VoodooShield/Cyberlock

Discussion in 'other anti-malware software' started by CloneRanger, Dec 7, 2011.

  1. VoodooShield

    VoodooShield Registered Member

    Joined:
    Dec 9, 2011
    Posts:
    5,881
    Location:
    United States
    Yeah, they are currently not editable, but I can change that if we need to. All of the command lines are handled automatically, so I am not sure that we need to add that or not. Thank you!
     
  2. VoodooShield

    VoodooShield Registered Member

    Joined:
    Dec 9, 2011
    Posts:
    5,881
    Location:
    United States
    The "c:\windows\system32\rundll32.exe" shell32.dll,shellexec_rundll e:\start.html block will probably have to be added manually by clicking Allow. There will be some command lines that have to be allowed manually. Thank you!
     
  3. VoodooShield

    VoodooShield Registered Member

    Joined:
    Dec 9, 2011
    Posts:
    5,881
    Location:
    United States
    Same here, I think it is best to just add it manually by clicking Allow.
     
  4. siketa

    siketa Registered Member

    Joined:
    Oct 25, 2012
    Posts:
    2,718
    Location:
    Gaia
    See...that is why I want to edit that command line from

    c:\windows\system32\rundll32.exe c:\windows\system32\pla.dll,plahost "lsc memory" "0x828_0x438_0x672f6987"
    to
    c:\windows\system32\rundll32.exe c:\windows\system32\pla.dll,plahost "lsc memory" *

    because "0x828_0x438_0x672f6987" part always changes and with "*" wildcard I think it should not warn any more....but for now VS forgets the change.
     
    Last edited: Mar 30, 2015
  5. VoodooShield

    VoodooShield Registered Member

    Joined:
    Dec 9, 2011
    Posts:
    5,881
    Location:
    United States
    Version 2.31m is working great with EaseUS Todo in windows 7 and 8.1, but please let me know if this continues to be an issue! The filemanager issues are fixed in 2.31m, along with the user log refresh and the Power Shell option, thank you for the recommendation! I tried 7zip, but could not get a command line block, so please let me know how to make the block appear. If you set a password in Settings / Utility, VS will block the Task Manager and all of the other apps that can kill VS. We might add a different self protection method at some point, I am looking into all of the options.

    When the computer is running a web app and is at risk, and VS is ON, it really needs to block cmd.exe, so I am not sure there is a way around that or not.

    I think it is important to keep the whitelist as small as possible, that way the attack surface is as small as possible. Otherwise, we will end up needlessly adding thousands or tens of thousands of items to the whitelist, and increasing the attack surface. If you right click on VS and click "Take Snapshot", it will ask you if you want to take an advanced snapshot. If you take an advanced snapshot, VS will add pretty much everything that needs to be added. Thank you!
     
  6. VoodooShield

    VoodooShield Registered Member

    Joined:
    Dec 9, 2011
    Posts:
    5,881
    Location:
    United States
  7. VoodooShield

    VoodooShield Registered Member

    Joined:
    Dec 9, 2011
    Posts:
    5,881
    Location:
    United States
    Thank you, I appreciate that!
     
  8. VoodooShield

    VoodooShield Registered Member

    Joined:
    Dec 9, 2011
    Posts:
    5,881
    Location:
    United States
    Cool, thank you Baldrick!
     
  9. VoodooShield

    VoodooShield Registered Member

    Joined:
    Dec 9, 2011
    Posts:
    5,881
    Location:
    United States
    The helper.exe from thunderbird is a different issue, but it is fixed in 2.31m, which I will post soon. I tested the AlarmClock.gadget, but nothing odd happened, so it must have been a driveby from the website, it is hard to say. VS should block rootkits as well, so I am not sure where that came from. Thank you for letting me know!
     
  10. VoodooShield

    VoodooShield Registered Member

    Joined:
    Dec 9, 2011
    Posts:
    5,881
    Location:
    United States
    Great to hear, thank you!
     
  11. VoodooShield

    VoodooShield Registered Member

    Joined:
    Dec 9, 2011
    Posts:
    5,881
    Location:
    United States
  12. VoodooShield

    VoodooShield Registered Member

    Joined:
    Dec 9, 2011
    Posts:
    5,881
    Location:
    United States
    This should be fixed by now, if not please let me know!
     
  13. VoodooShield

    VoodooShield Registered Member

    Joined:
    Dec 9, 2011
    Posts:
    5,881
    Location:
    United States
    This should be fixed as well, if not, please let me know! Thank you!
     
  14. VoodooShield

    VoodooShield Registered Member

    Joined:
    Dec 9, 2011
    Posts:
    5,881
    Location:
    United States
    Great to hear, thank you. Yeah, some command lines just have to be allowed manually, unfortunately.
     
  15. VoodooShield

    VoodooShield Registered Member

    Joined:
    Dec 9, 2011
    Posts:
    5,881
    Location:
    United States
    I think this is fixed in 2.31m, if not, please let me know, thank you!
     
  16. VoodooShield

    VoodooShield Registered Member

    Joined:
    Dec 9, 2011
    Posts:
    5,881
    Location:
    United States
    Yeah, this might happen from time to time with Windows XP until we figure out what we are going to do with the KMD.
     
  17. VoodooShield

    VoodooShield Registered Member

    Joined:
    Dec 9, 2011
    Posts:
    5,881
    Location:
    United States
    Wildcards are handled automatically in VS, but this is fixed in 2.31m. You will have to click Allow once, but it will remember it from then on.
     
  18. VoodooShield

    VoodooShield Registered Member

    Joined:
    Dec 9, 2011
    Posts:
    5,881
    Location:
    United States
    Yeah, this issue is only for XP.
     
  19. VoodooShield

    VoodooShield Registered Member

    Joined:
    Dec 9, 2011
    Posts:
    5,881
    Location:
    United States
    Yeah, they work great together!
     
  20. VoodooShield

    VoodooShield Registered Member

    Joined:
    Dec 9, 2011
    Posts:
    5,881
    Location:
    United States
    Great to hear, sorry it took so long to fix!
     
  21. VoodooShield

    VoodooShield Registered Member

    Joined:
    Dec 9, 2011
    Posts:
    5,881
    Location:
    United States
    Yeah, if we need to make the command lines editable, then we will. Please try 2.31m after I post it a little later today, and if it is still an issue then we can make them editable. Thank you!
     
  22. VoodooShield

    VoodooShield Registered Member

    Joined:
    Dec 9, 2011
    Posts:
    5,881
    Location:
    United States
    Hopefully I did not miss any of the posts, but if I did, please let me know! I will post 2.31m soon, and I think pretty much all of the issues are fixed, but if not, please let me know!
     
  23. VoodooShield

    VoodooShield Registered Member

    Joined:
    Dec 9, 2011
    Posts:
    5,881
    Location:
    United States
  24. Triple Helix

    Triple Helix Specialist

    Joined:
    Nov 20, 2004
    Posts:
    13,275
    Location:
    Ontario, Canada
    It's working very well Dano so hope you can look after the other bugs buddy!

    Daniel :)
     
    Last edited: Mar 31, 2015
  25. ProTruckDriver

    ProTruckDriver Registered Member

    Joined:
    Sep 18, 2008
    Posts:
    1,444
    Location:
    "An Apple a Day, Keeps Microsoft Away"
    Updated to the latest version (m) over the top of version (l). I have VS set so it doesn't start when windows starts. The reason being is this HP computer takes about 45 seconds to 1 minute to get an internet connection after loading apps. (That will be fixed after I reformat, if I ever get around to it). VS didn't save my setting in: "Start VoodooShield When I Start Windows".

    VooDooShield Unable to Connect.JPG
     
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.