Reply
Keylogger Crusher
Voyager10
Posts: 434
Registered: ‎05-03-2008

Great Bug in Quarantine Restore found

Norton 2012 have a great Bug with quarantine restore



A Example:

 

Norton found a False Positive as "Trojan.Gen" and quarantine this File , now you go to Quarantine and Restore this False Positive File over the Default in the Window with the Exclusion check .

 

Norton now do not exclusion this File, Norton do exclusion the Signatur "Trojan.Gen" , that means in the Future you are not protected against "Trojan.gen" .

 

The error has been confirmed by other Users.

Newbie
diddsen
Posts: 1
Registered: ‎09-24-2011

Re: Great Bug in Quarantine Restore found

i can confirm this!

 

 

 

 

Keylogger Crusher
Voyager10
Posts: 434
Registered: ‎05-03-2008

Re: Great Bug in Quarantine Restore found

[ Edited ]

I am very surprised that there is no Symantec feedback on this Security Issue , on German Norton Forum Users ask if this Signature Exception is correct or not on File Restore with Quarantine. 

 

It is time that this issue is taken seriously.

Symantec Employee
reese_anschultz
Posts: 2,562
Registered: ‎04-08-2008

Re: Great Bug in Quarantine Restore found

I've been having some internal discussions about this for a few days now. The English restore screen looks like this:

 

Quarantine Restore

 

Notice to modify this change you are directed to "Signature to Exclude from scan". Checking this box does, indeed, disable the signature that triggered the detection.

 

This topic is currently being discussed inhouse to see how the wording and/or default behavior can be improved. Until such changes are made available you can manually exclude the file via the Items to Exclude from Scans setting to prevent future detections.

Reese Anschultz
Senior Software Quality Assurance Manager, Symantec Corporation

Keylogger Crusher
Voyager10
Posts: 434
Registered: ‎05-03-2008

Re: Great Bug in Quarantine Restore found

Thanks ,

 

You see we have only this 1 Exclude Marking and most People think this is the right Exclusion Marking and disable their  Protection against gen. Signatures. 

The Point is how many People are now affected and what will Symantec do that these People are protected in the Future. 

delphinium
Posts: 9,680
Kudos: 2,855
Solutions: 282
Registered: ‎11-21-2008

Re: Great Bug in Quarantine Restore found

It does seem a bit risky to exclude the signature of a heuristic detection, which I believe is the point that Voyager10 is making.  While each Trojan.Gen may have a different behaviour or characteristic, how does Norton handle the exclusion.  If it excludes ALL Trojan.Gen detections this is dangerous.  If it excludes on the behaviour, this is also dangerous.  Perhaps a heuristic detection should not have an option for exclusion at all, but remain in quarantine until exonerated.

Under certain circumstances profanity provides relief denied even to prayer.
Mark Twain
Keylogger Crusher
Voyager10
Posts: 434
Registered: ‎05-03-2008

Re: Great Bug in Quarantine Restore found

[ Edited ]

While each Trojan.Gen may have a different behaviour or characteristic, how does Norton handle the exclusion.

 

Norton found in my Virus Folder thousands of files as Trojan.Gen or Packed.Generic.322 or Trojan.ADH .. are you sure with the exclusion of 1 signature the files can be kept apart with Norton? I would not take this risk. 

 

The crux of the matter is Symantec should delete ALL Signature Exclusions with the next Patch , to protect the User.