ndch Цитата: значит на 2000 не работает в sandboxie тоже.
В Sandboxie всё работает - вы просто не умеете его готовить
[more]
Executing: d:\temp_sys.exe
LoadLibrary(user32.dll) [d:\temp_sys.exe]
LoadLibrary(kernel32.dll) [d:\temp_sys.exe]
LoadLibrary(comctl32.dll) [d:\temp_sys.exe]
LoadLibrary(shlwapi.dll) [d:\temp_sys.exe]
LoadLibrary(advapi32.dll) [d:\temp_sys.exe]
LoadLibrary(gdi32.dll) [d:\temp_sys.exe]
LoadLibrary(oleaut32.dll) [d:\temp_sys.exe]
LoadLibrary(ole32.dll) [d:\temp_sys.exe]
GetModuleHandle(lz32.dll) [d:\temp_sys.exe]
LoadLibrary(lz32.dll) [d:\temp_sys.exe]
RegOpenKeyEx(HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Performance) [d:\temp_sys.exe]
GetModuleHandle(KERNEL32.DLL) [d:\temp_sys.exe]
GetModuleHandle(Kernel32) [d:\temp_sys.exe]
LoadLibrary(c:\windows\windowsshell.manifest) [d:\temp_sys.exe]
OpenProcessToken(D:\temp_sys.exe) [d:\temp_sys.exe]
RegOpenKeyEx(HKLM\Software\Microsoft\Windows NT\CurrentVersion\LanguagePack) [d:\temp_sys.exe]
LoadLibrary(shell32) [d:\temp_sys.exe]
RegOpenKeyEx(HKLM\SYSTEM\Setup) [d:\temp_sys.exe]
LoadLibrary(shell32.dll) [d:\temp_sys.exe]
GetModuleHandle(LPK.DLL) [d:\temp_sys.exe]
RegCreateKeyEx(HKCU\Console,(null)) [d:\temp_sys.exe]
OpenProcess(d:\temp_sys.exe) [d:\temp_sys.exe]
CreateRemoteThread(d:\temp_sys.exe) [d:\temp_sys.exe]
Copy(D:\temp_sys.exe->\temp_sys.exe) [d:\temp_sys.exe]
RegCreateKeyEx(HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon,(null)) [d:\temp_sys.exe]
RegSetValueEx(HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\ConsoleSelfCount, REG_DWORD: 345600000) [d:\temp_sys.exe]
RegSetValueEx(HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Userinit, REG_SZ: C:\WINDOWS\system32\userinit.exe,\temp_sys.exe) [d:\temp_sys.exe]
LoadLibrary(c:\windows\system32\uxtheme.dll) [d:\temp_sys.exe]
LoadLibrary(uxtheme.dll) [d:\temp_sys.exe]
LoadLibrary(d:\program files\yandex\punto switcher\pshook.dll) [d:\temp_sys.exe]
RegOpenKeyEx(HKLM\Software\Microsoft\Rpc\PagedBuffers) [d:\temp_sys.exe]
RegOpenKeyEx(HKLM\Software\Microsoft\Rpc) [d:\temp_sys.exe]
RegOpenKeyEx(HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\temp_sys.exe\RpcThreadPoolThrottle) [d:\temp_sys.exe]
RegOpenKeyEx(HKLM\Software\Policies\Microsoft\Windows NT\Rpc) [d:\temp_sys.exe]
LoadLibrary(rpcrt4.dll) [d:\temp_sys.exe]
LoadLibrary(pshook.dll) [d:\temp_sys.exe]
LoadLibrary(imagehlp.dll) [d:\temp_sys.exe]
CreateFileMapping(d:\temp_sys.exe) [d:\temp_sys.exe]
GetModuleHandle(User32) [d:\temp_sys.exe]
RegOpenKeyEx(HKCU\Software\Yandex\Punto Switcher\3.1\PSHook) [d:\temp_sys.exe]
RegOpenKeyEx(HKCU\Software\Yandex\Punto Switcher\3.1\PSHook32) [d:\temp_sys.exe]
LoadLibrary(d:\program files\unlocker\unlockerhook.dll) [d:\temp_sys.exe]
LoadLibrary(unlockerhook.dll) [d:\temp_sys.exe]
LoadLibrary(d:\program files\abbyy lingvo x3\lvhook.dll) [d:\temp_sys.exe]
GetModuleHandle(ntdll.dll) [d:\temp_sys.exe]
LoadLibrary(lvhook.dll) [d:\temp_sys.exe]
LoadLibrary(psapi.dll) [d:\temp_sys.exe]
RegOpenKeyEx(HKCU\SOFTWARE\ABBYY\Lingvo\14.0\Debug) [d:\temp_sys.exe]
RegOpenKey(HKLM\Software\Microsoft\Windows NT\CurrentVersion\IMM) [d:\temp_sys.exe]
RegOpenKeyEx(HKLM\Software\Microsoft\Windows NT\CurrentVersion\IMM) [d:\temp_sys.exe]
GetModuleHandle(version.dll) [d:\temp_sys.exe]
LoadLibrary(version.dll) [d:\temp_sys.exe]
LoadLibrary(c:\windows\system32\msctfime.ime) [d:\temp_sys.exe]
LoadLibrary(c:\windows\system32\ole32.dll) [d:\temp_sys.exe]
LoadLibrary(msctfime.ime) [d:\temp_sys.exe]
GetModuleHandle(C:\WINDOWS\system32\ntdll.dll) [d:\temp_sys.exe]
RegOpenKey(HKCU\SOFTWARE\Microsoft\CTF) [d:\temp_sys.exe]
RegOpenKeyEx(HKCU\SOFTWARE\Microsoft\CTF) [d:\temp_sys.exe]
GetModuleHandle(ole32.dll) [d:\temp_sys.exe]
LoadLibrary(c:\windows\system32\asycfilt.dll) [d:\temp_sys.exe]
LoadLibrary(asycfilt.dll) [d:\temp_sys.exe]
LoadLibrary(imm32.dll) [d:\temp_sys.exe]
GetModuleHandle(C:\WINDOWS\system32\Msimtf.dll) [d:\temp_sys.exe]
GetKeyState() [d:\temp_sys.exe]
[/more]