VoodooShield/Cyberlock

Discussion in 'other anti-malware software' started by CloneRanger, Dec 7, 2011.

  1. gorblimey

    gorblimey Registered Member

    Joined:
    Jan 19, 2017
    Posts:
    158
    Location:
    West Oz
    Now if it was @cruelsister... I wasn't impressed with the lack of a voice-over.
     
  2. Peter2150

    Peter2150 Global Moderator

    Joined:
    Sep 20, 2003
    Posts:
    20,590
    I agree. I can't tell what he did. If you allow something to run all bets are off. When I started testing VS, I tested in both always on, and autopilot. Nothing got bye. Of course if you keep playing after the first block all bets may be off.
     
  3. imuade

    imuade Registered Member

    Joined:
    Aug 4, 2016
    Posts:
    751
    Location:
    Italy
    From the video, you can clearly see:
    • he deleted the previously taken snapshot, so there's no whitelisted malware (0m12s)
    • once the malware in the excel file runs, it disables VS (1m18s), that's why it can encypt the files. Doesn't VS have a self-defense?
     
  4. imuade

    imuade Registered Member

    Joined:
    Aug 4, 2016
    Posts:
    751
    Location:
    Italy
    I can understand that it's difficult to admit a bypass in a SW we use and we love... there are a lot of such examples in the Comodo Forum...
     
  5. Peter2150

    Peter2150 Global Moderator

    Joined:
    Sep 20, 2003
    Posts:
    20,590
    Hi imuade

    I don't know anything about Comodo, don't run it don't go to their forum. The only thing I do know is I've taken over 300+ samples from MalwareTips, and run them against VS. Nothing has gone undetected and stopped by VS. Also I know how Cruelsister tests and she is good. But other then her, I pay no attention to Youtube stuff.
     
  6. imuade

    imuade Registered Member

    Joined:
    Aug 4, 2016
    Posts:
    751
    Location:
    Italy
    The same guy bypassed AppGuard...
    https://www.youtube.com/watch?v=KinwLc4SqpQ&ytbChannel=F4zzx
     
  7. Gillor

    Gillor Registered Member

    Joined:
    Jul 12, 2013
    Posts:
    88
    Location:
    UK
    It's not clear to me what he is doing either. I have just thrown three sources of Cerber ransomware at VS in Autopilot mode and it's warned on all three. In fact to date I must have run the best part of 1000 pieces of malware against VS and nothing has so far bypassed it. Not impossible but I really can't see much doing so either if my experience is anything to go by.
     
  8. VoodooShield

    VoodooShield Registered Member

    Joined:
    Dec 9, 2011
    Posts:
    5,881
    Location:
    United States
    Yeah, this is Adam (F4zzx)… he told me about this targeted attack a while back, and the only fix is to implement self-protection in VS, which we will be doing soon. Do you guys remember when I posted on wilders that there is a very specific script that will kill VS and allow a bypass? Well, Adam was the one that told me about this targeted attack… I am not sure why he felt the need to make it public.

    We will implement self-protection soon. BTW, this trick would most likely work on any security software that does not have self-protection.
     
  9. VoodooShield

    VoodooShield Registered Member

    Joined:
    Dec 9, 2011
    Posts:
    5,881
    Location:
    United States
  10. Peter2150

    Peter2150 Global Moderator

    Joined:
    Sep 20, 2003
    Posts:
    20,590

    It's very easy to bypass Appguard, if you turn it off. And look at the date of the video and the version of Appguard. imuade do you not have anything better to do.
     
  11. VoodooShield

    VoodooShield Registered Member

    Joined:
    Dec 9, 2011
    Posts:
    5,881
    Location:
    United States
    I am not sure what all security products have self protection or not... but if they do not, and the other developers want to know more about this bypass, I would be happy to let them know how it works. Basically, the only way to defend against this (as far as I know) is to have self-protection.
     
  12. TonyW

    TonyW Registered Member

    Joined:
    Oct 12, 2005
    Posts:
    2,741
    Location:
    UK
    This surprises me also since you two are now working together on VS. It's not as though that video was made ages ago.
     
  13. VecchioScarpone

    VecchioScarpone Registered Member

    Joined:
    Aug 29, 2015
    Posts:
    343
    Location:
    Down Under the Southern Cross
    Dan
    You are very generous with your work.
    Allow me a rookie question. What will self protection do once implemented. How should I react to it in the remote case the feature is triggered?
     
  14. Triple Helix

    Triple Helix Specialist

    Joined:
    Nov 20, 2004
    Posts:
    13,275
    Location:
    Ontario, Canada
    Well in the case of WSA if you try to terminate the 2 WRSA.exe Processes it will block the process and if you try to crash the 2 processes then they restart and to add if you want to shut down WSA you have to fill out a CAPTCHA so in this case WSA is protected from being terminated by Malware or without the user knowing. Maybe something like that for VS?

    2017-03-06_19-04-59.png 2017-03-06_19-07-27.png 2017-03-06_19-07-50.png 2017-03-06_19-08-12.png
     
  15. Circuit

    Circuit Registered Member

    Joined:
    Oct 7, 2014
    Posts:
    939
    Location:
    Land o fruits and nuts, and more crime.
    In the case of AppGuard:
     

    Attached Files:

  16. VecchioScarpone

    VecchioScarpone Registered Member

    Joined:
    Aug 29, 2015
    Posts:
    343
    Location:
    Down Under the Southern Cross
  17. lunarlander

    lunarlander Registered Member

    Joined:
    Apr 30, 2011
    Posts:
    326
    Hi Dan,

    Wondering if Voodoo Shield will detect RATs.

    Did anyone test it against remote access trojans ? I think they are really deadly.
     
  18. VoodooShield

    VoodooShield Registered Member

    Joined:
    Dec 9, 2011
    Posts:
    5,881
    Location:
    United States
    Adam and I do not actually work together... he has just found 2-3 vulnerabilities in the past that he let me know about so I could fix them. I would have fixed this last vulnerability by adding self-protection already, but I had to wait until VS was completely stable. Thank you!
     
  19. VoodooShield

    VoodooShield Registered Member

    Joined:
    Dec 9, 2011
    Posts:
    5,881
    Location:
    United States
    It should be very similar to what TH posted below... thank you TH! You won't notice any difference, except you will no longer be able to kill VS using the task manager ;). VS inherently protects itself (with the exception of Adam's script), so adding self-protection was never a great priority. Thank you!
     
  20. VoodooShield

    VoodooShield Registered Member

    Joined:
    Dec 9, 2011
    Posts:
    5,881
    Location:
    United States
    Yeah, RAT's should not be a problem at all for VS. Thank you!
     
  21. VoodooShield

    VoodooShield Registered Member

    Joined:
    Dec 9, 2011
    Posts:
    5,881
    Location:
    United States
    Yeah, as soon as we wrap up the web management console, we will be adding new features, including self-protection ;). Thank you!
     
  22. VoodooShield

    VoodooShield Registered Member

    Joined:
    Dec 9, 2011
    Posts:
    5,881
    Location:
    United States
    Hehehe ;). Do you have an example? I need to go through the posts I missed soon... I am pretty far behind. Thank you guys, talk to you soon!
     
  23. imuade

    imuade Registered Member

    Joined:
    Aug 4, 2016
    Posts:
    751
    Location:
    Italy
    Yes, I could have spent my time better by reading such smart and brilliant posts, like this one from you :rolleyes: and from a Global Moderator :eek:
     
    Last edited: Mar 7, 2017
  24. imuade

    imuade Registered Member

    Joined:
    Aug 4, 2016
    Posts:
    751
    Location:
    Italy
    Hi Dan,

    first thing, nice to meet you and thanks a lot for your great product :thumb:
    About self-protection, I think that's the basic of any security product. If you don't have self-defense it's like you place a reinforced door in your home, but then you forget to lock it :p
    By the way, I'm sure you'll update VS soon to add this feature :)
     
    Last edited: Mar 7, 2017
  25. RobbieMacG

    RobbieMacG Registered Member

    Joined:
    Nov 15, 2016
    Posts:
    3
    Location:
    Brisbane
    I'm running Voodooshield Pro, BitDefender Total Security 2017 & Adguard. Sandboxie Pro & Chrome.

    Am I able to safely turn off or lower the BitDefender On-access scanning and/or Active Threat Control?
    Started getting random lock-ups on my Asus Zenbook Flip, purchased last October.

    Uninstalled BD and reinstalled it & that seems to have helped but I'm getting about-ready to refresh Windows due to the issues.
     
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.