Reply
Super Spyware Scolder
3play
Posts: 236
Registered: 01-21-2010

NEW - Download Insight always report Reser.Reputation.1 to unknown or unproven file

I create a new thread because I don't see an existing one concenrning this. I think it is very important.

 

Ever since I have upgraded my versions of Norton 2010 to 17.5 I noticed that Download Insight no longer reports yellow pop-up to files with Unproven , Untrusted or Poor reputation . This used to be with previous builds (17.0 , 17.1 ...) . Instead of reporting yellow and giving the user the option to decide , it automatically scans and deletes the file - all such files are marked red and deleted Reser.Reputation.1

 

Although this might be helpful in most cases , this way of working is prone to False Positive Alerts.

One just creates a harmless self-extracting archive and make this SFX into exe . This sfx exe contains a PDF file (harmless one) and it is marked automatically as a threat Reser.Reputation.1

 

You could try it with random unknown exe with Unproven or ... reputation

 

test.PNG

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

Any comments ?

Super Spam Squasher
cgoldman
Posts: 2,621
Registered: 06-25-2008

Re: NEW - Download Insight always report Reser.Reputation.1 to unknown or unproven file

Sorry but I do not understand what you are doing to get a problem. I can create an executable zip file containing a pdf and I have no issue.In your case what action are you performing when you have created the exe?

Super Spyware Scolder
3play
Posts: 236
Registered: 01-21-2010

Re: NEW - Download Insight always report Reser.Reputation.1 to unknown or unproven file

[ Edited ]

cgoldman wrote:

I can create an executable zip file containing a pdf and I have no issue.In your case what action are you performing when you have created the exe?


After you create this , upload it somewhere and then download it with your browser (IE or Firefox) . This way Download Insight will analyse it and produce a false positive alarm of a threat .

 

Thy this - it contains just a PDF - a magazine - harmless PDF into sfx exe

http://hotfile.com/dl/25486875/92f250e/Rosi_Ivanova.exe.html?uploadid=25486875&fname=Rosi_Ivanova.ex...

 

http://hotfile.com/get/25486875/4b5be806/3a92a51/Rosi_Ivanova.exe

 

fp.PNG

Super Spyware Scolder
3play
Posts: 236
Registered: 01-21-2010

Re: NEW - Download Insight always report Reser.Reputation.1 to unknown or unproven file

Just made an experiment to proove what I am talking about

 

See the pictures

 

http://i48.tinypic.com/16a33pg.png  and  http://i48.tinypic.com/14uuoo0.png

Keylogger Crusher
Voyager10
Posts: 431
Registered: 05-03-2008

Re: NEW - Download Insight always report Reser.Reputation.1 to unknown or unproven file

[ Edited ]

i restore this File vom Quarantine , Sonar2 detect und delete this File ... are you sure that is Clean ?

 

http://img64.imageshack.us/img64/751/65522836.jpg

 

the file have harmful actions, so the reputation detection

Super Spyware Scolder
3play
Posts: 236
Registered: 01-21-2010

is Re: NEW - Download Insight always report Reser.Reputation.1 to unknown or unproven file

This file particularly might not be clean but you can test with any other file . I supposed you can create your own exe (example a self-extract one from an archive and fill it with harmless files) , then upload that exe somewhere and attemp to download it.

 

Check out the result. Obviously there is something wrong with this. Note that it was not like that a few days ago

Super Spam Squasher
cgoldman
Posts: 2,621
Registered: 06-25-2008

Re: is Re: NEW - Download Insight always report Reser.Reputation.1 to unknown or unproven file


3play wrote:

This file particularly might not be clean but you can test with any other file . I supposed you can create your own exe (example a self-extract one from an archive and fill it with harmless files) , then upload that exe somewhere and attemp to download it.

 

Check out the result. Obviously there is something wrong with this. Note that it was not like that a few days ago


 

I have been able to reproduce the issue you raise. I used winzip 14 to build a zip file (it is necessary to use legacy compression) and then to convert to winzip executable. I uploaded the exe to my own website (using Cuteftp)  and downloaded using http.

 

The downloaded file is picked up by Norton's and removed in quarantine. The desciption is Reser.Reputation.1

I will try to get a SYmantec employee to look at this and response.

 

Spyware Scolder
JRosenfeld
Posts: 97
Registered: 11-02-2008

Re: NEW - Download Insight always report Reser.Reputation.1 to unknown or unproven file

dbrisendine
Posts: 5,546
Kudos: 1,264
Solutions: 260
Registered: 10-06-2008

Re: is Re: NEW - Download Insight always report Reser.Reputation.1 to unknown or unproven file

I can confirm this as stated by the OP.  Create a sfx file and then download via http and Download Insight graps the file first and then when restored from Quarantine, SONAR2 grabs it also.

Super Spyware Scolder
3play
Posts: 236
Registered: 01-21-2010

Re: is Re: NEW - Download Insight always report Reser.Reputation.1 to unknown or unproven file

Thank you for your confirmation,guys!

Hopefully Symanec notice it and fix - it happens with any executable with unknown status for Download Insight