Sandboxie is Weird After Trojans

Discussion in 'Sandboxie (SBIE Open Source) Plus & Classic' started by Capricornia, Jan 7, 2021.

  1. Capricornia

    Capricornia Registered Member

    Joined:
    Apr 16, 2018
    Posts:
    103
    Location:
    Sacramento, CA
    Hello. My computer had recently been acting kind of weird and I did a thorough scan with Eset and they found and neutralized 5 Trojans. But after that my Sandboxie program stopped working and I can't Modify or Uninstall it from Apps & features in Settings because the buttons are grayed out. Also, I must have deleted it and installed it again from Major Greeks because it's dated 01/06/21 from yesterday. Plus, Eset calls the trojan "a variant of Win32/Agent.ABZW.gen trojan."

    Additionally, since I always use Sandoxie(or used to), the only way that I can think of how this trojan slipped in is from downloading an image and allow Sandboxie to Recover it. Although, I usually use a free image hosting site to host an image and then save it to my computer from there, but I forgot to do that this time. But other than that, that's the only way that I think I may have gotten this trojan. Also, as you see from one of my images, some of the trojans are associated with Sandboxie, even though I was actually running Sandboxie at the time during the Eset scan before Sandboxie stopped. Plus, it appears that Microsoft security won't allow me to download any other Sandboxie links because it says that Sandboxie is dangerous to my computer.

    eset.scan.01.06.21.jpg apps.n.features.jpg
     
    Last edited: Jan 7, 2021
  2. Buster_BSA

    Buster_BSA Registered Member

    Joined:
    Nov 29, 2009
    Posts:
    748
    Download the installer, uninstall from there and then reinstall.
     
  3. Capricornia

    Capricornia Registered Member

    Joined:
    Apr 16, 2018
    Posts:
    103
    Location:
    Sacramento, CA
    I'm sorry, but could you be more specific because I don't quite understand what you mean... Sorry.
     
  4. Buster_BSA

    Buster_BSA Registered Member

    Joined:
    Nov 29, 2009
    Posts:
    748
  5. Capricornia

    Capricornia Registered Member

    Joined:
    Apr 16, 2018
    Posts:
    103
    Location:
    Sacramento, CA
    Okay, when I did that, I got the Delete messages(I clicked twice) at the bottom of my screen. And when I clicked Keep, it took me to another page and gave the Microsoft Defender message. See second image. sandboxie.installer.jpg


    microsoft.defender.sandboxie.installer.jpg
     
  6. Capricornia

    Capricornia Registered Member

    Joined:
    Apr 16, 2018
    Posts:
    103
    Location:
    Sacramento, CA
    Also, I clicked on the Show more link and and clicked on Keep and it seemed to download and install, but nothing different happened except the way it looked:

    sandboxie.installer.keep.jpg
     
  7. Capricornia

    Capricornia Registered Member

    Joined:
    Apr 16, 2018
    Posts:
    103
    Location:
    Sacramento, CA
    Okay, Buster_BSA, I found an Install Anyway link(or something like that) on the Microsoft Defender Dialogue shield and clicked on it and was able to install Sandboxie again and was able to uninstall it, and I'm about to reboot now... See you on the other side. :)
     
  8. Capricornia

    Capricornia Registered Member

    Joined:
    Apr 16, 2018
    Posts:
    103
    Location:
    Sacramento, CA
    I'm back in business. Thank you very much, Buster_BSA. :thumb:
     
  9. Capricornia

    Capricornia Registered Member

    Joined:
    Apr 16, 2018
    Posts:
    103
    Location:
    Sacramento, CA
    Oh, no! Just when you thought it was safe to go back in the water. :( Also, since a picture speaks a thousand words, below in the images is what happened.
    sandboxie.problem.jpg sandboxie.problem.2.jpg
     
  10. Capricornia

    Capricornia Registered Member

    Joined:
    Apr 16, 2018
    Posts:
    103
    Location:
    Sacramento, CA
    And I'm also getting a SBIE2101 error message.
     
  11. bjm_

    bjm_ Registered Member

    Joined:
    May 22, 2009
    Posts:
    4,457
    Location:
    .
    Complain to SAS about them producing false positives, as their customer you can do that.
    Can't you set exclusions in SAS to tolerate Sandboxie-Plus / Sandboxie?
     
    Last edited: Jan 7, 2021
  12. Buster_BSA

    Buster_BSA Registered Member

    Joined:
    Nov 29, 2009
    Posts:
    748
    You must allow Sandboxie's driver to operate. Your antispyware is blocking it.

    Add "SbieDrv.sys" to SUPERAntiSpyware's exclusion (white) list.
     
    Last edited: Jan 8, 2021
  13. Peter 123

    Peter 123 Registered Member

    Joined:
    Feb 1, 2009
    Posts:
    596
    Location:
    Austria
    @Capricornia:
    Concerning the two messages by Sandboxie in your pictures: I got exactly the same messages when trying to install v. 5.46.0.

    You only need to (try to) install Sandboxie a second time --> then choose the option to uninstall the existing version (+ saying "Yes" to keeping the ini.file if you like to stay with your old settings) --> then restart your computer.

    And now it should work. (Finally I had to do this procedure two times, if I remember correctly).

    But all this only if you get the messages again after having fixed the issue with your antispyware, as described by Buster_BSA and bjm.
     
  14. Freki123

    Freki123 Registered Member

    Joined:
    Jan 20, 2015
    Posts:
    337
    Just a reminder: Sandboxie from David Xanatos got a signed driver but not signed exes. So some AV will just flag files for that reason.
    You could report the files as a fp to your AV vendor and maybe they will fix it.
    Got also a download problem with FF while MS edge said it was ok.
     
    Last edited: Jan 8, 2021
  15. Capricornia

    Capricornia Registered Member

    Joined:
    Apr 16, 2018
    Posts:
    103
    Location:
    Sacramento, CA
    It wasn't SAS. I had just did a SAS scan(which showed clean) and then I tried to launch Sandboxie and the image still had the SAS dialogue box because I couldn't close it until I closed the Sandboxie dialogue boxes and I wanted to show the images of the Sandboxie dialogue boxes.
     
  16. Capricornia

    Capricornia Registered Member

    Joined:
    Apr 16, 2018
    Posts:
    103
    Location:
    Sacramento, CA
    It's not SAS. See my post above.
     
  17. Capricornia

    Capricornia Registered Member

    Joined:
    Apr 16, 2018
    Posts:
    103
    Location:
    Sacramento, CA
    Hmmm. Okay, I'll try it twice. Although, I still think that the trojan did something to my computer and my software. o_O
     
  18. bjm_

    bjm_ Registered Member

    Joined:
    May 22, 2009
    Posts:
    4,457
    Location:
    .
    What is/are your resident security solution/s?
    Do you still feel your machine has infection/s?
    Maybe, try:
    Save backup of Sandboxie.ini...just in case
    Disable your resident security solutions.
    Uninstall 5.45 + if asked retain Sandboxie.ini > restart machine (not Shut down) > install v0.5.4b / 5.46.1 - Hotfix
    Release Release v0.5.4 / 5.46.1 - Hotfix · sandboxie-plus/Sandboxie · GitHub
     
    Last edited: Jan 8, 2021
  19. Capricornia

    Capricornia Registered Member

    Joined:
    Apr 16, 2018
    Posts:
    103
    Location:
    Sacramento, CA
    Well, I did it twice and it looks like the second time wasn't the charm. :( And I'm getting the same error messages and dialogues boxes. Plus, it's showing that Microsoft Defender is blocking it. See images below along with #5 Reply.
    windows.protected.jpg windows.protected.2.jpg
     
  20. bjm_

    bjm_ Registered Member

    Joined:
    May 22, 2009
    Posts:
    4,457
    Location:
    .
    What is/are your resident security solution/s?
    Do you still feel your machine has infection/s?
    Disable Microsoft Defender Antivirus and any other resident security solutions.
    Disable Microsoft Defender SmartScreen in Edge
    Save Sandboxie-Plus 0.5.4b / Sandboxie 5.46.1 installer to your desktop.
    Uninstall 5.45 + retain Sandboxie.ini > restart machine (not Shut down) > install v0.5.4b / 5.46.1 - Hotfix
    Release Release v0.5.4 / 5.46.1 - Hotfix · sandboxie-plus/Sandboxie · GitHub
    After you install Sandboxie-Plus / Sandboxie. Exclude Sandoxie-Plus / Sandboxie folder in Microsoft Defender Antivirus and any other resident security solutions.
     
    Last edited: Jan 8, 2021
  21. Capricornia

    Capricornia Registered Member

    Joined:
    Apr 16, 2018
    Posts:
    103
    Location:
    Sacramento, CA
    I temporarily disabled my Windows Defender Virus & threat protection, but that didn't help. Also, I have a full version of Malewarybytes, but I don't think that's blocking Sandboxie.
     
  22. Capricornia

    Capricornia Registered Member

    Joined:
    Apr 16, 2018
    Posts:
    103
    Location:
    Sacramento, CA
    I don't think so. Because previously, my Settings icon and Paint 3D icon, which I had pinned to the taskbar, had disappeared. But that isn't happening now. Plus, the Eset scan said all the trojans were gone.
     
  23. bjm_

    bjm_ Registered Member

    Joined:
    May 22, 2009
    Posts:
    4,457
    Location:
    .
    Yeah, I think Malwarebytes whitelisted Sandboxie.
    Are you running Malwarebytes Premium real-time?
    Do you register Malwarebytes Premium with Windows Security Center?
    Do you have mutual exclusions setup for Malwarebytes Premium and Microsoft Defender.
    Does SAS run real-time?
    Maybe, get Malwarebytes Forum to check your machine for malware.
    Why did you run ESET Online Scanner?
    ESET ripped out your Sandboxie install.
    Were my machine. I'd clean install Sandboxie-Plus.
    Good Luck
     
    Last edited: Jan 9, 2021
  24. bjm_

    bjm_ Registered Member

    Joined:
    May 22, 2009
    Posts:
    4,457
    Location:
    .
    Register Malwarebytes Premium with Windows Security Center + restart machine. Windows will disable Microsoft Defender seeing Malwarebytes Premium.
     
  25. mick92z

    mick92z Registered Member

    Joined:
    Apr 27, 2007
    Posts:
    548
    Location:
    Nottingham
    You never had any ' trojans '. All the detection's are false alarms, Eset, W.D, and SAS, which are picking up Sandboxies own files.I imagine a lot of other AV engines will flag them too. I am still using version 5.33.6 which was one of the last if not the last version while S.B was updated by Sophos. Apparently it has security issues but I will takes my chances.
    It is my opinion that S.B is becoming something used by an ever decreasing number of users desperate to keep something that has become problematic for the average user. All you can do is is whitelist the files, get your resident security programs vendors to whitelist the files ( which the probably won't ) or revert to 5.33.6 and take your chances
     
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.