VoodooShield/Cyberlock

Discussion in 'other anti-malware software' started by CloneRanger, Dec 7, 2011.

  1. VoodooShield

    VoodooShield Registered Member

    Joined:
    Dec 9, 2011
    Posts:
    5,881
    Location:
    United States
    Hey Baldrick, as far as the browsers go, you can just add a Custom Allowed Folder Settings / Custom... something like "c:\browsers".

    I have never heard of the folder "c:\windows\sysnative", where is that coming from? You can also add that folder to Custom Allowed Folders as well.

    The previous versions of VS should have blocked these folders as well. Are they new folders? Thank you!
     
  2. VoodooShield

    VoodooShield Registered Member

    Joined:
    Dec 9, 2011
    Posts:
    5,881
    Location:
    United States
    Thank you guys for the help! I think I just need to add "c:\windows\sysnative" to the windows allowed folders, after I find out if it is a windows protected folder or not. But that is really odd, I do not have that folder on my system, and have never heard of it. I will research it some more and have a fix sometime tonight or tomorrow. Basically, assuming that it is a windows protected folder, I will just add it to the list of other windows protected folders, (eg, system32, syswow64, etc), then I am sure it will work great. I tested this version on 3 systems for 3 days, and this did not appear at all. It must be because the cpn is now seeing the system folders / files that it did not see before. Anyway, it will be an easy fix, sorry about that!
     
  3. VoodooShield

    VoodooShield Registered Member

    Joined:
    Dec 9, 2011
    Posts:
    5,881
    Location:
    United States
    Hehehe, I tried to download the filehippo update checker, thinking that I would see the sysnative folder, but it is nowhere to be found! I will research that folder and figure out what to do.

    Thank you everyone, sorry about that!
     
  4. Defenestration

    Defenestration Registered Member

    Joined:
    Jul 17, 2004
    Posts:
    1,108
    C:\Windows\Sysnative is simply an alias for C:\Windows\System32 allowing a 32-bit application to access 64-bit apps on 64 bit Windows. It does not work for 64-bit processes (since they can access system32 directly). It was introduced in Vista. It's related to the file system re-direction feature.

    http://msdn.microsoft.com/en-us/library/windows/desktop/aa384187(v=vs.85).aspx
     
  5. VoodooShield

    VoodooShield Registered Member

    Joined:
    Dec 9, 2011
    Posts:
    5,881
    Location:
    United States
    Cool, thank you for the info! I do not have the sysnative folder on any of my computers, and I do not ever remember seeing that folder before. It is odd because since I have been working on VS, I have had to figure out what a lot of the folder do specifically, and I have never seen that one.

    This should fix the issue, although I obviously cannot test to be sure since I do not have that folder ;).

    http://www.voodooshield.com/freeoffer/Install VoodooShield.2.64 beta.exe
     
  6. Tarnak

    Tarnak Registered Member

    Joined:
    Feb 5, 2007
    Posts:
    5,295
    Should, I update or stay at 2.63 beta, since I know on XP, it is not applicable.
     
  7. VoodooShield

    VoodooShield Registered Member

    Joined:
    Dec 9, 2011
    Posts:
    5,881
    Location:
    United States
    Yeah, exactly, it is not applicable to XP, so you can skip this one. There are 2 small bugs that I am aware of so I will fix those, along with anything else you guys find, then you can update.

    The two bugs that I am working one are:

    1. The registration issue if there is not an internet connection. Although that might be fixed now... it is hard to test because there is not a good way to simulate a wireless connection not fully connecting.

    2. When the user drags and drops to VS, it works, but the Sandbox and Allow buttons prompt the user twice.


    Thank you guys!
     
  8. Tarnak

    Tarnak Registered Member

    Joined:
    Feb 5, 2007
    Posts:
    5,295
    Thanks...I am lazy, so less uninstalling and installing the better, for this ancient system. :)
     
  9. Tarnak

    Tarnak Registered Member

    Joined:
    Feb 5, 2007
    Posts:
    5,295
    However, I do notice that when I access settings, then Web apps tab, there is a sudden increase in CPU usage to about 25%, fluctuating.
     
  10. Triple Helix

    Triple Helix Specialist

    Joined:
    Nov 20, 2004
    Posts:
    13,275
    Location:
    Ontario, Canada
    Well 2.64 is running well and your Right I need to re-register after second reboot on my Laptop and why does it go into Smart Mode after the second reboot automatically? I will give it a go and let you know if I find any issues!

    Thanks,

    Daniel :)
     
  11. Triple Helix

    Triple Helix Specialist

    Joined:
    Nov 20, 2004
    Posts:
    13,275
    Location:
    Ontario, Canada
    Just got another Block from: 13/09/2014 9:05:49 AM Blocked rundll32.exe c:\windows\sysnative\rundll32.exe
     
  12. VoodooShield

    VoodooShield Registered Member

    Joined:
    Dec 9, 2011
    Posts:
    5,881
    Location:
    United States
    Ooops, I just noticed something, thank you TH! Since rundll32 is blacklisted when VS is ON, it will block it, if the path is c:\windows\sysnative\rundll32.exe. It should be an easy fix. Is there anyway someone can email me a screenshot of the contents of the c:\windows\sysnative\ folder? I want to make sure VS does not blacklist anything else in that folder.

    Edit: Ohhh, I see, the c:\windows\sysnative\ folder does not actually exist, it is just an alias like Defenestration mentioned. Let me see what I can do.
     
    Last edited: Sep 13, 2014
  13. VoodooShield

    VoodooShield Registered Member

    Joined:
    Dec 9, 2011
    Posts:
    5,881
    Location:
    United States
    Yeah, it is because VS is detecting the active Web Apps. I will see if I can do something about that. Thank you!
     
  14. VoodooShield

    VoodooShield Registered Member

    Joined:
    Dec 9, 2011
    Posts:
    5,881
    Location:
    United States
    I can make it so that VS does not go into Smart Mode automatically. Basically, on First Run, it is set to start in Training Mode. Then anything after first run, it will start in Smart Mode, unless Always ON has been selected, then it starts in Always ON. So whenever it is started again, it will either start in Smart or Always ON. But I can remove that code so that it starts in whatever mode it was in previously. What do you guys think?
     
  15. VoodooShield

    VoodooShield Registered Member

    Joined:
    Dec 9, 2011
    Posts:
    5,881
    Location:
    United States
  16. Baldrick

    Baldrick Registered Member

    Joined:
    May 11, 2002
    Posts:
    2,675
    Location:
    South Wales, UK
    Hi Dan, just got back and seen all of this. .64 will be installed within the hours and then given some wellie...as usual.

    Regards, Baldrick
     
  17. Baldrick

    Baldrick Registered Member

    Joined:
    May 11, 2002
    Posts:
    2,675
    Location:
    South Wales, UK
    I think start in whatever mode it was in previously. :thumb:
     
  18. Baldrick

    Baldrick Registered Member

    Joined:
    May 11, 2002
    Posts:
    2,675
    Location:
    South Wales, UK
    .64 is still blocking c:\windows\sysnative\rundll32.exe :(
     
  19. VoodooShield

    VoodooShield Registered Member

    Joined:
    Dec 9, 2011
    Posts:
    5,881
    Location:
    United States
    Ok, cool, we can have it start in the previous mode. I think the sysnative issue will be easy to fix, but can you tell me how to trigger it? Thank you!
     
  20. Baldrick

    Baldrick Registered Member

    Joined:
    May 11, 2002
    Posts:
    2,675
    Location:
    South Wales, UK
    Hi Dan

    Well, I seem to get it every time I start one of the browsers that I have installed in a folder whose path is C:\Browsers. I would suggest that you set up the same and stick a portable version of a browser in there and then try to run the browser in question.
     
  21. Defenestration

    Defenestration Registered Member

    Joined:
    Jul 17, 2004
    Posts:
    1,108
    You should be able to trigger it by creating a simple 32-bit executable which executes "c:\windows\sysnative\rundll32.exe" (eg. using CreateProcess() ) and run it on a 64-bit Windows or Vista or later.
     
  22. VoodooShield

    VoodooShield Registered Member

    Joined:
    Dec 9, 2011
    Posts:
    5,881
    Location:
    United States
    Cool, thank you guys, I will try one of those and see if I can reproduce it. Once I can, it should be super easy to fix.
     
  23. ichito

    ichito Registered Member

    Joined:
    Jan 14, 2011
    Posts:
    1,997
    Location:
    Poland - Cracow
    VS 2.63 works without issue on my Vista together with SpyShelter and Shadow Defender...is necessary change it into 2.64?
     
  24. MrGump

    MrGump Registered Member

    Joined:
    Sep 5, 2009
    Posts:
    406
    still getting issue with 2.64
    c:\windows\sysnative\rundll32.exe

    now when launching Internet Explorer and using File Hippo 'Update checker'
     
  25. VoodooShield

    VoodooShield Registered Member

    Joined:
    Dec 9, 2011
    Posts:
    5,881
    Location:
    United States
    No, the only change in 2.64 was trying to fix the sysnative issue. I downloaded both of the portable browsers and put them in the same folder as Baldrick, but I have been unable to reproduce this issue. Once we can reproduce it, it should be super simple to fix, but so far no luck on figuring out what triggers it. I will try the other option that Defenestration recommended, or better yet, I will tell the new developer about the issue, and hopefully he can fix it. He is working on the kmd right now, but this should be a quick fix.
     
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.