Detection discrepancies – V21 vs V22

The version 22 beta is not detecting malicious files that can be detected by Norton version 21 products.


To illustrate, file encrypting malware was tested under version 21 and version 22 beta for comparison. Some aspects of the following videos are in Russian, however Community members familiar with the Norton product interfaces should have no trouble understanding the content.


Version 22 beta – Download Insight reporting set to Always – Full infection process:

 

http://youtu.be/o1RuekogXdM


Version 22 beta – Download Insight reporting set to Always and Block Traffic for Malicious Applications set to Aggressive – includes Norton Power Eraser file analysis:

 

http://youtu.be/FgGsr1s6qJM

 

Norton 360 v21 – Auto-Protect removes the files (Trojan Horse) and mitigates the attack:

 

http://youtu.be/8oXEhQBmfz0


Expected behaviour:

 

Version 22 should be able to detect the malicious files using the same Trojan Horse signature that version 21 uses. This would prevent the users files from being encrypted. Yet again, Norton Community member elsewhere and I are seeing problems with file reputation: Power Eraser says Unknown, Norton Security says Good. Given that many features in the Norton products depend on accurate file reputation in order to provide effective protection, this issue with file reputation accuracy needs to be urgently addressed.

 

Norton Security 22.0.0.82 Beta

Norton 360 21.4.0.13

Windows 8.1 - 64 bit