VoodooShield/Cyberlock

Discussion in 'other anti-malware software' started by CloneRanger, Dec 7, 2011.

  1. bellgamin

    bellgamin Registered Member

    Joined:
    Aug 1, 2002
    Posts:
    8,102
    Location:
    Hawaii
    Gdata is a full-on AV including sigs + BB + rep whereas VS is more specialized. IMO, checks by VS take less time because they have less ground to cover. I suggest doing another trial by first adding the malware.exe to VS whitelist. Then execute malware.exe. I feel certain GData will pop an alert but I don't know whether or not VS will do so. Will it?

    IMO, comparing any AV versus VS is comparing apples & oranges.
     
  2. moredhelfinland

    moredhelfinland Registered Member

    Joined:
    Mar 31, 2009
    Posts:
    350
    Location:
    Finland
    @bellgamin
    Yes, but think about it like if VD is replaced by a malware. Malware can run, do some nasty things before an AV can react.
     
  3. bellgamin

    bellgamin Registered Member

    Joined:
    Aug 1, 2002
    Posts:
    8,102
    Location:
    Hawaii
    @moredhelfinland -- Good point. Okay, how about trying this: disable VS then run malware.exe. Did the malware get past GData?
     
  4. moredhelfinland

    moredhelfinland Registered Member

    Joined:
    Mar 31, 2009
    Posts:
    350
    Location:
    Finland
    @bellgamin
    Yes, GData nailed it. For some reason, if i disable VD cloud lookup (whitelist cloud), the malware.exe is still scanned by the "whitelist cloud".
     
  5. Cache

    Cache Registered Member

    Joined:
    May 20, 2016
    Posts:
    445
    Location:
    Mercia
    I am using the free version and have noticed that when I now turn on my PC, there is a VS pop up encouraging me to update to the latest version, which is of course the Pro free trial. Perfectly understandable behavior but I am quite happy with my 705 free version. I expect that my declining will only be tolerated for so long. Anyone have any inside knowledge on this matter?
     
  6. moredhelfinland

    moredhelfinland Registered Member

    Joined:
    Mar 31, 2009
    Posts:
    350
    Location:
    Finland
    Dan the Coder of VoodooShield deserves support. It's a one man project. A lot of major changes 705 vs the latest one is significant.
    I'm running VD with smart+relaxed mode. And it works absolutely great. Great piece of Software, indeed.
    Consider to buy it, i did.
     
  7. Cache

    Cache Registered Member

    Joined:
    May 20, 2016
    Posts:
    445
    Location:
    Mercia
    It is a great piece of software, I've been using it for around 7 years now and was a beta tester in the early days. I'll almost certainly buy the Pro version when I have to, I was just wondering how long I can postpone it for.
     
  8. Baldrick

    Baldrick Registered Member

    Joined:
    May 11, 2002
    Posts:
    2,675
    Location:
    South Wales, UK
    Get over to the Voodooshield site now and take advantage of the offer:

    "VOODOOSHIELD FREE HAS BEEN DISCONTINUED AS OF 5/5/2022!!! WE WILL BE OFFERING A 50% VOODOOSHIELD PRO DISCOUNT FOR A LIMITED TIME."

    Good deal so now is the time to take the plunge. :thumb:
     
  9. bellgamin

    bellgamin Registered Member

    Joined:
    Aug 1, 2002
    Posts:
    8,102
    Location:
    Hawaii
    AFAIK, whitelist cloud is primarily based on reputation. Rep checking is already included in top-tier AVs in addition to sig checking & behavior checking.

    I had same experience as you -- I turned off whitelist cloud but it continued to pop-up alerts on files that had already been cleared by my AV as well as VirusTotal.
     
  10. bauer24

    bauer24 Registered Member

    Joined:
    Jan 27, 2015
    Posts:
    7
  11. Triple Helix

    Triple Helix Specialist

    Joined:
    Nov 20, 2004
    Posts:
    13,275
    Location:
    Ontario, Canada
  12. Bertazzoni

    Bertazzoni Registered Member

    Joined:
    Apr 13, 2018
    Posts:
    657
    Location:
    Milan, Italia
    This is because Whitelist Cloud is still "part" of the VS engine. It checks both WC and VoodooAI. From the VS website:
    When you disable WC it won't create any firewall rules and won't trigger a separate alert, but the WC lookup is still part of the "blocked file" analysis.

    VS was re-worked in this way when Dan was no longer able to use VT as a lookup.
     
  13. Gandalf_The_Grey

    Gandalf_The_Grey Registered Member

    Joined:
    Jan 31, 2012
    Posts:
    1,189
    Location:
    The Netherlands
    Mail from Dan:
     
  14. Gandalf_The_Grey

    Gandalf_The_Grey Registered Member

    Joined:
    Jan 31, 2012
    Posts:
    1,189
    Location:
    The Netherlands
    Mail from Dan: VS 7.13:
     
  15. Krusty

    Krusty Registered Member

    Joined:
    Feb 3, 2012
    Posts:
    10,241
    Location:
    Among the gum trees
    Clean install of 7.13 and VS just shut itself down. I can't remember ever seeing VS do that before. :eek:

    Logs sent to Dan.
     
  16. digmor crusher

    digmor crusher Registered Member

    Joined:
    Jul 6, 2012
    Posts:
    1,172
    Location:
    Canada
    That is strange, what other security are you using on this computer?
     
  17. Krusty

    Krusty Registered Member

    Joined:
    Feb 3, 2012
    Posts:
    10,241
    Location:
    Among the gum trees
    Reply from Dan:

    "As far as VS crashing, it was an error in the Microsoft.AspNet.SignalR.Client dll. This is the dll that connects VS to the Web Management Console. It is the first time I have ever seen this bug, so it must have been a total fluke. But if it keeps happening please let me know."

    May not be relevant but monitoring.
     
  18. moredhelfinland

    moredhelfinland Registered Member

    Joined:
    Mar 31, 2009
    Posts:
    350
    Location:
    Finland
    So a malware writer can code a VS bypass with this information?
     
  19. Krusty

    Krusty Registered Member

    Joined:
    Feb 3, 2012
    Posts:
    10,241
    Location:
    Among the gum trees
    If and, or when I hear back from Dan I'll let you know.
     
  20. moredhelfinland

    moredhelfinland Registered Member

    Joined:
    Mar 31, 2009
    Posts:
    350
    Location:
    Finland
    I'm using VS as a "relaxed mode" with G Data AV (only check on execution) and this combo is a light as feather.
    So basically if VS let some malware thru, then there's G Data (on execution) and then in its "DeepRay" and "Beast" components to catch it.
    There are some cons about G Data, but that's does not belong in this thread.
     
  21. Krusty

    Krusty Registered Member

    Joined:
    Feb 3, 2012
    Posts:
    10,241
    Location:
    Among the gum trees
    Reply from Dan:

    "No, it’s not a concern at all. It is a Microsoft dll that crashed for some reason. We have been using it for many years and I have never seen it crash, so I am certain it was a fluke."
     
  22. moredhelfinland

    moredhelfinland Registered Member

    Joined:
    Mar 31, 2009
    Posts:
    350
    Location:
    Finland
    @Krusty
    Thank for the info and thanks to Dan too of course :D
     
  23. imdb

    imdb Registered Member

    Joined:
    Nov 2, 2011
    Posts:
    4,208
    whoa, i see that @VoodooShield is back on the forum again. welcome back, dan. :thumb:
     
  24. Gandalf_The_Grey

    Gandalf_The_Grey Registered Member

    Joined:
    Jan 31, 2012
    Posts:
    1,189
    Location:
    The Netherlands
    Mail from @VoodooShield :
     
  25. EASTER

    EASTER Registered Member

    Joined:
    Jul 28, 2007
    Posts:
    11,126
    Location:
    U.S.A. (South)
    Impressive. Thanks @Gandalf_The_Grey - Looks like forethought many moons ago is proven a formidable proactive approach where it concerns Windows systems fun files collection
     
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.