10-27-2008 02:05 AM - edited 10-27-2008 02:06 AM
I have Norton Internet Security 2009 installed. The auto-protect keeps picking up 15-20 of my files as Infostealer.Gampass, removes them, and dumps them in qarantine. It does this when there are no scans (on demand or idle) running, so I assume some other program on ym computer is accessing them.
The problem I have is, I cant make norton ignore this 'threat'. Clicking on exclusions brings up the list of threats, but Infostealer.Gampass is not listed there, and hence, i cannot stop norton from nuking my files 6-7 times a day.
At the moment, I have had to turn auto protect off as it has become so intrusive (antispyware, privacy control, heuristics and firewall are still ON). I am supplementing with threatfire and spyware doctor, until i can fins a fix (yes, i am aware they may have potential conflicts, but they run fine for me).
Does anyone know of a way to makr norton ignore this threat? Can any symantec mods suggest it to the engineers to include in future updates?
----
*Same problem with 'Hacktool'. Exclusions list hacktool.xxx, hacktool.yyy etc, but not just plain 'hacktool'.
10-27-2008 04:14 AM
Seems like a liget find to me. Did you read this.
http://securityresponse.symantec.com/security_resp
10-27-2008 04:33 AM
Yes, i am aware that it is a legit virus.
However, the files i know are 100% clean, havign decompiled some of them myself to check.
Iv also used virus total, and viruscan @ jotti .org to scan them.
Any way to shut norton up?
10-27-2008 04:41 AM - edited 10-27-2008 04:42 AM
10-27-2008 04:46 AM - edited 10-27-2008 04:49 AM
Most are security/administration tools -
computer remote control/management over LAN
password recovery
etc
not illegal, but certainyl suspicious if installed on a pc without the user knowing, hence norton flagging them
edit -
i've had these files for a while, and keeping them inside a rar used to be sufficient, but NIS09 seems to be much more 'accurate' at finding them
10-27-2008 08:00 AM
Spoke with an analyst @ virus tech support tonight. He said he'd pass the info on to engineering...
hopefully he does.
Guess i'll have to wait and see if the enxt round of definitions in the comign days resolves the problem
10-27-2008 11:24 AM
Hi
In NIS 2009, click "Settings" by the word "Computer", Now you will see in the list "Antispyware" with "on". Click "Configure" to the right.
Niow you see this.
Try un-ticking "Hack Tool".
The other thing if you know the files and where you have them located on you PC, you can add them one at a time to the Exclusion lists, both "Scan and "Auto Protect" lists. Select any file even .zip or .rar etc.

Click "Configure" to the right of "Scan Exclusions" then the 2 lists appear, Click the Add button for either list to browse and add the file(s) in question.
Quads
10-27-2008 04:11 PM
Quads wrote:Hi
In NIS 2009, click "Settings" by the word "Computer", Now you will see in the list "Antispyware" with "on". Click "Configure" to the right.
Niow you see this.
![]()
Try un-ticking "Hack Tool".
The other thing if you know the files and where you have them located on you PC, you can add them one at a time to the Exclusion lists, both "Scan and "Auto Protect" lists. Select any file even .zip or .rar etc.
Click "Configure" to the right of "Scan Exclusions" then the 2 lists appear, Click the Add button for either list to browse and add the file(s) in question.
Quads
With regard to the AntiSpyware, I would not un-check Hack Tool or anything else so you are Fully Protected becasue, if a Hack Tool did get on to your P.C. and you happen to have another on-demand Scanner and that picked the Hack Tool up, the User may complain that Norton "does not work"; you really need to be Fully Protected against all things "evil" on the Internet. :)
10-27-2008 07:11 PM - edited 10-27-2008 07:12 PM
Infostealer.Gampass is a generic detection for files. Most, in fact all, of the files detected as Gampass by N360, in this case, were keygens/cracks. I would move the slider about low risks to "remove automatically" and turn remove infected files to "automatic".
About Norton "nuking" 6-7 files of yours daily...it could be an network threat...anyone else in your network?
10-27-2008 07:39 PM - edited 10-27-2008 07:45 PM
Thanks for the reply Quads. I don't think unchecking those boxes work, as Infostealer.Gampass and Hacktool aren't actually isted under those categories.
