VoodooShield/Cyberlock

Discussion in 'other anti-malware software' started by CloneRanger, Dec 7, 2011.

  1. Tarnak

    Tarnak Registered Member

    Joined:
    Feb 5, 2007
    Posts:
    5,295
    Further details shown by WAR...

    VS_3.52_04.JPG
     
  2. Tarnak

    Tarnak Registered Member

    Joined:
    Feb 5, 2007
    Posts:
    5,295
    I had RAR on XP . But, don't know what comes with Windows 10. Must have built-in compression. Not sure how/what to test on Surface Book.
     
  3. Djigi

    Djigi Registered Member

    Joined:
    Aug 13, 2012
    Posts:
    554
    Location:
    Croatia
    I don't know if this happening before or is new?
    Every time PC is (re)started I get this message:

    Clipboard01.jpg
     
  4. paulderdash

    paulderdash Registered Member

    Joined:
    Dec 27, 2013
    Posts:
    4,644
    Location:
    Under a bushel ...
    On my secondary machine, Adguard also updated successfully with VS 3.51.
    But - I had forgotten to set VS to 'Disable / Install Mode' ... it was in 'Smart Mode', issued a block message, and when I clicked it to Allow, VS crashed (Shield and taskbar icon disappeared).
    So not sure what happened there, or if there may be a bug.
     
  5. Krusty

    Krusty Registered Member

    Joined:
    Feb 3, 2012
    Posts:
    10,241
    Location:
    Among the gum trees
    From memory you will get a pop up like that on Fridays with the free version.
     
  6. Mr.X

    Mr.X Registered Member

    Joined:
    Aug 10, 2013
    Posts:
    4,809
    Location:
    .
    Dan,

    On my main Win8.1 x64 v3.52 is causing lag for Sandboxie processes and Excubits drivers (FIDES and MZWriteScanner) still. Just like v3.51 did.

    See PM.
     
    Last edited: Feb 17, 2017
  7. Callender

    Callender Registered Member

    Joined:
    Jan 9, 2015
    Posts:
    172
    Location:
    London UK
    I've seen these pop ups about VS not detecting an internet connection since a few versions back. Somewere the result of an entry in HOSTS file but I never tracked down the culprit. I still get these pop ups on occions but not that often. Anyway regarding your question "Even if you are connected to internet.
    does VS retries or how many times VS tries to connect to cloud for verdict?"

    As far as I know there's no option to retry for a connection. If you know that the file is safe you can allow it. If it's something new that tried to run you should choose "Block" then scan the file using other methods. You can also edit whitelist / command lines in VS to unblock the file then try another scan with VS.

    Anyway the point is that internet connection detected or not detected - if VS prompts on a file you should investigate before allowing.
     
  8. boredog

    boredog Registered Member

    Joined:
    Feb 1, 2015
    Posts:
    2,499
    the only time I saw that was when my firewall blocked it.
     
  9. guest

    guest Guest

    Highly questionable and hypocritical actions from members that are personally trying to achieve maximum privacy here.

    Thanks for the new version, @VoodooShield. Can't wait to see what Alex is cooking up for us.
     
  10. boredog

    boredog Registered Member

    Joined:
    Feb 1, 2015
    Posts:
    2,499
    I did not know Dan wanted to remain anonymous. I just thought is was a good video. only found while browsing youtube videos on protection

    sorry Dan
     
  11. _CyberGhosT_

    _CyberGhosT_ Registered Member

    Joined:
    Mar 2, 2015
    Posts:
    457
    Location:
    MalwareTips "Your Security Advisor"
    Thanks Dan, trying out 352 now. ;)
     
  12. zarzenz

    zarzenz Registered Member

    Joined:
    May 19, 2002
    Posts:
    502
    Location:
    UK
    Thanks Dan, 352 is much better with regards to the number of command lines I'm seeing when I open any content using Firefox flashplayerplugin_24_0_0_194.exe.

    I used to see a new line for every new instance... now I just see one for the first instance then no more after that.

    I have tried adding the plugin when it's running to be auto detected in the Web Apps thinking this would remove the need for any command line to be created but I still see that first one every time even with it shown as a running Web App. However just to get the one now is a vast improvement on the situation I was seeing before with the multiple command lines being created on each new instance that the plugin was required.

    Great work as always and looking forward to any future developments.
     
  13. gorblimey

    gorblimey Registered Member

    Joined:
    Jan 19, 2017
    Posts:
    158
    Location:
    West Oz
    Hi Dan - 351 is working well. I'm seeing a lot of UAC elevation now, surun is picking it up and being pinged by VS like so:

    This one is in response to a click on a magnet link. I have made sure surun.exe and surun32.bin are whitelisted, but... I use surun because it gives my elevation while keeping my own user identity instead of being changed to Admin identity.
     

    Attached Files:

  14. Krusty

    Krusty Registered Member

    Joined:
    Feb 3, 2012
    Posts:
    10,241
    Location:
    Among the gum trees
    @gorblimey You should try 3.52.

    It may not solve your problems but it's the latest version and well worth trying.
     
  15. gorblimey

    gorblimey Registered Member

    Joined:
    Jan 19, 2017
    Posts:
    158
    Location:
    West Oz
    Hi Krusty - What's the best way of upgrading? Some programs do it seamlessly, but others have functionality changes. The last upgrade to 351 I disabled everything in sight, and did a full clean uninstall/reinstall, but that gets tedious after a few :(
    And I did remember to toggle JS ON for this reply--you can maybe tell I forgot it in my last :eek: There's a couple of sites that get annoying if I let them have the JS :thumbd:
     
  16. ExtremeGamerBR

    ExtremeGamerBR Registered Member

    Joined:
    Aug 3, 2010
    Posts:
    1,350
    Just install normally. It will overwrite any older version.

    Using 3.52, everything fine here.
     
  17. Moose World

    Moose World Registered Member

    Joined:
    Dec 19, 2013
    Posts:
    905
    Location:
    U.S. Citizen
    Salutations/Greetings!!!

    Is VS protection against the newest Cerber ransomware / Locky ?
    What about satana? And Fantom?

    Kind regards,
     
  18. Triple Helix

    Triple Helix Specialist

    Joined:
    Nov 20, 2004
    Posts:
    13,275
    Location:
    Ontario, Canada
    VS is a Lock so unless you let it run (Allow) then Yes it will protect you!
     
    Last edited: Feb 18, 2017
  19. Moose World

    Moose World Registered Member

    Joined:
    Dec 19, 2013
    Posts:
    905
    Location:
    U.S. Citizen
    @Triple Helix, thank you for the answer!!!:)

    What about boot time protection? If the a ransomware that forced the PC to reboot?

    Anyone?
     
  20. ExtremeGamerBR

    ExtremeGamerBR Registered Member

    Joined:
    Aug 3, 2010
    Posts:
    1,350
    To force the PC to reboot it would need to be executed. If it can't, them is not possible to force reboot.
     
  21. boredog

    boredog Registered Member

    Joined:
    Feb 1, 2015
    Posts:
    2,499
    I could be wrong but if ransomware got to the point where it actually rebooted your computer, I think game would be over unless you were using a program like shadow defender and you were in shadow mode when it happened. All I am saying is VS should be catching it before that point. According to a few testers here VS has been catching everything thrown at it.
     
  22. Triple Helix

    Triple Helix Specialist

    Joined:
    Nov 20, 2004
    Posts:
    13,275
    Location:
    Ontario, Canada
    Right! The point is to STOP it from running in the first place!
     
  23. illumination

    illumination Guest

    I can assure you that if it was executed, it's process would be suspended and you will have an alert from VS to quarantine or block the execution. This application as mentioned many times is a computer lock. You would literally have to allow the execution before you would find yourself in trouble.
     
  24. guest

    guest Guest

    This. Open Process Explorer, run an executable, watch it become purple/suspended until you choose a prompt from VS. This process has been 100% consistent for every file.
     
  25. Peter2150

    Peter2150 Global Moderator

    Joined:
    Sep 20, 2003
    Posts:
    20,590
    The beauty of VS is you can look before allowing it and get a feel for what it is. I've been "playing" and running Ransomware past my setup. VS and some other programs have caught all of it. I let some of it run to see what it does, but one something like Petra class stuff once you allow it to the point it reboots it's game over. Then lilke it was pointed out its either Shadow Defender or an image restore. Note some of the ransomware if not stopped early on will encrypt images on drives it can see them. One of the neat things about Shadowdefender is you can protect all your drives. But if you get to that point it was because you were careless with VS
     
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.