Reply
Regular Contributor
Niko233
Posts: 765
Registered: ‎06-25-2010

Re: Sonar 4 problem.

[ Edited ]

another mesage:

http://symantecclub.ru/viewtopic.php?f=48&t=5587&start=60#p88093

 

INDF
Active/regilar user
26-Jan-2012

 

By the way I made a video with Mayachok. Sample submitted by me. Let's they are think about it. ;)

 

video: http://www.youtube.com/watch?v=XoIXMzt9woI&feature=player_embedded


P.S. If somebody wants to talk about this problem, than this video must be posted there. :)

 

 

_______________________________________________

 

 

Hi, Krivanov!

 

Ну что ж не переводишь этот текст нашим на нашем форуме? или не дружишь с английским. скажи им о состоянии дел и что хотят разработчики. 2 видео запостили типа ретест и все в молоко - не то, что они хотели. что, все что ли не понимают что они написали?)

Why are you not translate this text to our peolpe on our forum? Tell them about how it goes, and what developers wants. 2 videos was posted with something like "retest" label and all of them are missed/goes not into target requested - they are not that developers wants. All of our forum members of that thread did not understand what developers talks about?

 

Hi Krivanov,

Привет, мужик!

 

Thanks for taking the time to test NIS and report the problem you encountered. I apologize for taking this long to respond.

Спасибо за то, что нашли время протестировать и доложить нам о проблеме, которую Вы встретили. Я извиняюсь за такую долгую задержку в отклике.

 

First off, NIS does not have any "hard-coded" behavior that excludes/trusts files that are run from the deskop.

Прежде всего, NIS не имеет какого-либо "жестко запрограммированного" поведения, которое исключает/доверяет файлам, запускаемым с рабочего стола.

 

I would like to request that you retry those tests by downloading those exes directly from internet links onto the desktop, instead of extracting those files from an encrypted .rar file.

Я бы хотел запросить повторно провести эти тесты путем загрузки этих исполняемых файлов непосредственно по Интернет-ссылкам на рабочий стол, вместо того чтобы распаковывать эти файлы из криптографированного/защищенного паролем RAR-архива.

 

Thanks for your help.

Спасибо за Вашу помощь! 

 

Regards,

 

Shane.

SONAR Team
С уважением, Шэйн (Shane).
Команда SONAR.

 

 

 

_________________

 

 

Как уже я сам думаю - это просто тупняк чтобы мы убедились, что продукт не так безнадежен - что компонент "Контроль загрузок" снесет файлы сразу после загрузки, но это же не корень проблемы, это маркетинг. Проблема в том, что не важно каким путем полученный файл запустившись из каких-либо папок заражает комп, а из других - нет. все. говорю всем своим знакомым что у нортона есть такая особенность а в свою очередь по цепочке это дойдет и до авторов вирусов. держись, нортон!

А вы как будто играете в испорченный телефон или без коммутатора - вы им одно - они вам другое, а в ответ на их запрос вы им первое же :)


спросите elsewhere - он если не всегда то почти всегда все сразу понимает! :)

 

As I as myself see the situation - that is just wasting of time to make sure us, that product is with hopes to destroy malware - that Download Insight component will delete files directly after download, but that is not the root of problem, it is marketing only. No matter where a malware from, problem is in that files executed from some directories are infect PC and from another folders did not infect PC. That is all. I am going to tell all my friends that Norton have this "feature" and by the circiut one by one it will be received by malware writers. Hold on, Norton!

So saiyng you all are playing in the broken phone or without switch/commutator - you told them one thing - they told you another thing and in the answer to their request you are send them first thing. :)

 

Ask elsewhere - he is always or very close to always uderstood all correctly at one moment! :)

Regular Contributor
Niko233
Posts: 765
Registered: ‎06-25-2010

Re: Sonar 4 problem.

Кстати! INDF если ты видишь этот (пользуясь случаем, хочу передать привет, прямо как на капитал-шоу Поле Чудес!)))) текст, напиши номер отправки образца вируса или повтори отправку снова, сохранив и предоставив этот новый номер.

Образцов присылают много - для нахождения нужного необходим номер. как и для куртки в раздевалке Большого театра.

 

By the way, INDF if you see that text please provide your submission tracking number or do it again to save and provide new number! Many submissions can easy mask your submission, number is needed. Like to find your outdoor clothes in the locker room of the Bolshoi theatre.

Regular Contributor
Niko233
Posts: 765
Registered: ‎06-25-2010

Re: Sonar 4 problem.

[ Edited ]

special for non-russian users about broken pnone and understanding (joke):

)))))

originally: http://symantecclub.ru/viewtopic.php?f=48&t=5587&start=20#p88005

 

Endi-701

Administrator

 

Shortened translate of comments below krivanov's post:

- Wow! Oh, God! Link to YouTube detected on the forum, but YouTube contained viruses!

- It can infect my computer and aftet that all the U.S.!

- We need to inform moderators, FBI and our president Barack Obama about it!

Moderators: Link on the YouTube was successfully deleted. USA security threat terminated!!! :D

 

They are understood nothing...

Symantec Employee
shane_pereira
Posts: 87
Registered: ‎04-13-2008

Re: Sonar 4 problem.

In case there was some miscommunication, I'll reiterate what I said earlier. SONAR will convict and remove malware that is run from the desktop. See screenshots below.

 

2.png

SONAR convicting malware run from desktop

Regular Contributor
Niko233
Posts: 765
Registered: ‎06-25-2010

Re: Sonar 4 problem.

shane_pereira, what is your configuration?

NIS version and full OS version? .NET Framework installed versions?

Symantec Employee
shane_pereira
Posts: 87
Registered: ‎04-13-2008

Re: Sonar 4 problem.

[ Edited ]

NIS 19.2.0.10 running on XP SP2 32-bit with no patches.

 

.NET framework is not installed.

 

NIS is in default configuration.

Regular Contributor
Niko233
Posts: 765
Registered: ‎06-25-2010

Re: Sonar 4 problem.

[ Edited ]

Thanks on fully-detailed answer! Guys, looks like you all are trick us... That is the key to stop SONAR? different samples?

Парни, похоже вы разыгрываете нас... Каков же ключ к тому чтобы СОНАР не сработал? разные образцы вирусов?

Phishing Phryer
DaveH
Posts: 4,689
Registered: ‎01-06-2010

Re: Sonar 4 problem.

[ Edited ]

I have had Sonar block items on the desktop too,  But the second video made by request sure looks like the malware sample was blocked when it was in another location but was able to run from a desktop folder.

 

Seems like it would be very easy to confirm.  The original poster here is a moderator of that forum.

If they could provide Shane with the sample used and the submission number from there report I'm sure it can be looked into.

 

Dave

Symantec Employee
shane_pereira
Posts: 87
Registered: ‎04-13-2008

Re: Sonar 4 problem.

[ Edited ]

Yep. We are still waiting for the sample.

 

Once we receive the sample here are the steps I am going to follow. You are welcome to try them yourself:

 

1. Put the sample on some webserver.

2. Disable Download Insight just to ensure that it does not block it as it most likely will. After all this thread is about testing SONAR, and not download insight.

3. I will download the sample from the webserver and save it to the desktop

4. I will then run it and see what happens.

Regular Visitor
INDF
Posts: 6
Registered: ‎07-06-2011

Re: Sonar 4 problem.

[ Edited ]

Niko233

I was uploaded it to the following location:
 
http://savepic.net/2368012.png

 
shane_pereira
 
SONAR remove some malwares from the desktop. But SONAR have better efficiency for fight against malwares that is run from the another locations. Users want powerful SONAR anytime, anywhere.