VoodooShield Latest

Gandalf_The_Grey

Level 76
Verified
Honorary Member
Top Poster
Content Creator
Well-known
Apr 24, 2016
6,601

Gandalf_The_Grey

Level 76
Verified
Honorary Member
Top Poster
Content Creator
Well-known
Apr 24, 2016
6,601
Actually, this happens pretty much every time we have a new public release. Edge detects VS as a virus… and I have reported it over and over and over to Microsoft, and they only fix the issue for the one release, so the next release I have to submit the file again. It is odd though, they never flag the beta releases, just the public ones that are posted on our main website. Thank you for letting me know, I will report this now.
Didn't had a download problem with the chromium-based Edge :unsure:
 

Gandalf_The_Grey

Level 76
Verified
Honorary Member
Top Poster
Content Creator
Well-known
Apr 24, 2016
6,601
does your version of edge still use smart screen? dan said ms does this with every released version but not the betas
Yes, it does:
Aantekening 2020-01-12 193647.jpg
 

Gandalf_The_Grey

Level 76
Verified
Honorary Member
Top Poster
Content Creator
Well-known
Apr 24, 2016
6,601
Hey guys, VoodooAi is back up and running again… there might have been some odd WLC results, mainly false positives while VoodooAi was down. The good news is that VS handled the issue extremely well, so now we know that even if VoodooAi goes down, VS will continue to run (with somewhat odd WLC results ;)).

VoodooAi went down after Azure had an issue on their end, which was described by a Microsoft rep as “We had an issue last week where the web service calls were failing. The engineering team found that this was due to the TLS1.2 enforcement that happened org wide. Hence, they had to update the services to TLS1.2 as well. I am sorry for the inconvenience caused by this.” That is just the way tech is… you just kind of have to roll with the punches. I mean, we could all be running 15 year old tech and it would be stable, or we can forge ahead and create new cool tech.

I also released a new version of the standalone version of WLC 1.06. A patched version of VS will be available soon, after I fix the other couple of items. Until then, VS will run normal, but you will not be able to see the VoodooAi result for new items. You can see them for old items because VS is grabbing them from the database.

Thank you guys, talk to you soon!
Hey Guys, here is the latest beta, and here are some of the things that were fixed, along with several optimizations.

  1. The VoodooAi API is working again
  2. WLC is using the new super-fast server with a 500 MB upload limit. I will be increasing the 500 MB upload limit on the actual website soon.
  3. The Wise Disk cleaner / no hash bug that caused the infinite scan is fixed. There still might be an issue or two that causes an infinite scan in the future, but we are getting close to fixing all of the no hash issues. If you do experience the infinite scan, please email me your Developer Logs and whitelist.db
  4. The WLC dll’s are filtered now. WLC and ML/Ai is not all that accurate with dll’s, so for the time being they are not going to be a part of the WLC list. I have some ideas on how to increase the accuracy that I will be working on soon. Besides, what really matters is that the executable or command line is blocked.
  5. Other minor optimizations.
@djg05, I tested the software you were having an issue with but was unable to reproduce the bug. Just to make sure we are working with the same file, is it named “install_home_accountz_v3_win_64bit.exe”? If you continue to have issues with 5.61beta, please email me your Developer Logs and whitelist.db.

VS 5.61 beta
https://voodooshield.com/Download/InstallVoodooShield561beta.exe
SHA-256: d8bf406a6ff060a38e727eee3540d07b26dd08851780cd54b460eaf644b053fa

Thank you guys, talk to you soon!
 

Gandalf_The_Grey

Level 76
Verified
Honorary Member
Top Poster
Content Creator
Well-known
Apr 24, 2016
6,601
New version 5.62 beta released:
Hey guys, sorry for the delay, this version has a few bug fixes and should fix the bug that most of you are experiencing with having to allow an item more than once, but if not please let me know!

VS 5.62 beta
https://voodooshield.com/Download/InstallVoodooShield562beta.exe
SHA-256: 19c0be7e18dc80b9a9aa576d9816ef7e5387027dd3d312b7fbbea3ed56a820b5

@djg05 and Mr.GumP, if you are still having this issues, please email me your DeveloperLog.log and DeveloperServiceLog.log.

Thank you guys, have a great weekend!
 
F

ForgottenSeer 823865

A permanent solution is to not use WLC, which is what I do.
You are a hater ! your free license should be revoked ! :p
WLC is revolutionary, go Dan i support you with it, the whole industry didn't even think of it at all (or lack of skills) when they all chose Blacklisting, you may have found a new way to make VS great again ! keep up the good work !
 
Last edited by a moderator:

Gandalf_The_Grey

Level 76
Verified
Honorary Member
Top Poster
Content Creator
Well-known
Apr 24, 2016
6,601

Lenny_Fox

Level 22
Verified
Top Poster
Well-known
Oct 1, 2019
1,120
@danb I have not used your program, so I have a question. A member was so kind to post some pictures of the User Interface.

1584805798714.png


WIth the default deny and allow from Program Files, most neatly installed programs would always run (it is a pity that Microsoft installs Windows Defender in ProgramData), so only programs executing from user folders could be blocked in theory.

For signed programs will update nicely with the "Autimatically allow items that match a digital signature in the whitelist snapshot" rule. Assuming the snapshot also looks at ProgramData and Users (sub folders), this rule would also allow programs outside Windows and Program Files to update nicely.

The beauty of building a user specific local signature based whitelist is that the risk of signed malware is minimal (95% of the malware is unsigned). The allow by signature only applies to vendors which are already trusted and installed. This greatly reduces risk of 5% signed malware not being recognized.

Does the cloud whitelist contain hashes of (unsigned) programs recognized by the AI-engine as probably malware, but are considered clean by Cuckoo sandbox or Virus Total checkup? Another purpose for the cloud whitelist could be to collect a large data base of trusted vendors by signature. The problem with this approach is that when you also allow trusted vendors by signature, the when to stop adding trusted vendors.

So what is in the cloud whitelist? Unsigned programs, signatures of trusted vendors, and/or .....?
 
Last edited:

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top