Norton Trusted Files versus Virus Total Antiviruses: 7 files accidentally observed

 

1) Most of us knew that Norton Trusted files are placed in white list and while run it - it will be not scanned by Norton - they can run easily and fast.

 

In summer 2010 I accidentally meet with Norton Trusted files but after upload to Virus Total (VT) Service was next results:

 

y1.PNG

 

Each of 7 files is Norton Trusted (NIS 18.1)

 

y2.PNG

 

 

http://www.virustotal.com/file-scan/report.html?id=adfc30d2fc23d79457fbbdd06d98b1405582637cb1a693b2dacd15954b5183b4-1292575893

 

http://www.virustotal.com/file-scan/report.html?id=187b38ad86e8314e62cb791a43717e6357594f03293cbebfdc473dcf41f4663b-1292576062

 

http://www.virustotal.com/file-scan/report.html?id=c6cfdbe6d8c5d3ef73fa5d27c2c17d7a923e594ebbfb32f068b28340ea97bb6c-1292576063

 

http://www.virustotal.com/file-scan/report.html?id=a8e962ce72186875ba6dd1dd907541ada4ea3dca0309b318a5aee4fc185e45f8-1292575902

 

http://www.virustotal.com/file-scan/report.html?id=b7463b715e45ceb2881d1bcc491553471683e9995353a9cddb5d11159e0268ac-1292575903

 

http://www.virustotal.com/file-scan/report.html?id=be82b4958024e874261a132cb3463c60d5d28a93004f3d98cb0069aedd8f67c3-1292575904

 

http://www.virustotal.com/file-scan/report.html?id=dc491472cf5d79f02a65f09dfdd97ec3bcb4a8b77894e90cd244eac636b778b7-1292575905

 

 

In the past I saw 4-6 false positives (FP) from 25-30 VT antiviruses, but I saw that it was really FP - files was from well know Software and Antivirus vendors. Some of Norton Trusted files (in collection was about 70-80 files) was reported by VT as malware but with 0-20 antiviruses, but they was not so strong (in my eyes) and I say that may be they are wrong... but antiviruses with nowadays few false alarms reported me about 7 files that they are malware (based on Avira, Microsoft, ESET and Kaspersky detections).

 

To review them:

Submission has been sent Fri Dec 17 01:24:40 PST 2010

Tracking #18553851

 

 

_________________________________________________________________________________________

 

 

 

2) 2-bytesNorton Trusted file with content of two symbols:

MZ

is Norton Trusted too.

 

y3.PNG

 

 

What is the payload of this included in while list item? How much users (more than 100,000 ?) and how often use this file? What for is this file - can it have the payload if it exits on some/many/every machines?