Shadow Defender or Sandboxie: If we choose

Discussion in 'sandboxing & virtualization' started by ocsi, Jun 1, 2011.

Thread Status:
Not open for further replies.
  1. moontan

    moontan Registered Member

    Joined:
    Sep 11, 2010
    Posts:
    3,931
    Location:
    Québec
    Why, thank you very much! ;) :D


    after reading all the good posts here that encouraged me to re-install SBie.

    it's one of the few problem-free and light security app around.
    there is a slight slow-down when launching the browser but no big deal really.

    i've allowed only IE9 and PDF-Xchange Viewer in the Start/Run restrictions and IE9 only for Internet restrictions.

    i get bugged once in awhile by rundll32.exe and dllhost.exe but not enough to allow them in the restrictions.
     
  2. Sully

    Sully Registered Member

    Joined:
    Dec 23, 2005
    Posts:
    3,719
    I have a strong liking anymore for in-built security. It is personal preference.

    I use SBIE because it works and for me is about as close to "set and forget" as any product I can think of.

    If one educates themselves on how SBIE works and the few changes in protocol that it brings, it is IMHO also one of the easiest security tools I know of.

    I must officially be a Sandboxie Fan Boy now ;) It is the one and only 3rd party application that I would recommend to anyone.

    The theoretical situation of having to choose is just that, theoretical. Anyone who has used the two knows that they perform different functions, and you might not always need both of them. But, if you do, there is no real reason to choose between the two, each will serve you fine separately or together.

    Sul.
     
  3. Page42

    Page42 Registered Member

    Joined:
    Jun 18, 2007
    Posts:
    6,944
    Location:
    USA
    Bo knows. :cool: :thumb:
     
  4. PJC

    PJC Very Frequent Poster

    Joined:
    Feb 17, 2010
    Posts:
    2,959
    Location:
    Internet
    Quite the Opposite!
    :thumb:
     
  5. John Bull

    John Bull Registered Member

    Joined:
    Nov 22, 2009
    Posts:
    904
    Location:
    London UK
    If Sully recommends something, you had better listen. He is a very good judge of programs and has no hang-ups, just an extremely knowledgeable appraisal of any situation, program or problem. One of my favourite Guru`s.

    So if he says SBxie, then SBxie it is.

    John
     
    Last edited: Jun 5, 2011
  6. 1820301060

    1820301060 Registered Member

    Joined:
    Jun 6, 2011
    Posts:
    3
    None of them. I am using the Returnil Lite.
     
  7. John Bull

    John Bull Registered Member

    Joined:
    Nov 22, 2009
    Posts:
    904
    Location:
    London UK
    This thread poses a fundamental question. It is about virtual programs, those which allow us to operate in a virtual environment which isolates our PC from all activity therein.

    A virtual system does not rely on vast ever growing and never up-to-date data bases of recognised inflectional material and kills all possible threats when the browser is closed. Nothing gets out into the main physical computer to infect our system.

    So it sounds as if using a virtual program is the ideal choice for every one of us, in theory making all AV and AM software redundant.

    So why is there any doubt about the concept of virtual operation ? It appears just a matter of which program to use as this thread asks. I do not know why the colossal industry of AV and AM is not rapidly declining in today`s world, if virtual systems are so perfect and an obvious indication of the future progression of computer operations.

    Please, can our more knowledgeable members expand on this point, not particularly to kick my butt, I am no expert and am willing to learn all the time, but to clarify this important matter.

    I use SBxie as you all know and my reading of many Forum posts and lots of associated web data leads me to believe that if SBxie, Returnil, Shadow Defender or some other similar virtual program is used, we do not need anything else.

    SBxie is so easy and invisible that I do not know it is there at all, but I do know that when I close my browser, all the bugs and nasties go with it.

    There must be a catch somewhere, what is it ?

    John
     
  8. moontan

    moontan Registered Member

    Joined:
    Sep 11, 2010
    Posts:
    3,931
    Location:
    Québec
    we're starting to see "alternatives" from AV vendors and developers.
    Kaspersky has some 'rollback' module and Avast has a decent sandbox.

    the problem is to make this technology as painless and transparent as possible for Joe/Jane Average.
     
  9. J_L

    J_L Registered Member

    Joined:
    Nov 6, 2009
    Posts:
    8,738
    Average computer users would be confused by virtualization programs, especially those system-wide ones. One reboot, and their new programs and settings are gone.

    Sandboxie will be easier, but teaching them how to recover safe files will be hard.
     
  10. bo elam

    bo elam Registered Member

    Joined:
    Jun 15, 2010
    Posts:
    6,147
    Location:
    Nicaragua
    You can set Direct file access so the user wont have to "recover"
    anything. Their favorite AV can check that downloaded files are OK.
    Sandboxie should be easy for all users but I agree, system wide
    virtualization programs can be confusing for the average person.


    Bo
     
  11. J_L

    J_L Registered Member

    Joined:
    Nov 6, 2009
    Posts:
    8,738
    Indeed that is true, but John Bull thinks AVs are redundant, as do yourself.
     
  12. PJC

    PJC Very Frequent Poster

    Joined:
    Feb 17, 2010
    Posts:
    2,959
    Location:
    Internet
    On the other hand, the possibility of No Longer Relying on [Real-Time] Scanners
    while Having a Light and Effective Security Setup for FREE (= Sandboxie and Returnil),
    has made many Average Users eager to educate themselves on these issues.
     
    Last edited: Jun 10, 2011
  13. John Bull

    John Bull Registered Member

    Joined:
    Nov 22, 2009
    Posts:
    904
    Location:
    London UK
    John Bull does not think AV`s and AM`s are redundant, he simply is saying that a virtual system is almost impenetrable and that these other traditional security programs look rather like being of little value with the introduction and progressive development of future virtual programs.

    OK, the despicable ~ Snipped as per TOS ~ who devote their entire miserable lives to wrecking everything that is good will not lay back and let it happen, but the ball is in their court and virtual systems at present beat them into a frazzle.

    Spending good money on some AV or AM program seems an economic lapse of judgement when one can simply install a reputable virtual program for FREE and to hell with Internet threats.

    John
     
    Last edited by a moderator: Jun 8, 2011
  14. Osaban

    Osaban Registered Member

    Joined:
    Apr 11, 2005
    Posts:
    5,618
    Location:
    Milan and Seoul
    I like to think that all applications that are currently available have a specific place in the security spectrum. To rely only on an AV/AM wouldn't be enough nowadays, and I agree Sandboxie or Shadow Defender will protect against almost any new type of malware (provided that the malware hasn't been specifically coded to defeat the sandbox or the virtual system).

    This is all fine as long as the user doesn't download and execute anything, because if one wants to download something from an unknown source then the only way to ascertain whether it is infected is to use a scanner.
    There are several excellent free scanners Avast, Avira, MBAM to name a few. I don't think they are redundant.
     
  15. chris1341

    chris1341 Guest

    We have to be careful we don't think all virtualisation software is like Sandboxie. It's not.

    If we use the 2 in the OP only SBIE can be used to restrict the behaviour of the virtualised application and what is spawned from it. SD in my experience will succesfully wash away all remnants of malware on reboot but will not stop it installing and running - potentially stealing data/keylogging etc in the time between install and reboot.

    Using SD on its own then, for me at any rate, is not an option. Using SBIE on it's own, with appropriate precautions such as start/run restriction and a strategy for confirming the safety of what you let out into the real system, can be.

    Having said that I don't think its essential to run real-time AV/AM with SD as long as you use something like Defensewall, Geswall, AppGaurd or even well implemented SRP to keep the nasties at bay until reboot.

    I use SBIE on all my systems with no real-time AV but do make use of on demand scanners and VT/Jotti as well as VM's for unknown apps.

    Virtualisation as long as it is backed up with some form of restriction (inbuilt or 3rd party) is great if you understand how to check what you need to instal is clean. If you know that AV/AM is a choice rather than a necessity. If you don't you need to keep the AV in real time in my opinion.

    Cheers
     
  16. bo elam

    bo elam Registered Member

    Joined:
    Jun 15, 2010
    Posts:
    6,147
    Location:
    Nicaragua
    J L, yes, I don't use antivirus real time but the type of user that you
    were talking about in post#34 would benefit by using their favorite
    antivirus and SBIE together, like I described on post#35, making it
    easier to recover safe files. If my grandma was a internet junky,
    I would set it her up that way.

    Bo
     
  17. John Bull

    John Bull Registered Member

    Joined:
    Nov 22, 2009
    Posts:
    904
    Location:
    London UK
    You`ve done it again BO, never fail.

    Whilst I have said a few things here, some right, some wrong, I am getting an enormous amount of interest and information out of this post.

    It is a good thread and very topical subject in today`s world of cut and thrust.
     
  18. majoMo

    majoMo Registered Member

    Joined:
    Aug 31, 2007
    Posts:
    994
    I agree. When needed I use Wondershare Time Freeze instead Shadow Defender. In general I use SandboxIE.
     
  19. J_L

    J_L Registered Member

    Joined:
    Nov 6, 2009
    Posts:
    8,738
    What are they going to do about downloaded files then?
     
  20. Osaban

    Osaban Registered Member

    Joined:
    Apr 11, 2005
    Posts:
    5,618
    Location:
    Milan and Seoul
    Pray they are not infected.
     
  21. PJC

    PJC Very Frequent Poster

    Joined:
    Feb 17, 2010
    Posts:
    2,959
    Location:
    Internet
    -In terms of Security (i.e. Checking Doubtful Files):
    They use VirusTotal, on-Demand Scanners, and on-Line Scanners.

    Countless users have stayed Malware-Free
    by using Sandboxing & Virtualization
    while they are Not relying on Real-Time Scanners.
     
    Last edited: Jun 9, 2011
  22. LowWaterMark

    LowWaterMark Administrator

    Joined:
    Aug 10, 2002
    Posts:
    18,280
    Location:
    New England
    Off-topic posts removed...

    Guys, no one asked you to stop discussing this topic, so, it's pointless to make a bunch of posts debating the forum rules. None were broken here. So, let's get back to the actual topic.

    If you do think a forum rule has been broken in some thread, please use the "Report Bad Post" ( [​IMG] ) feature to notify the forum staff instead of posting about it in the thread.
     
  23. John Bull

    John Bull Registered Member

    Joined:
    Nov 22, 2009
    Posts:
    904
    Location:
    London UK
    Just noticed that SD is a PAY program.

    Why on Earth bother to raise this thread ? SBxie is FREE unless you choose to pay for the more sophisticated version. I have found that FREE SBxie is absolutely perfect, so why pay for SD ? This factor alone appears to resolve this thread question precisely.

    If you really have a hang up, then go for Returnil FREE. You do not have to dig into your pocket to get a perfect security package that keeps you bug free.

    The thread is a non starter - to compare a PAY program with a FREE program + optional PAY is not logical and a waste of Forum time. You simply cannot compare bananas with apples, they are different commodities.

    Bottom line - just use SBxie and forget SD. Returnil is an excellent alternative and that is FREE as well.

    Why people line up programs that do not have a direct equality, I will never understand.
     
    Last edited: Jun 9, 2011
  24. pegr

    pegr Registered Member

    Joined:
    Apr 8, 2008
    Posts:
    2,280
    Location:
    UK
    Because they are different types of program, each with it's own pros and cons, so it's perfectly valid to have a discussion around the differences. Free vs Paid is just one dimension.
     
  25. moontan

    moontan Registered Member

    Joined:
    Sep 11, 2010
    Posts:
    3,931
    Location:
    Québec
    if you want to test programs SD id better as SBie will not let a program install drivers.
     
Thread Status:
Not open for further replies.
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.