Trust No Program
Reply to topic
shell32dll
Guest

Reply with quote


BSA Version : BSA 1.71
Sanboxie : 3.72

how can i fix this error?
Buster


Joined: 06 Aug 2007
Posts: 2185
Reply with quote
shell32dll wrote:
BSA Version : BSA 1.71
Sanboxie : 3.72

how can i fix this error?


Does the error appear with every application you test (like NOTEPAD.EXE) or only with one file?

If it happens only with one file: send me the file, please.
View user's profileSend private message
shell32dll
Guest

Reply with quote
Quote:
Does the error appear with every application you test (like NOTEPAD.EXE) or only with one file?

If it happens only with one file: send me the file, please.


yes sir.. every application that I test produces the error.. can you help me?
Scrapie


Joined: 18 May 2011
Posts: 49
Reply with quote
Hi there

Works fine for me under Win7 Prof. and Sandboxie v3.70.


Scrapie
View user's profileSend private message
Buster


Joined: 06 Aug 2007
Posts: 2185
Reply with quote
Scrapie wrote:
Works fine for me under Win7 Prof. and Sandboxie v3.70.


Update to 3.72. Wink
View user's profileSend private message
Buster


Joined: 06 Aug 2007
Posts: 2185
Reply with quote
shell32dll wrote:
yes sir.. every application that I test produces the error.. can you help me?


First update to BSA 1.72 and try again. It should crash anyway, but let´s try.

If version 1.72 does not work, send me a mail to the mail address that appears in the manual and I will send you a custom version that may help to locate the origin of the bug.
View user's profileSend private message
shell32dll
Guest

Reply with quote
i have found it. when i used LOG_API.DLL from folder BSA\LOG_API\, the program still working. the problem wll occur when i use the old version of LOG_API.DLL.
Buster


Joined: 06 Aug 2007
Posts: 2185
Reply with quote
shell32dll wrote:
i have found it. when i used LOG_API.DLL from folder BSA\LOG_API\, the program still working. the problem wll occur when i use the old version of LOG_API.DLL.


Yes, updating LOG_API is necessary.

I will try to introduce a checking in BSA so it checks you are using a valid LOG_API dll version.
View user's profileSend private message
Bsa.sys - Trojan false alarms?
matzen
Guest

Reply with quote
Hi

I´d like to know why is it that Bsa.sys, being such a small file, shows so many false positives (12!). Other files seem mostly clean (1 false positive at most).

https://www.virustotal.com/file/fc3dec19ba7387874099565192fd3ec28aeb396fc33f18275ac9c3d306237a1e/analysis/

Thank you!
Re: Bsa.sys - Trojan false alarms?
Buster


Joined: 06 Aug 2007
Posts: 2185
Reply with quote
matzen wrote:
I´d like to know why is it that Bsa.sys, being such a small file, shows so many false positives (12!). Other files seem mostly clean (1 false positive at most).


Because it makes use of certain APIs commonly used by malwares I guess.
View user's profileSend private message
Re: Bsa.sys - Trojan false alarms?
Scrapie


Joined: 18 May 2011
Posts: 49
Reply with quote
Buster wrote:
Because it makes use of certain APIs commonly used by malwares I guess.

No, the "detection" is simply based on the File-Hash. Change a single (!) byte (for example offset 2310 from 4D to 6D which wont break the driver) and the "detection" drops from 12 AV's to 2 AV's Rolling Eyes
AV's are full of s***t and love to copy "signatures" from each other so in the next test they score the same as the others - even if a "detection" makes no sense. They didn't even made the effort to generate a propper signature for the file. Easier to add a hash, done in a second and no danger of a FP...

Patched BSA.SYS *Click*


Scrapie
View user's profileSend private message
matzen
Guest

Reply with quote
thank you for your answers!
DrCoolZic


Joined: 08 Mar 2011
Posts: 5
Location: France
Reply with quote
I have updated Sandboxie to 3.72 (64bits) and BSA to 1.72
I have modified the sandboxie.ini with these lines:
Code:
InjectDll=U:\StaticProgram\bsa\LOG_API\64\LOG_API32.DLL
InjectDll64=U:\StaticProgram\bsa\LOG_API\64\LOG_API64.DLL
OpenWinClass=TFormBSA
NotifyDirectDiskAccess=y
ProcessLimit1=20
ProcessLimit2=30

When I click "Start Analysis" in BSA a window pops up saying "Window title does not match LOG_API string!"
What does that means ??? Is it a problem ?

Another small annoyance: I am using a dual screen display and any BSA windows displayed is located in the middle of the two screens (that is half on the left screen and half on the right screen). So each time it is necessary to move the windows displayed by BSA. The window is placed like that when you start the program but also when you execute commands like start/Finish analysis, malware analyzer etc. ... would be nice to fix this behavior perhaps by storing the last position of the windows (at least the main windows) ?

Thanks - Jean
View user's profileSend private message
Buster


Joined: 06 Aug 2007
Posts: 2185
Reply with quote
DrCoolZic wrote:
I have updated Sandboxie to 3.72 (64bits) and BSA to 1.72
I have modified the sandboxie.ini with these lines:
Code:
InjectDll=U:\StaticProgram\bsa\LOG_API\64\LOG_API32.DLL
InjectDll64=U:\StaticProgram\bsa\LOG_API\64\LOG_API64.DLL
OpenWinClass=TFormBSA
NotifyDirectDiskAccess=y
ProcessLimit1=20
ProcessLimit2=30

When I click "Start Analysis" in BSA a window pops up saying "Window title does not match LOG_API string!"
What does that means ??? Is it a problem ?


Did you click at "Options > Program Options > Change title" and changed BSA´s window title from "Buster Sandbox Analyzer" to other string?

DrCoolZic wrote:
Another small annoyance: I am using a dual screen display and any BSA windows displayed is located in the middle of the two screens (that is half on the left screen and half on the right screen). So each time it is necessary to move the windows displayed by BSA. The window is placed like that when you start the program but also when you execute commands like start/Finish analysis, malware analyzer etc. ... would be nice to fix this behavior perhaps by storing the last position of the windows (at least the main windows) ?

Thanks - Jean


Try with "Options > Program Options > Remember Window Position".
View user's profileSend private message
DrCoolZic


Joined: 08 Mar 2011
Posts: 5
Location: France
Reply with quote
Buster wrote:
Did you click at "Options > Program Options > Change title" and changed BSA´s window title from "Buster Sandbox Analyzer" to other string?

No - The title in the BSA window is "Buster Sandbox Analyzer"

DrCoolZic wrote:
Try with "Options > Program Options > Remember Window Position".

Did not know about this one!
But it is not really working! When I start the program it does remember the window position, however if I click "Start Analysis" the window is put back in center of the two screen and same happen when I click "Finish Analysis". However "Malware analyzer" does not move the window.
Also several popup windows like "Sandox folder not Empty", "Malware Behavior Analyzer Module", are open in midle of two screens.
View user's profileSend private message
Buster Sandbox Analyzer
You cannot post new topics in this forum
You can reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
All times are GMT  
Page 46 of 60  

Use the RSS feed to watch this topic for replies
  
  
 Reply to topic  

Sandboxie is Copyright © 2004-2012 by Sandboxie Holdings LLC.  All rights reserved.
Sandboxie.com | Contact Author
This site has been viewed 208,482,641 times since June 2004