VoodooShield discussion

Status
Not open for further replies.

erreale

Level 9
Verified
Content Creator
Malware Hunter
Well-known
Oct 22, 2016
409
Sorry me in advance for my bad Inglese...

Yesterday I had a problem with VS. I wanted to install an update for NVIDIA Gforce Experience as a set VS in Disable/Install Mode but an error occurred when installing. Thinking about an NVIDIA problem I removed the old program and tried an clean installation of Gforce Experience. Same problem! Then I went completely out of VS and only then the installation was successful. Has anyone had the same problem?
 

Evjl's Rain

Level 47
Thread author
Verified
Honorary Member
Top Poster
Content Creator
Malware Hunter
Apr 18, 2016
3,684
Sorry me in advance for my bad Inglese...

Yesterday I had a problem with VS. I wanted to install an update for NVIDIA Gforce Experience as a set VS in Disable/Install Mode but an error occurred when installing. Thinking about an NVIDIA problem I removed the old program and tried an clean installation of Gforce Experience. Same problem! Then I went completely out of VS and only then the installation was successful. Has anyone had the same problem?
did you disable VS DURING the installation process or BEFORE the installation process
if VS already shows a popup, you allow it, and then you put VS into install mode/disable -> it may show error
 

Azure

Level 28
Verified
Top Poster
Content Creator
Oct 23, 2014
1,712
Sorry me in advance for my bad Inglese...

Yesterday I had a problem with VS. I wanted to install an update for NVIDIA Gforce Experience as a set VS in Disable/Install Mode but an error occurred when installing. Thinking about an NVIDIA problem I removed the old program and tried an clean installation of Gforce Experience. Same problem! Then I went completely out of VS and only then the installation was successful. Has anyone had the same problem?
You can try getting support at Wilders. The VoodooShield developer is very active there.
VoodooShield ?

I will link your post over there.
 

Evjl's Rain

Level 47
Thread author
Verified
Honorary Member
Top Poster
Content Creator
Malware Hunter
Apr 18, 2016
3,684
i switched to install mode before of start the installer.
he's right, try to contact VS developer. He can help you to solve the problem or implement a fix in the next version
can you try to use VS in autopilot mode? I think it's more suitable for you can rarely cause problem like other modes
 

shmu26

Level 85
Verified
Honorary Member
Top Poster
Content Creator
Well-known
Jul 3, 2015
8,153
yes, I have seen VS do what you describe. Sometimes it just won't allow a process to run, unless you exit VS completely.

The solution that worked for me was:
1 exit VS
2 install/run software, and leave it running
3 restart VS, and tell it to whitelist everything it can find.

that should fix it!
 

Evjl's Rain

Level 47
Thread author
Verified
Honorary Member
Top Poster
Content Creator
Malware Hunter
Apr 18, 2016
3,684
It is often said that VoodooShield is whitelist based. Few days ago, it blocked chrome installer. Why? Shouldn't it be on the whitelist?
it whitelists the files in your PC and it doesn't have its own pre-made whitelist
also chrome installer is usually unknown to virustotal. I just checked my ChromeSetup.exe, no one has uploaded it to VT (I just uploaded it, first person to do so). That's why it's suspicious to VS
uY5Zvso.png



NOW, after I uploaded the file to VT:
JTnZIdP.png
 

Evjl's Rain

Level 47
Thread author
Verified
Honorary Member
Top Poster
Content Creator
Malware Hunter
Apr 18, 2016
3,684
Basically, you have to first upload it manually on virustotal.com , otherwise it will be marked as unknown?
I think it's for preventing 0-day malwares, in case they have not yet been uploaded to VT for analysis. They should be marked as unknown

I may contact VS dev., ask him if he can add a short list of some 100% trustful vendors like microsoft and google so this may prevent unnecessary popups like my first screenshot. However, malwares can fake the signatures and VS may allow it, who knows :oops:
 

TheMalwareMaster

Level 21
Verified
Honorary Member
Top Poster
Well-known
Jan 4, 2016
1,022
I think it's for preventing 0-day malwares, in case they have not yet been uploaded to VT for analysis. They should be marked as unknown

I may contact VS dev., ask him if he can add a short list of some 100% trustful vendors like microsoft and google so this may prevent unnecessary popups like my first screenshot. However, malwares can fake the signatures and VS may allow it, who knows :oops:
A good mesure of prevention. It's good as it is now
 
K

KGBagent47

I completely uninstalled zemana antilogger as it caused battery drain for my laptop using geek uninstaller. I also noticed ZAM service was still there but I got rid of it, now nothing related to zamana is running on my laptop except the portable version. I dont know why I still get freezing bug. perhaps because I use sleep function a lot

I think long term use of Sleep mode does contribute to the occasional freeze. A weekly restart is probably not a bad idea.
 

shmu26

Level 85
Verified
Honorary Member
Top Poster
Content Creator
Well-known
Jul 3, 2015
8,153
a lot of times, those installer files are downloaded into temp folders, which is a suspicious location. So VS will ignore the usual parent/child permissions, and treat the files suspiciously, until virus total gives them a clean bill of health.

About NVT ERP: it has a short list of trusted vendors. This list is customizable.
If you are looking for a program that will help you decide whether or not to trust a file, VS has the advantage over ERP.
 

shmu26

Level 85
Verified
Honorary Member
Top Poster
Content Creator
Well-known
Jul 3, 2015
8,153
oops, I forgot to mention that in this specific case, NVT ERP actually behaves more smoothly. This is because Google is on the default list of trusted vendors, so Chrome updates go without a hitch.
 

TheMalwareMaster

Level 21
Verified
Honorary Member
Top Poster
Well-known
Jan 4, 2016
1,022
About VS and command lines: Why VoodooShield is not set on Autopilot mode to allow all command lines coming from trusted installers? It's really annoying to click allow each time. That would be useful also for beginners, who don't usually interact with the product (if they don't click allow, their installation will stuck at a certain point). About disabling VS when installing a new product... That's not secure at all forbeginners, who could disable the software thinking to install a program, instead it was malware... They should be able to fully use their machine without turning off the product
 
Status
Not open for further replies.

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top