VoodooShield/Cyberlock

Discussion in 'other anti-malware software' started by CloneRanger, Dec 7, 2011.

  1. Tarnak

    Tarnak Registered Member

    Joined:
    Feb 5, 2007
    Posts:
    5,338
    I checked the log, which goes back to March, 2015...and nothing else shows up where this happens.
     
  2. VoodooShield

    VoodooShield Registered Member

    Joined:
    Dec 9, 2011
    Posts:
    5,881
    Location:
    United States
    Cool, does VS keep blocking it?
     
  3. VoodooShield

    VoodooShield Registered Member

    Joined:
    Dec 9, 2011
    Posts:
    5,881
    Location:
    United States
    For the record, someone just bypassed VoodooAi ;). imprimir_fatura_0004022016.exe and underscore2.exe both were detected as Safe, when they should have been detected as Unsafe. But whoever analyzed these files... it did pretty well considering that it detected all of the other ones in that batch, huh? If I am unable to track down these samples, can you send them to me sometime so I can add them to the training data?

    Time for a break, thanks for all of your guys help, talk to you soon!
     
  4. VoodooShield

    VoodooShield Registered Member

    Joined:
    Dec 9, 2011
    Posts:
    5,881
    Location:
    United States
    Whoever just uploaded the following samples, please contact me!!! Something went wrong, the probabilities were extremely high numbers that were out of range… Like this: 975874304771423, when they should be between 0 and 1.

    Are you running a Non-English version of Windows, or do you have some kind of firewall running? Thank you!

    25.exe

    8834F4FD855BC261DCEB17C9548E6523.exe

    mal1.exe

    run.exe

    us.exe

    ZAM.Portable.exe

    procexp.exe

    geek.exe

    iexplore.exe
     
  5. VoodooShield

    VoodooShield Registered Member

    Joined:
    Dec 9, 2011
    Posts:
    5,881
    Location:
    United States
    The above error is from AV Gurus from MT... I am not a member of that site, so can someone please have AV Gurus post on this thread if they are a member. If not, just have them contact me please.

    I am curious if they are running an English version of Windows or not, or if there is a firewall or something else that might be causing the issue!!!

    https://malwaretips.com/threads/voodooshield-ai-artificial-intelligence.56588/

    Sorry for so many posts ;). And you guys thought I disappeared ;).
     
  6. Krusty

    Krusty Registered Member

    Joined:
    Feb 3, 2012
    Posts:
    10,277
    Location:
    Among the gum trees
    Is VS's 'Cloud' safe, Dan?
     
  7. stapp

    stapp Global Moderator

    Joined:
    Jan 12, 2006
    Posts:
    24,465
    Location:
    UK
  8. Djigi

    Djigi Registered Member

    Joined:
    Aug 13, 2012
    Posts:
    554
    Location:
    Croatia
    I'm that member.
    OS: Win 10_x64 English with Croatian Keyboard
    Win firewall & EMET
    If you want I could test again.

    Maybe it's something with Virtual Machine because I was testing something beafore.

    BTW: when click on file got error
    http://s11.postimg.org/vsh5zeihf/Clipboard03.png
     

    Attached Files:

    Last edited: Feb 23, 2016
  9. ghodgson

    ghodgson Registered Member

    Joined:
    Dec 20, 2003
    Posts:
    835
    Location:
    UK
    Hi Dan/Vlad,
    I recently reset the whitelist and noticed that VS 3.08 beta is blocking some installed apps from the Program files folder, even though I have 'Automatically allow all software from the program files folders' ticked. One of them is Wordpad !
    They all seem to be from the x86 folder.
    VS blocked the following .........
    program files(x86)windowsnt\accessories\wordpad.exe
    program files(x86)\stdu viewer\stduviewerapp.exe (my installed .pdf reader)

    error1.png

    Cheers
    Gordon
     
  10. siketa

    siketa Registered Member

    Joined:
    Oct 25, 2012
    Posts:
    2,718
    Location:
    Gaia
    Dan, is this wrong decision or wrong graphics?
    It happens for every clean file Ai analyzes...bar shows "Safe" but the final verdict is "Unsafe". (?!?)
     

    Attached Files:

    • 1.jpg
      1.jpg
      File size:
      82.2 KB
      Views:
      24
    Last edited: Feb 23, 2016
  11. siketa

    siketa Registered Member

    Joined:
    Oct 25, 2012
    Posts:
    2,718
    Location:
    Gaia
    I can confirm Djigi's post...GUI crashes every time I click on a file name for details (multiple selection).
    Plus there are two GUI glitches, at least on FullHD resolution.
     

    Attached Files:

    • 1.jpg
      1.jpg
      File size:
      140.8 KB
      Views:
      8
    Last edited: Feb 23, 2016
  12. Cutting_Edgetech

    Cutting_Edgetech Registered Member

    Joined:
    Mar 30, 2006
    Posts:
    5,694
    Location:
    USA
    It crashed for me also a couple months ago, and I discovered I did not have Microsoft Framework 4.5 installed.
     
  13. siketa

    siketa Registered Member

    Joined:
    Oct 25, 2012
    Posts:
    2,718
    Location:
    Gaia
    I have just re-checked and Microsoft .NET Framework 4.5.2 is installed on my PC.
     
    Last edited: Feb 23, 2016
  14. Cutting_Edgetech

    Cutting_Edgetech Registered Member

    Joined:
    Mar 30, 2006
    Posts:
    5,694
    Location:
    USA
    Ok, thanks for confirming.
     
  15. siketa

    siketa Registered Member

    Joined:
    Oct 25, 2012
    Posts:
    2,718
    Location:
    Gaia
    NP...let's wait for Dan's/Vlad's reply.

    P.S. Another type of crash after browsing for a single file.
     

    Attached Files:

    • 3.jpg
      3.jpg
      File size:
      147.6 KB
      Views:
      12
    Last edited: Feb 23, 2016
  16. VoodooShield

    VoodooShield Registered Member

    Joined:
    Dec 9, 2011
    Posts:
    5,881
    Location:
    United States
    I am not sure what you mean by cloud safe. Like when I think of cloud safe, I think of like Mozy or Carbonite, and your files being safe in the cloud... is that what you mean?

    Here is how VoodooAi works in a nutshell. Watson is used to help build the models and determine which features we should in the "fingerprint", so it does not interact with VoodooAi / the cloud at all. I only use it on my own to help me build the models and determine which features are good indicators / predictors of

    Azure on the other hand is different... it does interact directly with VoodooAi, and VoodooAi uploads metadata directly to the Machine Learning component of Azure, and to a SQL Azure database. But, the data is just an array of strings, integers and binary variables, like this 1400, 3, True, -1, False (but there are about 25 or so variables).

    Either way, I am certain that Azure and Watson are both pretty secure. But anyway, is this what you mean?
     
  17. VoodooShield

    VoodooShield Registered Member

    Joined:
    Dec 9, 2011
    Posts:
    5,881
    Location:
    United States
    Hi, yeah, VS should block the "installer", a command line and the portable app once. After that, it should work fine, but if not, please let me know, thank you!
     
  18. VoodooShield

    VoodooShield Registered Member

    Joined:
    Dec 9, 2011
    Posts:
    5,881
    Location:
    United States
    Hi, thank you for your reply. I think I know what the problem is... let me make a few changes and we can try it again, thank you!
     
  19. VoodooShield

    VoodooShield Registered Member

    Joined:
    Dec 9, 2011
    Posts:
    5,881
    Location:
    United States
    Hey Gordon, thank you... Vlad will be able to answer this a lot better than I can.
     
  20. VoodooShield

    VoodooShield Registered Member

    Joined:
    Dec 9, 2011
    Posts:
    5,881
    Location:
    United States
    Hey siketa, I think I know what the problem is... let me make a few changes and we can try it again, thank you!
     
  21. VoodooShield

    VoodooShield Registered Member

    Joined:
    Dec 9, 2011
    Posts:
    5,881
    Location:
    United States
    Cool, thank you! The new version should automatically choose the correct compiled version of VoodooAi and copy it to the desktop, so unless you are running XP or Vista, .net is not required because it will just use the native version of .net for each OS.
     
  22. Cutting_Edgetech

    Cutting_Edgetech Registered Member

    Joined:
    Mar 30, 2006
    Posts:
    5,694
    Location:
    USA
    Ok, thank you for the update!
     
  23. siketa

    siketa Registered Member

    Joined:
    Oct 25, 2012
    Posts:
    2,718
    Location:
    Gaia
    Dan, does VS make re-analysis of already submitted sample(s) or it just shows the original verdict?
    Should I upload clean samples that received "Unsafe" verdict again?
     
  24. VoodooShield

    VoodooShield Registered Member

    Joined:
    Dec 9, 2011
    Posts:
    5,881
    Location:
    United States
  25. VoodooShield

    VoodooShield Registered Member

    Joined:
    Dec 9, 2011
    Posts:
    5,881
    Location:
    United States
    Yeah, once a user submits a sample, it is automatically added to the database so that it does not have to be reanalyzed by Azure... and that way it is quicker.

    I will remove all of the samples where there was an error from the database right now so it does not mess anything up, thank you!
     
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.