Ce sujet a besoin d'une solution.
Remerciements0

False positive? Software to charge printer cartridges removed - heur.Adv.MLB

Win 10 PC.
I use an Epson 3000 printer.  I have an airlock in one cartridge stopping it from working.   The solution offered by Fotospeed (providers of the Inkjet refillable cartridges) is to replace the chips on the inkjet cartridges (so the printer believes it is a brank new set of cartridges on a new printer.   Then to run software to "charge" the printer in the same way as you'd charge a machine on first commissioning before sale.... effectively this treats the ink path with the airlock as though it is an empty path to be filled prior to first use.

The software to Charge the cartridges AdjProj.exe is flagged as rarely used (as it has a niche use and would rarely be used by end users) but is being flagged by Norton 360 as containing a threat (heur.Adv.ML.B) and the file is deleted rather than quarantined .

So two questions:   How do I submit to Norton to check / evaluate - to ensure it is a false positive, and how do I resolve this so that I can get my printer working again?  

Thanks,  

Pièce Jointe: 

Réponses

Remerciements0

Re: False positive? Software to charge printer cartridges removed - heur.Adv.MLB

Report a suspected incorrect detection to Norton
https://support.norton.com/sp/en/us/home/current/solutions/v126152382

Submit a file to Norton
https://support.norton.com/sp/en/us/home/current/solutions/kb20090602171902EN

Respond to incorrect Norton alerts that a file is infected or a program or website is suspicious
https://support.norton.com/sp/en/us/home/current/solutions/kb20100222230832EN


Please tell us what Norton is telling you regarding this event.
For information regarding this event > from Norton pop-up > View Details > Copy to Clipboard &or from Norton history > More Options > Copy to Clipboard > paste here.

For second opinion choose File &/or Search hash at VirusTotal 

Remerciements0

Re: False positive? Software to charge printer cartridges removed - heur.Adv.MLB

Act on quarantined risks or threats
https://support.norton.com/sp/en/us/home/current/solutions/v6200305

Turn off or turn on Download Intelligence
https://support.norton.com/sp/en/us/norton-security/current/solutions/v23920640

Exclude files and folders from Norton Auto-Protect, SONAR, and Download Intelligence scans
https://support.norton.com/sp/en/us/home/current/solutions/v3672136

Fix problem detecting a file or program as a threat even after you exclude it from scan
https://support.norton.com/sp/en/us/home/current/solutions/v115455517

Configure Exclusions/Low Risks settings
https://support.norton.com/sp/en/us/norton-360/home/solutions/v15457075

Exclude files with low-risk signatures from Norton scans
https://support.norton.com/sp/en/us/home/current/solutions/v15463085

Remerciements0

Re: False positive? Software to charge printer cartridges removed - heur.Adv.MLB

MikeMartin247:

The software to Charge the cartridges AdjProj.exe is flagged as rarely used (as it has a niche use and would rarely be used by end users) but is being flagged by Norton 360 as containing a threat (heur.Adv.ML.B) and the file is deleted rather than quarantined .

So two questions:   How do I submit to Norton to check / evaluate - to ensure it is a false positive, and how do I resolve this so that I can get my printer working again?  
 

Curious, is your Norton Heuristic Protection on Automatic?
Have you tried turning off Heuristic Protection temporarily...to get your printer working?
Have you tried turning off Auto-Protect temporarily...to get your printer working?
Curious, what happens with Restore &or Options? 


Were my machine and I trusted the "software" as safe. 
I'd try Restore &or Options.
I'd try to get file checksum/hash with Copy to Clipboard > paste to Notepad. 
I'd try to get second opinion file at VirusTotal.  Sure sounds like a false positive. 
I'd submit AdjProj.exe as false positive and exclude the entire software folder.   
Just me. 

The software to Charge the cartridges AdjProj.exe is flagged as rarely used (as it has a niche use and would rarely be used by end users) but is being flagged by Norton 360 as containing a threat (heur.Adv.ML.B) and the file is deleted rather than quarantined .

Curious, is the "software AdjProj.exe" from Fotospeed or Epson.  
Is "software AdjProj.exe" free and publicly available?

Edit:  I'm seeing in your screenshot Adj.Prog.exe 

Remerciements0

Re: False positive? Software to charge printer cartridges removed - heur.Adv.MLB

fwiw ~ Google search AdjProg.exe - odds are not your AdjProg.exe
- posting for example:

Copy to Clipboard ->
Filename: AdjProg.exe
Threat name: Heur.AdvML.MFull Path: C:\Users\user\Desktop\epsont50qlrjxz\epsont50qlrjxz\epsont50qlrjxz\apsonT50_gr\AdjProg.exe

On computers as of 
6/25/2023 at 8:57:49 AM

Last Used 
6/25/2023 at 8:59:49 AM

Threat type: Heuristic Virus. Detection of a threat based on malware heuristics.

AdjProg.exeThreat name: Heur.AdvML.M
Locate

Few Users
Hundreds of users in the Norton Community have used this file.

Mature
This file was released 12 years 8 months  ago.

High
This file risk is high.

https: //api. 256file. com/download/388950_adjprog. exe
Downloaded File  from 256file. com
Source: External Media

AdjProg.exe
File Actions

File: C:\Users\user\Desktop\epsont50qlrjxz\epsont50qlrjxz\epsont50qlrjxz\apsonT50_gr\AdjProg. exe Removed

File Thumbprint - SHA:
0484ee006845fc148eadeab7d21ab9810834d3408febf9794b5e5066267d9cec
File Thumbprint - MD5:
7ef52c9e397fbc27c3983f7bdb36137a
 

VirusTotal [here]

Remerciements0

Re: False positive? Software to charge printer cartridges removed - heur.Adv.MLB

- posting for example:
Restore ->

Yes 

File Insight against AdjProg.exe

Copy to Clipboard

Filename: AdjProg.exe
Full Path: C:\Users\user\Desktop\epsont50qlrjxz\epsont50qlrjxz\epsont50qlrjxz\apsonT50_gr\AdjProg.exe

Developers 
Not Available

Version 
1.0.0.0

Identified 
6/25/2023 at 9:20:55 AM

Few Users
Hundreds of users in the Norton Community have used this file.

Mature
This file was released 12 years 8 months  ago.

Bad
There are many indications that this file is untrustworthy.

Source File: 
AdjProg.exe

File Thumbprint - SHA:
0484ee006845fc148eadeab7d21ab9810834d3408febf9794b5e5066267d9cec
File Thumbprint - MD5:
7ef52c9e397fbc27c3983f7bdb36137a

VirusTotal [here]

Remerciements0

Re: False positive? Software to charge printer cartridges removed - heur.Adv.MLB

- posting for example:
Options ->

Remerciements0

Re: False positive? Software to charge printer cartridges removed - heur.Adv.MLB

- posted for example:
'Upload a file' submission: Adj.Prog.exe 

//check submission status
https://submit.norton.com/?type=CHECK&submission_id=da6ab52b-4c10-4dac-b5bf-7f1c6f47555d

Remerciements0

Re: False positive? Software to charge printer cartridges removed - heur.Adv.MLB

- posting for example:
fwiw
~ from my Google search ... with Quarantine Restore + Exclude

Caveat: I do not have Epson printer.  

Remerciements0

Re: False positive? Software to charge printer cartridges removed - heur.Adv.MLB

@MikeMartin247
Sorry, my Google search is not finding your Adj.Prog.exe - Heur.AdvML.B

Category: Quarantine
Date & Time,Risk,Activity,Status,Recommended Action,Activity - Details
6/25/2023 10:39:28 AM,High,AdjProg.exe (Trojan.Gen.9) detected by Download Insight,Quarantined,Resolved - No Action Required,Threat Actions performed: 1
6/25/2023 10:39:28 AM,High,AdjProg.exe (Heur.AdvML.C) detected by Download Insight,Quarantined,Resolved - No Action Required,Threat Actions performed: 1
6/25/2023 9:17:08 AM,High,AdjProg.exe (Trojan.Gen.2) detected by Download Insight,Quarantined,Resolved - No Action Required,Threat Actions performed: 1
6/25/2023 8:59:49 AM,High,AdjProg.exe (Trojan.Gen.2) detected by Download Insight,Quarantined,Resolved - No Action Required,Threat Actions performed: 1
6/25/2023 8:59:49 AM,High,AdjProg.exe (Heur.AdvML.M) detected by Download Insight,Quarantined,Resolved - No Action Required,Threat Actions performed: 1

Remerciements0

Re: False positive? Software to charge printer cartridges removed - heur.Adv.MLB

FWIW ~ 

SantaFeBill wrote:
Norton IS 2014 wants to delete the Epson adjustment program (1.0.1, for the R3000), saying that it is a threat. Other major anti-malware programs (i.e., Malwarebytes and Emsisoft) don't have a problem.

I assume that a number of people here are using the program. Have you found it safe?

Adjustment programs allow you to in fact "Hack" your printer.  So they are seen or detected as Bad.  When you use them you need to close your anti virus software.

Joe

 https://www.dpreview.com/forums/thread/4130654

Remerciements0

Re: False positive? Software to charge printer cartridges removed - heur.Adv.MLB

I would like to suggest you to please uninstall previous Printer software as well as drivers.

and download new one from Official website, Here:- https://epson.com/Support/Printers/Single-Function-Inkjet-Printers/Epson...

Win 11 Pro version 23H2, |Certified Windows PC Troubleshooter|
Remerciements0

Re: False positive? Software to charge printer cartridges removed - heur.Adv.MLB

fwiw ~ regarding AdjProg.exe [here]

Filename: AdjProg.exe
Full Path: C:\Users\user\Desktop\epsont50qlrjxz\epsont50qlrjxz\epsont50qlrjxz\apsonT50_gr\AdjProg.exe

Developers 
Not Available

Version 
1.0.0.0

Identified 
6/25/2023 at 9:20:55 AM

Last Used 
6/25/2023 at 9:41:54 AM

Startup Item 
No

Few Users
Hundreds of users in the Norton Community have used this file.

Mature
This file was released 12 years 8 months  ago.

Trusted
Norton has given this file a trusted rating.

Source File: 
AdjProg.exe

File Thumbprint - SHA:
0484ee006845fc148eadeab7d21ab9810834d3408febf9794b5e5066267d9cec
File Thumbprint - MD5:
7ef52c9e397fbc27c3983f7bdb36137a
 

This thread is closed from further comment. Please visit the forum to start a new thread.