VoodooShield/Cyberlock

Discussion in 'other anti-malware software' started by CloneRanger, Dec 7, 2011.

  1. Krusty

    Krusty Registered Member

    Joined:
    Feb 3, 2012
    Posts:
    10,239
    Location:
    Among the gum trees
    Do both have internet access?
     
  2. Triple Helix

    Triple Helix Specialist

    Joined:
    Nov 20, 2004
    Posts:
    13,273
    Location:
    Ontario, Canada
    Different Command Lines on each system would be my guess.
     
  3. GrDukeMalden

    GrDukeMalden Registered Member

    Joined:
    Jun 16, 2016
    Posts:
    491
    Location:
    VPN city
    So what do I have to remove from my whitelist to make it work right?

    I did a super clean install of voodoo didn't even restore my settings and the LNK was blocked once and then never again.

    Mine does, presumably the other person's does too.
     
  4. GrDukeMalden

    GrDukeMalden Registered Member

    Joined:
    Jun 16, 2016
    Posts:
    491
    Location:
    VPN city
    So can anyone tell me why voodoo would block something on one system, but not others?
     
  5. Krusty

    Krusty Registered Member

    Joined:
    Feb 3, 2012
    Posts:
    10,239
    Location:
    Among the gum trees
    Sounds like a question for support@voodooshield.com.
     
  6. Bertazzoni

    Bertazzoni Registered Member

    Joined:
    Apr 13, 2018
    Posts:
    657
    Location:
    Milan, Italia
    Correct!
     
  7. GrDukeMalden

    GrDukeMalden Registered Member

    Joined:
    Jun 16, 2016
    Posts:
    491
    Location:
    VPN city
    Well he referred me here. I think because here there'd be a wider variety of VMs with different setups

    Has anyone here ever tested voodoo on a system that already has a bunch of stuff allowed in the local whitelist?

    Things like all the executable files of open office marked as vulnerable and web apps

    Discord marked as a vulnerable and web app.

    all the EXEs of steam and all the installed games from it marked as web and vulnerable apps.

    And then once you set up a VM with those protected by voodoo, run every kind of file-less malware you can find. including LNK files and office document files, PDFs, every kind of sneaky file like that and let me...and more importantly Dan of voodoo shield know about the results. For me, voodoo stopped blocking malicious LNK files once a good number of things were on the local whitelist

    and voodoo in my tests stopped blocking malicious DOC files once swriter was allowed in the local whitelist
     
  8. Bertazzoni

    Bertazzoni Registered Member

    Joined:
    Apr 13, 2018
    Posts:
    657
    Location:
    Milan, Italia
    I can't be of any help as I haven't used VS in a while and never test, use VM, etc.
     
  9. GrDukeMalden

    GrDukeMalden Registered Member

    Joined:
    Jun 16, 2016
    Posts:
    491
    Location:
    VPN city
    I stopped using voodoo. Ever since Dan implemented the contextual engine it wasn't as good. And by what I've experienced, if the local whitelist already has certain command lines allowed for legit applications, voodoo won't block any command lines that call upon the same system files....some of the time.

    If the old engine that wasn't contextual was still being used, those command lines would've been blocked until allowed by the user.

    Blocking legitimate applications is inevitable with whitelisting. And sometimes certain security software isn't good to mix with it. That's to be expected

    The whole point of a whitelisting application is to block first and figure out what it is whenever you need something to run. I can understand making it appeal to the average user by making it allow more things, but if it's at the cost of compromising even a little tiny bit of security then the whitelisting application isn't really a true whitelisting application.

    I would like to see a test of voodoo on a system that already has a lot of stuff allowed in the local whitelist. CMD based command lines, conhost based command lines, powershell based command lines, every kind of command line you can think of as long as it's meant to allow legitimate software to run.

    So far all the tests I've seen of voodoo were on totally clean installs with nothing allowed in voodoo's whitelist. Oh...and I've also noticed that my VPN will connect and swap proxies a lot faster now.
     
  10. Freki123

    Freki123 Registered Member

    Joined:
    Jan 20, 2015
    Posts:
    337
    @GrDukeMalden Maybe give cruelsister some suggestions on the other security forum (mal.) about what you think would maybe get VS off the rail. She likes to toy with security software and find ways to smuggle stuff around them.
     
  11. GrDukeMalden

    GrDukeMalden Registered Member

    Joined:
    Jun 16, 2016
    Posts:
    491
    Location:
    VPN city
    So it turns out...I was wrong about voodoo. But by all means, test it in a machine that has lots of legitimate applications allowed on it.

    Test it against all manner of file-less malware, DLL injections, all kinds of non-EXE typed stuff. I don't know if there's any flaws in voodoo, but the only way to find out is to test it regularly
     
  12. moredhelfinland

    moredhelfinland Registered Member

    Joined:
    Mar 31, 2009
    Posts:
    347
    Location:
    Finland
    Come on Dan, Steam skyrimlauncher.exe got flagged...even in "relaxed" mode. Huh.
     
  13. Gandalf_The_Grey

    Gandalf_The_Grey Registered Member

    Joined:
    Jan 31, 2012
    Posts:
    1,188
    Location:
    The Netherlands
    By mail from @VoodooShield VoodooShield 7.42 announced:
     
  14. stapp

    stapp Global Moderator

    Joined:
    Jan 12, 2006
    Posts:
    24,061
    Location:
    UK
    Thanks.
    Was offered it by auto install at boot.
    All seems fine.
     
  15. plat

    plat Registered Member

    Joined:
    Dec 19, 2018
    Posts:
    2,233
    Location:
    Brooklyn, NY
    Thanks, Gandalf_The_Grey! Installed my Windows 11 drive just for this update. Got some other stuff for Windows Insiders and Firefox to boot. All installed perfectly.
     
  16. Mops21

    Mops21 Registered Member

    Joined:
    Oct 5, 2010
    Posts:
    2,743
    Location:
    Germany
    Hi all

    Dan has postet some new Infos about Voodooshield on malwaretips forum see this link

    (10) Update - VoodooShield 7.0 | Page 25 | MalwareTips Forums

    With best Regards
    Mops21
     
  17. plat

    plat Registered Member

    Joined:
    Dec 19, 2018
    Posts:
    2,233
    Location:
    Brooklyn, NY
    Yes, I saw that. OK so he's going thru with the name change. Well, the one that sounds best and most relevant to me is: cyberlock.online b/c that's when VS is needed. Simple.

    Prob. he'll go with something else. :)
     
  18. moredhelfinland

    moredhelfinland Registered Member

    Joined:
    Mar 31, 2009
    Posts:
    347
    Location:
    Finland
    I dont recommend to post domain names in public, because some ones can register them easily. For business or for being a evil...
     
  19. Triple Helix

    Triple Helix Specialist

    Joined:
    Nov 20, 2004
    Posts:
    13,273
    Location:
    Ontario, Canada
    2023-04-14_19-11-57.jpg 2023-04-14_19-13-06.jpg
     
  20. plat

    plat Registered Member

    Joined:
    Dec 19, 2018
    Posts:
    2,233
    Location:
    Brooklyn, NY
    That looks pretty good. At least he's easing into the name change--it kind of reassures me at least, b/c I've become such a fan of this software (again).

    OK, so CyberLock/CybeLock.global ii is. :thumb:

    I'll install my Windows 11 drive in a bit to see how it works out on here. Don't expect any issues.
     
  21. Triple Helix

    Triple Helix Specialist

    Joined:
    Nov 20, 2004
    Posts:
    13,273
    Location:
    Ontario, Canada
    Working very well! https://cyberlock.global/
     
  22. stapp

    stapp Global Moderator

    Joined:
    Jan 12, 2006
    Posts:
    24,061
    Location:
    UK
    Installed over the top of 7.42 on Win 10.
    Chose to delete logs etc.
    Whitelist showed double entries for a lot of things so I reset it.
    All is running well.
     
  23. Alexhousek

    Alexhousek Registered Member

    Joined:
    Jul 25, 2009
    Posts:
    662
    Location:
    USA--Oregon
    Are most people installing over top of 7.42 or are most of you uninstalling VS and installing Cyberlock?
     
  24. plat

    plat Registered Member

    Joined:
    Dec 19, 2018
    Posts:
    2,233
    Location:
    Brooklyn, NY
    Well, I installed my Windows 11 drive and downloaded the latest 7.43 from the official website. I used HiBit Uninstaller to remove VoodooShield 7.42 and denied VS uninstaller and HiBit to remove my settings and whatnot (in other words: kept all my settings). It took maybe one second and I was registered as a result--there was no need to update any license key or anything. The UI looks basically the same, with "CyberLock" and the VS shield in the upper left side. Painless!

    Very good--I'm all set now.
     
  25. Gandalf_The_Grey

    Gandalf_The_Grey Registered Member

    Joined:
    Jan 31, 2012
    Posts:
    1,188
    Location:
    The Netherlands
    According to @VoodooShield :
    Personally, I uninstalled VoodooShield first and then installed CyberLock.
     
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.