Reply
Regular Contributor
Niko233
Posts: 765
Registered: ‎06-25-2010
Accepted Solution

Norton Trusted Files versus Virus Total Antiviruses: 7 files accidentally observed

[ Edited ]

 

1) Most of us knew that Norton Trusted files are placed in white list and while run it - it will be not scanned by Norton - they can run easily and fast.

 

In summer 2010 I accidentally meet with Norton Trusted files but after upload to Virus Total (VT) Service was next results:

 

y1.PNG

 

Each of 7 files is Norton Trusted (NIS 18.1)

 

y2.PNG

 

 

http://www.virustotal.com/file-scan/report.html?id=adfc30d2fc23d79457fbbdd06d98b1405582637cb1a693b2d...

 

http://www.virustotal.com/file-scan/report.html?id=187b38ad86e8314e62cb791a43717e6357594f03293cbebfd...

 

http://www.virustotal.com/file-scan/report.html?id=c6cfdbe6d8c5d3ef73fa5d27c2c17d7a923e594ebbfb32f06...

 

http://www.virustotal.com/file-scan/report.html?id=a8e962ce72186875ba6dd1dd907541ada4ea3dca0309b318a...

 

http://www.virustotal.com/file-scan/report.html?id=b7463b715e45ceb2881d1bcc491553471683e9995353a9cdd...

 

http://www.virustotal.com/file-scan/report.html?id=be82b4958024e874261a132cb3463c60d5d28a93004f3d98c...

 

http://www.virustotal.com/file-scan/report.html?id=dc491472cf5d79f02a65f09dfdd97ec3bcb4a8b77894e90cd...

 

 

In the past I saw 4-6 false positives (FP) from 25-30 VT antiviruses, but I saw that it was really FP - files was from well know Software and Antivirus vendors. Some of Norton Trusted files (in collection was about 70-80 files) was reported by VT as malware but with 0-20 antiviruses, but they was not so strong (in my eyes) and I say that may be they are wrong... but antiviruses with nowadays few false alarms reported me about 7 files that they are malware (based on Avira, Microsoft, ESET and Kaspersky detections).

 

To review them:

Submission has been sent Fri Dec 17 01:24:40 PST 2010

Tracking #18553851

 

 

_________________________________________________________________________________________

 

 

 

2) 2-bytesNorton Trusted file with content of two symbols:

MZ

is Norton Trusted too.

 

y3.PNG

 

 

What is the payload of this included in while list item? How much users (more than 100,000 ?) and how often use this file? What for is this file - can it have the payload if it exits on some/many/every machines?

 

Regular Contributor
Niko233
Posts: 765
Registered: ‎06-25-2010

Re: Norton Trusted Files versus Virus Total Antiviruses: 7 files accidentally observed

Does anybody of Norton/Symantec team can read this message?

Regular Contributor
BanMidou
Posts: 721
Registered: ‎12-17-2010

Re: Norton Trusted Files versus Virus Total Antiviruses: 7 files accidentally observed

:smileyindifferent:

 

WELL Hopefully SONAR will be able to detect these file.

 

Have you submitted them to syamntec

Midou

Regular Contributor
BanMidou
Posts: 721
Registered: ‎12-17-2010

Re: Norton Trusted Files versus Virus Total Antiviruses: 7 files accidentally observed

[ Edited ]

Untitled.jpgDoes not seem to be too dangerous but If you had submitted it to symantec what did they reply

Midou

Regular Contributor
Niko233
Posts: 765
Registered: ‎06-25-2010

Re: Norton Trusted Files versus Virus Total Antiviruses: 7 files accidentally observed

[ Edited ]

>WELL Hopefully SONAR will be able to detect these file.

 

SONAR will not proceed (or watching) this files as they placed in the white list of Norton trusted files as company itself.

 

 

>Have you submitted them to syamntec

 

Yes, as I wrote earlier

 

 

>Does not seem to be too dangerous

 

Some other great AV product vendors thinks with few false positives think not. Topic is started for finding an answer - wrong Norton Trusted entries or false positives from other famous and effective vendors too?

 

 

>but If you had submitted it to symantec what did they reply

 

Nothing as mainly many times before (not always) they save silent about this subject too...

 

 

Unfortunately in all likelihood since this is user-to-user help forum they more prefer to be silent in posting competent answers and post them only from time to time so many (about 80-85%) of interesting subjects (as I think) do not get any authoritative answers.

Posting like to something like space black hole. No one and nothing can escape from it and no replies from it, only gravity disturbance and light from other space bodies light distortion

 

Thanks for reviewing this article!

Regular Contributor
BanMidou
Posts: 721
Registered: ‎12-17-2010

Re: Norton Trusted Files versus Virus Total Antiviruses: 7 files accidentally observed

please be patient have you sent a PM to the any of the symantec Employee?

 

I got an instant reply.when I sent one!

 

 

please Wait for Gurus to come.

 

They can ask symantec employees to look into a prob. I think

Midou

Symantec Employee
Venkat_J
Posts: 1,111
Registered: ‎06-16-2010

Re: Norton Trusted Files versus Virus Total Antiviruses: 7 files accidentally observed

Hi Niko223,

 

Sorry I didn't reply any sooner.

 

Most of our employees are out of office and are enjoying their holidays. As a result, your message might not have received the appropriate attention. In the meantime, can you share the files with me so that I will be able to send these over to the team as soon as they're back.

 

Thank you for your understanding.

 

-Venkat

Venkat Jammalamadugu
Norton Forums Administrator
Consumer Products and Solutions
Symantec Corporation

Regular Contributor
Niko233
Posts: 765
Registered: ‎06-25-2010

Re: Norton Trusted Files versus Virus Total Antiviruses: 7 files accidentally observed

>please be patient 

here is two weeks, other topics months of waiting. Of cause in earlier topics will never be solved, months of waiting can't be, it is just skipping.

 

 

>have you sent a PM to the any of the symantec Employee?

No

1) I do not know who can answer in the observed field of product

2) Then I send a PM to some of admins with this subject and details, he tell me what this must be posted in forum. Apparently, all subjects must be posted in forum, so and this topic posted.

Send a PM of every post? Looks like paranoia. :) If post must be posted in forum, then may be a little attention to them may be brought without bombarding/spamming with PM. May be I am wrong, please tell me if it is so.

 

 

>can you share the files with me

Sorry, Venkat Jammalamadugu, for now I delete all collected files from my HDD who was waiting for answer as they and others was wating too long.

But earlier I submitted them to Symantec as listed in the first topic message (Tracking #18553851)

 

I just want to view the dinamics of possible changes, but if was no answers (on other topics too) I delete all relevant to subjects files and already put in my mind all this topics like unanswered.

 

Again, I do not want to just disturb Norton team, in opposite I only want to cooperate Norton team to make products more effective and user-friendly. May be I do something wrong, not in the needed way or direction...


Thanks to all who responded!

Regular Contributor
Niko233
Posts: 765
Registered: ‎06-25-2010

Re: Norton Trusted Files versus Virus Total Antiviruses: 7 files accidentally observed

Are there any advancements?

Symantec Employee
JohnM
Posts: 112
Registered: ‎04-08-2008

Re: Norton Trusted Files versus Virus Total Antiviruses: 7 files accidentally observed

[ Edited ]

 

Hi Niko233,


The files you submitted are mostly old MS-DOS programs, or remnants of such. With the exception of one, they are all either clean or harmless remnants of "joke" programs. The one for which detection was added is 757SPIN.COM.exe, added as Joke.Flash. This is an MS-DOS program which hooks keyboard interrupts and every time 50 keys are typed, it modifies the characters displayed on the screen.

Manually analyzing and reporting on samples like these is not a particularly efficient use of scarce resources. If you happen across the next Stuxnet however, please let us know.

JohnM