Jump to content


Photo

False Positive: WTW


  • Please log in to reply
6 replies to this topic

#1 Paweł Smotryś

Paweł Smotryś

    Active Member

  • Tester
  • PipPipPip
  • 90 posts
  • LocationNetherlands
  • OS:Windows 8.1 x64
  • AV:Emsisoft Anti-Malware
  • HIPS:Online Armor Premium
  • Other:HitmanPro

Posted 13 June 2012 - 05:30 AM

EAM's BB module detects WTW as spyware, but it is one of most popular polish instant messengers. Can it be whitelisted?
http://wtw.im/

Posted Image


#2 Arief Prabowo

Arief Prabowo

    Forum Veteran

  • Emsisoft Employee
  • 2797 posts
  • LocationIndonesia

Posted 13 June 2012 - 05:50 AM

Maybe they have an unexpected behavior, so it trigger the Behavior Blocker. If you trust the application just mark them as Allow.

Best regards,

Arief Prabowo [Research]

Emsisoft Team - http://www.emsisoft.com


#3 Paweł Smotryś

Paweł Smotryś

    Active Member

  • Tester
  • PipPipPip
  • 90 posts
  • LocationNetherlands
  • OS:Windows 8.1 x64
  • AV:Emsisoft Anti-Malware
  • HIPS:Online Armor Premium
  • Other:HitmanPro

Posted 13 June 2012 - 08:04 AM

That's what I did, but it can confuse new users, so maybe it is possible to whitelist this app?

Posted Image


#4 Arief Prabowo

Arief Prabowo

    Forum Veteran

  • Emsisoft Employee
  • 2797 posts
  • LocationIndonesia

Posted 13 June 2012 - 08:24 AM

Which files are causing the alerts? Please attach the file and the alert screenshots.

Best regards,

Arief Prabowo [Research]

Emsisoft Team - http://www.emsisoft.com


#5 Paweł Smotryś

Paweł Smotryś

    Active Member

  • Tester
  • PipPipPip
  • 90 posts
  • LocationNetherlands
  • OS:Windows 8.1 x64
  • AV:Emsisoft Anti-Malware
  • HIPS:Online Armor Premium
  • Other:HitmanPro

Posted 13 June 2012 - 09:24 AM

Looks like all the alerts are generated by main module - wtw.exe - take a look at the attached images and IDS log.

Posted Image


#6 Arief Prabowo

Arief Prabowo

    Forum Veteran

  • Emsisoft Employee
  • 2797 posts
  • LocationIndonesia

Posted 13 June 2012 - 09:56 AM

Ok thanks for the info. I will look into it.

Best regards,

Arief Prabowo [Research]

Emsisoft Team - http://www.emsisoft.com


#7 Paweł Smotryś

Paweł Smotryś

    Active Member

  • Tester
  • PipPipPip
  • 90 posts
  • LocationNetherlands
  • OS:Windows 8.1 x64
  • AV:Emsisoft Anti-Malware
  • HIPS:Online Armor Premium
  • Other:HitmanPro

Posted 13 June 2012 - 04:54 PM

It is good now. Thanks!

Posted Image





0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users