New Update VoodooShield CyberLock 7.0

omidomi

Level 71
Verified
Honorary Member
Top Poster
Malware Hunter
Well-known
Apr 5, 2014
6,001
Thank you, the latest tor.exe has been whitelisted, and there are several more that I need to go through. If it is still not working on your end, please post the SHA-256 hash and I will whitelist it as well.
Thanks...it work well no :)
 
  • Like
Reactions: danb

Gandalf_The_Grey

Level 76
Verified
Honorary Member
Top Poster
Content Creator
Well-known
Apr 24, 2016
6,572
@danb I had a command line block when there was an update of OneDrive included in this Patch Tuesday:
del /q "c:\program files\microsoft onedrive\update\onedrivesetup.exe"
Another block for a not signed privazer_remover.exe when updating to the latest version of PrivaZer.
 
Last edited:

danb

From VoodooShield
Thread author
Verified
Top Poster
Developer
Well-known
May 31, 2017
1,658
@danb I had a command line block when there was an update of OneDrive included in this Patch Tuesday:

Another block for a not signed privazer_remover.exe when updating to the latest version of PrivaZer.
That's crazy about the OneDrive block, I just added two exceptions in 7.25 ;). Can you please send me your DeveloperLog.log?

I probably cannot do anything about the privazer_remover block, but I will take a look at it. Thank you!
 
  • Like
Reactions: Gandalf_The_Grey

Gandalf_The_Grey

Level 76
Verified
Honorary Member
Top Poster
Content Creator
Well-known
Apr 24, 2016
6,572
That's crazy about the OneDrive block, I just added two exceptions in 7.25 ;). Can you please send me your DeveloperLog.log?

I probably cannot do anything about the privazer_remover block, but I will take a look at it. Thank you!
DeveloperLog.log sent by mail.
 
  • Like
Reactions: vtqhtr413 and danb

danb

From VoodooShield
Thread author
Verified
Top Poster
Developer
Well-known
May 31, 2017
1,658
Hi, this is no big deal but just curious.I version 7.15 I had about 30-35 megs usage. In version 7.25 I have about 65-70 megs used .Is there a reason for the uptick? Thanks
Yeah, this is due to ML.NET, as it keeps the ML models in memory. So the ML.NET analysis is super fast, it does use more RAM. We should be able to figure out how to reduce this some, hopefully to the 40 or so meg range. Thank you!
 

oldschool

Level 82
Verified
Top Poster
Well-known
Mar 29, 2018
7,102
@danb VS blocking printing process:
Code:
[07-13-2022 11:11:52] [INFO ] - RuleID: 6  | False | c:\windows\system32\spool\drivers\x64\3\e_yarnnme.exe |  /mon /fu "c:\users\xxxx\appdata\local\temp\epi3a8a.tmp" | c:\program files (x86)\microsoft\edge\application\msedge.exe | 0
[07-13-2022 11:11:52] [INFO ] - VoodooShield Blocked: c:\windows\system32\spool\drivers\x64\3\e_yarnnme.exe |  /mon /fu "c:\users\xxxx\appdata\local\temp\epi3a8a.tmp" | c:\program files (x86)\microsoft\edge\application\msedge.exe | 0 |  | RuleID: 6
[07-13-2022 11:12:20] [INFO ] - : c:\windows\system32\spool\drivers\x64\3\e_yarnnme.exe |  /mon /fu "c:\users\xxxx\appdata\local\temp\epi3a8a.tmp" | c:\program files (x86)\microsoft\edge\application\msedge.exe | 0 |
I don't think this version is ready for general release.

I have to say, I just don't think it performs as well as older versions and I'm not crazy about developments since WLC was introduced and later versions.
 
Last edited:

omidomi

Level 71
Verified
Honorary Member
Top Poster
Malware Hunter
Well-known
Apr 5, 2014
6,001
Thank you, the latest tor.exe has been whitelisted, and there are several more that I need to go through. If it is still not working on your end, please post the SHA-256 hash and I will whitelist it as well.
Again....(with new version of tor)
66.jpg
 

Freki123

Level 16
Verified
Top Poster
Aug 10, 2013
754
@oldschool VS doesn't like (random?) .tmp files in temp folders (at least for me). Whenever I got lots of blocks in a row it was often (random) .tmp files used by the internal updater of an app or so. I also had epson printer problems (signed epson file labeled as unsafe and I think some blocks also).
If you want to get it solved fast Dan's e-mail support is the way to go.
 

danb

From VoodooShield
Thread author
Verified
Top Poster
Developer
Well-known
May 31, 2017
1,658
Hey Guys!

We have a new VS and DefenderUI Pro! I will post the DefenderUI on the other thread.

The main change for VS 7.27 was refining the VS Rules feature. Hopefully it is working the way everyone likes, but please let me know what further adjustments we need to make.

Please keep in a mind, for example, if a file is already whitelisted in VS, and there is a block rule for a certain folder, VS will still allow the item because it is already whitelisted. There are other examples, but if you find something in the rules feature that just does not make sense, please let me know and I will look into it.

VS 7.27
SHA-256: d036263d887da28efbee904c36ce394540f9f465912dc19745cf8ac714fad675


Have a great weekend, thank you guys!

Dan
 

Trooper

Level 16
Verified
Top Poster
Well-known
Aug 28, 2015
772
Hey Guys!

We have a new VS and DefenderUI Pro! I will post the DefenderUI on the other thread.

The main change for VS 7.27 was refining the VS Rules feature. Hopefully it is working the way everyone likes, but please let me know what further adjustments we need to make.

Please keep in a mind, for example, if a file is already whitelisted in VS, and there is a block rule for a certain folder, VS will still allow the item because it is already whitelisted. There are other examples, but if you find something in the rules feature that just does not make sense, please let me know and I will look into it.

VS 7.27
SHA-256: d036263d887da28efbee904c36ce394540f9f465912dc19745cf8ac714fad675


Have a great weekend, thank you guys!

Dan

Thanks again Dan!!
 

Freki123

Level 16
Verified
Top Poster
Aug 10, 2013
754
@danb The VS 7.25 "Snapshot Scan" works in what way exactly?
Untitled.jpg
E.g. I whitelisted the "suspicious" Steam game "No mans sky" when the WLC showed it as "not safe". So when I start the rightclick "Snapshot Scan" the snapshot is still labled safe. If I whitelisted "virus.exe" would something different happen?
I found no info of how "Snapshot Scan" works or what it exactly checks (including/excluding whitelisted items?) and I'm curious :)
 

oldschool

Level 82
Verified
Top Poster
Well-known
Mar 29, 2018
7,102
@danb The VS 7.25 "Snapshot Scan" works in what way exactly?View attachment 268177E.g. I whitelisted the "suspicious" Steam game "No mans sky" when the WLC showed it as "not safe". So when I start the rightclick "Snapshot Scan" the snapshot is still labled safe. If I whitelisted "virus.exe" would something different happen?
I found no info of how "Snapshot Scan" works or what it exactly checks (including/excluding whitelisted items?) and I'm curious :)
I believe it's just been moved from inside settings to the context menu but the "All safe" message is new to me and I assume the snapshot scan has been integrated with WLC, so my guess is that in your example it would still show as safe because you whitelisted it.
 

Mops21

Level 34
Verified
Honorary Member
Content Creator
Oct 25, 2014
2,373
Hey

What settings and modes did you use i ask the german user of VS Pro

With best Regards
Mops21
 
  • Like
Reactions: danb

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top