Reply
Spam Squasher
silverhawk
Posts: 494
Registered: ‎12-15-2008

Re: Norton Retail Submissions Tracker

[ Edited ]

Powerful and deadly rogue named as smart protector, i have seen today, Norton safeweb also failed. Mozilla and Internet Explorer phishing filter however blocked them.

 

http://i248.photobucket.com/albums/gg181/sweetvivek007/fail.jpg

 

Tracking #13263968          

https://www.virustotal.com/analisis/663a9e45c1f90b0ce3136cf1627974205361113cc5d26da6e965c8754e39f52a...

 

 


Message Edited by silverhawk on 10-15-2009 11:39 PM
Genuine Windows 8 x64 Pro (MSDN); NIS 2013; HP Pavallion G6 with AMD Core 2 Quad A10; 6 GB RAM; ; 1TB Western Digital HDD, AMD Radeon 2.5 GB Graphics Card
Bot Obliterator
Quads
Posts: 13,255
Registered: ‎07-21-2008

Re: Norton Retail Submissions Tracker

[ Edited ]

Hi

 

Although the downloaded file from the site "SmartProtector.exe" is not blocked or detected,    The 2 main files that the .exe file downloads to install "Smart Protector'  on to your system is detected, blocks one being created, and Quarantines the other.

 

16/10/2009 7:56 p.m.,High,setup.exe (Suspicious.MH690.A) detected by Auto-Protect,Quarantined,Resolved - No Action

16/10/2009 7:56 p.m.,High,smartprotector[1].exe (Suspicious.MH690.A) detected by Auto-Protect,Blocked,Resolved - No Action 

 

Quads 

Message Edited by Quads on 10-16-2009 07:24 PM
Symantec Employee
JohnM
Posts: 112
Registered: ‎04-08-2008

Re: Norton Retail Submissions Tracker

Hi silverhawk,


silverhawk wrote:
Tracking #13261575

 

Symantec automatic response

 

We have analyzed your submission.  The following is a report of our
findings for each file you have submitted:

filename:  sys files.zip
machine: Machine
result: See the developer notes

filename: 49D2D2D924.sys
machine: Machine
result: See the developer notes

filename: KGyGaAvL.sys
machine: Machine
result: See the developer notes

Customer notes:



Developer notes:
 sys files.zip is a container file of type  ZIP
49D2D2D924.sys is a data file.  This file is contained by   sys files.zip
KGyGaAvL.sys Our automation was unable to identify any malicious content in this submission.
 The file will be stored for further human analysis  This file is contained by   sys files.zip

 

Virustotal found nothing with any scanner.

 

http://i248.photobucket.com/albums/gg181/sweetvivek007/Untitled-10.jpg

 

This submission include my pc file, which i think may be a threat as i found in program data folder of windows 7, it does not come when i clean install windows, it comes when i install some of my common used programs.


All files in Tracking #13261575 are clean.

 

Keep up the good work ;) 

 

JohnM

Symantec Employee
JohnM
Posts: 112
Registered: ‎04-08-2008

Re: Norton Retail Submissions Tracker

Hi Quads,


Quads wrote:

Hi

 

Although the downloaded file from the site "SmartProtector.exe"  the 2 main file that the .exe file downloads to install "Smart Protector' is detected, blocks one being created, and Quarantines the other.

 

16/10/2009 7:56 p.m.,High,setup.exe (Suspicious.MH690.A) detected by Auto-Protect,Quarantined,Resolved - No Action

16/10/2009 7:56 p.m.,High,smartprotector[1].exe (Suspicious.MH690.A) detected by Auto-Protect,Blocked,Resolved - No Action 

 

Quads 


You beat me to it. Nice work.

 

JohnM

Spam Squasher
silverhawk
Posts: 494
Registered: ‎12-15-2008

Re: Norton Retail Submissions Tracker

[ Edited ]

 


Quads wrote:

Hi

 

Although the downloaded file from the site "SmartProtector.exe" is not blocked or detected,    The 2 main files that the .exe file downloads to install "Smart Protector'  on to your system is detected, blocks one being created, and Quarantines the other.

 

16/10/2009 7:56 p.m.,High,setup.exe (Suspicious.MH690.A) detected by Auto-Protect,Quarantined,Resolved - No Action

16/10/2009 7:56 p.m.,High,smartprotector[1].exe (Suspicious.MH690.A) detected by Auto-Protect,Blocked,Resolved - No Action 

 

Quads 

Message Edited by Quads on 10-16-2009 07:24 PM

 

Thanks for clarifying the situation, today i executed the file in my testing pc and yes Norton blocked it..Great going Norton..

 

Happy Diwali to all..

Message Edited by silverhawk on 10-16-2009 06:28 PM
Genuine Windows 8 x64 Pro (MSDN); NIS 2013; HP Pavallion G6 with AMD Core 2 Quad A10; 6 GB RAM; ; 1TB Western Digital HDD, AMD Radeon 2.5 GB Graphics Card
Spam Squasher
silverhawk
Posts: 494
Registered: ‎12-15-2008

Re: Norton Retail Submissions Tracker

[ Edited ]

 


JohnM wrote:

Hi silverhawk,


silverhawk wrote:
Tracking #13261575

 

Symantec automatic response

 

We have analyzed your submission.  The following is a report of our
findings for each file you have submitted:

filename:  sys files.zip
machine: Machine
result: See the developer notes

filename: 49D2D2D924.sys
machine: Machine
result: See the developer notes

filename: KGyGaAvL.sys
machine: Machine
result: See the developer notes

Customer notes:



Developer notes:
 sys files.zip is a container file of type  ZIP
49D2D2D924.sys is a data file.  This file is contained by   sys files.zip
KGyGaAvL.sys Our automation was unable to identify any malicious content in this submission.
 The file will be stored for further human analysis  This file is contained by   sys files.zip

 

Virustotal found nothing with any scanner.

 

http://i248.photobucket.com/albums/gg181/sweetvivek007/Untitled-10.jpg

 

This submission include my pc file, which i think may be a threat as i found in program data folder of windows 7, it does not come when i clean install windows, it comes when i install some of my common used programs.


All files in Tracking #13261575 are clean.

 

Keep up the good work ;) 

 

JohnM


 

Thanks john for letting me know about these files..

 

Happy Diwali to all.

Message Edited by silverhawk on 10-16-2009 06:30 PM
Genuine Windows 8 x64 Pro (MSDN); NIS 2013; HP Pavallion G6 with AMD Core 2 Quad A10; 6 GB RAM; ; 1TB Western Digital HDD, AMD Radeon 2.5 GB Graphics Card
Spam Squasher
silverhawk
Posts: 494
Registered: ‎12-15-2008

Re: Norton Retail Submissions Tracker

[ Edited ]

One story to share..

 

Today only i installed Norton on my father laptop which came preinstalled with McAfee by dell, as his McAfee got stumbled and could not protect data of his hard work, 2 days back some rogue did it what i have come to know after investigation. 

 

Then he said me to install Norton on his laptop as well, as i use it, he was amazed by new performance of his laptop, that mcafee might have slowed it down till now. Well after 30 days he will purchase for this laptop. He is trialing right now. And i installed Norton as he got unsatisfied by mcafee  protection. 

 

And i Norton as it has proved to be the best among all..It's soooooooo powerful in all aspects. And you won't believe, Norton caught one threat in this laptop. wow..!!

 

That is why i just loveeeeee Norton.

 

Dell XPS laptop 2.13 GHZ processor, 3 GB DDR3 RAM, 250 GB HDD, Vista Home Premium SP2 , ATI Radeon 3670 HD Graphics.

Message Edited by silverhawk on 10-16-2009 07:22 PM
Genuine Windows 8 x64 Pro (MSDN); NIS 2013; HP Pavallion G6 with AMD Core 2 Quad A10; 6 GB RAM; ; 1TB Western Digital HDD, AMD Radeon 2.5 GB Graphics Card
Spam Squasher
silverhawk
Posts: 494
Registered: ‎12-15-2008

Re: Norton Retail Submissions Tracker

 Tracking #13274909

http://www.virustotal.com/analisis/131e5271582d4e6486b9fd4da8393275577d59be5944fd7f47fcb8ae700c08c0-...

 

http://www.threatexpert.com/report.aspx?md5=8b790d51d32b8f878d5057ba01c2beaa

 

Happy diwali to all.

Genuine Windows 8 x64 Pro (MSDN); NIS 2013; HP Pavallion G6 with AMD Core 2 Quad A10; 6 GB RAM; ; 1TB Western Digital HDD, AMD Radeon 2.5 GB Graphics Card
Spam Squasher
silverhawk
Posts: 494
Registered: ‎12-15-2008

Re: Norton Retail Submissions Tracker

3 New threats

 

Tracking #13309281

 

 http://www.virustotal.com/analisis/3b7914c0e73bb360d3928c9166992e6243680bea5cd5e08bb0c182abb4da1db0-...

Genuine Windows 8 x64 Pro (MSDN); NIS 2013; HP Pavallion G6 with AMD Core 2 Quad A10; 6 GB RAM; ; 1TB Western Digital HDD, AMD Radeon 2.5 GB Graphics Card
Spam Squasher
silverhawk
Posts: 494
Registered: ‎12-15-2008

Re: Norton Retail Submissions Tracker

Tracking #13312698

http://www.virustotal.com/analisis/21b9a61631027bb3ddaadfba4dce15f5891e86c9f72c9f5d7049e10813fd3e80-...

 

We have analyzed your submission.  The following is a report of our
findings for each file you have submitted:

filename:  svchost.zip
machine: Machine
result: See the developer notes

filename: svchost.exe
machine: Machine
result: See the developer notes

Customer notes:



Developer notes:
 svchost.zip is a container file of type  ZIP
svchost.exe Our automation was unable to identify any malicious content in this submission.
 The file will be stored for further human analysis  This file is contained by   svchost.zip

 

Genuine Windows 8 x64 Pro (MSDN); NIS 2013; HP Pavallion G6 with AMD Core 2 Quad A10; 6 GB RAM; ; 1TB Western Digital HDD, AMD Radeon 2.5 GB Graphics Card