Heur.AdvML.B

Hallo

Ich arbeite mit dBase 10.2.2.0 und Windows 10. Seit kurzem wird eine mit dem dBase-Kompiler erstellte EXE-Datei von Norton security gelöscht. Es erscheint ein Hiweis auf den Virus "Heur.AdvML.B" . Ich kann mir nicht vorstellen, wie der Virus diese EXE kontaminieren soll.
Wie kann ich diese Löschungen verhindern?

Danke

Silvio
.

[Hinweis: diese Frage wurde urspruenglich geposted im Board Norton Internet Security | Norton Antivirus | Norton 360 und wurde hierher verschoben um Produkt-uebergreifend zu informieren. 2016-11-03BS]

Hallo @Ei Pee

 

 

Das Programm kannst Du NortonLifeLock melden( LINK). 

 

 

 

 

I believe this is related to TeamViewer which I don't use and began with the last March Windows update.

Instructions to post screenshots can be found here
https://community.norton.com/forums/how-post-image-forums-0

Your image...

Well that did not help as much as I thought. The only items I have in quarantine show where they were downloaded from. From this Origin tab, click on the Options link at the bottom right and see if there is an option to report the file to Norton. I cannot remember if that is there and my Quarantine items do not have the options link.

Your previous image shows the file is in  QTUpdate\msi.dll.  Do you have an app with QT in the name? Maybe QT Creator? if so, this sounds like an update that may be triggering the Norton detection. 

 

Eclosed is the Origin

Try clicking on the Origin tab to see where the msi.dll file has come from. 

png_18897.png

I am enclosing a screenshot of the indicated file.  Does this help?

Please tell us what Norton is telling you regarding this event.
For information regarding event > from Norton pop-up > View Details > Copy to Clipboard &or from Norton history > More Options > Copy to Clipboard > paste.

For second opinion choose File &/or Search hash at VirusTotal 


Act on quarantined risks or threats
https://support.norton.com/sp/en/us/home/current/solutions/v6200305

Turn off or turn on Download Intelligence
https://support.norton.com/sp/en/us/norton-security/current/solutions/v23920640

Exclude files and folders from Norton scans
https://support.norton.com/sp/en/us/home/current/solutions/v3672136

Norton detects a file or program as a threat even after you exclude it from scan
https://support.norton.com/sp/en/us/home/current/solutions/v115455517

Configure Exclusions/Low Risks settings
https://support.norton.com/sp/en/us/norton-360/home/solutions/v15457075

Exclude files with low-risk signatures from Norton scans
https://support.norton.com/sp/en/us/home/current/solutions/v15463085

Heur.AdvML.B is not the file name. It is the suspected malware name that is being detected in a file being scanned. Look in Norton History to get the file name. Open the classic 360 interface by clicking on Open beside Device Security in the My Norton interface. Then double click on the Security pillar, then click on History. From the drop down list at the left, click on Quarantine. Click on one of the listings for this detection and then click on More Options at the bottom right. From there click the Activity tab and it will list the file path to the detected file. Post that file name here and we can help determine if it is something that can be trusted.

 

Hallo Silvio,

In naja's Link betrifft Dich der Abschnitt "False-Positive":

Melden von Falschmeldungen

  • Senden von Dateien, die als Falschmeldung angesehen werden: Senden Sie falsch erkannte Dateien über die Seite "Report a Suspected Erroneous Detection (False Positive)" (Melden einer vermuteten Falschmeldung).

    <p>Weitere Informationen finden Sie unter <a href="https://support.norton.com/sp/de/de/home/current/solutions/kb20100222230832EN_EndUserProfile_de_de" title="">Das Norton-Produkt meldet fälschlicherweise, dass eine Datei infiziert oder ein Programm oder eine Website verdächtig sei (Falschmeldung)</a>.</p>
    </li>
    

 bzw. "Software Whitelisting Request" da es sich um eine .exe handelt.

Mit bestem Gruss

Beate Seidl

Hallo @Silvio Veronesi       

  Willkommen im Forum.

Melde das betreffende Programm Symantec( LINK).  

Info- LINK über "Heur.AdvML.B"

MfG
naja

Hello

Please follow the directions in this link to submit a file to see if it's a false positive.

https://submit.symantec.com/false_positive/   or to

www.virustotal.com

Thanks.

 

Norton Security identified & removed two instances of Heur.AdvML.B from our network. In both instances, the infected file was a Norton Antivirus setup file from 2004 that was downloaded directly from norton.com. Is this a false positive or a real virus?

Appears Norton agrees mine was a false positive

In relation to submission [3971077].

Upon further analysis and investigation we have verified your submission and, as such, the detection(s) for the following file(s) will be removed from our products:

Filename: razoapi8.dll
MD5: B480EB15863635BBBAEE4C17DE8B2117
SHA256: 2080408B68634716424417F946B32FFF3563BE654B1C1D2FD0DFDEFC6D6C5372
Result: Whitelisting for above file is taking effect from now on.

 

Done, thanks all

Hello John

Please post the tracking number to that Symantec Employee in the thread that bjm posted.

Thanks.

Yup, from my resubmit tonight.  A least one other poor soul shares my pain

JohnOzuk:  The tracking number for your submission is: 3971077, please reference this tracking number in any further correspondence on this issue.

Please see > https://community.norton.com/en/comment/7075321#

Thanks.  This time submit sent me to a confirmation page,  On Monday it seemed to do nothing.  Not sure what was going on.  Here is number

 

The tracking number for your submission is: 3971077, please reference this tracking number in any further correspondence on this issue.