<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Harmless Risk...???? in Norton Internet Security / Norton AntiVirus</title>
    <link>http://community.norton.com/t5/Norton-Internet-Security-Norton/Harmless-Risk/m-p/34728#M14988</link>
    <description>&lt;p&gt; &lt;/p&gt;&lt;hr&gt;&lt;p&gt;Reese Wrote:&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;Shridhar,&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;I passed these two files past our SONAR team and they have identified them as false positive detections. Corrected definitions should be available some time tomorrow (10/22).&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;hr&gt;Hi Reese . &lt;strong&gt;I just checked those files again(on 10/24) and found that ,still they are getting detected by SONAR&lt;/strong&gt;.&lt;p&gt; &lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;This time the file is &lt;strong&gt;shell_inst.exe  &lt;/strong&gt;instead of &lt;strong&gt;Safemode_inst.exe&lt;/strong&gt;.&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;But the main thing is  One False Positive is still there there.&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;Please try and correct it!!!!!!!&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;Hre is the link for the file at &lt;strong&gt;Virus total &lt;/strong&gt;:&lt;a target="_blank" href="http://www.virustotal.com/analisis/5b18559d7d18bda98bd68b3b40614ced"&gt;http://www.virustotal.com/analisis/5b18559d7d18bda98bd68b3b40614ced&lt;/a&gt;&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;and I have again submitted the same file to &lt;strong&gt;&lt;span&gt;Symantec Security Response&lt;/span&gt;&lt;/strong&gt; with the tracking no. &lt;strong&gt;&lt;span class="HcCDpe"&gt;#9994234.&lt;/span&gt;&lt;/strong&gt;&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;div class="message-edit-history"&gt;&lt;span class="edit-author"&gt;Message Edited by Shridhar on &lt;/span&gt;&lt;span class="local-date"&gt;10-24-2008&lt;/span&gt;&lt;span class="local-time"&gt; 11:08 PM&lt;/span&gt;&lt;/div&gt;&lt;div class="message-edit-history"&gt;&lt;span class="edit-author"&gt;Message Edited by Shridhar on &lt;/span&gt;&lt;span class="local-date"&gt;10-24-2008&lt;/span&gt;&lt;span class="local-time"&gt; 11:09 PM&lt;/span&gt;&lt;/div&gt;</description>
    <pubDate>Fri, 24 Oct 2008 17:39:23 GMT</pubDate>
    <dc:creator>Shridhar</dc:creator>
    <dc:date>2008-10-24T17:39:23Z</dc:date>
    <item>
      <title>Harmless Risk...????</title>
      <link>http://community.norton.com/t5/Norton-Internet-Security-Norton/Harmless-Risk/m-p/33192#M13856</link>
      <description>&lt;p&gt;I have  a disc which contains two risks ,which were detected by SONAR.&lt;/p&gt;&lt;p&gt;Currently I have NIS 2009.Before having NIS 2009 I used to install the disc without any threat notice shown by  Norton,and even when I did not have Norton. &lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;&lt;strong&gt;Now, I don't disagree that  the files are risks or Viruses &lt;/strong&gt;&lt;/p&gt;&lt;p&gt;the fact is, if they are security threats ,why they did not cause any trouble(it may be smaller or bigger)to my system ?&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;My system was working perfectly in above discussed cases also without showing any sign of misbehaviour or slowdowns.&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;&lt;strong&gt;I trust Norton hence I don't believe so..........but are they False Positives ?  &lt;/strong&gt;&lt;/p&gt;</description>
      <pubDate>Sun, 19 Oct 2008 09:38:40 GMT</pubDate>
      <guid>http://community.norton.com/t5/Norton-Internet-Security-Norton/Harmless-Risk/m-p/33192#M13856</guid>
      <dc:creator>Shridhar</dc:creator>
      <dc:date>2008-10-19T09:38:40Z</dc:date>
    </item>
    <item>
      <title>Re: Harmless Risk...????</title>
      <link>http://community.norton.com/t5/Norton-Internet-Security-Norton/Harmless-Risk/m-p/33196#M13859</link>
      <description>Send the Files to symantec Security Response: &lt;a target="_blank" href="https://submit.symantec.com/websubmit/retail.cgi"&gt;https://submit.symantec.com/websubmit/retail.cgi&lt;/a&gt;.</description>
      <pubDate>Sun, 19 Oct 2008 11:09:47 GMT</pubDate>
      <guid>http://community.norton.com/t5/Norton-Internet-Security-Norton/Harmless-Risk/m-p/33196#M13859</guid>
      <dc:creator>Floating_Red</dc:creator>
      <dc:date>2008-10-19T11:09:47Z</dc:date>
    </item>
    <item>
      <title>Re: Harmless Risk...????</title>
      <link>http://community.norton.com/t5/Norton-Internet-Security-Norton/Harmless-Risk/m-p/33199#M13862</link>
      <description>&lt;p&gt;Hi Shirdhar&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;If the risks are detected by SONAR, but are not in the Symantec Virus Definition base, then possibly they are benign.&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;As Floating_Red suggests, I would ask you submit the files to &lt;a target="_blank" href="https://submit.symantec.com/websubmit/retail.cgi"&gt;Symantec Security Response&lt;/a&gt; for analysis.&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;Can you let us know the results, thanks.&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;Edit: As an exercise, can you upload the files to &lt;a target="_blank" href="http://www.virustotal.com/"&gt;Virus Total&lt;/a&gt;, and let us know if other vendors are picking them up as security risks, thanks.&lt;/p&gt;&lt;div class="message-edit-history"&gt;&lt;span class="edit-author"&gt;Message Edited by johna on &lt;/span&gt;&lt;span class="local-date"&gt;10-19-2008&lt;/span&gt;&lt;span class="local-time"&gt; 09:44 PM&lt;/span&gt;&lt;/div&gt;</description>
      <pubDate>Sun, 19 Oct 2008 11:44:26 GMT</pubDate>
      <guid>http://community.norton.com/t5/Norton-Internet-Security-Norton/Harmless-Risk/m-p/33199#M13862</guid>
      <dc:creator>johna</dc:creator>
      <dc:date>2008-10-19T11:44:26Z</dc:date>
    </item>
    <item>
      <title>Re: Harmless Risk...????</title>
      <link>http://community.norton.com/t5/Norton-Internet-Security-Norton/Harmless-Risk/m-p/33201#M13864</link>
      <description>&lt;blockquote&gt;&lt;hr&gt;johna wrote:&lt;br&gt;&lt;p&gt;If the risks are detected by SONAR, but are not in the Symantec Virus Definition base, then possibly they are benign.&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;As Floating_Red suggests, I would ask you submit the files to &lt;a target="_blank" href="https://submit.symantec.com/websubmit/retail.cgi"&gt;Symantec Security Response&lt;/a&gt; for analysis.&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;Can you let us know the results, thanks.&lt;/p&gt;&lt;div class="message-edit-history"&gt;&lt;span class="edit-author"&gt;Message Edited by johna on &lt;/span&gt;&lt;span class="local-date"&gt;10-19-2008&lt;/span&gt;&lt;span class="local-time"&gt; 09:38 PM&lt;/span&gt;&lt;/div&gt;&lt;hr&gt;&lt;/blockquote&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;Thanks for Editing your Message; now he has got two people &amp;quot;asking&amp;quot; the Thread-Starter to Submit the Files to s.S.R..  :smileysurprised:&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;Can you tell us what your &lt;em&gt;Advanced Heuristic Protection&lt;/em&gt; is on, which can be located in the &lt;em&gt;Computer Settings&lt;/em&gt;.&lt;/p&gt;</description>
      <pubDate>Sun, 19 Oct 2008 11:44:26 GMT</pubDate>
      <guid>http://community.norton.com/t5/Norton-Internet-Security-Norton/Harmless-Risk/m-p/33201#M13864</guid>
      <dc:creator>Floating_Red</dc:creator>
      <dc:date>2008-10-19T11:44:26Z</dc:date>
    </item>
    <item>
      <title>Re: Harmless Risk...????</title>
      <link>http://community.norton.com/t5/Norton-Internet-Security-Norton/Harmless-Risk/m-p/33202#M13865</link>
      <description>&lt;p&gt;Thanks Floating_Red&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;Will be interesting to see what Virus Total comes up with.&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;John&lt;/p&gt;&lt;div class="message-edit-history"&gt;&lt;span class="edit-author"&gt;Message Edited by johna on &lt;/span&gt;&lt;span class="local-date"&gt;10-19-2008&lt;/span&gt;&lt;span class="local-time"&gt; 09:49 PM&lt;/span&gt;&lt;/div&gt;</description>
      <pubDate>Sun, 19 Oct 2008 11:49:51 GMT</pubDate>
      <guid>http://community.norton.com/t5/Norton-Internet-Security-Norton/Harmless-Risk/m-p/33202#M13865</guid>
      <dc:creator>johna</dc:creator>
      <dc:date>2008-10-19T11:49:51Z</dc:date>
    </item>
    <item>
      <title>Re: Harmless Risk...????</title>
      <link>http://community.norton.com/t5/Norton-Internet-Security-Norton/Harmless-Risk/m-p/33234#M13897</link>
      <description>&lt;p&gt; &lt;/p&gt;&lt;hr&gt;Floating_Red wrote:&lt;p&gt; &lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt; Can you tell us what your &lt;em&gt;Advanced Heuristic Protection&lt;/em&gt; is on, which can be located in the &lt;em&gt;Computer Settings&lt;/em&gt;.&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;hr&gt;Hello Floating_Red&lt;p&gt; &lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;I have got Advanced Heuristic Protection as &lt;em&gt;&lt;strong&gt;Aggresive &lt;/strong&gt;&lt;/em&gt;.Every security option that Norton has got under &lt;em&gt;&lt;strong&gt;Settings&lt;/strong&gt;&lt;/em&gt; option is HIGH on my computer.&lt;/p&gt;&lt;p&gt; &lt;/p&gt;</description>
      <pubDate>Sun, 19 Oct 2008 13:08:37 GMT</pubDate>
      <guid>http://community.norton.com/t5/Norton-Internet-Security-Norton/Harmless-Risk/m-p/33234#M13897</guid>
      <dc:creator>Shridhar</dc:creator>
      <dc:date>2008-10-19T13:08:37Z</dc:date>
    </item>
    <item>
      <title>Re: Harmless Risk...????</title>
      <link>http://community.norton.com/t5/Norton-Internet-Security-Norton/Harmless-Risk/m-p/33235#M13898</link>
      <description>Aggressive can give you FP's but it has not for me. I would rather have FP's then be less secure.</description>
      <pubDate>Sun, 19 Oct 2008 13:10:42 GMT</pubDate>
      <guid>http://community.norton.com/t5/Norton-Internet-Security-Norton/Harmless-Risk/m-p/33235#M13898</guid>
      <dc:creator>Dieselman743</dc:creator>
      <dc:date>2008-10-19T13:10:42Z</dc:date>
    </item>
    <item>
      <title>Re: Harmless Risk...????</title>
      <link>http://community.norton.com/t5/Norton-Internet-Security-Norton/Harmless-Risk/m-p/33237#M13900</link>
      <description>&lt;p&gt; Hi Shridhar&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;Actually, as far as I know, aggressive heuristics only applies to scans and auto protect, not SONAR.&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;Did you upload the files to Virus Total?&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;Thanks.&lt;/p&gt;&lt;div class="message-edit-history"&gt;&lt;span class="edit-author"&gt;Message Edited by johna on &lt;/span&gt;&lt;span class="local-date"&gt;10-19-2008&lt;/span&gt;&lt;span class="local-time"&gt; 11:25 PM&lt;/span&gt;&lt;/div&gt;</description>
      <pubDate>Sun, 19 Oct 2008 13:25:07 GMT</pubDate>
      <guid>http://community.norton.com/t5/Norton-Internet-Security-Norton/Harmless-Risk/m-p/33237#M13900</guid>
      <dc:creator>johna</dc:creator>
      <dc:date>2008-10-19T13:25:07Z</dc:date>
    </item>
    <item>
      <title>Re: Harmless Risk...????</title>
      <link>http://community.norton.com/t5/Norton-Internet-Security-Norton/Harmless-Risk/m-p/33239#M13902</link>
      <description>I will be applying it shortly and i'll let you know what happens andi've submitted it to Symantec as you said.</description>
      <pubDate>Sun, 19 Oct 2008 13:27:17 GMT</pubDate>
      <guid>http://community.norton.com/t5/Norton-Internet-Security-Norton/Harmless-Risk/m-p/33239#M13902</guid>
      <dc:creator>Shridhar</dc:creator>
      <dc:date>2008-10-19T13:27:17Z</dc:date>
    </item>
    <item>
      <title>Re: Harmless Risk...????</title>
      <link>http://community.norton.com/t5/Norton-Internet-Security-Norton/Harmless-Risk/m-p/33245#M13907</link>
      <description>&lt;blockquote&gt;&lt;hr&gt;Shridhar wrote:&lt;br&gt;&lt;p&gt;I have  a disc which contains two risks ,which were detected by SONAR.&lt;/p&gt;&lt;p&gt;Currently I have NIS 2009.Before having NIS 2009 I used to install the disc without any threat notice shown by  Norton,and even when I did not have Norton. &lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;&lt;strong&gt;&lt;br&gt;&lt;/strong&gt;&lt;/p&gt;&lt;p&gt;&lt;u&gt;&lt;em&gt;&lt;strong&gt;the fact is, if they are security threats ,why they did not cause any trouble(it may be smaller or bigger)to my system ?&lt;/strong&gt;&lt;/em&gt;&lt;/u&gt;&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;&lt;u&gt;&lt;em&gt;&lt;strong&gt;My system was working perfectly in above discussed cases also without showing any sign of misbehaviour or slowdowns.&lt;/strong&gt;&lt;/em&gt;&lt;/u&gt;&lt;/p&gt;&lt;p&gt;&lt;u&gt;&lt;em&gt;&lt;strong&gt; &lt;/strong&gt;&lt;/em&gt;&lt;/u&gt;&lt;/p&gt;&lt;p&gt;&lt;strong&gt;I trust Norton hence I don't believe so..........but are they False Positives ?  &lt;/strong&gt;&lt;/p&gt;&lt;hr&gt;&lt;/blockquote&gt;&lt;p&gt;It is extremely hard to get a &amp;quot;full&amp;quot; infection nowadays with all the Windows Patches. I had 5 instances of Vundo on my computer, according to N360, but there were no pop-ups, my desktop background stayed the same, and nothing suspicious really happened; high cpu usage, etc, except for a rundll in my Task Manager. &lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt; &lt;/p&gt;</description>
      <pubDate>Sun, 19 Oct 2008 13:34:16 GMT</pubDate>
      <guid>http://community.norton.com/t5/Norton-Internet-Security-Norton/Harmless-Risk/m-p/33245#M13907</guid>
      <dc:creator>Tech0utsider</dc:creator>
      <dc:date>2008-10-19T13:34:16Z</dc:date>
    </item>
    <item>
      <title>Re: Harmless Risk...????</title>
      <link>http://community.norton.com/t5/Norton-Internet-Security-Norton/Harmless-Risk/m-p/33246#M13908</link>
      <description>&lt;p&gt;Hi Shridhar&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;It normally takes a couple of days to get a reply from SSR, let us know.&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;Thanks!&lt;/p&gt;&lt;p&gt; &lt;/p&gt;</description>
      <pubDate>Sun, 19 Oct 2008 13:35:31 GMT</pubDate>
      <guid>http://community.norton.com/t5/Norton-Internet-Security-Norton/Harmless-Risk/m-p/33246#M13908</guid>
      <dc:creator>johna</dc:creator>
      <dc:date>2008-10-19T13:35:31Z</dc:date>
    </item>
    <item>
      <title>Re: Harmless Risk...????</title>
      <link>http://community.norton.com/t5/Norton-Internet-Security-Norton/Harmless-Risk/m-p/33248#M13910</link>
      <description>thanks for quick replies</description>
      <pubDate>Sun, 19 Oct 2008 13:39:06 GMT</pubDate>
      <guid>http://community.norton.com/t5/Norton-Internet-Security-Norton/Harmless-Risk/m-p/33248#M13910</guid>
      <dc:creator>Shridhar</dc:creator>
      <dc:date>2008-10-19T13:39:06Z</dc:date>
    </item>
    <item>
      <title>Re: Harmless Risk...????</title>
      <link>http://community.norton.com/t5/Norton-Internet-Security-Norton/Harmless-Risk/m-p/33267#M13923</link>
      <description>&lt;blockquote&gt;&lt;hr&gt;johna wrote:&lt;br&gt;&lt;p&gt;Actually, as far as I know, aggressive heuristics only applies to scans and auto protect, not SONAR.&lt;/p&gt;&lt;hr&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;This does apply to S.O.N.A.R.; not sure about AutoProtect or Scans.&lt;/p&gt;&lt;/blockquote&gt;&lt;p&gt; &lt;/p&gt;</description>
      <pubDate>Sun, 19 Oct 2008 14:33:18 GMT</pubDate>
      <guid>http://community.norton.com/t5/Norton-Internet-Security-Norton/Harmless-Risk/m-p/33267#M13923</guid>
      <dc:creator>Floating_Red</dc:creator>
      <dc:date>2008-10-19T14:33:18Z</dc:date>
    </item>
    <item>
      <title>Re: Harmless Risk...????</title>
      <link>http://community.norton.com/t5/Norton-Internet-Security-Norton/Harmless-Risk/m-p/33284#M13938</link>
      <description>&lt;p&gt;Hi Floating_Red&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;Advanced heuristics certainly applies to Auto Protect and Scans,  as far as SONAR goes I'm almost certain it doesn't, let me double check to make sure.&lt;/p&gt;</description>
      <pubDate>Sun, 19 Oct 2008 16:20:19 GMT</pubDate>
      <guid>http://community.norton.com/t5/Norton-Internet-Security-Norton/Harmless-Risk/m-p/33284#M13938</guid>
      <dc:creator>johna</dc:creator>
      <dc:date>2008-10-19T16:20:19Z</dc:date>
    </item>
    <item>
      <title>Re: Harmless Risk...????</title>
      <link>http://community.norton.com/t5/Norton-Internet-Security-Norton/Harmless-Risk/m-p/33290#M13943</link>
      <description>&lt;p&gt;The one thing unmentioned that I think is vital is this:  Some security risks do not make themselves apparant.  They are written to do their maliciousness invisibly, whether it is to steal identity information or to place timebombs, they will not do anything in the current moment to make the user aware of them.  No slowdowns, no flashing messages with jokes or warnings, no obvious taking over of anything.&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;I am concerned by the number of people who say &amp;quot;I know my computer is not infected because I don't see any symptoms.&amp;quot;&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;Unfortunately, it doesn't work that way.  And that is why we need security software.&lt;/p&gt;</description>
      <pubDate>Sun, 19 Oct 2008 16:40:16 GMT</pubDate>
      <guid>http://community.norton.com/t5/Norton-Internet-Security-Norton/Harmless-Risk/m-p/33290#M13943</guid>
      <dc:creator>mijcar</dc:creator>
      <dc:date>2008-10-19T16:40:16Z</dc:date>
    </item>
    <item>
      <title>Re: Harmless Risk...????</title>
      <link>http://community.norton.com/t5/Norton-Internet-Security-Norton/Harmless-Risk/m-p/33368#M14000</link>
      <description>&lt;blockquote&gt;&lt;hr&gt;mijcar wrote:&lt;br&gt;&lt;p&gt;The one thing unmentioned that I think is vital is this:  Some security risks do not make themselves apparant.  They are written to do their maliciousness invisibly, whether it is to steal identity information or to place timebombs, they will not do anything in the current moment to make the user aware of them.  No slowdowns, no flashing messages with jokes or warnings, no obvious taking over of anything.&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;I am concerned by the number of people who say &amp;quot;I know my computer is not infected because I don't see any symptoms.&amp;quot;&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;Unfortunately, it doesn't work that way.  And that is why we need security software.&lt;/p&gt;&lt;hr&gt;&lt;/blockquote&gt;&lt;p&gt;Excellent theory; maybe that is another reason why Vundo was not so apparent on my system. &lt;/p&gt;</description>
      <pubDate>Sun, 19 Oct 2008 22:42:37 GMT</pubDate>
      <guid>http://community.norton.com/t5/Norton-Internet-Security-Norton/Harmless-Risk/m-p/33368#M14000</guid>
      <dc:creator>Tech0utsider</dc:creator>
      <dc:date>2008-10-19T22:42:37Z</dc:date>
    </item>
    <item>
      <title>Re: Harmless Risk...????</title>
      <link>http://community.norton.com/t5/Norton-Internet-Security-Norton/Harmless-Risk/m-p/33455#M14047</link>
      <description>&lt;p&gt; &lt;/p&gt;&lt;hr&gt;johna wrote:&lt;p&gt; &lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;Hi Shirdhar&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;If the risks are detected by SONAR, but are not in the Symantec Virus Definition base, then possibly they are benign.&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;As Floating_Red suggests, I would ask you submit the files to &lt;strong&gt;Symantec Security Response&lt;/strong&gt; for analysis.&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;Can you let us know the results, thanks.&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;Edit: As an exercise, can you upload the files to &lt;strong&gt;Virus Total&lt;/strong&gt;, and let us know if other vendors are picking them up as security risks, thanks.&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;hr&gt;Hi johna !!!&lt;p&gt; &lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;I have uploaded the files to&lt;strong&gt; &lt;/strong&gt;&lt;span&gt;&lt;strong&gt;Virus Total &lt;/strong&gt; &lt;/span&gt;but I they are not showing the file as risk or virus.&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;&lt;strong&gt;I repeat, the risk was shown by &lt;em&gt;SONAR &lt;/em&gt;and not by &lt;em&gt;Auto-Protect&lt;/em&gt; or &lt;em&gt;Virus Sacnner&lt;/em&gt; .&lt;/strong&gt;&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;For more information, here is the link: for one of the files-&lt;a target="_blank" href="http://www.virustotal.com/analisis/b49592101ffb00a3b97eec534a4dbd6e"&gt;http://www.virustotal.com/analisis/b49592101ffb00a3b97eec534a4dbd6e&lt;/a&gt;&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;Another file is showing the same result on the site.&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;div class="message-edit-history"&gt;&lt;span class="edit-author"&gt;Message Edited by Shridhar on &lt;/span&gt;&lt;span class="local-date"&gt;10-20-2008&lt;/span&gt;&lt;span class="local-time"&gt; 03:45 PM&lt;/span&gt;&lt;/div&gt;&lt;div class="message-edit-history"&gt;&lt;span class="edit-author"&gt;Message Edited by Shridhar on &lt;/span&gt;&lt;span class="local-date"&gt;10-20-2008&lt;/span&gt;&lt;span class="local-time"&gt; 04:19 PM&lt;/span&gt;&lt;/div&gt;&lt;div class="message-edit-history"&gt;&lt;span class="edit-author"&gt;Message Edited by Shridhar on &lt;/span&gt;&lt;span class="local-date"&gt;10-20-2008&lt;/span&gt;&lt;span class="local-time"&gt; 04:20 PM&lt;/span&gt;&lt;/div&gt;</description>
      <pubDate>Mon, 20 Oct 2008 10:50:18 GMT</pubDate>
      <guid>http://community.norton.com/t5/Norton-Internet-Security-Norton/Harmless-Risk/m-p/33455#M14047</guid>
      <dc:creator>Shridhar</dc:creator>
      <dc:date>2008-10-20T10:50:18Z</dc:date>
    </item>
    <item>
      <title>Re: Harmless Risk...????</title>
      <link>http://community.norton.com/t5/Norton-Internet-Security-Norton/Harmless-Risk/m-p/33465#M14055</link>
      <description>&lt;p&gt;Hi Shridhar&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;Try running the files again, and when SONAR blocks them, catch the name of the file detected, and it's location, and advise of same.&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;Thanks!&lt;/p&gt;</description>
      <pubDate>Mon, 20 Oct 2008 11:08:47 GMT</pubDate>
      <guid>http://community.norton.com/t5/Norton-Internet-Security-Norton/Harmless-Risk/m-p/33465#M14055</guid>
      <dc:creator>johna</dc:creator>
      <dc:date>2008-10-20T11:08:47Z</dc:date>
    </item>
    <item>
      <title>Re: Harmless Risk...????</title>
      <link>http://community.norton.com/t5/Norton-Internet-Security-Norton/Harmless-Risk/m-p/33479#M14069</link>
      <description>&lt;hr&gt;&lt;p&gt; johna wrote:&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;Hi Shridhar&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;Try running the files again, and when SONAR blocks them, catch the name of the file detected, and it's location, and advise of same.&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;Thanks!&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;hr&gt;Hi johna !!!!!!!&lt;p&gt; &lt;/p&gt;&lt;p&gt;I did what you have said above and SONAR is showing the risks namely :&lt;strong&gt;shell_inst.exe&lt;/strong&gt; and &lt;strong&gt;safemode_inst.exe &lt;/strong&gt;.&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;Their locations are  &lt;em&gt;&lt;strong&gt;c:\documents and settings\shridhar\local settings\temp\shell_inst.exe&lt;/strong&gt;&lt;/em&gt;&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;(Note :'shridhar' is the user name).&lt;/p&gt;&lt;p&gt;The other one is  in that program's folder.&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt; &lt;/p&gt;</description>
      <pubDate>Mon, 20 Oct 2008 12:27:11 GMT</pubDate>
      <guid>http://community.norton.com/t5/Norton-Internet-Security-Norton/Harmless-Risk/m-p/33479#M14069</guid>
      <dc:creator>Shridhar</dc:creator>
      <dc:date>2008-10-20T12:27:11Z</dc:date>
    </item>
    <item>
      <title>Re: Harmless Risk...????</title>
      <link>http://community.norton.com/t5/Norton-Internet-Security-Norton/Harmless-Risk/m-p/33480#M14070</link>
      <description>&lt;p&gt;Do you have any idea about this fact that Virus Total is not showing any alert but &lt;strong&gt;SONAR &lt;/strong&gt;is showing it .&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;I am still waiting for response from &lt;strong&gt;Symantec Security Respons&lt;/strong&gt;e before saying it to be a &lt;strong&gt;False Positive &lt;/strong&gt;&lt;/p&gt;&lt;div class="message-edit-history"&gt;&lt;span class="edit-author"&gt;Message Edited by Shridhar on &lt;/span&gt;&lt;span class="local-date"&gt;10-20-2008&lt;/span&gt;&lt;span class="local-time"&gt; 06:02 PM&lt;/span&gt;&lt;/div&gt;</description>
      <pubDate>Mon, 20 Oct 2008 12:32:22 GMT</pubDate>
      <guid>http://community.norton.com/t5/Norton-Internet-Security-Norton/Harmless-Risk/m-p/33480#M14070</guid>
      <dc:creator>Shridhar</dc:creator>
      <dc:date>2008-10-20T12:32:22Z</dc:date>
    </item>
  </channel>
</rss>

