Sandboxie Plus (Sbie fork)

Discussion in 'Sandboxie (SBIE Open Source) Plus & Classic' started by DavidXanatos, Apr 9, 2020.

Thread Status:
Not open for further replies.
  1. catspyjamas

    catspyjamas Registered Member

    Joined:
    Jul 1, 2011
    Posts:
    288
    Location:
    New Zealand
    OK @DavidXanatos , I re-uploaded the installer to virustotal because it's the only way I know to see what the SHA256 Check Sums are. :)

    Excellent, I think that all matches OK, but what is the Downloadly_ir_exe thing on the file name? That isn't present on the name of the installer. Also where it says Community - that is where the weird comment about the file showing on malshare.com is, if you need to check that out.


    So if my SHA256 Check Sums is matching OK, then I can rest assured the file is clean and not been tampered with? Thanks so much for checking this out. Hopeefully someone else with Windows Defender can provide more details about those Temp files if you need them.
     
    Last edited by a moderator: Oct 12, 2020
  2. Brummelchen

    Brummelchen Registered Member

    Joined:
    Jan 3, 2009
    Posts:
    5,919
    VT results are not allowed here. If you have a special problem with your antivirus you should ask it that special. Nevertheless, this thread contains answers to exclude sandboxie or its driver sbiedrv.sys.
    Obfuscation does not change anything when the target file is written, any antivirus check files on writing. In fact, it has a dubious touch you should not do it.

    You mentioned so often that this driver has a questionable certificate. :rolleyes: And you are working on this special issue.
     
  3. DavidXanatos

    DavidXanatos Developer

    Joined:
    Sep 6, 2006
    Posts:
    2,327
    Location:
    Viena
    the file hash the hash summ 52ae02dbc7b6f1569adc041daaf5aff27beb3774d82a8f4bb6e0df82494c5f56 and is legit
    Someone added somethign to the filename


    The point of it is to have the file on the system and multiple attempts to bypass the antivirus, of-cause it will detect it but than it may delete it without asking and with the obfuscated original the tool can just retry it hoping you have fixed the issue.

    Without the obfuscated original you would need to re run the installer every time your Antivirus fool breaks something.
     
  4. Brummelchen

    Brummelchen Registered Member

    Joined:
    Jan 3, 2009
    Posts:
    5,919
    Good point, but unfortunately it doesn't change the result. (at this moment) The installation is broken, either on download, execution (extraction) or installing files. To prevent scanning on download you have to secure content with a password. No scanner can look inside. But that is away from nsis options, I tried in 2012 similar with 4fc77d02a5fdcc2f1588c97970992cfa and abandoned it due this problem. ofc the package was secure :D but there exists installers where content is not scanable, and also not extractable.
     
  5. DavidXanatos

    DavidXanatos Developer

    Joined:
    Sep 6, 2006
    Posts:
    2,327
    Location:
    Viena
  6. Brummelchen

    Brummelchen Registered Member

    Joined:
    Jan 3, 2009
    Posts:
    5,919
    nice work, but a lot to do.
     
  7. bjm_

    bjm_ Registered Member

    Joined:
    May 22, 2009
    Posts:
    4,457
    Location:
    .
    Malwarebytes already (since ~Sept 19) whitelisted SbieDrv.sys.
    https://forums.malwarebytes.com/topic/264089-malwareai3719570885-reported-with-sandboxie/
     
  8. mantra

    mantra Registered Member

    Joined:
    Jan 25, 2005
    Posts:
    6,176
    hi
    may I know why there is no more the zip portable version ?
    there are all exe
    thanks
     
  9. DavidXanatos

    DavidXanatos Developer

    Joined:
    Sep 6, 2006
    Posts:
    2,327
    Location:
    Viena
    because the plus installer has a "extract only" option, so the zip is redundant, plus upload to github is painstakingly slow.
     
  10. zmechys

    zmechys Registered Member

    Joined:
    Dec 29, 2012
    Posts:
    1,155
    Location:
    usa
    David,

    Thank you for your hard work.
    I'm one of those fans that totally understand the value of Sandboxie.
    Maybe, it could be a good idea to have a yearly Sandboxie usage fee, even for a minuscule amount of $10/year?
    With so many Sandboxie users, it would be possible for you to cover all those set-up/running charges, and something could be left for your work.
     
  11. DavidXanatos

    DavidXanatos Developer

    Joined:
    Sep 6, 2006
    Posts:
    2,327
    Location:
    Viena
    The work is done except for all the pages with the SBIE messages,
    with the right conversion tool its just a bit of hand massaging the few broken parts ;)

    please go through this index: https://xanasoft.com/sandboxie/allpages/
    and tell ne whats still broken or whats obsolete i.e. all the licensing stuff...


    Also I really should fill up my homepage with more content :D
    Any Volunteers to help me with it?
     
    Last edited: Oct 12, 2020
  12. mirko_

    mirko_ Registered Member

    Joined:
    Oct 12, 2020
    Posts:
    4
    Location:
    in front of my pc
    Hello, I just installed your latest release sandboxie-plus 5.43.5 x64, everything looks good. Great work, i only have one concern and i don't know if it's my pc or it is the inteded way how this release should work.
    When i start a process in a sandbox and i terminate it, this process stay on the control window with the status 'terminated'. If this is only a visual behaviour it doesn't matter much, but i'm wondering if, when i use the sandboxie api to list all processes pids, will i get the terminated processes too or only the ones running ? is it possible somehow to remove the terminated processes ?
     
  13. goofwear

    goofwear Registered Member

    Joined:
    Oct 13, 2020
    Posts:
    2
    Location:
    USA
  14. goofwear

    goofwear Registered Member

    Joined:
    Oct 13, 2020
    Posts:
    2
    Location:
    USA
  15. stapp

    stapp Global Moderator

    Joined:
    Jan 12, 2006
    Posts:
    24,068
    Location:
    UK
  16. henryg1

    henryg1 Registered Member

    Joined:
    Jun 14, 2020
    Posts:
    411
    Location:
    uk
    Everyone should switch to Firefox anyway.
     
  17. Azure Phoenix

    Azure Phoenix Registered Member

    Joined:
    Nov 22, 2014
    Posts:
    1,560
    eh, no thanks
     
  18. DavidXanatos

    DavidXanatos Developer

    Joined:
    Sep 6, 2006
    Posts:
    2,327
    Location:
    Viena
    It does not seam to be possible you may need to enable something in your profile,
    you can send me an email on my gmail.com address: xanatosdavid[at]....
     
  19. Special

    Special Registered Member

    Joined:
    Mar 23, 2016
    Posts:
    454
    Location:
    .
  20. DavidXanatos

    DavidXanatos Developer

    Joined:
    Sep 6, 2006
    Posts:
    2,327
    Location:
    Viena
  21. catspyjamas

    catspyjamas Registered Member

    Joined:
    Jul 1, 2011
    Posts:
    288
    Location:
    New Zealand
    After seeing your comment Special I thought I'd give it a go, as so far I've only installed it on one machine. Happy to report I've just successfully installed Sandboxie 5.43.6 (64bit) on my Windows 1909 machine, over the top of 5.33.6. And... this time Windows Defender didn't squawk once! So looks like MS have added an exclusion to Windows Defender for SbieDrv.sys, and whatever it tripped up on that went to my Temp folder on my other machine. :) :)

    Once I've finished what I'm doing I'll update my other machine which runs 2004. I'll post back if I run into issues.
     
  22. sbieuser

    sbieuser Registered Member

    Joined:
    Oct 13, 2020
    Posts:
    2
    Location:
    germany
    Hello,

    as chrome 86.x on sandboxie 5.33.2 (@ WIn 10 home) didn not work anymore (no acces to any website - allwas "crashed") I tried Sandboxie-Plus-x64-v0.4.2.exe from https://github.com/sandboxie-plus/Sandboxie/releases.
    What I painfully miss is "quick recovery", that sandboxie 5.33.2 allways offered me, every time I downloaded a file. I could then decide for myself whether I wanted to keep it or not, what I and my kids often eally need (e.g. pictures for homework etc).

    How can I get sandboxie 5.33.2 to work for Chrome 86..... again or
    How can I get sandboxie-Plus-x64-v0.4.2. to offer "quick recovery"?

    Thanks,
    Tom
     
  23. sbieuser

    sbieuser Registered Member

    Joined:
    Oct 13, 2020
    Posts:
    2
    Location:
    germany
    seems, I meen "instant recovery" - that dialogue that come everytime I downloaded a file....
     
  24. catspyjamas

    catspyjamas Registered Member

    Joined:
    Jul 1, 2011
    Posts:
    288
    Location:
    New Zealand
    @sbieuser due you mean the Immediate Recovery box that pops up at the end of a file download? If you do, it's still there for me on Chromium Edge and Sandboxie 5.43.6 (64bit). It's working well. What version of Sandboxie did you download?

    EDIT - oops, just re-read your post and saw you downloaded the Sandboxie Plus version, not the classic version. Sorry, I'm not sure about that one...
     
  25. mirko_

    mirko_ Registered Member

    Joined:
    Oct 12, 2020
    Posts:
    4
    Location:
    in front of my pc
    @DavidXanatos Hello, i will just reupload my question seems it got lost between the other posts.
    I just installed your latest release sandboxie-plus 5.43.5 x64, everything looks good. Great work, i only have one concern and i don't know if it's my pc or it is the inteded way how this release should work.
    When i start a process in a sandbox and i terminate it, this process stay on the control window with the status 'terminated'. If this is only a visual behaviour it doesn't matter much, but i'm wondering if, when i use the sandboxie api to list all processes pids, will i get the terminated processes too or only the ones running ? is it possible somehow to remove the terminated processes ?
     
Thread Status:
Not open for further replies.
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.