« Reply #131 on: April 23, 2011, 02:49:38 AM »
I ran the AutoSandbox Test Tool from a limited user account and allowed it to be sandboxed. No text file was created nor was the indicated HKCU key added. However, there was another registry entry created. I ran RegEdit non-virtualized from a Command Prompt to search for autosandboxtest. I am running Avast Free.
[HKEY_USERS\__aswSnx private storage\autosandboxme.e_{c7a72eef-6d06-11e0-aa17-0013200b7107}\Registry\USER\S-1-5-21-2232638717-1984840243-2864733914-1005\SofTWare\MicROSoft\WinDOws\CurRENTVERsion\Run]
"autosandboxtest"="If you can see this text even from a non-virtualized application then the application (avast! autosandboxme) wasn't sandboxed properly."
That is the "virtualized" registry entry (__aswSnx private storage), I also has this entry with admin account while test tool is running. Once test tool was closed the entry disappear.
Your entry does not disappear after closing all sandboxed application?
It persisted for several minutes at least. I was able to find it although the AutoSandbox Test Tool was already closed. Now, it is no longer there, >6 hours later. It likely takes a few minutes to clean house. Also, RegEdit likely was displaying it from the opened state, even though the cleanup had already occurred. I exited RegEdit without saving, so that didn't alter anything.
I knew that __aswSnx had to do with Avast Sandbox. The (avast! autosandboxme) wasn't sandboxed properly is what I am questioning.

Logged
AMD A6-5350M APU with Radeon HD Graphics, 8.0GB RAM, Win7 Pro SP1 64bit, IE11
i7-3610QM 2.3GHZ, 8.0GB Ram, Nvidia GeForce GT 630M 2GB, Win7 Pro SP1 64bit, IE 11
Common to both: Avast Premium Security 19.7.2388, WinPatrol Plus, SpywareBlaster 5.5, Opera 12.18, Firefox 68.0.2, MBam Free, CCleaner