Opening Chrome Gives SBIE2327

In Sandboxie 5.30 (64-bit) opening Google Chrome inevitably gives the following error:  SBIE2327 Error in COM server: [35 / 258].  This is typically followed after several seconds by the un-requested opening of "https://helpx.adobe.com/acrobat/kb/acrobat-pro-chrome-extension.html" in a new tab.  I first noticed this behavior shortly after Sandboxie offered (and I installed and activated) the 5.30 update.  Does anybody know what's going on, how to fix it?

Background:  I'm running Windows 7 SP1 (updated regularly) on a Lenovo 530 laptop.  I recently set up a new sandbox specifically for Chrome but with additional permission to make changes outside the sandbox only to Chrome preferences.  Before that, however, I was getting the same behavior in a temporary sandbox with no special settings. -- jclarkw

Parents Reply Children
  • Does Chrome work fine outside the Sandbox? -- YES.
    Does the problem go away if you disable the extension? -- I never installed the Acrobat extension.  (Perhaps that's why it is asking me to do so?)
    Do other browsers present the same issue? -- NO.  I have not used IE for quite a while, but I constantly use Firefox in the default box.

    Are you using a new Sandboxie configuration file, or is it old? Please post it here -- The complete config. is old, but the Chrome sandbox in which this occurs is new.  Complete config. posted below.
    Can you please provide the rest of the required info so that I can test the behavior? -- See further below. -- jclarkw

     


    [GlobalSettings]

    Template=nVidia_nView
    Template=7zipShellEx
    Template=AdobeDistiller
    Template=AdobeLicensing
    Template=AdobeAcrobatReader
    Template=OfficeClickToRun
    Template=SynapticsTouchPad
    Template=OfficeLicensing
    Template=Microsoft_Security_Essentials
    ActivationPrompt=n

    [DefaultBox]

    ConfigLevel=7
    AutoRecover=y
    Template=WindowsFontCache
    Template=Firefox_Bookmarks_DirectAccess
    Template=BlockPorts
    Template=LingerPrograms
    Template=Chrome_Phishing_DirectAccess
    Template=Firefox_Phishing_DirectAccess
    Template=AutoRecoverIgnore
    RecoverFolder=%{374DE290-123F-4565-9164-39C4925E467B}%
    RecoverFolder=%Personal%
    RecoverFolder=%Favorites%
    RecoverFolder=%Desktop%
    BorderColor=#00FFFF
    Enabled=y
    BoxNameTitle=n
    AutoDelete=y
    NeverDelete=n
    OpenFilePath=firefox.exe,%AppData%\Mozilla\Firefox\Profiles\vwr8xdvl.default\storage-sync.sqlite
    OpenFilePath=firefox.exe,%AppData%\Mozilla\Firefox\Profiles\vwr8xdvl.default\browser-extension-data\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}\storage.js

    [UserSettings_572605B3]

    SbieCtrl_UserName=administrator1
    SbieCtrl_BoxExpandedView=DefaultBox
    SbieCtrl_NextUpdateCheck=1553972913
    SbieCtrl_UpdateCheckNotify=y
    SbieCtrl_ShowWelcome=n
    SbieCtrl_WindowCoords=256,192,515,351
    SbieCtrl_ActiveView=40021
    SbieCtrl_EnableLogonStart=n
    SbieCtrl_EnableAutoStart=y
    SbieCtrl_AddDesktopIcon=y
    SbieCtrl_AddQuickLaunchIcon=n
    SbieCtrl_AddContextMenu=y
    SbieCtrl_AddSendToMenu=y
    SbieCtrl_AutoApplySettings=n
    SbieCtrl_ProcessViewColumnWidths=250,70,300

    [UserSettings_182A0306]

    SbieCtrl_UserName=willett
    SbieCtrl_ShowWelcome=n
    SbieCtrl_NextUpdateCheck=1559316971
    SbieCtrl_UpdateCheckNotify=n
    SbieCtrl_EnableLogonStart=n
    SbieCtrl_EnableAutoStart=y
    SbieCtrl_AddDesktopIcon=y
    SbieCtrl_AddQuickLaunchIcon=n
    SbieCtrl_AddContextMenu=y
    SbieCtrl_AddSendToMenu=y
    SbieCtrl_WindowCoords=355,0,797,560
    SbieCtrl_ActiveView=40021
    SbieCtrl_AutoApplySettings=n
    SbieCtrl_ProcessViewColumnWidths=250,70,300
    SbieCtrl_HideWindowNotify=n
    SbieCtrl_RecoverTarget=E:\Willett Movable Folders\My Documents\Computer\Hardware\Lenovo Laptop\W530
    SbieCtrl_RecoverTarget=E:\Willett Movable Folders\My Documents\Computer\Software\ShadowProtect
    SbieCtrl_RecoverTarget=E:\Willett Movable Folders\My Documents\Computer\Hardware\Comcast
    SbieCtrl_RecoverTarget=E:\Willett Movable Folders\My Documents\Computer\Software\ZoneAlarm Extreme Security\Alternatives\FireFox
    SbieCtrl_RecoverTarget=E:\Willett Movable Folders\My Documents\Products and Services\Medical
    SbieCtrl_RecoverTarget=E:\Willett Movable Folders\My Documents\Computer\Hardware\TP-LINK
    SbieCtrl_RecoverTarget=E:\Willett Movable Folders\My Documents\Astronomy\My Cell Design
    SbieCtrl_RecoverTarget=E:\Willett Movable Folders\My Documents\Professional\Scientific Articles
    SbieCtrl_RecoverTarget=E:\Willett Movable Folders\My Documents\Products and Services
    SbieCtrl_RecoverTarget=E:\Willett Movable Folders\My Documents\Financial
    SbieCtrl_RecoverTarget=E:\Willett Movable Folders\My Documents\Computer\Hardware\Runbox
    SbieCtrl_SaveRecoverTargets=y
    SbieCtrl_EditConfNotify=n
    SbieCtrl_ReloadConfNotify=n
    SbieCtrl_BoxExpandedView=Chrome,Internet_Explorer,Outlook,Temporary

    [UserSettings_65340663]

    SbieCtrl_UserName=jwadministrator
    SbieCtrl_ShowWelcome=n
    SbieCtrl_NextUpdateCheck=1559316616
    SbieCtrl_UpdateCheckNotify=n
    SbieCtrl_WindowCoords=332,54,1014,513
    SbieCtrl_ActiveView=40021
    SbieCtrl_ProcessViewColumnWidths=250,70,300
    SbieCtrl_RecoverTarget=E:\Willett Movable Folders\My Documents\Computer\Software\ZoneAlarm Extreme Security\Alternatives\FireFox
    SbieCtrl_SaveRecoverTargets=y

    [Internet_Explorer]

    ConfigLevel=7
    AutoRecover=y
    Template=WindowsFontCache
    Template=Firefox_Bookmarks_DirectAccess
    Template=BlockPorts
    Template=LingerPrograms
    Template=Chrome_Phishing_DirectAccess
    Template=Firefox_Phishing_DirectAccess
    Template=AutoRecoverIgnore
    RecoverFolder=%{374DE290-123F-4565-9164-39C4925E467B}%
    RecoverFolder=%Personal%
    RecoverFolder=%Favorites%
    RecoverFolder=%Desktop%
    BorderColor=#00FFFF
    Enabled=y
    BoxNameTitle=n
    AutoDelete=y
    NeverDelete=n

    [TemplateSettings]

    Tmpl.Office_Outlook.willett=E:\Willett Movable Folders\My Documents\Outlook Files

    [Outlook]

    Enabled=y
    ConfigLevel=7
    AutoRecover=y
    BlockNetworkFiles=y
    Template=Office_Outlook
    Template=qWave
    Template=WindowsFontCache
    Template=BlockPorts
    Template=LingerPrograms
    Template=Chrome_Phishing_DirectAccess
    Template=Firefox_Phishing_DirectAccess
    Template=AutoRecoverIgnore
    RecoverFolder=%{374DE290-123F-4565-9164-39C4925E467B}%
    RecoverFolder=%Personal%
    RecoverFolder=%Favorites%
    RecoverFolder=%Desktop%
    BorderColor=#00FFFF
    NotifyInternetAccessDenied=y
    BoxNameTitle=-
    AutoDelete=y
    NeverDelete=n
    CopyLimitKb=3145728

    [Temporary]

    Enabled=y
    ConfigLevel=7
    AutoRecover=y
    BlockNetworkFiles=y
    Template=qWave
    Template=WindowsFontCache
    Template=BlockPorts
    Template=LingerPrograms
    Template=Chrome_Phishing_DirectAccess
    Template=Firefox_Phishing_DirectAccess
    Template=AutoRecoverIgnore
    RecoverFolder=%{374DE290-123F-4565-9164-39C4925E467B}%
    RecoverFolder=%Personal%
    RecoverFolder=%Favorites%
    RecoverFolder=%Desktop%
    BorderColor=#00FFFF,ttl
    AutoDelete=y
    NeverDelete=n

    [Chrome]

    Enabled=y
    ConfigLevel=7
    BlockNetworkFiles=y
    Template=Chrome_Preferences_DirectAccess
    Template=qWave
    Template=WindowsFontCache
    Template=BlockPorts
    Template=LingerPrograms
    Template=Chrome_Phishing_DirectAccess
    Template=Firefox_Phishing_DirectAccess
    Template=AutoRecoverIgnore
    RecoverFolder=%{374DE290-123F-4565-9164-39C4925E467B}%
    BorderColor=#00FFFF
    BoxNameTitle=n
    AutoDelete=y
    NeverDelete=n

     

    Chrome Version 74.0.3729.169 (Official Build) (64-bit)

    Microsoft Security Essentials:
         Antimalware Client Version: 4.10.209.0
         Engine Version: 1.1.15900.4
         Antivirus definition: 1.293.2496.0
         Antispyware definition: 1.293.2496.0
         Network Inspection System Engine Version: 2.1.14600.4
         Network Inspection System Definition Version: 119.0.0.0

    I think that covers it...

  • Hi jclarkw,

    Thanks for the info. So, to clarify, Chrome does NOT try to get the adobe extension outside sandboxie? Can you triple check it is not there using a different profile? Sandboxie reads what happens on your host, so it would not randomly bring up an adobe extension.

    I do see you have 3 templates for Adobe:
    Template=AdobeDistiller
    Template=AdobeLicensing
    Template=AdobeAcrobatReader

    Try turning them off to see if that changes the behavior:
    Configure ---> Software compatibility ---> uncheck the Adobe templates.
    Configure --> Reload configuration
    Delete the contents of your Sandbox (relaunch Chrome outside Sbie to double check it is not loading the extension in the background. After confirming, close Chrome outside).
    Launch Chrome in the Sandbox you just emptied.

    Last, but not least, this looks related to an issue posted in the Adobe forums (this is a third party site, proceed at your own discretion). Have a look at this thread which describes a very similar scenario, and there is a solution a few posts below:
    https://forums.adobe.com/thread/2464007

    Let me know the outcome.

    Regards,

    Barb@Sophos
    Community Support Engineer | Sophos Technical Support
    Knowledge Base  |  @SophosSupport  | Sign up for SMS Alerts
    If a post solves your question use the 'This helped me' link.

     

  • Thanks, Barb, for the suggestions.  It looks as though you've put me on the right track, but all of this will take me some weeks to check out -- extensive travel schedule June 4th through July 21st.

    One question:  Would a failed attempt to get Acrobat from inside the sandbox also cause the SBIE2327 error? -- jclarkw

  • Hi jclarkw,

    I am not sure, here's more information about what triggers that message:
    https://www.sandboxie.com/SBIE2327

    It is based on communication between the Sandbox and X thing.  

    Please, let us know how things go after you get a chance to test the steps.

    Thanks!

    Barb@Sophos
    Community Support Engineer | Sophos Technical Support
    Knowledge Base  |  @SophosSupport  | Sign up for SMS Alerts
    If a post solves your question use the 'This helped me' link.