VoodooShield/Cyberlock

Discussion in 'other anti-malware software' started by CloneRanger, Dec 7, 2011.

  1. Peter2150

    Peter2150 Global Moderator

    Joined:
    Sep 20, 2003
    Posts:
    20,590
    I didn't do a normal exit, not sure what I did. At any rate locking the application fine, locking the computer NOPE What ever I did was with the alert, and I don't think there was any notice about rebooting. I just a machine that was frozen.
     
  2. boredog

    boredog Registered Member

    Joined:
    Feb 1, 2015
    Posts:
    2,499
    OK Peter when Dan is not so busy maybe he will explain. Although I think he did explain his new protection locks entire computer so when a program trys to shut down Voodoo , Voodoo lock entire computer down.
     
  3. Triple Helix

    Triple Helix Specialist

    Joined:
    Nov 20, 2004
    Posts:
    13,275
    Location:
    Ontario, Canada
    If it's not to late can you send Dan your logs if you still have them?
     
  4. Peter2150

    Peter2150 Global Moderator

    Joined:
    Sep 20, 2003
    Posts:
    20,590
    Unfortunately I don't have them. Since I had a breather but wasn't sure I was out the water, I just did a quick uninstall, waited to the coast was clear and installed 3.53. Candidly I was leary enough I never left 3.53 on the other machine.
     
  5. Gandalf_The_Grey

    Gandalf_The_Grey Registered Member

    Joined:
    Jan 31, 2012
    Posts:
    1,188
    Location:
    The Netherlands
    Today there was update KB4015438 for Windows 10. Initially it failed.
    I had to set VoodooShield in install mode before I could successfully install this update.
    Is this normal behavior for 3.55 beta 2 ?
    Never had to do this with previous versions.
     
    Last edited: Mar 20, 2017
  6. VecchioScarpone

    VecchioScarpone Registered Member

    Joined:
    Aug 29, 2015
    Posts:
    343
    Location:
    Down Under the Southern Cross
    General thought:
    Those who have no issues must be wondering how such extreme occurrences could happen, quite understandable.
    Twice 3.55 did not executed at all during startup/reboot in conjunction to: refer my post #14849 and subsequent ones.
    That left me feel exposed. (Freaked out actually)
    If such a program like VS are for the masses, I'm with Peter on this one.
     
  7. Krusty

    Krusty Registered Member

    Joined:
    Feb 3, 2012
    Posts:
    10,240
    Location:
    Among the gum trees
    Me too.
     
  8. VecchioScarpone

    VecchioScarpone Registered Member

    Joined:
    Aug 29, 2015
    Posts:
    343
    Location:
    Down Under the Southern Cross
    G'day.

    Feels good not to be alone. For a while, due to lack of bugs reports on this thread I felt I was wacko o_O
     
  9. Krusty

    Krusty Registered Member

    Joined:
    Feb 3, 2012
    Posts:
    10,240
    Location:
    Among the gum trees
    Yeah, I haven't felt comfortable with any of the new builds which included the self defence module. I've tried 'em all but keep going back to stable and reliable 3.53.
     
  10. Antarctica

    Antarctica Registered Member

    Joined:
    Feb 25, 2003
    Posts:
    2,180
    Location:
    Canada
    Also back to V3.53. This afternoon a Driver from VS would not start and the program closed by itself.
     
  11. VecchioScarpone

    VecchioScarpone Registered Member

    Joined:
    Aug 29, 2015
    Posts:
    343
    Location:
    Down Under the Southern Cross
    "VS 3,53 rules!" he he
    I have no doubt Dan will get it right.
    "Forza Dan" (":)Keep going Dan")
     
  12. guest

    guest Guest

    Something like this:
    ERP_Self-defense.png
    I think, adding such an option would be a good idea.
     
  13. Tarnak

    Tarnak Registered Member

    Joined:
    Feb 5, 2007
    Posts:
    5,296
    I just shutdown VS from the tray icon, "exit" button. I thought that "self-protection", meant that I would get some kind of warning, like 'are you sure yo want to terminate VS', but I didn't. Maybe, I am not understanding what is meant by self-protection.
     
  14. Achelous

    Achelous Registered Member

    Joined:
    Mar 20, 2017
    Posts:
    10
    Location:
    UK
    +1.

    We also need to remember that many other factors come into play in terms of self-defense, it should not all evolve around protecting the processes (VoodoShield.exe and VoodoShieldService.exe). For example, the device driver (vsscanner.sys) is vulnerable because it can be unloaded (stop and delete the service) and then the process monitoring will not continue without the user being notified - bear in mind that I tested this myself, there was absolutely nothing to try and stop me from doing this.

    Overall, process protection is just the start of it, and there is no point in them taking the self-defense mechanisms further until they've done a proper implementation of process protection. The current is hardly sufficient at all (in my opinion at least), due to the inconvenience of locking down the system, and because the processes are not actually "protected" from termination... If you will.

    I do understand that this whole self-defense approach is new and all experimental, I look forward to seeing the implementations for the stable release.
     
  15. plat1098

    plat1098 Guest

    Just got a sneaky little Windows kb 4015438, getting used to these. As I restarted, oops, left VS enabled. But, the update went very quickly, finished installing in about 1 minute. That, at least, is reassuring!
     
  16. smith2006

    smith2006 Registered Member

    Joined:
    Mar 28, 2006
    Posts:
    808
    Thank you for the reply.:)

    The strange thing is It seems to be running fine today after logging on. :eek:

    Anyway I have forwarded the dev service logs to support for the attention of Dan.
     
  17. VecchioScarpone

    VecchioScarpone Registered Member

    Joined:
    Aug 29, 2015
    Posts:
    343
    Location:
    Down Under the Southern Cross
    You are welcome.
    Most of the bugs I experienced where randomly happening too.
    We should not forget that Dan asked the community to trying it out and send feedback,
    3.55 is not a stable version.
     
  18. guest

    guest Guest

    Exactly, and how many average users ( VS target market) will know (or even care) to analyze and differentiate malwares behaviors from normal file behavior in those kind of sandboxes? almost none.
     
  19. paulderdash

    paulderdash Registered Member

    Joined:
    Dec 27, 2013
    Posts:
    4,644
    Location:
    Under a bushel ...
    I think there has been some 'scope creep'. I have never used the sandbox feature. I think Dan tries to please everyone, but I guess he wouldn't add something he doesn't deem desirable at least ...
     
  20. paulderdash

    paulderdash Registered Member

    Joined:
    Dec 27, 2013
    Posts:
    4,644
    Location:
    Under a bushel ...
    Dan - just a question based on a statement in another thread: https://www.wilderssecurity.com/threads/cybergenic-shade-sandbox-tool.380371/page-6#post-2661225 though I guess you are busy with this self-protection and other stuff ...

    @cruelsister's comment: Finally, recent malware seem to be using a lag time feature- they may not activate for a few minutes or a few hours whether it is in a VM or not.
    Would this have any implications for VS which in Smart mode, only locks the computer when it is at risk e.g. online?
     
  21. stapp

    stapp Global Moderator

    Joined:
    Jan 12, 2006
    Posts:
    24,067
    Location:
    UK
    I am going to remove 3.55 as it is causing me a lot of issues. When it locked up for me after a boot nothing would work..taskmanager etc, and this morning had more issues so it's coming off.

    Here are some of the many entries from the DevLog.log
    [03-20-2017 11:15:18] [ERROR] - VoodooShield has entered self-protection mode. | C:\Program Files\VoodooShield\Notify.exe | C:\Program Files\VoodooShield\VoodooShieldService.exe | True | False
    [03-20-2017 11:15:18] [ERROR] - VoodooShield has entered self-protection mode. | C:\Windows\system32\AUDIODG.EXE | C:\Windows\System32\svchost.exe | True | False
    [03-20-2017 11:15:18] [ERROR] - VoodooShield has entered self-protection mode. | C:\Windows\system32\AUDIODG.EXE | C:\Windows\System32\svchost.exe | True | False
    [03-20-2017 11:15:18] [ERROR] - VoodooShield has entered self-protection mode. | C:\Windows\system32\AUDIODG.EXE | C:\Windows\System32\svchost.exe | True | False
    [03-20-2017 11:15:18] [ERROR] - VoodooShield has entered self-protection mode. | C:\Windows\system32\AUDIODG.EXE | C:\Windows\System32\svchost.exe | True | False
    [03-20-2017 11:15:18] [ERROR] - VoodooShield has entered self-protection mode. | C:\Windows\system32\AUDIODG.EXE | C:\Windows\System32\svchost.exe | True | False
    [03-20-2017 11:15:18] [ERROR] - VoodooShield has entered self-protection mode. | C:\Windows\system32\AUDIODG.EXE | C:\Windows\System32\svchost.exe | True | False
    [03-20-2017 11:15:18] [ERROR] - VoodooShield has entered self-protection mode. | C:\Windows\system32\AUDIODG.EXE | C:\Windows\System32\svchost.exe | True | False
    [03-20-2017 11:15:18] [ERROR] - VoodooShield has entered self-protection mode. | C:\Windows\system32\AUDIODG.EXE | C:\Windows\System32\svchost.exe | True | False
    [03-20-2017 11:15:18] [ERROR] - VoodooShield has entered self-protection mode. | C:\Windows\system32\AUDIODG.EXE | C:\Windows\System32\svchost.exe | True | False
    [03-20-2017 11:15:18] [ERROR] - VoodooShield has entered self-protection mode. | C:\Windows\system32\AUDIODG.EXE | C:\Windows\System32\svchost.exe | True | False
    [03-20-2017 11:15:18] [ERROR] - VoodooShield has entered self-protection mode. | C:\Windows\system32\AUDIODG.EXE | C:\Windows\System32\svchost.exe | True | False
    [03-20-2017 11:15:18] [ERROR] - VoodooShield has entered self-protection mode. | C:\Windows\system32\AUDIODG.EXE | C:\Windows\System32\svchost.exe | True | False
    [03-20-2017 11:15:18] [ERROR] - VoodooShield has entered self-protection mode. | C:\Windows\system32\AUDIODG.EXE | C:\Windows\System32\svchost.exe | True | False
    [03-20-2017 11:15:18] [ERROR] - VoodooShield has entered self-protection mode. | C:\Windows\system32\AUDIODG.EXE | C:\Windows\System32\svchost.exe | True | False
    [03-20-2017 11:15:18] [ERROR] - VoodooShield has entered self-protection mode. | C:\Windows\system32\AUDIODG.EXE | C:\Windows\System32\svchost.exe | True | False
    [03-20-2017 11:15:18] [ERROR] - VoodooShield has entered self-protection mode. | C:\Windows\system32\AUDIODG.EXE | C:\Windows\System32\svchost.exe | True | False
    [03-20-2017 11:15:18] [ERROR] - VoodooShield has entered self-protection mode. | C:\Windows\system32\AUDIODG.EXE | C:\Windows\System32\svchost.exe | True | False
    [03-20-2017 11:15:18] [ERROR] - VoodooShield has entered self-protection mode. | C:\Windows\system32\AUDIODG.EXE | C:\Windows\System32\svchost.exe | True | False
    [03-20-2017 11:15:18] [ERROR] - VoodooShield has entered self-protection mode. | C:\Windows\system32\AUDIODG.EXE | C:\Windows\System32\svchost.exe | True | False
    [03-20-2017 11:15:18] [ERROR] - VoodooShield has entered self-protection mode. | C:\Windows\system32\AUDIODG.EXE | C:\Windows\System32\svchost.exe | True | False
    [03-20-2017 11:15:20] [ERROR] - VoodooShield has entered self-protection mode. | C:\Windows\system32\SearchProtocolHost.exe | C:\Windows\system32\SearchIndexer.exe | True | False
    [03-20-2017 11:15:20] [ERROR] - VoodooShield has entered self-protection mode. | C:\Windows\system32\SearchProtocolHost.exe | C:\Windows\system32\SearchIndexer.exe | True | False
    [03-20-2017 11:15:20] [ERROR] - VoodooShield has entered self-protection mode. | C:\Windows\system32\LogonUI.exe | C:\Windows\system32\wininit.exe | True | False
    [03-20-2017 11:15:20] [ERROR] - VoodooShield has entered self-protection mode. | C:\Windows\servicing\TrustedInstaller.exe | C:\Windows\system32\services.exe | True | False
    [03-20-2017 11:15:20] [INFO ] - This process is being blocked: C:\Windows\servicing\TrustedInstaller.exe|C:\Windows\system32\services.exe|True|False

    [03-20-2017 14:33:44] [ERROR] - VoodooShield has entered self-protection mode. | C:\Program Files\VoodooShield\Notify.exe | C:\Program Files\VoodooShield\VoodooShieldService.exe | True | False
    [03-20-2017 14:33:46] [ERROR] - VoodooShield has entered self-protection mode. | C:\Windows\system32\SearchProtocolHost.exe | C:\Windows\system32\SearchIndexer.exe | True | False
    [03-20-2017 14:33:46] [ERROR] - VoodooShield has entered self-protection mode. | C:\Windows\system32\SearchProtocolHost.exe | C:\Windows\system32\SearchIndexer.exe | True | False
    [03-20-2017 14:33:46] [ERROR] - VoodooShield has entered self-protection mode. | C:\Windows\system32\LogonUI.exe | C:\Windows\system32\wininit.exe | True | False


    [03-21-2017 06:16:38] [ERROR] - VoodooShield has entered self-protection mode. | C:\Program Files\VoodooShield\Notify.exe | C:\Program Files\VoodooShield\VoodooShieldService.exe | True | False
    [03-21-2017 06:16:41] [ERROR] - VoodooShield has entered self-protection mode. | C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe | C:\Windows\system32\services.exe | True | False
    [03-21-2017 06:16:42] [ERROR] - VoodooShield has entered self-protection mode. | C:\Windows\System32\smss.exe | \SystemRoot\System32\smss.exe | True | False
     
  22. paulderdash

    paulderdash Registered Member

    Joined:
    Dec 27, 2013
    Posts:
    4,644
    Location:
    Under a bushel ...
    I've had no issues, yet. But there does still seem to be a problem. :cautious:
     
  23. Triple Helix

    Triple Helix Specialist

    Joined:
    Nov 20, 2004
    Posts:
    13,275
    Location:
    Ontario, Canada
    No issues here either!
     
  24. Peter2150

    Peter2150 Global Moderator

    Joined:
    Sep 20, 2003
    Posts:
    20,590
    Self protection should protect that software package, not lock up the whole computer. Just a bad idea.
     
  25. illumination

    illumination Guest

    I agree. If the average/novice users around my area where to have this happen, they would flip out and demand it be removed. Because of this, I can no longer suggest this product to them.

    One thing it seems a few are having a hard time wrapping their brains around here, is that Voodooshield was NEVER meant to be a standalone product. Matter of fact, it was designed to be an optional replacement to UAC. It is a companion product, meant to be run with other security. If those same users want full lock down of their systems, maybe they should look into Policy Restriction instead of gradually ruining what was, a great product.
     
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.