Twister-AntiTrojenVirus Thread.

Discussion in 'other anti-virus software' started by Taliscicero, Dec 3, 2008.

Thread Status:
Not open for further replies.
  1. Fuzzfas

    Fuzzfas Registered Member

    Joined:
    Jun 24, 2007
    Posts:
    2,753
    There are 2 ways for online submission.

    1) Tools ---> Submission --> Online submit false positive. In that case, you will have to browse to the file and select it. It will then be uploaded to Filseclab.

    2) Via email. Put the file(s) that are false positives in a zipped file and send them to <falsealarm [at] filseclab.com> (it's the mail address that appears if you click "email false positive under Tools-->Submission".

    "What file"?

    - The exact file that Twister flagged as virus. You can check the log to see exact path and name.

    Csv file?? No, you must sent exactly the file that caused the false positive.
     
  2. bryanjoe

    bryanjoe Registered Member

    Joined:
    Feb 23, 2006
    Posts:
    380
    Wow, i have more than 300 FPs..... got to do it 300 times...
    i tried but it doesnt allow any connection

    i have done this instead...but as a csv file...
     
  3. Fuzzfas

    Fuzzfas Registered Member

    Joined:
    Jun 24, 2007
    Posts:
    2,753
    300?! We have a new winner! :D In this case, it's best to copy them all in a folder, zip it and send it via email. If they are all in a folder you can also "mass-online submit them", by holding down the mouse key and selecting them all. An online submission window will start and will start uploading all the selected one by own without further input from you.

    Where did this csv file come up from? o_O Anyway, csv won't be of any help. They need the real code. Check your PM.
     
  4. bryanjoe

    bryanjoe Registered Member

    Joined:
    Feb 23, 2006
    Posts:
    380

    maybe i do it wrongly..... i click "Log" and export...
     
  5. Fuzzfas

    Fuzzfas Registered Member

    Joined:
    Jun 24, 2007
    Posts:
    2,753
    Ah, i see! Yes, unfortunately the log won't help. They 'd have to download all your applications in there (assuming they can understand which they are) and install them.

    I am afraid you have to see in the log which is the executable and path and put it in a new folder and send it to them. With 300 that will be nasty... :ninja:

    You must find each of the files mentioned in the log, copy it to a new folder and when you are finished, zip the folder and email it with title "False positives".

    If you have trusted the files, they must also be listed in "extended options". So if you see (for example) C: Program Files/Abiword/bin/Abiword.exe, you have to browse your C disk, go to Abiword folder, bin subfolder, copy the Abiword.exe in a new folder with the files to send to Filseclab. So it's the "Abiword.exe" the one you must send in this example.
     
  6. bryanjoe

    bryanjoe Registered Member

    Joined:
    Feb 23, 2006
    Posts:
    380
    i see... thanks for the clarifications.

    There is this file size limit of 2.0MB by Filsecab..
    i have this file "gimp-2.6.exe" that is 4.5MB.
    I select this file through the online submission...
     
  7. bryanjoe

    bryanjoe Registered Member

    Joined:
    Feb 23, 2006
    Posts:
    380
    sorry i zipped it up and trying the submission now...
     
  8. bryanjoe

    bryanjoe Registered Member

    Joined:
    Feb 23, 2006
    Posts:
    380
    While Submission fails...

    Status "Cannot connect to server"
     
  9. Fuzzfas

    Fuzzfas Registered Member

    Joined:
    Jun 24, 2007
    Posts:
    2,753
    Yes, the 2MB limit is unfortunate... In such cases, the only way is to send it via email (zipped).

    Don't be sorry... I wish Twister didn't have so many false positives... It's not your fault.
     
  10. Fuzzfas

    Fuzzfas Registered Member

    Joined:
    Jun 24, 2007
    Posts:
    2,753
    Are you sure your firewall isn't blocking it? In my case, i just tested to submit something and it did. For online submissions, if i remember well, you need to give permission to Twister.exe, port 80 outbound.
     
  11. bryanjoe

    bryanjoe Registered Member

    Joined:
    Feb 23, 2006
    Posts:
    380
    Still unable to upload. Even though i have disabled CIS..
    I have no problem with the usual liveupdate..
     
  12. Fuzzfas

    Fuzzfas Registered Member

    Joined:
    Jun 24, 2007
    Posts:
    2,753
    I have CIS too and submission works fine... Try to put all files in a folder, zip it and send it to Mr. Chu's mail... I don't know what to say. Live Update and submission use different internet access btw, if i remember correctly. The update uses filup.exe. The submission must be using Twister.exe. Maybe your ISP has dns problems towards China at this moment?
     
  13. bryanjoe

    bryanjoe Registered Member

    Joined:
    Feb 23, 2006
    Posts:
    380
    nevermind i will try later.
    thanks
     
  14. Fuzzfas

    Fuzzfas Registered Member

    Joined:
    Jun 24, 2007
    Posts:
    2,753

    In case you haven't rebooted since the last program update yesterday, try rebooting too before trying to re-submit them again. You never know...
     
  15. roger_m

    roger_m Registered Member

    Joined:
    Jan 25, 2009
    Posts:
    8,626
    Well it did disable and relaunch itself, but it's still the old version! Also I had to disable live update, as when live update ran it started downloading the updated version again. So I disabled it so it doesn't download and install at 45 meg update every three hours.

    Yes I was thinking I might have to do that, but I'll see what happens when I reboot. Since I always have many web pages open and several programs running I only ever reboot when Windows stops working and is no longer usable and I "have" to reboot.
     
  16. Taliscicero

    Taliscicero Registered Member

    Joined:
    Feb 7, 2008
    Posts:
    1,439
    If anyone needs to submit any FP's its more easy to just RAR them up and send them to Bright Chu, since he will prioritise them for you, hes nice like that :D

    Also good knews for twister update!
     
  17. bryanjoe

    bryanjoe Registered Member

    Joined:
    Feb 23, 2006
    Posts:
    380

    i uninstalled SSM, Threatfire, CIS and AppGuard...
    but upload Online FPs still fail to connect....

    Don't think is firewall problem...cos i have tried with PCTools and now OA free...
     
  18. bryanjoe

    bryanjoe Registered Member

    Joined:
    Feb 23, 2006
    Posts:
    380
  19. bryanjoe

    bryanjoe Registered Member

    Joined:
    Feb 23, 2006
    Posts:
    380
    this is my settings ...
     

    Attached Files:

  20. bryanjoe

    bryanjoe Registered Member

    Joined:
    Feb 23, 2006
    Posts:
    380
    anyone uses this?
     

    Attached Files:

  21. Fuzzfas

    Fuzzfas Registered Member

    Joined:
    Jun 24, 2007
    Posts:
    2,753
    Bryan Joe, i don't know what to say... If it isn't the firewall, it must be some conflict. I don't think it's the settings, but anyway, you can try mine.

    http://img23.imageshack.us/img23/866/86732543bi1.png

    The upload works for me.

    http://img22.imageshack.us/img22/9962/79679030dy8.png

    If all fails, you can uninstall and reinstall the new installer and see if things run better. In the meantime, send the false positive via email to Mr. Chu.

    BTW, most probably the reason that you get so many false positives, is that you have enabled the "Enable virus infection disease" and "enabled virus immunity system". They both warn on inceased number of false positives and that it's not reccommended. Same for the extended database. Try disabling them temporarily and do a new scan. See if false positives are less. Twister is already paranoid enough at default settings.

    I 've never had to use it... fortunately.
     
    Last edited: Feb 5, 2009
  22. Fuzzfas

    Fuzzfas Registered Member

    Joined:
    Jun 24, 2007
    Posts:
    2,753
    Well, BryanJoe, i installed the Gimp over Shadow Defender, and soon enough, about 172 false positives, ALL of them flagged as Trojan Zzzeeelatiiin of course.

    So i uploaded them:

    http://img7.imageshack.us/img7/7102/85621589mc2.png

    Practically, it's every plug in + the main gimp executable. Now i will also send them via email (the gimp.exe is over 2MB), just to make sure this will attract their attention.
     
  23. Fuzzfas

    Fuzzfas Registered Member

    Joined:
    Jun 24, 2007
    Posts:
    2,753
    I have sent the first mail to Mr. Chu, i am sending a second with all samples to the "official" false positive email...

    I must say, BryanJoe, you 've hit the jackpot with this one. You are officially the new false positive champion in a single Twister scan!

    http://img518.imageshack.us/img518/9820/55597297cl7.png

    Zhelatin baby!

    Honestly, i haven't searched what this Zhelatin does. But it's the most common false positive in Twister. If i were them, since they obviously can't fix it, i would remove its signature all together and if someone gets infected by the REAL Zhelatin, well, bad luck.

    The worse thing, is that i am afraid , dear Bryan Joe, that it can happen like with Abiword. And so, they will fix this now, but when the next Gimp comes out, it may flag AGAIN all new exes as Zhelatin. And sending 170+ files everytime, isn't fun.

    Mr. Chu, please do something about Zhelatin! :thumbd: Once and for all!

    I want to see new names in false positive alerts! :D
     
  24. Miyagi

    Miyagi Registered Member

    Joined:
    Mar 12, 2005
    Posts:
    426
    Location:
    None
    From the Filseclab website (Chinese page) using Google translation:

    Second edition V7 R3 (7.32) new features (2009.02.04):

    - Solve some system to monitor state of network access to share files slow situation.
    - VISTA enhanced under FAT/FAT32 file system support.
    - To further upgrade the kernel to optimize efficiency.
    - To improve the auto-update feature to achieve complete silence.
    - To improve the registry monitoring of TXT / INI associated alarm sensitivity.
    - Optimization of all the virus database and re-packaging.
     
  25. Fuzzfas

    Fuzzfas Registered Member

    Joined:
    Jun 24, 2007
    Posts:
    2,753
    Thank you Miyagi! I wish they were informing more, us , poor english speaking users, too... I don't understand the first one. Anyway, better than nothing.
     
Thread Status:
Not open for further replies.
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.