VoodooShield/Cyberlock

Discussion in 'other anti-malware software' started by CloneRanger, Dec 7, 2011.

  1. VoodooShield

    VoodooShield Registered Member

    Joined:
    Dec 9, 2011
    Posts:
    5,881
    Location:
    United States
    Hey everyone, sorry, this week has been way crazy... mainly because I have been working to figure out that last odd bug. I think it is fixed now... once it is ready I will let you guys know.

    Also, I know I have a few pms and posts to catch up on, I will do that asap.

    BTW, I found something very interesting... it is a ransomware simulator / pen test tool. If you test VS, please make sure you disable the parent process feature first ;).

    I just tested VS with ransim, and it it seems that after the first time VS blocked one of the spawned payloads, it crashed the ransim tool (an error handling issue in the ransim tool)... so I am assuming that would count for a pass ;).

    https://www.knowbe4.com/typ-ransim-form

    Thank you guys... we are getting close with everything, have great weekend!
     
  2. khanyash

    khanyash Registered Member

    Joined:
    Apr 4, 2011
    Posts:
    2,438
    Dan,

    VAi scans .exe, VAi 2 will scan more file extensions?

    And hope standalone portable VAi 2 will be there too.
     
    Last edited: Nov 18, 2016
  3. Baldrick

    Baldrick Registered Member

    Joined:
    May 11, 2002
    Posts:
    2,692
    Location:
    South Wales, UK
    Hi Dan

    I sincerely hope that you are trying to have a quieter weekend after "this week has been way crazy"? ;)

    Have been giving 3.48 a bit of a work out and so far I have yet to find anything untoward. Planning to clear all data, uninstall & clean install for a final (for me) test...but so far looking great under Win 10 Pro 64bit...with UAC on 'Never notify', and VS running in 'Always On' mode.

    Regards, Baldrick
     
  4. boredog

    boredog Registered Member

    Joined:
    Feb 1, 2015
    Posts:
    2,499
  5. Gandalf_The_Grey

    Gandalf_The_Grey Registered Member

    Joined:
    Jan 31, 2012
    Posts:
    1,236
    Location:
    The Netherlands
    You don't see it in the User Log?
     
  6. boredog

    boredog Registered Member

    Joined:
    Feb 1, 2015
    Posts:
    2,499
    yes I do now it just took a while.

    ok here is the deal. clicking on the exe voodoo blocks the file but right click and select scan I get a pop up saying the file is good.
    see screen shots.
     

    Attached Files:

  7. Gandalf_The_Grey

    Gandalf_The_Grey Registered Member

    Joined:
    Jan 31, 2012
    Posts:
    1,236
    Location:
    The Netherlands
    Strange, no block here. I could beform the test. On my system it was stopped by Emsisoft Anti-Malware, but not by VoodooShield or Malwarebytes 3.0.2 Beta.
     
  8. boredog

    boredog Registered Member

    Joined:
    Feb 1, 2015
    Posts:
    2,499
    at first appguard stopped then WAR. turned them off and tested with voodoo. always on and paranoid mode. and I think I unticked the right parent process as per dan.
     

    Attached Files:

  9. boredog

    boredog Registered Member

    Joined:
    Feb 1, 2015
    Posts:
    2,499
  10. lunarlander

    lunarlander Registered Member

    Joined:
    Apr 30, 2011
    Posts:
    326
    Bad news

    With VS348 ( set to Always ON, but may have no relevance ) when you switch users, the second login goes to a black screen. The mouse cursor is still active, and when I press ctrl-alt-del, the correct menu is shown ( the one that has an option to allow you to change password ). So it is definitely logged in, just that the desktop doesn't show and is black.

    Then I exited VS in the first session, and was able to log in properly in the second.

    Re-installed VS345 and it doesn't happen no more.
     
    Last edited: Nov 20, 2016
  11. guest

    guest Guest

    But it was possible to switch accounts with earlier versions?
     
  12. Houley456

    Houley456 Registered Member

    Joined:
    Feb 9, 2007
    Posts:
    200
    Total Security 360 blocked it.....
     
  13. Krusty

    Krusty Registered Member

    Joined:
    Feb 3, 2012
    Posts:
    10,444
    Location:
    Among the gum trees
    Last edited: Nov 20, 2016
  14. lunarlander

    lunarlander Registered Member

    Joined:
    Apr 30, 2011
    Posts:
    326
    Yes it was able to switch users in VS345
     
  15. Djigi

    Djigi Registered Member

    Joined:
    Aug 13, 2012
    Posts:
    554
    Location:
    Croatia
    Block or Allow (VS Free, Smart Mode)?

    Clipboard01.jpg
     
  16. guest

    guest Guest

    it's signed by Microsoft, and it's an important system-file,...
    Allow
     
  17. Cache

    Cache Registered Member

    Joined:
    May 20, 2016
    Posts:
    460
    Location:
    Mercia
    That file was whitelisted on my system when I installed VS. So allow it.
     
  18. Djigi

    Djigi Registered Member

    Joined:
    Aug 13, 2012
    Posts:
    554
    Location:
    Croatia
    I just testing RanSim.exe and if Allow that the score is not good:

    Clipboard01.jpg
     
  19. boredog

    boredog Registered Member

    Joined:
    Feb 1, 2015
    Posts:
    2,499
    djigi

    I have been getting them warnings for the last , I can't remember how many builds. I kept mentioning it but still there. happens every morning when I boot up.
    if you don't click any of the options on that popup , you could get as many as 12 of those warnings. in other words let the popup close itself.
     
  20. askmark

    askmark Registered Member

    Joined:
    Jul 7, 2016
    Posts:
    392
    Location:
    united kingdom
    You can't test RanSim with VoodooShield free as you need to amend the advanced options, you need to use Voodooshield Pro and follow Dan's instructions:

     
  21. OSTexo

    OSTexo Registered Member

    Joined:
    Oct 28, 2016
    Posts:
    27
    Location:
    United States
    Hello,

    I noticed some VS behavior that is a little puzzling to me. If I disable protection while in a browser and then re-enable it before closing the web app the VS icon stays locked (blue) even if the web app is closed (I'm testing this in Smart Mode). Shouldn't the icon turn red when running in Smart Mode in this case to let the user know that the PC is not locked?
     
  22. Dark Star 72

    Dark Star 72 Registered Member

    Joined:
    May 27, 2007
    Posts:
    778
    Not so. I ran Ransim against VS free in Autopilot and it blocked all five scenarios. VS does of course prevent Ransim from starting so you have to Allow the following pop-ups to get to the test page
    Ransimsetup.exe
    Ransim.exe
    Launcher.exe
    Prepare.bat
    Once you start the test you just let VS do it's own thing and it blocks all five.
     

    Attached Files:

  23. Djigi

    Djigi Registered Member

    Joined:
    Aug 13, 2012
    Posts:
    554
    Location:
    Croatia
    I have portable version.
    I put it on the desktop, run RanSim.exe, VS (Auto-Pilot Mode) block it and I allow it.
    Clipboard01.jpg

    After that no more pop ups.
    Here are the screenshot of User Log, dllhost.exe is blocked and Command Lines.
    Clipboard02.jpg Clipboard03.jpg

    Test is just freeze like this:
    Clipboard04.jpg
     
  24. Djigi

    Djigi Registered Member

    Joined:
    Aug 13, 2012
    Posts:
    554
    Location:
    Croatia
    OK, now I add this to whitelist:
    • Ransim.exe
    • Launcher.exe
    • Prepare.bat
    And test is done (not 100% protected)

    Clipboard01.jpg Clipboard02.jpg
     
  25. Let me get this straight, you had to whitelist it to run it, yet you think it is not 100% protected, because the test says so after you whitelisted it?
     
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.