New Shadow Defender 1.1 beta out

Discussion in 'sandboxing & virtualization' started by pidbo, Jan 20, 2008.

Thread Status:
Not open for further replies.
  1. trjam

    trjam Registered Member

    Joined:
    Aug 18, 2006
    Posts:
    9,102
    Location:
    North Carolina USA
    My mother-in-law.:rolleyes:
     
  2. BlueZannetti

    BlueZannetti Registered Member

    Joined:
    Oct 19, 2003
    Posts:
    6,590
    Potentially dynamic areas that could be inconvenient or difficult to replace. That could include:
    • A regularly updated program folder like an AV, if used
    • The My Documents folder for any user on the system
    • Email post office locations for any user of the system
    • A download folder where you tend to place deliberately downloaded programs
    Those types of folders/files.

    Blue
     
  3. trjam

    trjam Registered Member

    Joined:
    Aug 18, 2006
    Posts:
    9,102
    Location:
    North Carolina USA
    Basically I have the one for my daughter to save her games to. I have one for documents that I may create. I switch them around from time to time depending on what I do. The nice thing is, if in shadow mode I need to create or save something that I haven’t excluded, I can use the commit now to save it. There is plenty of flexibility in it to accommodate your needs. The key to remember is that for every excluded or commit now change, can create a hole for malware to slip through. That is why I find keeping a AV or HIPS is pretty much required.

    A on demand or online scanner works well. You can use one before rebooting just to scan your excluded folders.
     
  4. Peter2150

    Peter2150 Global Moderator

    Joined:
    Sep 20, 2003
    Posts:
    20,590
    Only thing I have on the exclusion list is on my D: drive, and that is the VM machine directory. It is over 50gb, which is why.

    Pete
     
  5. Meriadoc

    Meriadoc Registered Member

    Joined:
    Mar 28, 2006
    Posts:
    2,642
    Location:
    Cymru
    I purchased a license awhile ago - time to install.

    Will SD recognize usb drives?
     
  6. Peter2150

    Peter2150 Global Moderator

    Joined:
    Sep 20, 2003
    Posts:
    20,590
    If I remember right I believe it does.
     
  7. Meriadoc

    Meriadoc Registered Member

    Joined:
    Mar 28, 2006
    Posts:
    2,642
    Location:
    Cymru
    ...and no reboot of course.

    edit: on non system.
     
    Last edited: Jan 22, 2008
  8. trjam

    trjam Registered Member

    Joined:
    Aug 18, 2006
    Posts:
    9,102
    Location:
    North Carolina USA
    correct, except on exiting. For now.;)
     
  9. aigle

    aigle Registered Member

    Joined:
    Dec 14, 2005
    Posts:
    11,164
    Location:
    UK / Pakistan
    Does it satnds against Robodog trojan?
     
  10. trjam

    trjam Registered Member

    Joined:
    Aug 18, 2006
    Posts:
    9,102
    Location:
    North Carolina USA
    yes


    Version 1.0.0.129 - Decemeber 25, 2007
    New: defeat robodog(a malware)
    Fix: sometimes an annoying message will appear when rebooting pc
     
  11. aigle

    aigle Registered Member

    Joined:
    Dec 14, 2005
    Posts:
    11,164
    Location:
    UK / Pakistan
    Thanks trjam!

    Does it makes any change to MBR?
    What about Clean MBR tool discussed in another thread? wil they fix it?

    Thanks
     
  12. QQ2595

    QQ2595 Registered Member

    Joined:
    Jan 6, 2008
    Posts:
    159
    I have tested the new beta with CleanMBR and new Robot dog which can infect the explorer.exe and iexplper.exe.

    the CleanMBR bypassed the new beta and new Robot dog from Winzheng.com also bypassed the new beta.

    I have sent these files to the support email. Some videos about my testing will be available soon on Youtobe.com.
     
  13. aigle

    aigle Registered Member

    Joined:
    Dec 14, 2005
    Posts:
    11,164
    Location:
    UK / Pakistan
    Thanks QQ2595!

    New Robodog..? U mean they relaesed a new version that bypassed SD again?

    Pls check ur PM box as well.
     
    Last edited: Jan 22, 2008
  14. trjam

    trjam Registered Member

    Joined:
    Aug 18, 2006
    Posts:
    9,102
    Location:
    North Carolina USA
    there can never be a 100 percent, well SD and Sandboxie come close.;)
     
  15. QQ2595

    QQ2595 Registered Member

    Joined:
    Jan 6, 2008
    Posts:
    159
    Yes, it seems the Robot Dog update every week and some other new virus which can bypass SD's Shadow device came out too.

    here is a chinese forums about the new version of Robot Dog on Jan.25.

    {Removed possible malware link - please refer to TOS}
     
  16. trjam

    trjam Registered Member

    Joined:
    Aug 18, 2006
    Posts:
    9,102
    Location:
    North Carolina USA
    Tony just emailed me and said he can not download the new robodog and cleanMBR bypass from the link. Can you please email support directly so he can expedite a fix for both. Thank you.
     
  17. QQ2595

    QQ2595 Registered Member

    Joined:
    Jan 6, 2008
    Posts:
    159
    yes, I will send it to your support email soon. BTW, I have found two serious bugs of new beta and old version. Just sent my report to your PM.
     
    Last edited: Jan 23, 2008
  18. aigle

    aigle Registered Member

    Joined:
    Dec 14, 2005
    Posts:
    11,164
    Location:
    UK / Pakistan
    Hi QQ2595, I PMed u but no reply.

    Thanks
     
  19. demoneye

    demoneye Registered Member

    Joined:
    Dec 30, 2007
    Posts:
    1,356
    Location:
    ISRHell
    i totaly agree with you mate. "commit now change, can create a hole for malware to slip through"

    thats why deepfreeze never give this option in there software

    cheers:thumb:
     
  20. Perman

    Perman Registered Member

    Joined:
    Nov 23, 2005
    Posts:
    2,161
    Hi,

    Perhaps this "commit" flexibility has prevented the very first virtualization program"--surfer" from further development.

    A flexibility/convenience in any given security application sometimes leads to a bigger headache. IMO
     
  21. demoneye

    demoneye Registered Member

    Joined:
    Dec 30, 2007
    Posts:
    1,356
    Location:
    ISRHell
    use ani EXE (AE) from faronic and thoos new *puppy* wont bother you any more ;)
     
  22. Peter2150

    Peter2150 Global Moderator

    Joined:
    Sep 20, 2003
    Posts:
    20,590
    I for one like the commit flexibility. I have one safe site where I download jpg's. They've always been fine, and it's convenient to be able to right click and commit. True it does force you to use the best security software of all, which we all have, our brains.

    Pete
     
  23. QQ2595

    QQ2595 Registered Member

    Joined:
    Jan 6, 2008
    Posts:
    159
    Agree, it is a weakness. but seems useful for home users.

    The exclusion list of ShadowDefender/ShadowUsers and File Manager in Retrurnil already used by some new virus in Asia.:)

    BTW, there are 1,130,000 pages refered Robot Dog in Baidu.com(famous chinese search engine).
    http://www.baidu.com/s?wd=%BB%FA%C6%F7%B9%B7&cl=3
     
  24. trjam

    trjam Registered Member

    Joined:
    Aug 18, 2006
    Posts:
    9,102
    Location:
    North Carolina USA
    Sorry, a little to much for me to read.;)
     
  25. QQ2595

    QQ2595 Registered Member

    Joined:
    Jan 6, 2008
    Posts:
    159
    Yes, in fact, thousands of Robot Dog type spyware came out in the past month.

    About the big "hole" of Shadow device bypass, will Tony find a way to cover that?

    Thanks.
     
Thread Status:
Not open for further replies.
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.