01-23-2010 10:04 PM
I create a new thread because I don't see an existing one concenrning this. I think it is very important.
Ever since I have upgraded my versions of Norton 2010 to 17.5 I noticed that Download Insight no longer reports yellow pop-up to files with Unproven , Untrusted or Poor reputation . This used to be with previous builds (17.0 , 17.1 ...) . Instead of reporting yellow and giving the user the option to decide , it automatically scans and deletes the file - all such files are marked red and deleted Reser.Reputation.1
Although this might be helpful in most cases , this way of working is prone to False Positive Alerts.
One just creates a harmless self-extracting archive and make this SFX into exe . This sfx exe contains a PDF file (harmless one) and it is marked automatically as a threat Reser.Reputation.1
You could try it with random unknown exe with Unproven or ... reputation
Any comments ?
01-23-2010 10:19 PM
Sorry but I do not understand what you are doing to get a problem. I can create an executable zip file containing a pdf and I have no issue.In your case what action are you performing when you have created the exe?
01-23-2010 10:24 PM - last edited on 01-23-2010 10:28 PM
cgoldman wrote:I can create an executable zip file containing a pdf and I have no issue.In your case what action are you performing when you have created the exe?
After you create this , upload it somewhere and then download it with your browser (IE or Firefox) . This way Download Insight will analyse it and produce a false positive alarm of a threat .
Thy this - it contains just a PDF - a magazine - harmless PDF into sfx exe
http://hotfile.com/get/25486875/4b5be806/3a92a51/R
01-24-2010 12:14 AM
Just made an experiment to proove what I am talking about
See the pictures
http://i48.tinypic.com/16a33pg.png and http://i48.tinypic.com/14uuoo0.png
01-24-2010 06:19 AM - last edited on 01-24-2010 06:24 AM
i restore this File vom Quarantine , Sonar2 detect und delete this File ... are you sure that is Clean ?
http://img64.imageshack.us/img64/751/65522836.jpg
the file have harmful actions, so the reputation detection
01-24-2010 06:49 AM
This file particularly might not be clean but you can test with any other file . I supposed you can create your own exe (example a self-extract one from an archive and fill it with harmless files) , then upload that exe somewhere and attemp to download it.
Check out the result. Obviously there is something wrong with this. Note that it was not like that a few days ago
01-24-2010 11:05 AM
3play wrote:This file particularly might not be clean but you can test with any other file . I supposed you can create your own exe (example a self-extract one from an archive and fill it with harmless files) , then upload that exe somewhere and attemp to download it.
Check out the result. Obviously there is something wrong with this. Note that it was not like that a few days ago
I have been able to reproduce the issue you raise. I used winzip 14 to build a zip file (it is necessary to use legacy compression) and then to convert to winzip executable. I uploaded the exe to my own website (using Cuteftp) and downloaded using http.
The downloaded file is picked up by Norton's and removed in quarantine. The desciption is Reser.Reputation.1
I will try to get a SYmantec employee to look at this and response.
01-24-2010 03:07 PM
01-24-2010 03:17 PM
I can confirm this as stated by the OP. Create a sfx file and then download via http and Download Insight graps the file first and then when restored from Quarantine, SONAR2 grabs it also.
01-24-2010 08:07 PM
Thank you for your confirmation,guys!
Hopefully Symanec notice it and fix - it happens with any executable with unknown status for Download Insight