with quote
Thanks for the update regarding this program.

Another program I've found useful is the Mitec Windows Registry Recovery Tool. You can mount the reghive after you run your sandboxed application and see exactly what it's added to the "registry" as far as it knows. Smile

So if it's added policies, you will know. Any entries in the sandboxed registry can be viewed with ease using this tool.

http://www.mitec.cz/wrr.html

_________________
Everything is so different, yet I am the same...
View user's profileSend private message
tzuk


Joined: 22 Jun 2004
Posts: 15003
Reply with quote
majoMo, I can add this utility here if you want:

http://www.sandboxie.com/index.php?ContributedUtilities

_________________
tzuk
View user's profileSend private message
majoMo


Joined: 30 Jun 2008
Posts: 13
Reply with quote
@ tzuk, very interesting the "Contributed Utilities page". It seems useful for SandboxIE'users really. Like requested, the answer is affirmative: I want. Thanks for your kindly information.
View user's profileSend private message
tzuk


Joined: 22 Jun 2004
Posts: 15003
Reply with quote
My pleasure. Let me know if you don't me to host the file on this server. Or if you're ok with it, let me know when I should update the copy that I host here.

http://www.sandboxie.com/index.php?ContributedUtilities
View user's profileSend private message
majoMo


Joined: 30 Jun 2008
Posts: 13
Reply with quote
@ tzuk, to host in that server it's well. When any update comes out I'll inform you firstly.

Regards.
View user's profileSend private message
How do I safely uninstall this?
MrZ


Joined: 23 Feb 2009
Posts: 1
Reply with quote
The program after install in Vista seems to put files in different places, for example I found "wait.exe" and "regdiff.exe" in my c:\users\myname\appdata\local folder. Later they disappeared from that folder! I know they were there at one time, then they disappeared.

Can you explain where these various executables are? Where else would your program put them?
View user's profileSend private message
majoMo


Joined: 30 Jun 2008
Posts: 13
Reply with quote
The files used by SandboxDiff in that folder (temporarily) are listed in help file.
View user's profileSend private message
regdump.exe error
t-max
Guest

Reply with quote
Hi,
I get an error with regdump.exe, after making an installation of MS Office 2003.

Does anybody know what can be causing it?
majoMo


Joined: 30 Jun 2008
Posts: 13
Reply with quote
Hi t-max, thanks for your reporting.

I was able to reproduce that error with same app.. In fact the file "regdump.exe", used by SandboxDiff, crashed when loading the hive file; there is a bug in that executable indeed (it's an unusual bug with it).

It seems that when loading some hive files "regdump.exe" crashes.

Consequences? The registries changes in "Comp-Reg.txt" file isn't complete; it record the changes until the crash time. Tip: when "regdump.exe" crashes the reliable and accurate registry changes are in the file "Comp-Reg.REG.txt" (in .reg format).

In the next release I'll reenforce SandboxDiff to check the reliableness in "Comp-Reg.REG.txt" record. At least we can have one trusty registry changes file if occur a crash in that file.
View user's profileSend private message
majoMo


Joined: 30 Jun 2008
Posts: 13
Reply with quote
SandboxDiff updated.

Changes:

- Analyzing/Comparing process far faster now.


Download in: Contributed Utilities page.
View user's profileSend private message
comp-reg error
gyp


Joined: 24 May 2009
Posts: 0
Reply with quote
In comp-reg.txt I am getting

1d0
< hive path err
\ No newline at end of file

Otherwise seems to be functioning very easy
View user's profileSend private message
SandboxDiff - Registry/Files changes
You cannot post new topics in this forum
You can reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
All times are GMT  
Page 3 of 7  

Use the RSS feed to watch this topic for replies
  
  
 Reply to topic  

Sandboxie is Copyright © 2004-2012 by Sandboxie Holdings LLC.  All rights reserved.
Sandboxie.com | Contact Author
This site has been viewed 208,289,212 times since June 2004