VoodooShield/Cyberlock

Discussion in 'other anti-malware software' started by CloneRanger, Dec 7, 2011.

  1. VoodooShield

    VoodooShield Registered Member

    Joined:
    Dec 9, 2011
    Posts:
    5,881
    Location:
    United States
    I think this might be because I had the installer remove the 3 .dat files (snapshot, settings and userlog) during the beta test, just to make sure everything ran smooth (ha!), and that there were no issues with the database. The new version that I will release soon does not do this anymore, so please let me know if it continues to happen! Thank you!
     
  2. Overkill

    Overkill Registered Member

    Joined:
    Mar 16, 2012
    Posts:
    2,343
    Location:
    USA
    Great! thanks :D
     
  3. VoodooShield

    VoodooShield Registered Member

    Joined:
    Dec 9, 2011
    Posts:
    5,881
    Location:
    United States
    Thank you Tarnak, good catch! Yeah, I will have to fix that. I know exactly what is wrong, but it might take a little while to fix. In the meantime, whenever you need to start the Windows Installer Service, you will need to turn VS OFF (Disable Protection, Training Mode, Smart Mode (Web Apps Closed) or Always ON (click to turn OFF). Thanks again!
     
  4. VoodooShield

    VoodooShield Registered Member

    Joined:
    Dec 9, 2011
    Posts:
    5,881
    Location:
    United States
    Ok, I THINK this is the answer, if not, please let me know. I just tried installing VS with Revo and it would not let me. Revo told me that it did not have access to the VS folder in Program Files, so I then uninstalled VS and deleted the VoodooShield folder from Program Files, and it worked. Please try this, and if it does not work, let me know. Thank you!
     
  5. VoodooShield

    VoodooShield Registered Member

    Joined:
    Dec 9, 2011
    Posts:
    5,881
    Location:
    United States
    The new sandboxing feature is almost ready! I am not that familiar with sandboxing, so I was curious if someone who was familiar with sandboxing could answer a silly question for me. What happens when a user tries to run an installer sandboxed? Since the installer typically has to do things that require admin privileges, it probably is not a good idea to run an installer sandboxed, correct? So how should we handle this? I was thinking, if it is just a normal exe, then VS can run it sandboxed, but if it is an installer, then we should prompt the user that it cannot run the installer sandboxed? Am I on the right track? Any help would be greatly appreciated!
     
  6. Tarnak

    Tarnak Registered Member

    Joined:
    Feb 5, 2007
    Posts:
    5,304
    Glad to help...I worked out that the only way to bypass the problem was to exit VS, via the systray icon.
     
  7. Tarnak

    Tarnak Registered Member

    Joined:
    Feb 5, 2007
    Posts:
    5,304
    I noticed this, too....Should I do anything?

    ScreenShot_VoodooShield_v2.40 beta_install_10.gif
     
  8. Triple Helix

    Triple Helix Specialist

    Joined:
    Nov 20, 2004
    Posts:
    13,277
    Location:
    Ontario, Canada
    Hi Dan no it's gone but it will not play nice with my new VPN service as it uses Appdata Temp folder and a new Temp Folder and file everytime I start it so it's never the same name so I can't Whitelist it when ever I start it and VS just freaks out per say so do you have any Idea's? Here is the VPN service https://www.privateinternetaccess.com/

    Thanks,

    Daniel :)
     
  9. Triple Helix

    Triple Helix Specialist

    Joined:
    Nov 20, 2004
    Posts:
    13,277
    Location:
    Ontario, Canada
    Yea I seen that to, is it alright Dan to remove the Items on there if we don't use the programs?

    TIA,

    Daniel :)
     
  10. Tarnak

    Tarnak Registered Member

    Joined:
    Feb 5, 2007
    Posts:
    5,304
    I have another one, but it lists, additional software running on my system. I don't I need do anything with the others, at the moment. Dan, will let us know. :)

    ScreenShot_VoodooShield_v2.40 beta_install_11.gif
     
  11. VoodooShield

    VoodooShield Registered Member

    Joined:
    Dec 9, 2011
    Posts:
    5,881
    Location:
    United States
    Hmmm, I am not sure what to do about this. I tested under XP and could not get the processes to repeat like that. The code is written so that it ignores duplicates, but obviously it is different under XP ;). I will see what I can do, thank you!
     
  12. VoodooShield

    VoodooShield Registered Member

    Joined:
    Dec 9, 2011
    Posts:
    5,881
    Location:
    United States
    Hey TH, I tried to download the software for the VPN service, but it looks like they do not have a trial. What is the exact path of the appdata temp folder (I realize that it changes)? Does VS block it, or does it do something else freaky? Thank you!
     
  13. VoodooShield

    VoodooShield Registered Member

    Joined:
    Dec 9, 2011
    Posts:
    5,881
    Location:
    United States
    Yeah, definitely! I just added some of the more common web apps, but you can modify them however you want! I am sure a lot of users are going to wonder that as well, but I would like to leave them in because most users will not modify these settings anyway. I should put some instructions on that tab ;). Thank you!
     
  14. VoodooShield

    VoodooShield Registered Member

    Joined:
    Dec 9, 2011
    Posts:
    5,881
    Location:
    United States
    Hopefully my last post makes sense, if not, please let me know!
     
  15. VoodooShield

    VoodooShield Registered Member

    Joined:
    Dec 9, 2011
    Posts:
    5,881
    Location:
    United States
  16. Tarnak

    Tarnak Registered Member

    Joined:
    Feb 5, 2007
    Posts:
    5,304
    Well, that is different... after clicking through to allow, I then got an instruction to close VS, which I did...but then nothing...It looks like the install, just stalled. I will reboot and see, what happens with VS.

    ScreenShot_VoodooShield_v2.41 beta_install_01.gif ..... ScreenShot_VoodooShield_v2.41 beta_install_02.gif
     
  17. Overkill

    Overkill Registered Member

    Joined:
    Mar 16, 2012
    Posts:
    2,343
    Location:
    USA
    What exactly is the web apps tab for?
     
  18. Tarnak

    Tarnak Registered Member

    Joined:
    Feb 5, 2007
    Posts:
    5,304
    Just what I thought, after the reboot...still VS 2.40 is installed. This was showing in the logs.

    ScreenShot_VoodooShield_v2.41 beta_install_09.gif
     
  19. djg05

    djg05 Registered Member

    Joined:
    Apr 6, 2005
    Posts:
    1,565
    I have a problem with 2.4. When I go to add an app to the web app panel, VS in TM shoots up to 28% and the machine slows to a crawl making it impossible to make any changes.

    Win 8.1/64

    Will what happens in 2.41 later today.
     
  20. Overkill

    Overkill Registered Member

    Joined:
    Mar 16, 2012
    Posts:
    2,343
    Location:
    USA
    I installed 2.41 but it will not start...


    Image2.jpg
     
  21. VoodooShield

    VoodooShield Registered Member

    Joined:
    Dec 9, 2011
    Posts:
    5,881
    Location:
    United States
    Yeah, we have to figure out the best way to get users to choose Install instead of Allow when installing new software. The Allow button is meant for exe's that are not installers. The installer should have prompted you that VS was running, and that you have to right click and choose exit before installing the new version... I will check it out though. Thank you!
     
  22. VoodooShield

    VoodooShield Registered Member

    Joined:
    Dec 9, 2011
    Posts:
    5,881
    Location:
    United States
    The Web Apps tab is where you can add your own unique web browsers, email clients, etc, so that VS will toggle in smart mode with them ;).
     
  23. VoodooShield

    VoodooShield Registered Member

    Joined:
    Dec 9, 2011
    Posts:
    5,881
    Location:
    United States
    Yeah, I tried to dial it back a little, but then the polling interval was a little high. So 2.41 will do the same thing, but I have some other ideas I can try. Thank you!
     
  24. VoodooShield

    VoodooShield Registered Member

    Joined:
    Dec 9, 2011
    Posts:
    5,881
    Location:
    United States
    Hmmm, that is odd. You might try to uninstall VS, reboot, and then reinstall. Please let me know if you continue to receive this message! Thank you!
     
  25. Baldrick

    Baldrick Registered Member

    Joined:
    May 11, 2002
    Posts:
    2,675
    Location:
    South Wales, UK
    Hi Dan

    Am still running v2.40 but I am now starting to get an excessive number of rundll32.exe being blocked and the occassional for regsvr32.dll as evidenced by the following:

    30/07/2014 16:23:06Blockedregsvr32.exec:\windows\system32\regsvr32.execa24aef558647274d019dfb4d7fd1506d84ec278795c30ba53b81bb36130dc57
    29/07/2014 22:11:29Blockedrundll32.exec:\windows\system32\rundll32.exef5691b8f200e3196e6808e932630e862f8f26f31cd949981373f23c9d87db8b9
    29/07/2014 22:11:28Blockedrundll32.exec:\windows\system32\rundll32.exef5691b8f200e3196e6808e932630e862f8f26f31cd949981373f23c9d87db8b9
    29/07/2014 22:11:28Blockedrundll32.exec:\windows\system32\rundll32.exef5691b8f200e3196e6808e932630e862f8f26f31cd949981373f23c9d87db8b9
    29/07/2014 22:11:27Blockedrundll32.exec:\windows\system32\rundll32.exef5691b8f200e3196e6808e932630e862f8f26f31cd949981373f23c9d87db8b9
    29/07/2014 22:11:27Blockedrundll32.exec:\windows\system32\rundll32.exef5691b8f200e3196e6808e932630e862f8f26f31cd949981373f23c9d87db8b9
    29/07/2014 21:46:56Blockedrundll32.exec:\windows\system32\rundll32.exef5691b8f200e3196e6808e932630e862f8f26f31cd949981373f23c9d87db8b9
    29/07/2014 21:46:56Blockedrundll32.exec:\windows\system32\rundll32.exef5691b8f200e3196e6808e932630e862f8f26f31cd949981373f23c9d87db8b9
    29/07/2014 21:46:55Blockedrundll32.exec:\windows\system32\rundll32.exef5691b8f200e3196e6808e932630e862f8f26f31cd949981373f23c9d87db8b9
    29/07/2014 20:59:32Blockedrundll32.exec:\windows\system32\rundll32.exef5691b8f200e3196e6808e932630e862f8f26f31cd949981373f23c9d87db8b9
    29/07/2014 20:59:31Blockedrundll32.exec:\windows\system32\rundll32.exef5691b8f200e3196e6808e932630e862f8f26f31cd949981373f23c9d87db8b9
    29/07/2014 20:59:31Blockedrundll32.exec:\windows\system32\rundll32.exef5691b8f200e3196e6808e932630e862f8f26f31cd949981373f23c9d87db8b9
    29/07/2014 20:59:31Blockedrundll32.exec:\windows\system32\rundll32.exef5691b8f200e3196e6808e932630e862f8f26f31cd949981373f23c9d87db8b9
    29/07/2014 20:59:30Blockedrundll32.exec:\windows\system32\rundll32.exef5691b8f200e3196e6808e932630e862f8f26f31cd949981373f23c9d87db8b9


    I see that v2.41 is available so will install that and see if I can reproduce this...just thought that you should be aware.

    Regards


    Baldrick
     
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.