Alternative to Sandboxie?

The machines we love to hate

Moderator: Wiz Feinberg

Ray Minich
Posts: 6431
Joined: 22 Jul 2003 12:01 am
Location: Bradford, Pa. Frozen Tundra
State/Province: -
Country: United States

Alternative to Sandboxie?

Post by Ray Minich »

I've been using Sandboxie on my WinXP machine to open files that may have malware in them. It's a "virtual machine" program that isolates the opened file from the rest of the operating system in order to prevent invasive maneuvers by the opened file.

Sandboxie does take up some system resources and has a couple of nuisances I tire of.

Now I'm in Windows 7 land.

Does anyone know of a suitable alternative virtual machine program that has better performance or tighter protection specs?

Thanks all.
Lawyers are done: Emmons SD-10, 3 Dekleys including a D10, NV400, and lots of effects units to cover my clams...
User avatar
Wiz Feinberg
Posts: 6115
Joined: 8 Jan 1999 1:01 am
Location: Mid-Michigan, USA
State/Province: Michigan
Country: United States

Post by Wiz Feinberg »

I use Acronis True Image. It contains a module that runs everything in a VM, until the next reboot. At that time you can decide whether to accept the changes made to the system, or restore the previous setup.

Rejecting the changes eliminates everything done by the program or malware you are testing.

Caveat: One needs to use caution to avoid running malware that overwrites the MBR, such as TDSS-4 or Mebroot, etc. You would have to discard the VM before rebooting to avoid this from occurring.

Safety net: Acronis can be used to image the C drive before testing the malware. Should an MBR infector take hold, restore the image, including the MBR.
"Wiz" Feinberg, Moderator SGF Computers Forum
Security Consultant
Twitter: @Wizcrafts
Main web pages: Wiztunes Steel Guitar website | Wiz's Security Blog | My Webmaster Services | Wiz's Security Blog