VoodooShield/Cyberlock

Discussion in 'other anti-malware software' started by CloneRanger, Dec 7, 2011.

  1. djg05

    djg05 Registered Member

    Joined:
    Apr 6, 2005
    Posts:
    1,565
    I restored my baseline last night. Checked the Registry for Voodoo and came up with "%icpvoodoo44.devicedesc%" and similar. I am guessing that that is not connected with VS?

    Checked the system drive and no instance of VS.

    Then installed 1.26.10 and the same result of it stalling. Only 3rd party security installed was Avast and SBIE. The latter should not be an issue. This also rules out Private f/w. Took 3 attempts to get it to register.

    My first attempt got interrupted by dinner and found that it had BSOD when I came back an hour or so later, though I had disconnected the router.

    I have also found that VS blocks access to Regedit even with the option ticked in Tweaks. This was in .10 and also in .11 .
     
  2. VoodooShield

    VoodooShield Registered Member

    Joined:
    Dec 9, 2011
    Posts:
    5,881
    Location:
    United States
    Wow, that is very odd. So you were running a previous version, and you upgraded to 1.26.11, and it did not remember your old registration? Would it let you reenter your registration? It must be a bug, I will test it right now. Sorry about that, I will look at it right now, thank you.
     
  3. djg05

    djg05 Registered Member

    Joined:
    Apr 6, 2005
    Posts:
    1,565
    Have gone back to my baseline and installed 1.26.11 afresh. This is using Win 8/64. Again the login window is blanked out of all script and also the icon is just a white square. Has to be forced closed 2 or 3 times. Win reports it as not responding. This does not happen with Win 7/64
     
  4. djg05

    djg05 Registered Member

    Joined:
    Apr 6, 2005
    Posts:
    1,565
    Just to clarify Dan. It is not the registration but opening Regedit.
     
  5. VoodooShield

    VoodooShield Registered Member

    Joined:
    Dec 9, 2011
    Posts:
    5,881
    Location:
    United States
    After you restored your baseline and installed VS, did it say Expired? Yes, "%icpvoodoo44.devicedesc%" has nothing to do with VS.

    Have you found out what caused the BSOD yet? Cutting_Edgetech was having a BSOD as well. I really do not see how the changes in VS could have caused it, but I guess anything is possible. What do you use for a screensaver on that machine?

    As far as regedit is concerned... checking the option in tweaks only makes it so that regedit is not blacklisted, but you still have to whitelist it if you want it to run when VS is ON. Then if you were to uncheck that option after whitelisting it, VS would then block it if VS is ON.
     
  6. VoodooShield

    VoodooShield Registered Member

    Joined:
    Dec 9, 2011
    Posts:
    5,881
    Location:
    United States
    Hmmm, 7 and 8 should act the same, but I can install 8 on my test computer later to see if I can reproduce the error.

    So VS is telling you that it is expired?
     
  7. djg05

    djg05 Registered Member

    Joined:
    Apr 6, 2005
    Posts:
    1,565
    When eventually VS comes to life it does show expired, prior to that it is just white box.

    Just blank screen for screensaver

    Noted about Tweaks. Think though that you need some explanation that it will not automatically be allowed - that is the inference from that box and probably others will think the same and you will be pestered with more questions.

    The BSOD maybe a red herring. Don't think the VS liked hanging around in a hung state and Windows might have interfered. Don't have that install - went back to baseline.
     
  8. VoodooShield

    VoodooShield Registered Member

    Joined:
    Dec 9, 2011
    Posts:
    5,881
    Location:
    United States
    I will try it on a clean install of 8 tonight and see what result I get. I wonder if that happens if you remove all of the computers from the web interface first?

    Sounds good, I will make a note on the tweaks page, thank you.

    I hope VS is not causing the BSOD. I believe Cutting_Edgetech later figured out that VS was not the cause of his BSOD. The problem is, I really would like to release this new version to the public ASAP, but I cannot if VS is causing a BSOD. So I hope we figure it out soon!
     
  9. siketa

    siketa Registered Member

    Joined:
    Oct 25, 2012
    Posts:
    2,718
    Location:
    Gaia
    Dan, take it step by step and don't rush it more than it's needed.
    There is no perfect, 100% bug-free software.
    ;)
     
  10. VoodooShield

    VoodooShield Registered Member

    Joined:
    Dec 9, 2011
    Posts:
    5,881
    Location:
    United States
    Oh, I know. I really do not rush, but I do like to make as much progress as possible. It is crazy though... the timing and toggling with VS is very, very touchy. The other 2 developers have said that all along as well. For example, I just made one change, then out of the blue the Allow button on the prompt quit working. It was a pretty easy fix, but bugs like that kind of drive me crazy ;).

    But you are right, I need to take it step by step. This is not a race ;).
     
  11. djg05

    djg05 Registered Member

    Joined:
    Apr 6, 2005
    Posts:
    1,565
    In the Tweaks window. If the boxes are not ticked does it mean they blacklisted? I see that rundll32 is in my white list - is this correct?
     
  12. VoodooShield

    VoodooShield Registered Member

    Joined:
    Dec 9, 2011
    Posts:
    5,881
    Location:
    United States
    Yes, that is correct, if the box is unchecked, they are blacklisted. Now that I think about it, maybe we should have done that the other way around. We can change it if we need to.

    Basically, rundll32 has to be whitelisted since it is the windows process that helps dll's to run, it is kind of the parent process. So if rundll32 is blacklisted, new dll's cannot spawn if VS is ON. I hope that makes sense, if not, please let me know!
     
    Last edited: Sep 3, 2013
  13. Triple Helix

    Triple Helix Specialist

    Joined:
    Nov 20, 2004
    Posts:
    13,458
    Location:
    Ontario, Canada
    Is it safe to install this version or should I wait?

    Daniel
     
  14. VoodooShield

    VoodooShield Registered Member

    Joined:
    Dec 9, 2011
    Posts:
    5,881
    Location:
    United States
    I think it is safe, I really do not think that VS caused the 2 BSOD. Cutting_Edgetech narrowed his down to a Ricoh Driver, which VS has nothing to do with at all. I do not think djg05 has figured out his issue yet. I have been running it for 2 days or so on 3 different computers and it is running great. The new one will be ready very soon. I am hoping it will be bug free, and the last public release before the new engine and kill method.
     
  15. djg05

    djg05 Registered Member

    Joined:
    Apr 6, 2005
    Posts:
    1,565
    Thanks - the question is why it is on my whitelist with it being unchecked?
     
  16. VoodooShield

    VoodooShield Registered Member

    Joined:
    Dec 9, 2011
    Posts:
    5,881
    Location:
    United States
    Sorry ;). Well, since it is an essential windows file, it has to be on your whitelist. But when VS is ON, it is blacklisted in case a virus tries to attack your system with the help of a dll. When VS is OFF, it is not blacklisted so VS can learn new processes. Does that make sense? It really is hard to explain why we did it that way.
     
  17. VoodooShield

    VoodooShield Registered Member

    Joined:
    Dec 9, 2011
    Posts:
    5,881
    Location:
    United States
  18. Triple Helix

    Triple Helix Specialist

    Joined:
    Nov 20, 2004
    Posts:
    13,458
    Location:
    Ontario, Canada
    Thanks Dan working very well. :thumb:

    Daniel ;)
     
  19. hayc59

    hayc59 Updates Team

    Joined:
    Feb 9, 2002
    Posts:
    2,841
    Location:
    KEEP USA GREAT
    thank you Dan wonderful update ;)
     
  20. VoodooShield

    VoodooShield Registered Member

    Joined:
    Dec 9, 2011
    Posts:
    5,881
    Location:
    United States
    Cool, thank you TH and hayc59!
     
  21. djg05

    djg05 Registered Member

    Joined:
    Apr 6, 2005
    Posts:
    1,565
    Running ok here once loaded.

    Just a nit pick. On the Tweaks page, should "do not" be "does not". Also can the font size be increased on that line since it is difficult to read.
     
  22. djg05

    djg05 Registered Member

    Joined:
    Apr 6, 2005
    Posts:
    1,565
    Ok - understand.

    The reason I asked was that I had VS running with defaults and a note popped from the firewall saying that rundll32 was allowed. So effectively VS was overruled by the firewall. Am I reading that correctly.

    This is probably me but I find the setting for the Tweaks page to be ambiguous. How about "Tick items to add to the White List"

    Just a thought.
     
  23. VoodooShield

    VoodooShield Registered Member

    Joined:
    Dec 9, 2011
    Posts:
    5,881
    Location:
    United States
    Good point, thank you, I will change that.
     
  24. VoodooShield

    VoodooShield Registered Member

    Joined:
    Dec 9, 2011
    Posts:
    5,881
    Location:
    United States
    I see what you are saying, but these options do not actually add the items to the whitelist. But they do blacklist the items when VS is ON, and the blacklist overrides the whitelist. For example, if you start a cmd prompt window with VS OFF, then turn VS ON, it should kill the window. I have never liked the phrase "Do not Blacklist" and have been looking for another way to explain these options. So now that you know more about how these options work, can you think of another way I can explain these options? Thank you!
     
  25. VoodooShield

    VoodooShield Registered Member

    Joined:
    Dec 9, 2011
    Posts:
    5,881
    Location:
    United States
    Ok, I think this will be 1.27. IT WILL PROMPT YOU TO UPDATE UNTIL I UPLOAD IT TO THE PUBLIC, BUT PLEASE DO NOT, that will just take you back the previous version.

    Also, I made a small, but important change. It really should not cause any issues for anyone, but I would like to see if you guys would please try it first just to make sure. It is running great for me. It was a small change with the "~" that I overlooked, but now we should no longer see the "~" in the whitelist or log. It seemed to make VS run even better as well.

    Please let me know how it is running for you guys, thank you!


    https://voodooshield.com/freeoffer/Install VoodooShield.1.27.exe
     
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.