<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Improve Cloud Detection and SONAR in Product Suggestions</title>
    <link>http://community.norton.com/t5/Product-Suggestions/Improve-Cloud-Detection-and-SONAR/m-p/419464#M1663</link>
    <description>&lt;p&gt;Thanks Nico, the file is indeed malicious.&lt;/p&gt;&lt;br /&gt;
&lt;div&gt;It drops a file which modifies the host file and attempts to download other malicious files. Detection for both dropper and dropped files has been added as Trojan.Horse.&lt;/div&gt;&lt;br /&gt;
&lt;div&gt;JohnM&lt;/div&gt;</description>
    <pubDate>Tue, 22 Mar 2011 08:33:00 GMT</pubDate>
    <dc:creator>JohnM</dc:creator>
    <dc:date>2011-03-22T08:33:00Z</dc:date>
    <item>
      <title>Improve Cloud Detection and SONAR</title>
      <link>http://community.norton.com/t5/Product-Suggestions/Improve-Cloud-Detection-and-SONAR/m-p/415570#M1658</link>
      <description>&lt;p&gt;Cloud detection (such as WS.Repuration.1, Suspicious.Cloud.x, etc.) are used only directly after download or first access it. After that - restoring from Quarantine, or unpack it again - Norton is not recognize a threat in this file. What is the regognize algorithms? First - delete all, after - use as long as you want. Threats if they are recognized as bad - must be recognized as bad untill next update (engine, definitions, behav. or heur. engines, cloud information).&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;&lt;img src="http://community.norton.com/t5/image/serverpage/image-id/13820i5527D51D4C45ADA3/image-size/original?v=mpbl-1&amp;amp;px=-1" border="0" alt="u3.png" title="u3.png" align="center" /&gt;&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;Although bad Cloud information - threat was able to start own procedures:&lt;/p&gt;
&lt;p&gt;1) downloaded 1 MB file from the Internet&lt;/p&gt;
&lt;p&gt;2) fully rewrited hosts file and write in it about 10 own entries&amp;nbsp;(!not recognized by NPE!)&lt;/p&gt;
&lt;p&gt;3) maked Task Manager disabled via the appropriate registry item (recognized by NPE, !but can't be fixed!)&lt;/p&gt;
&lt;p&gt;4) maked Command Prompt disabled (!not recognized by NPE!)&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;&lt;img src="http://community.norton.com/t5/image/serverpage/image-id/13816iA2C283B8FF13C6C3/image-size/original?v=mpbl-1&amp;amp;px=-1" border="0" alt="u1.png" title="u1.png" align="center" /&gt;&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;5) other&amp;nbsp;(not recognized by NPE)&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;&lt;img src="http://community.norton.com/t5/image/serverpage/image-id/13818iB3946C806F47A6F4/image-size/original?v=mpbl-1&amp;amp;px=-1" border="0" alt="u2.png" title="u2.png" align="center" /&gt;&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;Where SONAR was? Where it looked? So many malware actions from must-be-restricted-in-actions bad reputation file!&lt;/p&gt;
&lt;p&gt;Previously I saw many malware that SONAR blocks at once. Here I saw no bahaviour monitoring in this case.&lt;/p&gt;
&lt;p&gt;May be this sample uses slightly new model of infection tactics&lt;/p&gt;
&lt;p&gt;How many (different&amp;nbsp;tactics) and (actions of the same tactics)&amp;nbsp;samples can I write to make product saw and protect against this? :)) Are there in company a specialists of different malware actions?&amp;nbsp;You are analysing thousands malware samples everyday, you know how actions can be executed in Windows. So why you can't recognize suspicious actions or at least display to user this list of actions and processes&amp;nbsp;that made them like Windows Defender (at least on WinXP does and better)?&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;Please! Improve your product! Sophisticated to end users? Make an option to turn off and on it (make off by default)&lt;/p&gt;
&lt;p&gt;Lets start to fight agains malware together!&amp;nbsp;Display user messages about system changes made and make at once suspicious sample auto-submissions!&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;Missed threats at sendspace and rapidshare. &amp;nbsp;&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;&lt;em&gt;---&lt;/em&gt;&lt;/p&gt;
&lt;p&gt;&lt;em&gt;NIS 18.5.0.125 (fully updated)&lt;/em&gt;&lt;/p&gt;
&lt;p&gt;&lt;em&gt;WinXP Prof. SP3 32bit x86&lt;/em&gt;&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;&lt;em&gt;[Edited Idea subject for clarity and removed links to third-party sites as per the &lt;a href="http://community.norton.com/t5/About-This-Community/Participation-Guidelines/m-p/5/message-uid/5#U5" target="_self"&gt;Participation Guidelines &lt;/a&gt;and &lt;a href="http://community.norton.com/t5/About-This-Community/Terms-of-Service/m-p/1#U1" target="_self"&gt;Terms of Service&lt;/a&gt;]&lt;/em&gt;&lt;/p&gt;</description>
      <pubDate>Tue, 22 Mar 2011 02:46:34 GMT</pubDate>
      <guid>http://community.norton.com/t5/Product-Suggestions/Improve-Cloud-Detection-and-SONAR/m-p/415570#M1658</guid>
      <dc:creator>Niko233</dc:creator>
      <dc:date>2011-03-22T02:46:34Z</dc:date>
    </item>
    <item>
      <title>Re: Improve Cloud Detection and SONAR</title>
      <link>http://community.norton.com/t5/Product-Suggestions/Improve-Cloud-Detection-and-SONAR/m-p/418974#M1659</link>
      <description>&lt;p&gt;Hi Niko233! &amp;nbsp;I am happy you took the time to give NIS product recommendations. &amp;nbsp;Are you saying that the logic behind reputation scanning needs to be re-thought? &amp;nbsp;If so, let me see if a Symantec employee who works on that feature can respond. &amp;nbsp;&lt;/p&gt;</description>
      <pubDate>Mon, 21 Mar 2011 17:01:49 GMT</pubDate>
      <guid>http://community.norton.com/t5/Product-Suggestions/Improve-Cloud-Detection-and-SONAR/m-p/418974#M1659</guid>
      <dc:creator>RebeccaO</dc:creator>
      <dc:date>2011-03-21T17:01:49Z</dc:date>
    </item>
    <item>
      <title>Re: Improve Cloud Detection and SONAR</title>
      <link>http://community.norton.com/t5/Product-Suggestions/Improve-Cloud-Detection-and-SONAR/m-p/419310#M1660</link>
      <description>&lt;p&gt;Alright, if I do not forget it, I will tell you.&lt;/p&gt;&lt;p&gt;And if you submit malware sample on that I posted non-direct link in this idea message to Norton team - it will be great! :)&lt;/p&gt;</description>
      <pubDate>Tue, 22 Mar 2011 01:03:21 GMT</pubDate>
      <guid>http://community.norton.com/t5/Product-Suggestions/Improve-Cloud-Detection-and-SONAR/m-p/419310#M1660</guid>
      <dc:creator>Niko233</dc:creator>
      <dc:date>2011-03-22T01:03:21Z</dc:date>
    </item>
    <item>
      <title>Re: Improve Cloud Detection and SONAR</title>
      <link>http://community.norton.com/t5/Product-Suggestions/Improve-Cloud-Detection-and-SONAR/m-p/419408#M1661</link>
      <description>&lt;p&gt;Tracking #19582565&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;&amp;gt;microsoftoffice2010activatorkeygenbythecrew.exe Our automation was unable&lt;br&gt;to identify any malicious content in this submission. &lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;Can't execute this under Virtual machine Environment or some test software and see why SONAR detect this? :))))&lt;/p&gt;&lt;p&gt;Than improve automation detection!!! I open an America? Nothing at all! And I think that just sometimes a brain can help to organize, create and improve anything. Head just need to be in use to reach something, not for wear a hat only. Why to be so frozen, so classic, trivial and non-original?&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;By the way - how many antiviruses have Sandbox feature for users? Not a few.&lt;/p&gt;&lt;p&gt;Symantec till now can't provide this feature for itself automation detectors and users. Bad.&lt;/p&gt;</description>
      <pubDate>Tue, 22 Mar 2011 04:13:22 GMT</pubDate>
      <guid>http://community.norton.com/t5/Product-Suggestions/Improve-Cloud-Detection-and-SONAR/m-p/419408#M1661</guid>
      <dc:creator>Niko233</dc:creator>
      <dc:date>2011-03-22T04:13:22Z</dc:date>
    </item>
    <item>
      <title>Re: Improve Cloud Detection and SONAR</title>
      <link>http://community.norton.com/t5/Product-Suggestions/Improve-Cloud-Detection-and-SONAR/m-p/419452#M1662</link>
      <description>&lt;p&gt;Different results: my PC vs. Symantec &amp;lt;on&amp;gt; virustotal.com&lt;/p&gt;&lt;p&gt;&lt;a target="_blank" href="http://community.norton.com/t5/Norton-Internet-Security-Norton/Different-results-my-PC-vs-Symantec-virustotal-com/td-p/419440"&gt;http://community.norton.com/t5/Norton-Internet-Security-Norton/Different-results-my-PC-vs-Symantec-virustotal-com/td-p/419440&lt;/a&gt;&lt;/p&gt;</description>
      <pubDate>Tue, 22 Mar 2011 06:07:27 GMT</pubDate>
      <guid>http://community.norton.com/t5/Product-Suggestions/Improve-Cloud-Detection-and-SONAR/m-p/419452#M1662</guid>
      <dc:creator>Niko233</dc:creator>
      <dc:date>2011-03-22T06:07:27Z</dc:date>
    </item>
    <item>
      <title>Re: Improve Cloud Detection and SONAR</title>
      <link>http://community.norton.com/t5/Product-Suggestions/Improve-Cloud-Detection-and-SONAR/m-p/419464#M1663</link>
      <description>&lt;p&gt;Thanks Nico, the file is indeed malicious.&lt;/p&gt;&lt;br /&gt;
&lt;div&gt;It drops a file which modifies the host file and attempts to download other malicious files. Detection for both dropper and dropped files has been added as Trojan.Horse.&lt;/div&gt;&lt;br /&gt;
&lt;div&gt;JohnM&lt;/div&gt;</description>
      <pubDate>Tue, 22 Mar 2011 08:33:00 GMT</pubDate>
      <guid>http://community.norton.com/t5/Product-Suggestions/Improve-Cloud-Detection-and-SONAR/m-p/419464#M1663</guid>
      <dc:creator>JohnM</dc:creator>
      <dc:date>2011-03-22T08:33:00Z</dc:date>
    </item>
    <item>
      <title>Re: Improve Cloud Detection and SONAR</title>
      <link>http://community.norton.com/t5/Product-Suggestions/Improve-Cloud-Detection-and-SONAR/m-p/419498#M1664</link>
      <description>&lt;p&gt;Thanks on comments, but I want to this sample been analyzed as slightly new threats infection methods - to add this into SONAR. It is download trusted file and may be use it in giving it own malware actions. the tree of processes need to be detected&amp;nbsp;(constructed) and analyzed for initiation process for malware. That is I really want. Today is no way to definitions as main component, it is only can help to heart of AV: behaviour monitor (SONAR in Norton).&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;Where are the such times?&lt;/p&gt;
&lt;p&gt;&lt;a href="http://www.youtube.com/watch?v=EjWh0AJh58M" target="_blank"&gt;http://www.youtube.com/watch?v=EjWh0AJh58M&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;Fragment from 29 min 30sec to 30:30&lt;/p&gt;
&lt;p&gt;How&amp;nbsp;joyfully and elegant it was!! :)&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;---&lt;/p&gt;
&lt;p&gt;My thoughts:&lt;/p&gt;
&lt;p&gt;Every respectable by itself Virus must be hidden by rootkit&lt;/p&gt;
&lt;p&gt;Every&amp;nbsp;respectable by itself Antivirus must have behaviour monitor component to detect malware actions of new/unknown threats.&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;&lt;font size="1" color="#ff0000"&gt;[edit: Fixed posting error.]&lt;/font&gt;&lt;/strong&gt;&lt;/p&gt;</description>
      <pubDate>Wed, 23 Mar 2011 14:54:03 GMT</pubDate>
      <guid>http://community.norton.com/t5/Product-Suggestions/Improve-Cloud-Detection-and-SONAR/m-p/419498#M1664</guid>
      <dc:creator>Niko233</dc:creator>
      <dc:date>2011-03-23T14:54:03Z</dc:date>
    </item>
  </channel>
</rss>

