What is your Sandboxie setup?

Discussion in 'sandboxing & virtualization' started by Konata Izumi, Oct 19, 2011.

Thread Status:
Not open for further replies.
  1. syncmaster913n

    syncmaster913n Registered Member

    Joined:
    Mar 24, 2012
    Posts:
    153
    I just started using Sandboxie a few days ago, here's my config at the moment. If anyone has any comments or ideas/input, please feel free.

    Code:
    
    [GlobalSettings]
     
    Template=Microsoft_EMET
    Template=ComodoInternetSecurity
    Template=VPNTunnel
    Template=Avira_Antivirus
    Template=7zipShellEx
    Template=KeyScrambler
    ProcessGroup=<StartRunAccess_Documents>,foxit reader.exe,foxitr~1.exe,scalc.exe,soffice.exe
    ProcessGroup=<StartRunAccess_Tools>,ccleaner.exe,tempcleaner.exe,tempcl~1.exe,flashcookiescleaner.exe,flashc~1.exe,stripper.exe,hos3tvtp.exe,muicacheview.exe,muicac~1.exe,regseeker.exe,regsee~1.exe
    ProcessGroup=<StartRunAccess_Video>,vlc.exe
    ProcessGroup=<StartRunAccess_uTorrent>,utorrent.exe
    ProcessGroup=<InternetAccess_uTorrent>,utorrent.exe
    ProcessGroup=<StartRunAccess_Browser>,chrome.exe
    ProcessGroup=<InternetAccess_Browser>,chrome.exe
    EditAdminOnly=n
    ForceDisableAdminOnly=n
    ForgetPassword=n
     
    [UserSettings_08DA01C0]
     
    SbieCtrl_UserName=user
    SbieCtrl_NextUpdateCheck=1333717990
    SbieCtrl_UpdateCheckNotify=y
    SbieCtrl_ShowWelcome=n
    SbieCtrl_WindowLeft=276
    SbieCtrl_WindowTop=188
    SbieCtrl_WindowWidth=660
    SbieCtrl_WindowHeight=450
    SbieCtrl_ActiveView=40021
    SbieCtrl_AutoApplySettings=n
    SbieCtrl_HideWindowNotify=n
    SbieCtrl_BoxExpandedView_DefaultBox=y
    SbieCtrl_EditConfNotify=n
    SbieCtrl_ReloadConfNotify=n
    SbieCtrl_RecoverTarget=C:\Users\User\Desktop
    SbieCtrl_SaveRecoverTargets=y
    SbieCtrl_SettingChangeNotify=n
    SbieCtrl_BoxExpandedView_Browser=n
    SbieCtrl_BoxExpandedView_Documents=y
    SbieCtrl_BoxExpandedView_Video=y
    SbieCtrl_BoxExpandedView_Tools=y
    SbieCtrl_BoxExpandedView_uTorrent=y
     
    [Browser]
     
    ConfigLevel=7
    Template=BlockPorts
    Template=AutoRecoverIgnore
    Template=Firefox_Phishing_DirectAccess
    Template=LingerPrograms
    RecoverFolder=%Desktop%
    Enabled=y
    ClosedFilePath=\Device\Mup\
    ClosedFilePath=C:\Program Files\Malwarebytes' Anti-Malware\
    ClosedFilePath=C:\Program Files\COMODO\
    ClosedFilePath=C:\Program Files\TrueCrypt\
    ClosedFilePath=H:\
    ClosedFilePath=I:\
    ClosedFilePath=C:\Program Files\7-Zip\
    ClosedFilePath=C:\Program Files\Avira\
    ClosedFilePath=C:\Program Files\CCleaner\
    ClosedFilePath=C:\Program Files\DAEMON Tools Pro\
    ClosedFilePath=C:\Program Files\EMET\
    ClosedFilePath=C:\Program Files\epson\
    ClosedFilePath=C:\Program Files\Eraser\
    ClosedFilePath=C:\Program Files\Foxit Software\
    ClosedFilePath=C:\Program Files\Internet Explorer\
    ClosedFilePath=C:\Program Files\Java\
    ClosedFilePath=C:\Program Files\KeyScrambler\
    ClosedFilePath=C:\Program Files\NapiProjekt\
    ClosedFilePath=C:\Program Files\Nokia\
    ClosedFilePath=C:\Program Files\OpenOffice.org 3\
    ClosedFilePath=C:\Program Files\Steam\
    ClosedFilePath=C:\Program Files\VideoLAN\
    ClosedFilePath=C:\Program Files\uTorrent\
    ClosedFilePath=C:\Program Files\Yahoo!\
    ClosedFilePath=C:\Program Files\Winamp\
    ClosedFilePath=D:
    ClosedFilePath=E:\
    ClosedFilePath=F:\
    ClosedFilePath=G:\
    ClosedFilePath=K:\
    ClosedFilePath=L:\
    ClosedFilePath=%Local AppData%\Amazon\
    ClosedFilePath=%Local AppData%\Apps\
    ClosedFilePath=%Local AppData%\ArcSoft\
    ClosedFilePath=%Local AppData%\Deployment\
    ClosedFilePath=%Local AppData%\Diagnostics\
    ClosedFilePath=%Local AppData%\Eraser 6\
    ClosedFilePath=%Local AppData%\Temp\
    ClosedFilePath=%Local AppData%\uTorrent\
    ClosedFilePath=%Local AppData%\VirtualStore\
    ClosedFilePath=!<InternetAccess_Browser>,\Device\Http\*
    ClosedFilePath=!<InternetAccess_Browser>,\Device\Nsi
    ClosedFilePath=!<InternetAccess_Browser>,\Device\RawIp6
    ClosedFilePath=!<InternetAccess_Browser>,\Device\Udp6
    ClosedFilePath=!<InternetAccess_Browser>,\Device\Tcp6
    ClosedFilePath=!<InternetAccess_Browser>,\Device\Ip6
    ClosedFilePath=!<InternetAccess_Browser>,\Device\RawIp
    ClosedFilePath=!<InternetAccess_Browser>,\Device\Udp
    ClosedFilePath=!<InternetAccess_Browser>,\Device\Tcp
    ClosedFilePath=!<InternetAccess_Browser>,\Device\Ip
    ClosedFilePath=!<InternetAccess_Browser>,\Device\Afd*
    ReadFilePath=C:\Adobe\
    ReadFilePath=C:\Google\
    ReadFilePath=C:\Windows\
    ReadKeyPath=\REGISTRY\MACHINE\SOFTWARE\Classes\CLSID\{23170F69-40C1-278A-1000-000100020000}
    ReadKeyPath=HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\
    OpenIpcPath=*\BaseNamedObjects*\KSEncStatusEvent
    OpenIpcPath=*\BaseNamedObjects*\KSProcEvent*
    OpenIpcPath=*\BaseNamedObjects*\KSEncryptionEvent*
    OpenIpcPath=*\BaseNamedObjects*\KeyScrambler*
    OpenIpcPath=\Device\KeyScrambler
    OpenIpcPath=*\BaseNamedObjects*\7zMap*
    OpenIpcPath=*\BaseNamedObjects*\7zCompressMapping*
    OpenPipePath=\Device\NamedPipe\KSTIPipe*
    OpenFilePath=firefox.exe,*\urlclassifier*.sqlite*
    AutoRecoverIgnore=.dtapart
    AutoRecoverIgnore=.download
    AutoRecoverIgnore=.tmp
    AutoRecoverIgnore=.dlm
    AutoRecoverIgnore=.leechget
    AutoRecoverIgnore=.jc!
    AutoRecoverIgnore=.part
    AutoDelete=y
    NeverDelete=n
    NotifyInternetAccessDenied=y
    NotifyStartRunAccessDenied=y
    DropAdminRights=y
    ClosedIpcPath=!<StartRunAccess_Browser>,*
    DeleteCommand="C:\Program Files\Eraser\Eraser.exe" addtask --quiet --method=ecbf4998-0b4f-445c-9a06-23627659e419 --schedule=now --dir="%SANDBOX\\%"
     
    [Documents]
     
    ConfigLevel=7
    Template=BlockPorts
    Template=AutoRecoverIgnore
    Template=Firefox_Phishing_DirectAccess
    Template=LingerPrograms
    Enabled=y
    ClosedFilePath=\Device\Http\*
    ClosedFilePath=\Device\Nsi
    ClosedFilePath=\Device\RawIp6
    ClosedFilePath=\Device\Udp6
    ClosedFilePath=\Device\Tcp6
    ClosedFilePath=\Device\Ip6
    ClosedFilePath=\Device\RawIp
    ClosedFilePath=\Device\Udp
    ClosedFilePath=\Device\Tcp
    ClosedFilePath=\Device\Ip
    ClosedFilePath=\Device\Afd*
    ClosedFilePath=\Device\Mup\
    ClosedFilePath=C:\Program Files\Malwarebytes' Anti-Malware\
    ClosedFilePath=C:\Program Files\COMODO\
    ClosedFilePath=C:\Program Files\TrueCrypt\
    ClosedFilePath=H:\
    ClosedFilePath=I:\
    ClosedFilePath=K:\
    ClosedFilePath=L:\
    ClosedFilePath=C:\Program Files\7-Zip\
    ClosedFilePath=C:\Program Files\Avira\
    ClosedFilePath=C:\Program Files\CCleaner\
    ClosedFilePath=C:\Program Files\DAEMON Tools Pro\
    ClosedFilePath=C:\Program Files\EMET\
    ClosedFilePath=C:\Program Files\epson\
    ClosedFilePath=C:\Program Files\Eraser\
    ClosedFilePath=C:\Program Files\Internet Explorer\
    ClosedFilePath=C:\Program Files\Java\
    ClosedFilePath=C:\Program Files\KeyScrambler\
    ClosedFilePath=C:\Program Files\NapiProjekt\
    ClosedFilePath=C:\Program Files\Nokia\
    ClosedFilePath=C:\Program Files\Steam\
    ClosedFilePath=C:\Program Files\VideoLAN\
    ClosedFilePath=C:\Program Files\uTorrent\
    ClosedFilePath=C:\Program Files\Yahoo!\
    ClosedFilePath=C:\Program Files\Winamp\
    ClosedFilePath=D:
    ClosedFilePath=E:\
    ClosedFilePath=F:\
    ClosedFilePath=G:
    ClosedFilePath=!<InternetAccess_Browser>,\Device\Http\*
    ClosedFilePath=!<InternetAccess_Browser>,\Device\Nsi
    ClosedFilePath=!<InternetAccess_Browser>,\Device\RawIp6
    ClosedFilePath=!<InternetAccess_Browser>,\Device\Udp6
    ClosedFilePath=!<InternetAccess_Browser>,\Device\Tcp6
    ClosedFilePath=!<InternetAccess_Browser>,\Device\Ip6
    ClosedFilePath=!<InternetAccess_Browser>,\Device\RawIp
    ClosedFilePath=!<InternetAccess_Browser>,\Device\Udp
    ClosedFilePath=!<InternetAccess_Browser>,\Device\Tcp
    ClosedFilePath=!<InternetAccess_Browser>,\Device\Ip
    ClosedFilePath=!<InternetAccess_Browser>,\Device\Afd*
    ClosedFilePath=%Local AppData%\
    ReadKeyPath=\REGISTRY\MACHINE\SOFTWARE\Classes\CLSID\{23170F69-40C1-278A-1000-000100020000}
    ReadKeyPath=HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\
    OpenIpcPath=*\BaseNamedObjects*\KSEncStatusEvent
    OpenIpcPath=*\BaseNamedObjects*\KSProcEvent*
    OpenIpcPath=*\BaseNamedObjects*\KSEncryptionEvent*
    OpenIpcPath=*\BaseNamedObjects*\KeyScrambler*
    OpenIpcPath=\Device\KeyScrambler
    OpenIpcPath=*\BaseNamedObjects*\7zMap*
    OpenIpcPath=*\BaseNamedObjects*\7zCompressMapping*
    OpenPipePath=\Device\NamedPipe\KSTIPipe*
    OpenFilePath=firefox.exe,*\urlclassifier*.sqlite*
    AutoRecoverIgnore=.dtapart
    AutoRecoverIgnore=.download
    AutoRecoverIgnore=.tmp
    AutoRecoverIgnore=.dlm
    AutoRecoverIgnore=.leechget
    AutoRecoverIgnore=.jc!
    AutoRecoverIgnore=.part
    AutoDelete=y
    NeverDelete=n
    NotifyInternetAccessDenied=y
    ReadFilePath=C:\Windows\
    RecoverFolder=%Desktop%
    DropAdminRights=y
    NotifyStartRunAccessDenied=y
    ClosedIpcPath=!<StartRunAccess_Documents>,*
    DeleteCommand="C:\Program Files\Eraser\Eraser.exe" addtask --quiet --method=ecbf4998-0b4f-445c-9a06-23627659e419 --schedule=now --dir="%SANDBOX\\%"
     
    [Video]
     
    ConfigLevel=7
    Template=BlockPorts
    Template=AutoRecoverIgnore
    Template=Firefox_Phishing_DirectAccess
    Template=LingerPrograms
    Enabled=y
    ClosedFilePath=\Device\Http\*
    ClosedFilePath=\Device\Nsi
    ClosedFilePath=\Device\RawIp6
    ClosedFilePath=\Device\Udp6
    ClosedFilePath=\Device\Tcp6
    ClosedFilePath=\Device\Ip6
    ClosedFilePath=\Device\RawIp
    ClosedFilePath=\Device\Udp
    ClosedFilePath=\Device\Tcp
    ClosedFilePath=\Device\Ip
    ClosedFilePath=\Device\Afd*
    ClosedFilePath=\Device\Mup\
    ClosedFilePath=C:\Program Files\Malwarebytes' Anti-Malware\
    ClosedFilePath=C:\Program Files\COMODO\
    ClosedFilePath=C:\Program Files\TrueCrypt\
    ClosedFilePath=H:\
    ClosedFilePath=I:\
    ClosedFilePath=K:\
    ClosedFilePath=L:\
    ClosedFilePath=C:\Program Files\7-Zip\
    ClosedFilePath=C:\Program Files\Avira\
    ClosedFilePath=C:\Program Files\CCleaner\
    ClosedFilePath=C:\Program Files\DAEMON Tools Pro\
    ClosedFilePath=C:\Program Files\EMET\
    ClosedFilePath=C:\Program Files\epson\
    ClosedFilePath=C:\Program Files\Eraser\
    ClosedFilePath=C:\Program Files\Foxit Software\
    ClosedFilePath=C:\Program Files\Internet Explorer\
    ClosedFilePath=C:\Program Files\Java\
    ClosedFilePath=C:\Program Files\KeyScrambler\
    ClosedFilePath=C:\Program Files\NapiProjekt\
    ClosedFilePath=C:\Program Files\Nokia\
    ClosedFilePath=C:\Program Files\OpenOffice.org 3\
    ClosedFilePath=C:\Program Files\Steam\
    ClosedFilePath=C:\Program Files\uTorrent\
    ClosedFilePath=C:\Program Files\Yahoo!\
    ClosedFilePath=C:\Program Files\Winamp\
    ClosedFilePath=D:
    ClosedFilePath=E:\
    ClosedFilePath=G:
    ClosedFilePath=!<InternetAccess_Browser>,\Device\Http\*
    ClosedFilePath=!<InternetAccess_Browser>,\Device\Nsi
    ClosedFilePath=!<InternetAccess_Browser>,\Device\RawIp6
    ClosedFilePath=!<InternetAccess_Browser>,\Device\Udp6
    ClosedFilePath=!<InternetAccess_Browser>,\Device\Tcp6
    ClosedFilePath=!<InternetAccess_Browser>,\Device\Ip6
    ClosedFilePath=!<InternetAccess_Browser>,\Device\RawIp
    ClosedFilePath=!<InternetAccess_Browser>,\Device\Udp
    ClosedFilePath=!<InternetAccess_Browser>,\Device\Tcp
    ClosedFilePath=!<InternetAccess_Browser>,\Device\Ip
    ClosedFilePath=!<InternetAccess_Browser>,\Device\Afd*
    ClosedFilePath=%Local AppData%\
    ReadKeyPath=\REGISTRY\MACHINE\SOFTWARE\Classes\CLSID\{23170F69-40C1-278A-1000-000100020000}
    ReadKeyPath=HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\
    OpenIpcPath=*\BaseNamedObjects*\KSEncStatusEvent
    OpenIpcPath=*\BaseNamedObjects*\KSProcEvent*
    OpenIpcPath=*\BaseNamedObjects*\KSEncryptionEvent*
    OpenIpcPath=*\BaseNamedObjects*\KeyScrambler*
    OpenIpcPath=\Device\KeyScrambler
    OpenIpcPath=*\BaseNamedObjects*\7zMap*
    OpenIpcPath=*\BaseNamedObjects*\7zCompressMapping*
    OpenPipePath=\Device\NamedPipe\KSTIPipe*
    OpenFilePath=firefox.exe,*\urlclassifier*.sqlite*
    AutoRecoverIgnore=.dtapart
    AutoRecoverIgnore=.download
    AutoRecoverIgnore=.tmp
    AutoRecoverIgnore=.dlm
    AutoRecoverIgnore=.leechget
    AutoRecoverIgnore=.jc!
    AutoRecoverIgnore=.part
    AutoDelete=y
    NeverDelete=n
    NotifyInternetAccessDenied=y
    ReadFilePath=C:\Windows\
    DropAdminRights=y
    NotifyStartRunAccessDenied=y
    ClosedIpcPath=!<StartRunAccess_Video>,*
    DeleteCommand="C:\Program Files\Eraser\Eraser.exe" addtask --quiet --method=ecbf4998-0b4f-445c-9a06-23627659e419 --schedule=now --dir="%SANDBOX\\%"
     
    [Tools]
     
    ConfigLevel=7
    Template=BlockPorts
    Template=AutoRecoverIgnore
    Template=Firefox_Phishing_DirectAccess
    Template=LingerPrograms
    Enabled=y
    ReadKeyPath=\REGISTRY\MACHINE\SOFTWARE\Classes\CLSID\{23170F69-40C1-278A-1000-000100020000}
    ReadKeyPath=HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\
    OpenIpcPath=*\BaseNamedObjects*\KSEncStatusEvent
    OpenIpcPath=*\BaseNamedObjects*\KSProcEvent*
    OpenIpcPath=*\BaseNamedObjects*\KSEncryptionEvent*
    OpenIpcPath=*\BaseNamedObjects*\KeyScrambler*
    OpenIpcPath=\Device\KeyScrambler
    OpenIpcPath=*\BaseNamedObjects*\7zMap*
    OpenIpcPath=*\BaseNamedObjects*\7zCompressMapping*
    OpenPipePath=\Device\NamedPipe\KSTIPipe*
    LingerProcess=RealSched.exe
    LingerProcess=RunDll32.exe
    LingerProcess=GoogleToolbarNotifier.exe
    LingerProcess=GoogleUpdate.exe
    LingerProcess=SynCor.exe
    LingerProcess=JUSched.exe
    LingerProcess=Adobe_Updater.exe
    LingerProcess=AcroRd32.exe
    LingerProcess=mscorsvw.exe
    OpenFilePath=firefox.exe,*\urlclassifier*.sqlite*
    AutoRecoverIgnore=.dtapart
    AutoRecoverIgnore=.download
    AutoRecoverIgnore=.tmp
    AutoRecoverIgnore=.dlm
    AutoRecoverIgnore=.leechget
    AutoRecoverIgnore=.jc!
    AutoRecoverIgnore=.part
    AutoDelete=y
    NeverDelete=n
    NotifyInternetAccessDenied=y
    DropAdminRights=y
    ClosedFilePath=\Device\Http\*
    ClosedFilePath=\Device\Nsi
    ClosedFilePath=\Device\RawIp6
    ClosedFilePath=\Device\Udp6
    ClosedFilePath=\Device\Tcp6
    ClosedFilePath=\Device\Ip6
    ClosedFilePath=\Device\RawIp
    ClosedFilePath=\Device\Udp
    ClosedFilePath=\Device\Tcp
    ClosedFilePath=\Device\Ip
    ClosedFilePath=\Device\Afd*
    ClosedFilePath=%Local AppData%\Amazon\
    ClosedFilePath=%Local AppData%\Apps\
    ClosedFilePath=%Local AppData%\ArcSoft\
    ClosedFilePath=%Local AppData%\Deployment\
    ClosedFilePath=%Local AppData%\Diagnostics\
    ClosedFilePath=%Local AppData%\Temp\
    ClosedFilePath=%Local AppData%\uTorrent\
    ClosedFilePath=%Local AppData%\VirtualStore\
    ClosedFilePath=%Local AppData%\Adobe\
    ClosedFilePath=%Local AppData%\Google\
    NotifyStartRunAccessDenied=y
    ClosedIpcPath=!<StartRunAccess_Tools>,*
    DeleteCommand="C:\Program Files\Eraser\Eraser.exe" addtask --quiet --method=ecbf4998-0b4f-445c-9a06-23627659e419 --schedule=now --dir="%SANDBOX\\%"
     
    [uTorrent]
     
    ConfigLevel=7
    Template=BlockPorts
    Template=AutoRecoverIgnore
    Template=Firefox_Phishing_DirectAccess
    Template=LingerPrograms
    Enabled=y
    ClosedFilePath=!<InternetAccess_uTorrent>,\Device\Http\*
    ClosedFilePath=!<InternetAccess_uTorrent>,\Device\Nsi
    ClosedFilePath=!<InternetAccess_uTorrent>,\Device\RawIp6
    ClosedFilePath=!<InternetAccess_uTorrent>,\Device\Udp6
    ClosedFilePath=!<InternetAccess_uTorrent>,\Device\Tcp6
    ClosedFilePath=!<InternetAccess_uTorrent>,\Device\Ip6
    ClosedFilePath=!<InternetAccess_uTorrent>,\Device\RawIp
    ClosedFilePath=!<InternetAccess_uTorrent>,\Device\Udp
    ClosedFilePath=!<InternetAccess_uTorrent>,\Device\Tcp
    ClosedFilePath=!<InternetAccess_uTorrent>,\Device\Ip
    ClosedFilePath=!<InternetAccess_uTorrent>,\Device\Afd*
    ClosedFilePath=\Device\Mup\
    ClosedFilePath=C:\Program Files\Malwarebytes' Anti-Malware\
    ClosedFilePath=C:\Program Files\COMODO\
    ClosedFilePath=C:\Program Files\TrueCrypt\
    ClosedFilePath=H:\
    ClosedFilePath=I:\
    ClosedFilePath=K:\
    ClosedFilePath=L:\
    ClosedFilePath=C:\Program Files\7-Zip\
    ClosedFilePath=C:\Program Files\Avira\
    ClosedFilePath=C:\Program Files\CCleaner\
    ClosedFilePath=C:\Program Files\DAEMON Tools Pro\
    ClosedFilePath=C:\Program Files\EMET\
    ClosedFilePath=C:\Program Files\epson\
    ClosedFilePath=C:\Program Files\Eraser\
    ClosedFilePath=C:\Program Files\Internet Explorer\
    ClosedFilePath=C:\Program Files\Java\
    ClosedFilePath=C:\Program Files\KeyScrambler\
    ClosedFilePath=C:\Program Files\NapiProjekt\
    ClosedFilePath=C:\Program Files\Nokia\
    ClosedFilePath=C:\Program Files\Steam\
    ClosedFilePath=C:\Program Files\VideoLAN\
    ClosedFilePath=C:\Program Files\Yahoo!\
    ClosedFilePath=C:\Program Files\Winamp\
    ClosedFilePath=D:
    ClosedFilePath=E:\
    ClosedFilePath=F:\
    ClosedFilePath=G:
    ClosedFilePath=!<InternetAccess_Browser>,\Device\Http\*
    ClosedFilePath=!<InternetAccess_Browser>,\Device\Nsi
    ClosedFilePath=!<InternetAccess_Browser>,\Device\RawIp6
    ClosedFilePath=!<InternetAccess_Browser>,\Device\Udp6
    ClosedFilePath=!<InternetAccess_Browser>,\Device\Tcp6
    ClosedFilePath=!<InternetAccess_Browser>,\Device\Ip6
    ClosedFilePath=!<InternetAccess_Browser>,\Device\RawIp
    ClosedFilePath=!<InternetAccess_Browser>,\Device\Udp
    ClosedFilePath=!<InternetAccess_Browser>,\Device\Tcp
    ClosedFilePath=!<InternetAccess_Browser>,\Device\Ip
    ClosedFilePath=!<InternetAccess_Browser>,\Device\Afd*
    ClosedFilePath=%Local AppData%\Amazon\
    ClosedFilePath=%Local AppData%\Apps\
    ClosedFilePath=%Local AppData%\ArcSoft\
    ClosedFilePath=%Local AppData%\Deployment\
    ClosedFilePath=%Local AppData%\Diagnostics\
    ClosedFilePath=%Local AppData%\Temp\
    ClosedFilePath=%Local AppData%\VirtualStore\
    ClosedFilePath=%Local AppData%\Adobe\
    ClosedFilePath=%Local AppData%\Google\
    ClosedFilePath=%Local AppData%\Eraser 6\
    ReadKeyPath=\REGISTRY\MACHINE\SOFTWARE\Classes\CLSID\{23170F69-40C1-278A-1000-000100020000}
    ReadKeyPath=HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\
    OpenIpcPath=*\BaseNamedObjects*\KSEncStatusEvent
    OpenIpcPath=*\BaseNamedObjects*\KSProcEvent*
    OpenIpcPath=*\BaseNamedObjects*\KSEncryptionEvent*
    OpenIpcPath=*\BaseNamedObjects*\KeyScrambler*
    OpenIpcPath=\Device\KeyScrambler
    OpenIpcPath=*\BaseNamedObjects*\7zMap*
    OpenIpcPath=*\BaseNamedObjects*\7zCompressMapping*
    OpenPipePath=\Device\NamedPipe\KSTIPipe*
    OpenFilePath=firefox.exe,*\urlclassifier*.sqlite*
    AutoRecoverIgnore=.dtapart
    AutoRecoverIgnore=.download
    AutoRecoverIgnore=.tmp
    AutoRecoverIgnore=.dlm
    AutoRecoverIgnore=.leechget
    AutoRecoverIgnore=.jc!
    AutoRecoverIgnore=.part
    AutoDelete=y
    NeverDelete=n
    NotifyInternetAccessDenied=y
    ReadFilePath=C:\Windows\
    RecoverFolder=%Desktop%
    DropAdminRights=y
    NotifyStartRunAccessDenied=y
    ClosedIpcPath=!<StartRunAccess_uTorrent>,*
    DeleteCommand="C:\Program Files\Eraser\Eraser.exe" addtask --quiet --method=ecbf4998-0b4f-445c-9a06-23627659e419 --schedule=now --dir="%SANDBOX\\%
    
    
     
    Last edited: Mar 27, 2012
Thread Status:
Not open for further replies.
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.