VoodooShield Latest

F

ForgottenSeer 69673

The FP has been taken care of by MS. Guessing they are using a hash and when a file's hash changes, it is flagged. I think Cylance works similar.
Every single time I get a new insider build Cylance quarantines a file or two.
 

shmu26

Level 85
Verified
Honorary Member
Top Poster
Content Creator
Well-known
Jul 3, 2015
8,153
The FP has been taken care of by MS. Guessing they are using a hash and when a file's hash changes, it is flagged. I think Cylance works similar.
Every single time I get a new insider build Cylance quarantines a file or two.
It happens also with NoVirusThanks products. It's very common for MS to do that.
 

Lightning_Brian

Level 15
Verified
Top Poster
Content Creator
Sep 1, 2017
743
Wow! Just simply wowzers!! Dan is the man. I'm happy to see so much great progression and fantastic work being put into this great software.

Malwaretipers hooah for continuing to post the latest builds and information here. I really enjoy using this product on my build. Any new builds I complete for people get the free version of VoodooShield and the people in most cases opt for the Pro version not long after, because of how great the product is. Without VoodooShield on a computer the computer itself seems incomplete to me now - I know it sounds funny, but it is true!

I'm truly impressed by this great software!

Dan, keep up the great work my friend!

~Brian
 

oldschool

Level 85
Verified
Top Poster
Well-known
Mar 29, 2018
7,625
Wow! Just simply wowzers!! Dan is the man. I'm happy to see so much great progression and fantastic work being put into this great software.

Malwaretipers hooah for continuing to post the latest builds and information here. I really enjoy using this product on my build. Any new builds I complete for people get the free version of VoodooShield and the people in most cases opt for the Pro version not long after, because of how great the product is. Without VoodooShield on a computer the computer itself seems incomplete to me now - I know it sounds funny, but it is true!

I'm truly impressed by this great software!

Dan, keep up the great work my friend!

~Brian

Watch out or you'll be accused of "Fanboy-ism"! :LOL: I love it too! That's why I upgraded some time ago (y)

@shmu26 and other posters - WD still flagging the new build. Maybe some more time needed for FP to clear. No problem, this version is just some little details.

EDIT: I just saw this on COU:

Microsoft fixed the false positive... but I had to complete the following to get it to work, the entire report is below. On a side note... I see why people complain about false positives... this is what I would call a "true" false positive. When VoodooAi is a little high, and it still is on occasion, that is not a freaking false positive... you can easily click the allow button. This incident with MS was a true FP, and inbuilt security software should have zero (or a number approaching zero) false positives. Then the user adds what security layers they like. WD has become much more effective over the years, but at the expense of incidences like this. If you want my opinion... I do not think it will be too much longer until all anyone ever needs is WD and VS.

Anyway, thank you for letting me know about the FP!!!


installvoodooshield.exe

Submission ID: 4a061e1a-2d75-4fc3-9d74-e41401ed4b9b

Status: Completed

Submitted by: ***@voodooshield.com

Submitted: Nov 3, 2018 2:49:59 PM

User Opinion: Incorrect detection

Analyst comments:


We have removed the detection. Please follow the steps below to clear cached detection and obtain the latest malware definitions.

1. Open command prompt as administrator and change directory to c:\Program Files\Windows Defender
2. Run “MpCmdRun.exe -removedefinitions -dynamicsignatures”
 
F

ForgottenSeer 69673

Dan just posted this lol






"BTW, the false positive was fixed for a couple of hours, but it seems to be back. I resubmitted the file and we will see what happens
wink.gif
."
 
F

ForgottenSeer 72227

Dan just posted this lol






"BTW, the false positive was fixed for a couple of hours, but it seems to be back. I resubmitted the file and we will see what happens
wink.gif
."

Hmmm interesting, I just downloaded it now and it was fine with WD at high settings, it wasn't flagged. Another member on COU uploaded it to VT and it was not flagged by Microsoft.
 
F

ForgottenSeer 72227

Nope! I tried clearing the cache and downloading again to no avail! Version 4.63 and prior were technically beta. 4.64 is what is released on his site. I'm on 1803. Oh well, someone will figure it out! :whistle:

@oldschool just want to clarify, is WD flagging VS as malware for you, or is it saying it's safe? I'm on 1809 and just downloaded it again from his site and it was fine. It is indeed very strange. I do have my BAFS level set to "Block" which has even less tolerance than "highest", so it is indeed strange why its working for some and not others.

Actually a quick question, do you have the new sandboxing feature enabled? I have it disabled.

As you said, Im sure it will be sorted out.:coffee:
 

oldschool

Level 85
Verified
Top Poster
Well-known
Mar 29, 2018
7,625
From Dan, earlier:

Thank you TH! Yeah, I am not sure which engine is listed on VT for Microsoft... but when you submit a FP to MS, you have to choose from following list of MS security products. At this point the only product we know that has a FP is "Windows Defender Antivirus (Windows 10)" so that is what I chose. Besides, you always hear how the VT results might be different from the endpoint product results, so your guess is as good as mine
wink.gif
.

System Center Endpoint Protection
Windows Defender Antivirus (Windows 10)
Windows Intune
Microsoft DaRT
Microsoft Forefront Client Security
Microsoft Forefront Endpoint Protection 2010
Microsoft Forefront Protection for SharePoint
Microsoft Forefront Server Security
Microsoft Security Essentials
Office 365 and Exchange Online Protection
System Center 2012 Endpoint Protection
Windows Defender (Windows
cool.gif

Windows Defender (Windows 7, Windows Vista, or Windows XP)
Windows Server Antimalware
Other

There were massive changes between 4.53 and 4.64. We did not seem to have any issues at all until I updated our download link to 4.64 (in other words... versions prior to 4.64 were never linked on our site). I wonder if that has anything to do with it... especially since if you download VS in Chrome and then scan with WD 10 (fully updated), it does not have a FP. So I am guessing that it is some feature in Edge that has a bug or something... it is hard to say. Either way I am sure they will have it fixed soon. Thank you guys!
 

oldschool

Level 85
Verified
Top Poster
Well-known
Mar 29, 2018
7,625
@oldschool just want to clarify, is WD flagging VS as malware for you, or is it saying it's safe? I'm on 1809 and just downloaded it again from his site and it was fine. It is indeed very strange. I do have my BAFS level set to "Block" which has even less tolerance than "highest", so it is indeed strange why its working for some and not others.

Actually a quick question, do you have the new sandboxing feature enabled? I have it disabled.

As you said, Im sure it will be sorted out.:coffee:

Flagged as virus. Attempted download with Edge. Yes, new sandboxing enabled but I'm going to disable - if I can remember how. :LOL:
 
F

ForgottenSeer 72227

Flagged as virus. Attempted download with Edge. Yes, new sandboxing enabled but I'm going to disable - if I can remember how. :LOL:

Interesting I downloaded it through Edge as well lol, ah good old Microsoft :ROFLMAO:

When I disabled it I just deleted it from the "System Variables" list and restarted :)
 

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top