There is an update about Sandboxie from my side:

It is possible for a hacker to read any data stored on the pc. It is therefore important to restrict file access in the sandboxie config.

In my case, this would be:
- C:/users (self-explanatory)
- D:/ (this is where my programs are installed, firefox is still accessible on C:/Programs (x86)/...)
- E:/ (this is where my usb-sticks are mounted)