VoodooShield/Cyberlock

Discussion in 'other anti-malware software' started by CloneRanger, Dec 7, 2011.

  1. Djigi

    Djigi Registered Member

    Joined:
    Aug 13, 2012
    Posts:
    554
    Location:
    Croatia

    Attached Files:

  2. VoodooShield

    VoodooShield Registered Member

    Joined:
    Dec 9, 2011
    Posts:
    5,881
    Location:
    United States
    Yeah, I was just checking the database and noticed that too ;). Let me think of what else might be causing this issue... I will check with Vlad to see what he thinks too. Thank you!
     
  3. VoodooShield

    VoodooShield Registered Member

    Joined:
    Dec 9, 2011
    Posts:
    5,881
    Location:
    United States
    Can you please copy the entire "Unhanded Exception" error message and PM it to me?
     
  4. Djigi

    Djigi Registered Member

    Joined:
    Aug 13, 2012
    Posts:
    554
    Location:
    Croatia
    If this could help:
    It's on virtual machine (VirtualBox)
    Info:
     

    Attached Files:

    • 1.png
      1.png
      File size:
      68 KB
      Views:
      20
  5. Djigi

    Djigi Registered Member

    Joined:
    Aug 13, 2012
    Posts:
    554
    Location:
    Croatia
  6. VoodooShield

    VoodooShield Registered Member

    Joined:
    Dec 9, 2011
    Posts:
    5,881
    Location:
    United States
    Cool, thank you, I will see if I can figure out what is causing the issue right now. Yeah, it works fine on VirtualBox for me, so it is probably something else.
     
  7. VoodooShield

    VoodooShield Registered Member

    Joined:
    Dec 9, 2011
    Posts:
    5,881
    Location:
    United States
  8. Djigi

    Djigi Registered Member

    Joined:
    Aug 13, 2012
    Posts:
    554
    Location:
    Croatia
    Sure...
    Here is Win 7_x64 in Virtualbox, same thing :thumbd:
    Error - http://www51.zippyshare.com/v/TNRbCd5u/file.html
     

    Attached Files:

  9. VoodooShield

    VoodooShield Registered Member

    Joined:
    Dec 9, 2011
    Posts:
    5,881
    Location:
    United States
    Hmmm, this is really odd, there must be a simple explanation ;).

    Have you tried it without a VM just to see what happens?

    Also, can you please try 3-4 files, then assuming that it acts up, can you please send me those files?

    Thank you for all of your help, we will figure this out soon!
     
  10. Rasheed187

    Rasheed187 Registered Member

    Joined:
    Jul 10, 2004
    Posts:
    17,606
    Location:
    The Netherlands
    Yes good point, I also don't know why we didn't get to see the malware successfully loaded. So things are quite unclear.
     
  11. Triple Helix

    Triple Helix Specialist

    Joined:
    Nov 20, 2004
    Posts:
    13,277
    Location:
    Ontario, Canada
    Works well here on Win 10 x64.

    Daniel ;)

    2016-02-23_14-12-23.png
     
  12. Djigi

    Djigi Registered Member

    Joined:
    Aug 13, 2012
    Posts:
    554
    Location:
    Croatia
    One file is OK but when try 2 or more and then select one of them on the right then it crush.
     
  13. VoodooShield

    VoodooShield Registered Member

    Joined:
    Dec 9, 2011
    Posts:
    5,881
    Location:
    United States
  14. VoodooShield

    VoodooShield Registered Member

    Joined:
    Dec 9, 2011
    Posts:
    5,881
    Location:
    United States
    Ahhhh, now we are on to something ;). Is this true with running it in a VM and not running it in a VM?

    Also, do you drag and drop, or do you click the button and select the files?

    Also, are you seeing results you would expect to see when you analyze one file, or are the results clearly incorrect or way off?
     
  15. Triple Helix

    Triple Helix Specialist

    Joined:
    Nov 20, 2004
    Posts:
    13,277
    Location:
    Ontario, Canada
    4 EXE's at a time working well. Looks like it's needs to expand on the right side? 2/.....

    2016-02-23_15-06-03.png
     
  16. Djigi

    Djigi Registered Member

    Joined:
    Aug 13, 2012
    Posts:
    554
    Location:
    Croatia
    1. It's the same on VM or not VM.
    2. Drag'n'drop
    3. Here are some pictures with 3 legit files

    Picture 1:
    Safe .dll - VodooAi say Unsafe, slider is on Safe side

    Picture 2:
    3 safe files D'n'D - VoodooAi say Suspisicus & Unsafe

    Picure 3:
    Click on files names for details (on the right) VoodooAi Error message
     

    Attached Files:

  17. VoodooShield

    VoodooShield Registered Member

    Joined:
    Dec 9, 2011
    Posts:
    5,881
    Location:
    United States
    Thank you TH!

    BTW, please keep in mind that when analyzing multiple files, you can click on the items in the Safe and Suspicious / Unsafe boxes and it will display some details on the item. We almost need a box for suspicious as well... otherwise users will think that files that are just a little past the Safe upper limit are being detected as Unsafe, when really they are being detected as suspicious. Either way, we still need to figure out where to set the limits for safe, suspicious and unsafe, but really what matters are the probabilities.

    For example, in VS's Cuckoo Sandbox, if the results are 2.5 / 10, the file is called suspicious, and to me, that is a little low... the lower limit for suspicious files should be closer to 5 or so (at a minimum).

    Also, please keep in mind, we just started the VoodooAi project 5 months ago... and 2 of those five months I stopped working on it (and basically quit the project about 50 times, hehehe), because it was so frustrating to get everything right. The only thing that kept me going was that I saw the math working, so I knew it was possible to get it right. Over the next 3-4 months, the results will only continue to get better, especially when we have much larger training data sets (the current training data set is only 179,177 samples!!!). But even with the limited training data set, I am very happy with the results so far... they are 2-3 times better than I expected.
     
    Last edited: Feb 23, 2016
  18. VoodooShield

    VoodooShield Registered Member

    Joined:
    Dec 9, 2011
    Posts:
    5,881
    Location:
    United States
    Hmmm, something is still not right... it should look like TH's screenshot from post #8663.

    If you can analyze 3-4 samples at one time, then send me the files, I think there is a chance that will help a lot. Thanks again!
     
  19. VoodooShield

    VoodooShield Registered Member

    Joined:
    Dec 9, 2011
    Posts:
    5,881
    Location:
    United States
    BTW... this is a great example of the need to increase the lower limit for suspicious files to .75 or so, that way files like this we be detected as safe. Once we have more data, we will be able to pinpoint the exact limits we should use.
     
  20. VoodooShield

    VoodooShield Registered Member

    Joined:
    Dec 9, 2011
    Posts:
    5,881
    Location:
    United States
    The thing that is odd is that all of the features are being extracted from the files properly, and ALL of those numbers are correct and look great. The only numbers that are not correct are the 3 probability results that are returned from Azure... and for some reason they are sky high (like 2934237432972297 or something), but they should be between 0.0000 and 1.0000... which btw I have never seen while working on this project. We will figure it out one way or another ;).
     
  21. Djigi

    Djigi Registered Member

    Joined:
    Aug 13, 2012
    Posts:
    554
    Location:
    Croatia
    Add one file from desktop for analyze and it is OK (picture 1)
    Picture 2 - add 9 malware files (looks OK?) - Download malware pack from here: hxxp://www59.zippyshare.com/v/i29h3Zay/file.html
    Picture 3 - click on files (26.exe), VoodooAi crush
    (if you want I can record quick/short video)
     

    Attached Files:

    Last edited: Feb 23, 2016
  22. Djigi

    Djigi Registered Member

    Joined:
    Aug 13, 2012
    Posts:
    554
    Location:
    Croatia
  23. Moose World

    Moose World Registered Member

    Joined:
    Dec 19, 2013
    Posts:
    905
    Location:
    U.S. Citizen
    Watch the video in Post: # 8674. Was Zemana a false positive?
    I quess because it still in beta?
     
  24. VladimirM

    VladimirM Developer

    Joined:
    Sep 16, 2015
    Posts:
    153
    Location:
    Jerusalem, Israel
    VoodooShield 3.09 Beta Release
    You can download it from https://voodooshield.com/Download/beta3/InstallVoodooShield.exe

    System requirements:
    • Windows Vista sp1 and above (XP is not supported!)
    • .NET 2.0/3.5 and above
    What's new in VoodooShield 3.09 Beta:

    This release contains:
    • Added the new Edit form for editing Command Lines with wildcard support (currently only * and ? are supported for wildcards)
    • Added search box to Whitelist, Command lines and Quarantine lists
    • Improved performance of User Log, Whitelist, Quarantine and Command Line lists
    • Some small bugs fixes

    Known issues

    • Sometimes gray user prompt is shown - have direction of an investigation
    Have a good day,
    Vladimir
     
  25. Krusty

    Krusty Registered Member

    Joined:
    Feb 3, 2012
    Posts:
    10,256
    Location:
    Among the gum trees
    Vlad,

    When I click on Edit the Edit window is too long for my laptop screen so there is no way to see what is off to the right. :(
     
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.