Reply
Regular Contributor
TrDo
Posts: 244
Registered: ‎11-26-2008
Accepted Solution

Downloader Alert from NIS09..False Positive or Real Threat?

Hello everyone..Long time since last visit..Hope everyone is fine..

 

Here is my issue.  I've had a game-Poker Superstars II-, in my pc since last September(08, that is), which I purchased legally.

 

I have been playing this game up until-around- Jan/Feb 09, when I stopped for one reason or another.  Last night, when I tried to play after Jan/Feb, I realized that I could not for some reason. I uninstalled the game and tried installing again (I have the setup file on my pc, since the day of purchase), but auto-protect alert kept coming-up, with a "Downloader" virus warning not allowing me to install.

 

I have disabled the auto-protect, installed the game and enable the auto-protect.  Immediately, the auto-protect placed the .exe file of the game in quarantine, again with the "Downloader" virus warning.  Now, the odd thing is that I run full system scans every two days for the last two years and up until Jan/Feb 09 I've had no kind of warning from NIS09.

 

I want to understand what happened and suddenly my game is a possible source of a "Downloader" virus threat.  Is it a false positive? Is it a real one? and if so what about the September 08-Jan/Feb 09 period that I was playing that game with no warnings from NIS09?

 

If it's a real threat-and now it is recognized by NIS09 due to definitions updates- how come my pc has not been infected by viruses during the September 08-Jan/Feb 09 period ?

 

I would appreciate your input and thoughts please, because these things do not make sence to me, at all.

 

Thank you in advance.

 

TrDo.

 

P.S. I have submitted the file to Symantec for analysis, but I don't know if and how they proceed from there on.  Do they publish these results anywhere? Or is it for their own consumption?

 

 

Phil_D
Posts: 7,286
Topics: 190
Kudos: 2,357
Solutions: 365
Registered: ‎06-10-2008

Re: Downloader Alert from NIS09..False Positive or Real Threat?

Hi TrDo,

 

Your post sounds similar to the ones here.

 

I'm trying to get a clarification of the issue.

Norton 360 • Norton Internet Security • Norton Zone | XP SP3 • Windows 7 Professional SP1 x64
• PLEASE, BACKUP or EXPORT your Identity Safe Data on a regular basis •

Regular Contributor
TrDo
Posts: 244
Registered: ‎11-26-2008

Re: Downloader Alert from NIS09..False Positive or Real Threat?

[ Edited ]

Hi Phil_D,

 

Thanks for the input.  Yes, these incidents sound similar, but they involve on-line sites.  In any case, I would truly appreciate your further clarifications.

 

Thanks again.

 

TrDo.

Message Edited by TrDo on 04-17-2009 06:43 PM
Phil_D
Posts: 7,286
Topics: 190
Kudos: 2,357
Solutions: 365
Registered: ‎06-10-2008

Re: Downloader Alert from NIS09..False Positive or Real Threat?

Hi TrDo,

 

I understand your situation is different from the others, but I do see similarities: gaming / downloader / just occurred recently.

 

Do you have the full name of the threat detected?

 

Thanks.

Norton 360 • Norton Internet Security • Norton Zone | XP SP3 • Windows 7 Professional SP1 x64
• PLEASE, BACKUP or EXPORT your Identity Safe Data on a regular basis •

Regular Contributor
TrDo
Posts: 244
Registered: ‎11-26-2008

Re: Downloader Alert from NIS09..False Positive or Real Threat?

Hey Phil_D,

 

Here are the details:

 

Component: Virus Scanner

 

Definition Version: 2009.04.16.048

 

Eraser Version:109.1.0.61

 

Risk name: Downloader   http://securityresponse.symantec.com/security_response/writeup.jsp?docid=2002-101518-4323-99

(although this link provided in the quarantine section, is a quite old definition of Downloader from 2001 and risk is depicted as "low" in this link)

 

Risk cat: Virus

 

Risk type: File Based

 

Severity: High

 

 

Hope this helps.  Thanks alot.

 

TrDo.

 

Regular Contributor
TrDo
Posts: 244
Registered: ‎11-26-2008

Re: Downloader Alert from NIS09..False Positive or Real Threat?

Hey guys,

 

Any news on that, or any new info relating to this issue would be appreciated.

 

Thanks.

 

TrDo.

Keylogger Crusher
Voyager10
Posts: 434
Registered: ‎05-03-2008

Re: Downloader Alert from NIS09..False Positive or Real Threat?

h??p://c-a-r-a-t.mybrute.com/

 

Only Symantec/Norton say Virus , no other AV detected a Virus.

 

uc[1].swf  - Downloader.Swif.C

 

False Positive or Real Threat ? 

Phil_D
Posts: 7,286
Topics: 190
Kudos: 2,357
Solutions: 365
Registered: ‎06-10-2008

Re: Downloader Alert from NIS09..False Positive or Real Threat?

Hi folks,

 

I brought this to the attention of Symantec on Friday and unfortunately now it is the weekend which may delay the investigation.

 

I think we need to let them to carefully examine this issue. I'm sure a response will be available shortly.

 

As soon as anything is known, I will let you know or a public notice may be posted.

 

Thanks for your patience.

Norton 360 • Norton Internet Security • Norton Zone | XP SP3 • Windows 7 Professional SP1 x64
• PLEASE, BACKUP or EXPORT your Identity Safe Data on a regular basis •

Keylogger Crusher
Voyager10
Posts: 434
Registered: ‎05-03-2008

Re: Downloader Alert from NIS09..False Positive or Real Threat?

hmm ? ;) all symantec employee on holiday?

 

 No ;)

 

RECENT LOGINS:
shannons  MJP  Allen_K  kishorec  

Regular Contributor
TrDo
Posts: 244
Registered: ‎11-26-2008

Re: Downloader Alert from NIS09..False Positive or Real Threat?

Hi Phil_D,

 

Thank you for your consistency.  I'll wait for your input.

 

Have a nice w/e mate. 

 

Thanks again.

 

TrDo.