Is there a Bug in Safe Mode Scan?

I tested it today, and I am getting false positives. Looks like the safe mode scan is more aggressive by default then it would normally is when you are not running in safemode. I am going to talk with devs on the AV team and see what they have to say about this and I will report back here what I find out. Thanks for your patience while we look into this.

My recent scan in SafeMode

SafeMode Scan results.gif

 


michaell wrote:

I tested it today, and I am getting false positives. Looks like the safe mode scan is more aggressive by default then it would normally is when you are not running in safemode. I am going to talk with devs on the AV team and see what they have to say about this and I will report back here what I find out. Thanks for your patience while we look into this.


This issue is not yet a "known issue". Why?

 

http://community.norton.com/t5/Norton-Internet-Security-Norton/Known-Issues-with-NIS-19-1/m-p/533014


noghere wrote:

michaell wrote:

I tested it today, and I am getting false positives. Looks like the safe mode scan is more aggressive by default then it would normally is when you are not running in safemode. I am going to talk with devs on the AV team and see what they have to say about this and I will report back here what I find out. Thanks for your patience while we look into this.


This issue is not yet a "known issue". Why?

 

http://community.norton.com/t5/Norton-Internet-Security-Norton/Known-Issues-with-NIS-19-1/m-p/533014


Because we dont have a bug filed on this, also might not be a bug since the default setting might be making the scanner more aggressive in finding threats. I still need to find that out tomorrow.

Hello Everyone, I just finished talking with Dev with AV engine. This is unexpected behaviour since the scanner is the same and should detect same files. What would be helpful is if you all of you that have posted in this thread can send me a private message and let me know what files are causing the false positives on your machine. We are going to need some files to test with here so we can find out why this is happening. Thanks.

So, info from Message 14  and from posted screen shots is not what you need. 

All I would know how to send in PM to you is same info I posted in Message 14.

Can I attach the actual file within PM environment.

afaik there is no way to attach file in PM

Perhaps, I would need to upload the files to the secure symantec online storage facility located at https://www.swapdrive.com/login.htm.

or, some other Symantec venue. 


bjm_ wrote:

So, info from Message 14  and from posted screen shots is not what you need. 

All I would know how to send in PM to you is same info I posted in Message 14.

Can I attach the actual file within PM environment.

afaik there is no way to attach file in PM

I would need to upload the logs to the secure symantec online storage facility located at https://www.swapdrive.com/login.htm.

 

I'm thinking you need to provide login creds


Yes I might be able to find some of those files online, but not everyone on this thread was as detailed about posting the information about the false positives as you were. I am not looking for logs though, I am looking for links so that I can download these files from the internet because looks like these are exe and msi files that are widely available to the public.

michaell

 

So, what are asking for ? 

What files are causing the false positives, what program they belong to, and if they can be downloaded from the internet, what is the url for the site. Please send me a private message with the information, do not post it here.

Um, how would I locate a link for > 60b5b6c.msi   9/06/2008   Windows Installer Package

I'll try to PM links for exe's

My Installer Folder has many, many folders and files.  The alpha numeric codes must mean something to someone.

Um, to me it's all a non native language.  :smileysad:

in that case the names should be fine. I am sure I will be able to find them seaching on the internet.

Hello michaell

So, your are able to reproduce inhouse and have deemed the scan results as false positives.

 

quote: I tested it today, and I am getting false positives. Looks like the safe mode scan is more aggressive by default then it would normally is when you are not running in safemode. I am going to talk with devs on the AV team and see what they have to say about this and I will report back here what I find out. Thanks for your patience while we look into this.

 

In my mind you should be able to reproduce this on your inhouse test boxes where the scan results are readily available.  exe links and names of msi files from a few users.... um,....OK... if it will help.

Am I wrong in thinking that Community Watch has received data on my Unresolved Security Risks?

 

At some point.  What will I do with my Unresolved Security Risks.  ~  Clear Entries ?

 

Thanks


bjm_ wrote:

Hello michaell

So, your are able to reproduce inhouse and have deemed the scan results as false positives.

 

quote: I tested it today, and I am getting false positives. Looks like the safe mode scan is more aggressive by default then it would normally is when you are not running in safemode. I am going to talk with devs on the AV team and see what they have to say about this and I will report back here what I find out. Thanks for your patience while we look into this.

 

In my mind you should be able to reproduce this on your inhouse test boxes where the scan results are readily available.  exe links and names of msi files from a few users.... um,....OK... if it will help.

Am I wrong in thinking that Community Watch has received data on my Unresolved Security Risks?

 

At some point.  What will I do with my Unresolved Security Risks.  ~  Clear Entries ?

 

Thanks


Well because we are trying to find a pattern here, and the devs on the AV team need more information to go on. So far from what I can tell it looks like it is only detecting setup and cab files. The information provided thus far has actually helped a lot in narrowing down what is going on.

As for the unresolved entries you can clear them since they are false positives. Just make sure they are not quarantined or deleted.

PM sent 2 U

 

Thanks

bjm_


michaell wrote:

As for the unresolved entries you can clear them since they are false positives. Just make sure they are not quarantined or deleted.


So, GUI ~~ "Clear Entries" is appropriate for false positives... this will clear Security History log  ~~ Unresolved Security Risks and any backup folder akin to Qbackup folder.

Question asked earlier.  Is there a backup folder somewhere akin to Qbackup for Unresolved Security Risks.

 

Thanks

bjm_


michaell wrote:

What files are causing the false positives, what program they belong to, and if they can be downloaded from the internet, what is the url for the site. Please send me a private message with the information, do not post it here.


PM sent.

Looks like the New Patch 19.1.1.3 Fixed the False Positives. Just did a FULL SCAN in safe mode, Results: ALL CLEAN!!

Thank you Michaell, Norton Devs, AV Team for the fix. :smileyvery-happy:

Your welcome, this actually was not in the 19.1.1 patch. Looks like Sonar team updated sonar not to detect these files in safe mode. If any one of you that reported the problem does not see it resolved with lattest live update please let us know!


michaell wrote:

Your welcome, this actually was not in the 19.1.1 patch. Looks like Sonar team updated sonar not to detect these files in safe mode. If any one of you that reported the problem does not see it resolved with lattest live update please let us know!


HI michaell,

 

Is the SONAR patch generally available? I ran Live Update and got the new patch release 19.1.1.3 patch, rebooted and ran live update again whereupon it received only a pulse update.

 

SAFE mode scan is still in progress but already it has detected one Heuristic virus which does not appear in a Normal mode scan. I'll update again when the scan is fully completed.

 

Thanks

Allen