Take caution! VoodooShield and WinRAR

Status
Not open for further replies.
W

Wave

Yes, now that I recall correctly I had to reach them with "Contact Us" then they activated my account.
I'm confused then since I can send Private Messages without a problem, however I'm still not fully activated yet. Most likely because I had only made 1 post at the time of creating the account and didn't sign in since then except for today (more than 3 months ago).
 
W

Wave

There should be an exception where any file extracted from RAR is inherently untrusted...
This will be more difficult because he won't be able to differentiate between a program which was extracted from a RAR and one that wasn't... How do you suppose he implements such functionality?
 
Last edited by a moderator:
  • Like
Reactions: Deleted member 2913
W

Wave

Source tracking. Basically, you follow chain of all events, like behavior blockers already do...
Yes, but this will require API hooking which will slow down the extraction process and isn't done through supported/documented methods - may become very unstable depending on future updates. The alternative, would be a device driver to monitor I/O operations, however this will cause additional slow-down as well.

Every piece of functionality like this comes with a price; performance, stability, etc.
 

shmu26

Level 85
Verified
Honorary Member
Top Poster
Content Creator
Well-known
Jul 3, 2015
8,153
He said he forgot to add something, and it will be fixed in the next version. VoodooShield ?
when I saw reports on the other forum that people are still suffering from silent blocking of program updates, I uninstalled VS once again, and went back to good ole NVT ERP. There are certain problems that those VS fixes just never seem to fix.
 

shmu26

Level 85
Verified
Honorary Member
Top Poster
Content Creator
Well-known
Jul 3, 2015
8,153
when I saw reports on the other forum that people are still suffering from silent blocking of program updates, I uninstalled VS once again, and went back to good ole NVT ERP. There are certain problems that those VS fixes just never seem to fix.
ummm, I think I misunderstood those reports. The people over there are now saying that the problem is fixed in the current version.
 

Av Gurus

Level 29
Verified
Honorary Member
Top Poster
Malware Hunter
Well-known
Sep 22, 2014
1,767
Sorry, I didn't understand this. What happened?

Like this:

Clipboard01.jpg
 

TheMalwareMaster

Level 21
Thread author
Verified
Honorary Member
Top Poster
Well-known
Jan 4, 2016
1,022
Yes, with this ransomware because it is high detection on VT.
Instead, I downloaded CDburnerxp( detection 8/56) and made the archive after downloading it. The archive wasn't kicked on opening. The problem keeps to be important for zero-day ransomware. If one is using WinRAR and VoodooShield and download this new piece of ransomware and opens it via WinRAR, he will be infected even if the sample has a VirusTotal detection
 

TheMalwareMaster

Level 21
Thread author
Verified
Honorary Member
Top Poster
Well-known
Jan 4, 2016
1,022
A small correction. The correct word is "archive" for one and "archives" for multiple ones. Not "arhive"
 
  • Like
Reactions: Av Gurus
Status
Not open for further replies.

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top