- Jan 4, 2016
- 1,022
@Lucent Warrior did some samples bypass VoodooShield or everything was blocked? I watched the video but I didn't understand. Thanks in advance
Nothing bypassed VS in this test. In the beginning what you probably seen was the one process still running in the Local Sandbox that i manually killed. As of now, if a process that is run in the local sandbox does not self/auto terminate, then you either have to kill it manually via the process or restart the system which resets the sandbox.@Lucent Warrior did some samples bypass VoodooShield or everything was blocked? I watched the video but I didn't understand. Thanks in advance
Thank you. Did you choose manually the "sandbox" option? You didn't click quarantine or block right?Nothing bypassed VS in this test. In the beginning what you probably seen was the one process still running in the Local Sandbox that i manually killed. As of now, if a process that is run in the local sandbox does not self/auto terminate, then you either have to kill it manually via the process or restart the system which resets the sandbox.
Yes, i manually chose to run a few of them in the local sandbox.Thank you. Did you choose manually the "sandbox" option?
Fine, Thanks again. I started installing this on autopilot into beginners computers and it really does its jobYes, i manually chose to run a few of them in the local sandbox.
When LW was testing in Malware Hub (with different name) lots of other members didn't get smart screen warning but he always do.
Malware pack was the same.
We could't not figure out why is that...
I can confirm that it was discussed, and i can also confirm that the OS file reputation system is supposed to work exactly as it does in my video. What the few of your are doing different that produces your results is beyond me as im not sitting in front of your systems.Can you confirm that a couple of time there was a debate about that in Malware Hub?
Exactly, and after you run that check, the next time you execute the sample you will not get a warning as you already allowed it for VT Hash Checker.In fact I also get W10 SS warnings when I only check reputation of a sample with VT Hash Checker
Exactly, and thats what my initial comment focused on.1. they are not always caught by smartscreen, just most.
2. very little detail in the OS file reputation system still makes it hard for a novice to know which way to turn, only information they receive with those is that the file is unknown to Smartscreen and they recommend "not running".
3. once the file has been let past smartscreen, it is totally up to the tested product to stop it or the system becomes infected.
4. most importantly, this is a brief review of the product, testing this method allowed me to show all aspects of dealing with a file via this product, and the ways to make choices/decisions.
Lucent Warrior
Maybe handy when you start or end the video with what your verdicts is and maybe sum up how it did in protection (that is why other member probably asked whether or not VS let something blocked everything).
So what is your verdict?
Thanks for the video