VoodooShield/Cyberlock

Discussion in 'other anti-malware software' started by CloneRanger, Dec 7, 2011.

  1. VoodooShield

    VoodooShield Registered Member

    Joined:
    Dec 9, 2011
    Posts:
    5,881
    Location:
    United States
    The models will get smarter over time, although it is already extremely accurate.

    MOST OF THE TIME, the false positives are not VoodooAi's fault. If a developer wants to release a file that, for example, is not signed, is packed and obfuscated into oblivion, and uses well known hacker tools while compiling their work, VoodooAi will ALWAYS classify this file as unsafe... I would be disappointed in VoodooAi if it did not ;).
     
  2. VoodooShield

    VoodooShield Registered Member

    Joined:
    Dec 9, 2011
    Posts:
    5,881
    Location:
    United States
    The raw data will always be the same for each model... the only time they will change is when the models are retrained, which I will be doing in a few weeks.

    And the sensitivity level does not affect the raw data at all. Does that make sense? If not, please let me know, thank you!
     
  3. VoodooShield

    VoodooShield Registered Member

    Joined:
    Dec 9, 2011
    Posts:
    5,881
    Location:
    United States
    Hehehe... good catch ;). I already know why it is doing that... I will fix this when I get a chance, thank you!
     
  4. VoodooShield

    VoodooShield Registered Member

    Joined:
    Dec 9, 2011
    Posts:
    5,881
    Location:
    United States
    Hehehe, yeah, he confused VS ;).
     
  5. VoodooShield

    VoodooShield Registered Member

    Joined:
    Dec 9, 2011
    Posts:
    5,881
    Location:
    United States
    Hmmm, I am not sure what you mean, please explain some more. Like, if the desktop shield gadget never shows up again, how are you right clicking on it? Please let me know and we will figure it out, thank you! BTW, please make sure you are running 3.45.
     
  6. VoodooShield

    VoodooShield Registered Member

    Joined:
    Dec 9, 2011
    Posts:
    5,881
    Location:
    United States
    Cool, that all looks perfect! Although, when I install new software that I know is good, I either disable VS or exit out of it first, but either way is fine. Like when I visit a client's office, the first thing I do is exit out of VS, because I know I am going to be performing maintenance, along with all of the other security software. And if I have to look something up online, I will start VS temporarily. Thank you!
     
  7. VoodooShield

    VoodooShield Registered Member

    Joined:
    Dec 9, 2011
    Posts:
    5,881
    Location:
    United States
    Yeah, I need to update the user guide... that is a new option.

    Actually, there is no other way of explaining it... just read the option several times and you will understand it. Thank you!
     
  8. VoodooShield

    VoodooShield Registered Member

    Joined:
    Dec 9, 2011
    Posts:
    5,881
    Location:
    United States
    Yeah, basically if both the blacklist scan and VoodooAi return safe results, the file will be auto allowed. This is probably safe, and while it would be extremely difficult to find something that will bypass both, we leave this option disabled by default, just to be safe.
     
  9. VoodooShield

    VoodooShield Registered Member

    Joined:
    Dec 9, 2011
    Posts:
    5,881
    Location:
    United States
    Yeah, they are the exact same numbers you see when you click the "Details" button on the user prompt... the 3 algorithm scores there are the raw scores... they will be identical until the models change. Anyway, these are the values that are stored. Thank you!
     
  10. VoodooShield

    VoodooShield Registered Member

    Joined:
    Dec 9, 2011
    Posts:
    5,881
    Location:
    United States
    Because you apparently had a web app running ;). If no web apps were running, VS would have been OFF, and it would have been auto allowed after the blacklist and Ai were determined to be clean.

    You can think of Smart Mode / OFF (no browsers running) as kind of like AutoPilot mode... they are very similar.

    But the main rule of VS is (and always has been)... if a web app is running, all new, non-whitelisted items are blocked.

    It look likes AutoPilot might be a better match for you... it would have auto allowed the file after it was determined to be clean by the blacklist and Ai. Thank you!
     
  11. VoodooShield

    VoodooShield Registered Member

    Joined:
    Dec 9, 2011
    Posts:
    5,881
    Location:
    United States
    Yeah, sometimes there will still be prompts ;). I actually got the name from Tesla Motors AutoPilot. The funny thing is that it is not 100% autopilot either... sometimes you have to grab the wheel ;).
     
  12. VoodooShield

    VoodooShield Registered Member

    Joined:
    Dec 9, 2011
    Posts:
    5,881
    Location:
    United States
    We might be able to make this optional in the future, thank you!
     
  13. VoodooShield

    VoodooShield Registered Member

    Joined:
    Dec 9, 2011
    Posts:
    5,881
    Location:
    United States
    Hmmm, it must mount like a USB / CD drive... I will take a look at it, it is on my to do list now. Thank you!
     
  14. VoodooShield

    VoodooShield Registered Member

    Joined:
    Dec 9, 2011
    Posts:
    5,881
    Location:
    United States
    Yeah, that is what is going on... the question is... do we fix it, or does Truecrypt ;). I will take a look at it, I think there is a super easy fix.
     
  15. VoodooShield

    VoodooShield Registered Member

    Joined:
    Dec 9, 2011
    Posts:
    5,881
    Location:
    United States
    Ok, I skipped a lot of posts, so if I missed anything, please let me know!

    Thank you for all of the compliments, I really appreciate all of them!

    Have a great weekend, thank you guys!
     
  16. Overkill

    Overkill Registered Member

    Joined:
    Mar 16, 2012
    Posts:
    2,343
    Location:
    USA
    Dan I am stumped with this issue, it happens with no security on my laptop(after a re-install), just not as bad as with VS installed. I don't know what the true culprit is, it's very annoying to say the least! I love VS, and it runs fine on my son's laptop and my other laptop, keep up the great work!
     
  17. Gandalf_The_Grey

    Gandalf_The_Grey Registered Member

    Joined:
    Jan 31, 2012
    Posts:
    1,194
    Location:
    The Netherlands
    Hi Dan. Have a great weekend. Please don't forget the chrome update block.
     
  18. EvjlsRain

    EvjlsRain Registered Member

    Joined:
    Apr 26, 2016
    Posts:
    31
    thanks for your answer. I absolutely have no problem with the right-click popup. perhaps, it can be annoying for someone else
    btw, could you have a look into local sandbox? it seems never work for me I don't know why. Is it due to the highly restricted rules that make the sandboxed apps malfunction?
     
  19. Tarnak

    Tarnak Registered Member

    Joined:
    Feb 5, 2007
    Posts:
    5,313
    I like layers went it comes to security. ;)
     
  20. Tarnak

    Tarnak Registered Member

    Joined:
    Feb 5, 2007
    Posts:
    5,313
    Thanks.:thumb:
     
  21. Tarnak

    Tarnak Registered Member

    Joined:
    Feb 5, 2007
    Posts:
    5,313
    I understand. For me, when I boot up, I am online. Just the way I like. ;) :)
     
  22. Tarnak

    Tarnak Registered Member

    Joined:
    Feb 5, 2007
    Posts:
    5,313
    I didn't have the option for this, but I knew it had to be an update for WSA...so, I allowed! I know what I am doing. ;)

    ScreenShot_VS_WSA-update_01.JPG ScreenShot_VS_WSA-update_02.JPG

    P.S. I had only booted up a few minutes earlier, and that is how WSA updates, silently. Unless, something like VS intercepts! :thumb: :)
     
  23. VoodooShield

    VoodooShield Registered Member

    Joined:
    Dec 9, 2011
    Posts:
    5,881
    Location:
    United States
    Cool, if you want me to remote in to your computer sometime, please let me know, we will figure it out, thank you!
     
  24. VoodooShield

    VoodooShield Registered Member

    Joined:
    Dec 9, 2011
    Posts:
    5,881
    Location:
    United States
    Yeah, thank you... that is the inaccessible file bug, it really is super easy to fix, I am just figuring out the best and most secure way to handle it.
     
  25. VoodooShield

    VoodooShield Registered Member

    Joined:
    Dec 9, 2011
    Posts:
    5,881
    Location:
    United States
    Sounds good, if you have any suggestions for the right click menu, please let me know.

    The local sandbox feature needs A LOT of work ;). Basically, any action that requires admin approval is blocked... which is why I am not the biggest fan of local sandboxing. As Yoda said... Do. Or do not. There is no try. ;).

    At some point I will probably improve the local sandboxing feature, but it is not a high priority right now. Utilizing Ai to determine the maliciousness of a file, pre-execution is a priority though ;).
     
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.