I still say sandboxie is the best defense when properly used when knowing a file could be malicious or you are savvy enough to use it.
It is not for most people, but it can be the best defense for you or others. Almost all users apply Sandboxie on demand, so it cannot be compared to Comodo which uses auto-containment.
I used Sandboxie for a few years and still have several sandboxes with very different restrictions on my old disk images.
Also, the term "best defense" has a different meaning for many people.
Edit.
Most users who use Sandboxie are unprotected against the attacks mentioned in this thread.
It is possible to use auto-sandboxed Windows Explorer (explorer.exe) for more security, but I knew only one person who used Sandboxie that way.