Twister-AntiTrojenVirus Thread.

Discussion in 'other anti-virus software' started by Taliscicero, Dec 3, 2008.

Thread Status:
Not open for further replies.
  1. Taliscicero

    Taliscicero Registered Member

    Joined:
    Feb 7, 2008
    Posts:
    1,439
    I'm sorry it was a bad joke on my part i was tired and cranky.

    Twister has a wierd ability to suprise and stump me completely.

    But any tests being done on Win7 or vista don't count in my oppinion since twister has never really been fully compatible with them, i think all tests for it should be done in XP because it shows the true ability of the program in a situation it would be functioning properly.

    And i'm not sure about Win7 but it may have a different file system that confused twister.
     
  2. roger_m

    roger_m Registered Member

    Joined:
    Jan 25, 2009
    Posts:
    8,626
    The filing system is unchanged in Windows 7. However I agree with you about running tests in XP since it has been determined that either Twister doesn't work in Winodws 7, or possibly only works for some people running Windows 7.
     
  3. bryanjoe

    bryanjoe Registered Member

    Joined:
    Feb 23, 2006
    Posts:
    380
    i installed Gimp 2.6 and twister prompted over a hundred viruses.....

    can anyone with Twister try installing and then scan... wanna know if its just me or FPs

    http://www.gimp.org/downloads/
     
  4. Saraceno

    Saraceno Registered Member

    Joined:
    Mar 24, 2008
    Posts:
    2,405
  5. bryanjoe

    bryanjoe Registered Member

    Joined:
    Feb 23, 2006
    Posts:
    380
  6. firzen771

    firzen771 Registered Member

    Joined:
    Oct 29, 2007
    Posts:
    4,815
    Location:
    Canada
  7. Fuzzfas

    Fuzzfas Registered Member

    Joined:
    Jun 24, 2007
    Posts:
    2,753
    LOL! Trojan Zhelatin strikes again! If someone searches the Twister threads, i 've been battling against FP with trojan Zhelatin for months. Every new version of Abiword is flagged as trojan Zhelatin!

    I 'm afraid there's a Zhelatin curse in Twister. You can only submit them as false positives and wait till they get fixed, like i do with Abiword.
     
  8. Dregg Heda

    Dregg Heda Registered Member

    Joined:
    Dec 13, 2008
    Posts:
    830
    Thanks for all the info everyone especially Zimzi and Zetelo. Sorry but I couldn't reply earlier as i have been very busy lately. Here are a couple more questions.

    How does FDDS work? Is it a classical HIPS? Is it chatty? Also registry protection will I assume inform you if any keys are added to the registry? Anyways I'm currently looking at other security apps like HIPS and virtualisation and gonna stick with my trial version of NOD32 but I would be really interested if there are any tests with twister on default settings.
     
  9. firzen771

    firzen771 Registered Member

    Joined:
    Oct 29, 2007
    Posts:
    4,815
    Location:
    Canada
    FDDS is a noisy Behavior Blocker. im not sure exactly about the registry protection.
     
  10. Taliscicero

    Taliscicero Registered Member

    Joined:
    Feb 7, 2008
    Posts:
    1,439
    Registry protect will flag newly installed programs so that malware cant install itself as easy threw Drive by downloads.
     
  11. bellgamin

    bellgamin Registered Member

    Joined:
    Aug 1, 2002
    Posts:
    8,123
    Location:
    Hawaii
    True, but there's a strategy for that. Namely, after installing Twister on your "clean system", use it to do a full-system-scan. Then *carefully* consider/trust all the resultant FPs.

    After that, Twister will become pretty quiet BUT -- when it does give an alert -- it is fairly certain to be something that you ought to look into.
    ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

    P.S. A well-seasoned Behavior Blocker is similar to the animal you get when you cross-breed a lion with a parrot -- when it talks, you better listen! :eek:
     
  12. firzen771

    firzen771 Registered Member

    Joined:
    Oct 29, 2007
    Posts:
    4,815
    Location:
    Canada



    LOL i like that
     
  13. Zimzi

    Zimzi Registered Member

    Joined:
    Jul 10, 2005
    Posts:
    289
    Registry Protector will flag only if it find a problem (suspicious information in the Windows Registry)!

    You can get more information on Twister Anti-TrojanVirus Help page under the "Registry Protector" link.

    P.S. I hope that this year Filseclab will publish not only the new version of the Twister, but, also, more modern and informative website.
     
  14. firzen771

    firzen771 Registered Member

    Joined:
    Oct 29, 2007
    Posts:
    4,815
    Location:
    Canada
    it would be interesting t see what the new version will be like, any ETA on its release?
     
  15. bryanjoe

    bryanjoe Registered Member

    Joined:
    Feb 23, 2006
    Posts:
    380
    Since there are many FPs, User can set safe files to "Trust".
    It then prompted that these trusted files will not be scanned again. Meaning excluded from subsequent scans...

    What are risks should these files are infected?
    How to minimize?


    PS. i have added about 400 files as trusted........ isnt it too much?? :(
     
  16. Zimzi

    Zimzi Registered Member

    Joined:
    Jul 10, 2005
    Posts:
    289
    Tonight I catched up a litlle more interesting malware. It is spyware/adware type of malware. On Virus Total only 4 programs recognize it as malware (mostly as a "suspicious"). The most well-known antimalware cannot detect it. I run the file on my PC to verify that it is a real malware, not a FP.

    Twister also cannot detect it by virus signatures, but Twister's File Dynamic Defense System (behavior analysis component) flag it (see picture) so malware can be stopped.
     

    Attached Files:

    Last edited: Feb 2, 2009
  17. bryanjoe

    bryanjoe Registered Member

    Joined:
    Feb 23, 2006
    Posts:
    380
    Hi Zimzi,

    How to resolve the issue of trusted files being subsequently infected?
    Cos twister will bypass it..
     
  18. Zimzi

    Zimzi Registered Member

    Joined:
    Jul 10, 2005
    Posts:
    289
    Assume that the solution is to not have a lot of trusted files. Also, you can choose "Trust Temp" option which allows the file to be considered trusted during the next five minutes. I am using the default settings and really very rarely have problems with false positives. I do not have even a single trusted file.
     
  19. bryanjoe

    bryanjoe Registered Member

    Joined:
    Feb 23, 2006
    Posts:
    380
    I am performing manual scan....
    so the option is not wat u have attached....

    only have Clean / Rename / Reimmunize / Trust
     
  20. Zimzi

    Zimzi Registered Member

    Joined:
    Jul 10, 2005
    Posts:
    289
    In that case the file marked as a trusted will not be scanned in the future when you are using on-demand scanning, but if such a file be launched Twister will catch it by real time protection by virus database or by FDDS module ...

    You can try this with Eicar test file.

    If you want to make such a file untrusted again, go to Twister main window - Extended options and remove the file from the right tab.
     
    Last edited: Feb 2, 2009
  21. renegade08

    renegade08 Registered Member

    Joined:
    Aug 26, 2008
    Posts:
    432
    Bryanjoe,

    I see in your signature that besides Twister you have other programs.

    Do you run the all at the same time?
    Are the some conflicts between Twister and some of the applications or conflict between different applications?

    Do you have D+(HIPS) activated in comodo or not?
    I think that SSM it's similar with D+ in comodo, right?
    Don't you think this is an overlap?

    Hey guys, would you reccomend for securing Twister running two HIPS at the same, D+ from comodo and EQS (or SSM) and even behavior blocker like Threatfire?
    And would this be problem, with too many applications?

    I'm saying this for Twister, not for every AV that is out there.
    I know that Twister doesn't have HTTP scanner, so would this be some preventive measure and securing Twister.

    Thanks.


    You setup seems pretty much interesting.
     
  22. bryanjoe

    bryanjoe Registered Member

    Joined:
    Feb 23, 2006
    Posts:
    380
    hi renegade08,

    I have run both SSM and D+ with twister previously.... No issues with it.
    Infact, i run Malware Defender previously as well.... hahaha....

    But for now it is those at my signature with D+ disabled.
     
  23. renegade08

    renegade08 Registered Member

    Joined:
    Aug 26, 2008
    Posts:
    432
    Hey,bryanjoe.

    Thank you for your quick response.

    And even you have ThreatFire beside all those programs.

    Man that setup is like killing spree (From Unreal Tournament). Pretty cool.
     
  24. bryanjoe

    bryanjoe Registered Member

    Joined:
    Feb 23, 2006
    Posts:
    380
    Hi, thanks for clarifications.
    I always thought that after setting it "Trusted", it will bypass the real time protection.
     
  25. Taliscicero

    Taliscicero Registered Member

    Joined:
    Feb 7, 2008
    Posts:
    1,439
    I wouldent recomend installing D+ with FDDS on but if you add all the FP's to trusted list then i dont see that much of an issue if you keep FFDS on medium or low setings.
     
Thread Status:
Not open for further replies.
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.