ISB.Downloader!gen252

Norton has begun detecting, blocking, and supposedly removing ISB.Downloader!gen252 about every four minutes, so obviously the 'removal' is not working.  Neither have a full Norton scan, a Norton Power Erase (with rootkit) scan, or pre-start scans by Malwarebytes and Windows Defender. 

This seems to be malware that keeps trying to use Powershell to do something that Norton detects, but no scanner is detecting the actual bad actor.  I would appreciate advice on getting rid of it. 

My system is Windows 10, with a reinstalled Chrome browser.

Norton's messages:  Auto-protect is processing security risk ISB.Downloader!gen252

We removed security risk ISB.Downloader!gen252. No further action is required.

We blocked a suspicious action from one or more programs. No further action is required.

Threat type: Heuristic Virus. Detection of a threat based on malware heuristics.

File Actions  File: PowerShell_C:\WINDOWS\System32\WindowsPowerShell\v1.0\powershell.exe_10.0.19041.1 No fix attempted

Threat name: SONAR.UserProc!g3

HtownPadre:
I'm writing to report that there was not a single Norton warning message about the SONAR virus over the weekend...

https://forums.malwarebytes.com/topic/309530-sonaruserprocg3/?do=findComment&comment=1625826 

https://forums.malwarebytes.com/topic/309530-sonaruserprocg3/

@Htownpadre

Did you post over on Malwarebytes Malware Removal Help?
Did you make False Positive submission? 

 

Maybe, it's False Positive waiting for user to make submission. 
Although, I'd figure Norton Community Watch was making submissions.  

Report a suspected incorrect detection to Norton
https://support.norton.com/sp/en/us/home/current/solutions/v126152382

Submit a file to Norton
https://support.norton.com/sp/en/us/home/current/solutions/kb20090602171902EN

Respond to incorrect Norton alerts that a file is infected or a program or website is suspicious
https://support.norton.com/sp/en/us/home/current/solutions/kb20100222230832EN

Filename: powershell.exe
Threat name: SONAR.UserProc!g3Full Path: c:\windows\system32\windowspowershell\v1.0\powershell.exe

____________________________

____________________________


On computers as of 
2/14/2024 at 7:29:07 AM

Last Used 
3/11/2024 at 7:15:00 PM

Startup Item 
No
Launched 
Yes
Behavioral Protection monitors for suspicious program activity on your computer.


____________________________


powershell.exeThreat name: SONAR.UserProc!g3
Locate


Many Users
Hundreds of thousands of users in the Norton Community have used this file.

Mature
This file was released 2 months  ago.

High
This file risk is high.


____________________________


Source: External Media


____________________________


File Thumbprint - SHA:
Not available
File Thumbprint - MD5:
Not available
 

This could possibly happen due to hijacked DNS or corrupt DNS or Winsock 
Have you done Flush DNS and Reset Winsock?
Have you tried checking for bad DNS entries?
In any case, this might be a serious issue, I would contact support and see if you can use their Virus Protection Promise policy.

https://community.norton.com/en/comment/8551099#comment-8551099

So far you've assumed that your ISB.Downloader!genxxx detections are related to your recent online purchase, but you might have just as easily visited an infected website that triggered a drive-by download from the insecure (http) site http:// airlinesphonenumbers. com/.  The Norton article What are Drive-by Downloads + Drive-by Attack Prevention Tips suggests that users install an ad blocker to their browser to help prevent these types of drive-by downloads. Do you have any browser extensions like uBlock Origin or Malwarebytes Browser Guard installed in your MS Edge browser? I have both these content blockers installed in my default Firefox browser as well as my MS Edge browser. 

https://community.norton.com/en/comment/8537355#comment-8537355

Hello... I've been following this thread for several days as I am experiencing the same recurring issue .... T9 and Malwarebytes haven't solved this ISB.Downloader!gen252 issue that seems to be hiding in PowerShell from November 14, 2023.  Any more recent thinking absent reinstalling PowerShell or other reset options?

https://community.norton.com/en/comment/8551373#comment-8551373

``````````````````````````````````````````````````````

https://community.norton.com/en/forums/isbdownloadergen252

https://community.norton.com/en/forums/isbdownloader-found-during-full-scan-any-ideas

Please tell us what Norton is telling you regarding this event.
For information regarding this event > from Norton pop-up > View Details > Copy to Clipboard &or from Norton history > More Options > Copy to Clipboard > paste here.


Malwarebytes offers free second opinion on-demand scanner. 
Malwarebytes Malware Removal Help offers free one-on-one help.
Malwarebytes staff & experts help all.  Malwarebytes subscription is not required. 

Watching this thread carry along with all the annotations. Its been posted that this is LOL ( Living off the land ) malware infected system .dll infliction which will continue to reappear every time the machine is restarted or from a cold boot. My suggestion is, backup your files onto a separate drive. Format the C:\ drive on the affected machine and install a CLEAN Windows install using the appropriate .iso images provided by Microsoft. 

Conversely, I would also review the safety of the browser(s) being used, referring to "protection" not "features", review where I download files and surf as well. More likely than not, this infection happened without any user knowledge. 

SA

Htownpadre:

Why DIY?  Malwarebytes didn't work....  Still searching for any relief...

Malwarebytes Malware Removal Help...didn't work?
Please post link to your topic over on Malwarebytes Malware Removal Help. 


Malwarebytes Malware Removal Help offers free one-on-one help.
Malwarebytes staff & experts help all.  Malwarebytes subscription is not needed. 

Why DIY?  Malwarebytes didn't work.... 

Still searching for any relief...

Why DIY?

Malwarebytes Malware Removal Help offers free one-on-one help.
Malwarebytes staff & experts help all.  Malwarebytes subscription is not needed. 
Were my machine: I'd ask for help. 
Malwarebytes Malware Removal Help
https://forums.malwarebytes.com/forum/108-malware-removal-help/

Good evening and thanks for commenting... T9 is another "virus fixer" recommended by a couple of sites, but it seems that today, it was identified by Norton as causing a problem... SONAR.UserProc!g3 is now also showing up with the "location" still being PowerShell, so I suppose I need to figure out how to delete and reinstall PowerShell as it seems rather necessary... I did run Norton Power Eraser which made a few tweaks, but no joy with respect to the captioned virus (now + the SONAR one)... 

Malwarebytes Malware Removal Help offers free one-on-one help.
Malwarebytes staff & experts help all.  Malwarebytes subscription is not needed. 
Were my machine: I'd ask for help. 
Malwarebytes Malware Removal Help
https://forums.malwarebytes.com/forum/108-malware-removal-help/


Or....
What is Norton Virus Protection Promise?
https://support.norton.com/sp/en/ca/home/current/solutions/v62458994

 

Hey guys,

 

I have exactly the same issue. That would be great if a fix could be provided by Norton instead of formatting the computer from scratch and reinstall all apps... For what I've read on other forum about this issue, this is a very sensitive and dangerous virus that should not be underestimated. These guys telling to format hard disk as soon as possible :(

 

Hope somebody will find a solution to this issue

Htownpadre:

I have run each of Malwarebytes and T9 (along with a full Norton scan), resulting in either: No viruses found or a mention of ISB.Downloader!gen.252 with "no action taken".... 

on-demand scans are weak protection
Malwarebytes Malware Removal Help will gather & analyze logs and run custom scripts & tools.  
What's T9? 

Did you run Norton Power Eraser...just to see? 

Htownpadre:
I am seeing the same messages and screens from above, multiple times.  When I ask for "location", the response is the PowerShell application, November 14, 2023. 

fwiw ~ my W10 Home 22H2 machine

Filename: powershell.exe
Full Path: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe

Developers 
Microsoft Corporation

Version 
10.0.19041.3636

Identified 
11/18/2023 

Many Users
Millions of users in the Norton Community have used this file.

Mature
This file was released 2 months  ago.

Trusted
Norton has given this file a trusted rating.

File Thumbprint - SHA:
64dd55e1c2373deed25c2776f553c632e58c45e56a0e4639dfd54ee97eab9c19
File Thumbprint - MD5:
6726185b70b5adf05e8a1a1df82ebf30

Were my machine.  I'd ask for help.  

Malwarebytes Malware Removal Help
https://forums.malwarebytes.com/forum/108-malware-removal-help/


Maybe, it's False Positive waiting for user to make submission. 
Although, I'd figure Norton Community Watch was making submissions.  

Report a suspected incorrect detection to Norton
https://support.norton.com/sp/en/us/home/current/solutions/v126152382

Submit a file to Norton
https://support.norton.com/sp/en/us/home/current/solutions/kb20090602171902EN

Respond to incorrect Norton alerts that a file is infected or a program or website is suspicious
https://support.norton.com/sp/en/us/home/current/solutions/kb20100222230832EN

 

Filename: ISB.Downloader!gen252
Full Path: Not Available

____________________________

____________________________


On computers as of 
Not Available

Last Used 
12/28/2023 at 3:49:21 PM

Startup Item 
No
Launched 
No
Threat type: Heuristic Virus. Detection of a threat based on malware heuristics.


____________________________


ISB.Downloader!gen252
Locate


Unknown
It is unknown how many users in the Norton Community have used this file.

Unknown
This file release is currently not known.

High
This file risk is high.


____________________________


Source: External Media


____________________________

File Actions

File: PowerShell_C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe_10.0.19041.1No fix attempted

____________________________


File Thumbprint - SHA:
Not available
File Thumbprint - MD5:
Not available
 

I am seeing the same messages and screens from above, multiple times.  When I ask for "location", the response is the PowerShell application, November 14, 2023.  I have run each of Malwarebytes and T9 (along with a full Norton scan), resulting in either: No viruses found or a mention of ISB.Downloader!gen.252 with "no action taken"....