Reply
lmacri
Posts: 901
Kudos: 208
Registered: ‎05-05-2009

Re: 90 heuristic threats identified on a full scan (not on safe mode) False Alarms??

[ Edited ]

Rogerror wrote:
All the 90 identified files are present on each drive. But only the "clean" Nov 5 clone is connected and on this no files/issues are identified. This suggests either the issues on the other drive are real and were generated between 5 & 9 Nov or possibly NIS 2012 was "updated" to generate falses in that period then "corrected".

Hi Rogerror:

 

Sorry, I went back and re-read your previous post in message # 8 and realized that you'd already told me that the 90 "problem" files were on your cloned drive as well.

 

Just a final thought, and this may be a complete coincidence, but Cody posted a question here a few days ago asking why Symantec had stopped delivering Intrusion Prevention updates via LiveUpdate.  I checked my LiveUpdate security history (History | Live Update) and there were no new IPS Definition updates delivered to my NIS 2011 product between Nov 5 and Nov 8, and I'm wondering now if something was the matter with some of the definition updates or exclusion lists delivered around Nov 4 that caused Symantec to temporarily suspend further updates for a few days.  If that's the case, it's odd that we didn't see more reports about false positives in the forum in the past week, but you never know.

----------

Windows Vista Home Premium 32-bit SP2 * NIS 2011 v. 18.6.0.29 * IE 9.0 * Firefox 8.0.0
HP Pavilion dv6835ca, Intel Core2Duo CPU T5550 @ 1.83 GHz, 3.0 GB RAM, NVIDIA GeForce 8400M GS

lmacri
Posts: 901
Kudos: 208
Registered: ‎05-05-2009

Re: 90 heuristic threats identified on a full scan (not on safe mode) False Alarms??

Hi Rogererror:

 

Just wanted you to know that agmns posted here today reporting the same problem in a thread titled NIS 2012 Suddenly Detecting Hundreds of Risks for Safe Files, and it looks like compressed .msi and .exe files are the target.  Has Symantec provided any response to your false positive reports?

---------

Windows Vista Home Premium 32-bit SP2 * NIS 2011 v. 18.6.0.29 * IE 9.0 * Firefox 8.0.0
HP Pavilion dv6835ca, Intel Core2Duo CPU T5550 @ 1.83 GHz, 3.0 GB RAM, NVIDIA GeForce 8400M GS

Contributor
agmns
Posts: 22
Registered: ‎08-13-2008

Re: 90 heuristic threats identified on a full scan (not on safe mode) False Alarms??

[ Edited ]

Hi Imacri,

 

Since this post already existed I'll switch my comments to here.

 

As you suggested I turned off "Scan Compressed Files" and did a manual scan of the drive containing most of the earlier infected files.  As you probably expected no risks were detected during that scan.  Turned it back on and rescanned and sure enough came up with a pile of infected files.

 

Also tried to update "Application Ratings" and every time get a message saying it could not connect to the server.  This may be due to server maintenance that Symantec was doing on the weekened (on another post) so I'll try that again later.

 

 

lmacri
Posts: 901
Kudos: 208
Registered: ‎05-05-2009

Re: 90 heuristic threats identified on a full scan (not on safe mode) False Alarms??

[ Edited ]

Hi Rogerror / agmns:

 

I received an update this morning via LiveUpdate for the Norton 2011 Behaviour and Security Heuristics.  It's possible you may be able to scan your compressed files now without turning off compressed file scanning (Settings | Computer Settings | Computer Scans | Compressed Files Scan) - assuming NIS 2012 received the same update in the past day or so and Symantec is actually working on a fix.

 

I went back through my LiveUpdate security history and the last update for the NIS 2011 Behaviour and Security Heuristics was delivered back on 02-Nov-2011.

 

Just FYI, the last release date for virus definitions and security updates for NIS 2012 is available here but it doesn't give a complete breakdown of release dates for each scanning engine.

 

Nov 15 Heuristics.jpg

 

--------

Windows Vista Home Premium 32-bit SP2 * NIS 2011 v. 18.6.0.29 * IE 9.0 * Firefox 8.0.0
HP Pavilion dv6835ca, Intel Core2Duo CPU T5550 @ 1.83 GHz, 3.0 GB RAM, NVIDIA GeForce 8400M GS

 

Contributor
agmns
Posts: 22
Registered: ‎08-13-2008

Re: 90 heuristic threats identified on a full scan (not on safe mode) False Alarms??

[ Edited ]

Hi Imaci / Rogerror.

 

So it appears my situation is solved, however I don't think it was any update that did it.

 

This is what I did:

 

  1. Backup Identity Safe Data to import later
  2. Deleted all the Norton related folders in c:\ProgamData folder while in Windows Safe Mode
  3. Did a complete uninstall using the Norton Removal Tool (In safe mode)
  4. Did a complete reinstall of NIS2012
  5. Ran LiveUpdate until there were no more updates
  6. Ran a full system scan ----- "No Risks Discovered"
  7. Imported Identity Safe Data that had been backed up

 

 

lmacri
Posts: 901
Kudos: 208
Registered: ‎05-05-2009

Re: 90 heuristic threats identified on a full scan (not on safe mode) False Alarms??

[ Edited ]

Hi Rogerror:

 

If you'd like to try a clean re-install of your NIS 2012 using the Norton Removal Tool I've posted instructions here with links to all the required files.

 

I noticed that mikedov and a few other people have been recommending that users go the extra step and delete the  C:\Program Files\Norton Internet Security folder after Step 7 of  those instructions (i.e., after the wipe with the Norton Removal Tool) as agmns suggested.  I've never heard of this extra step being required before but there may be something unusual with the new NIS 2012 files that the Norton Removal Tool isn't cleaning properly.

 

If this works then something must have gone seriously wrong with the delivery of one of the NIS updates installed by LiveUpdate in the past few weeks.  I would normally susect the NIS 2012 product update from v. 19.1.1.3 to v. 19.2.0.10 delivered on 08-Nov-2011 (see here for details) but it could have been any update delivered to your system between 05-Nov-2011 and 09-Nov-2011.

--------

Windows Vista Home Premium 32-bit SP2 * NIS 2011 v. 18.6.0.29 * IE 9.0 * Firefox 8.0.0
HP Pavilion dv6835ca, Intel Core2Duo CPU T5550 @ 1.83 GHz, 3.0 GB RAM, NVIDIA GeForce 8400M GS

lmacri
Posts: 901
Kudos: 208
Registered: ‎05-05-2009

Re: 90 heuristic threats identified on a full scan (not on safe mode) False Alarms??

[ Edited ]

Hi agmns:

 

Glad to hear the clean re-install of NIS 2012 solved your issue with compressed file scanning.  I'm just wondering now if your intermittent problem connecting to the Symantec servers to update your Application Ratings was also related to a corrupt NIS 2012 installation.

 

Just curious, but are you also running Windows XP SP3 like Rogerror?  Also, were you using NIS 2011 prior to installing NIS 2012 or were you using an older NIS 2009 or 2010 version before the upgrade?  There seem to be an unusual number of users having problems with NIS 2012 who installed over versions older than NIS 2011.

-------

Windows Vista Home Premium 32-bit SP2 * NIS 2011 v. 18.6.0.29 * IE 9.0 * Firefox 8.0.0
HP Pavilion dv6835ca, Intel Core2Duo CPU T5550 @ 1.83 GHz, 3.0 GB RAM, NVIDIA GeForce 8400M GS

Contributor
agmns
Posts: 22
Registered: ‎08-13-2008

Re: 90 heuristic threats identified on a full scan (not on safe mode) False Alarms??

Hi Imacri.:

 

Forgot to mention, as soon as the reinstall was complete the problem connecting to the Application Ratings servers disappeared as well.

 

I'm running Win7 Ultimate and I did install 2012 over NIS 2011.

 

 

lmacri
Posts: 901
Kudos: 208
Registered: ‎05-05-2009

Re: 90 heuristic threats identified on a full scan (not on safe mode) False Alarms??

[ Edited ]

Hi agmns:

 

Thanks for the feedback.  Installing over NIS 2011 normally shouldn't be a problem - it's actually the method Symantec recommends, and they only suggest performing a clean re-install with the Norton Removal Tool when there's a problem with NIS 2012 performance that can't be resolved with a configuration tweak - say, turning off the Idle Time Optimizer disk defragmenter on computers with a limited amount of RAM.

 

There must be some problem with the way the NIS 2012 installation wizard or NIS 2012 LiveUpdate is shutting down NIS services and background tasks or removing orphaned files from the hard drive when product upgrades/updates are performed.

---------

Windows Vista Home Premium 32-bit SP2 * NIS 2011 v. 18.6.0.29 * IE 9.0 * Firefox 8.0.0
HP Pavilion dv6835ca, Intel Core2Duo CPU T5550 @ 1.83 GHz, 3.0 GB RAM, NVIDIA GeForce 8400M GS