Offending URL from Flash player uninstaller.exe?

Vista Home Premium 32 bit with Vista SP2

NIS 17.8.0.5

 

I'm thinking this is not anything to be concerned with, but I though I'd check with the experts here

 

I just downloaded the flash player uninstaller from the adobe/macromedia website

(uninstall_flash_player.exe)

 

I noticed that at the same time I downloaded this There was an entry in my history as follows:

 

IPS Detection Statistical Submission

Local or Remote Attacker: 1

Sigset version 20101104.004

Application Name: \DEVICE\HARDDISKVOLUME1\PROGRAMFILES\INTERNETEXPLORER\IEXPLORE.EXE

Offending URL:  download. macromedia. com /pub/flashplayer/current/uninstall_flash_player.exe (I spaced this out so nobody would accidentally click on it)

remote address: 96. 6.11.191

Now it says status pending    No action required

So is this something that might be an issue/dangerous?

The actual file uninstall_flash_player.exe was acutially shown to be ok

Now one other thing, why did file for flash player not get checked by Download insight???

 

 

Vista Home Premium 32 bit with Vista SP2

NIS 17.8.0.5

 

I'm thinking this is not anything to be concerned with, but I though I'd check with the experts here

 

I just downloaded the flash player uninstaller from the adobe/macromedia website

(uninstall_flash_player.exe)

 

I noticed that at the same time I downloaded this There was an entry in my history as follows:

 

IPS Detection Statistical Submission

Local or Remote Attacker: 1

Sigset version 20101104.004

Application Name: \DEVICE\HARDDISKVOLUME1\PROGRAMFILES\INTERNETEXPLORER\IEXPLORE.EXE

Offending URL:  download. macromedia. com /pub/flashplayer/current/uninstall_flash_player.exe (I spaced this out so nobody would accidentally click on it)

remote address: 96. 6.11.191

Now it says status pending    No action required

So is this something that might be an issue/dangerous?

The actual file uninstall_flash_player.exe was acutially shown to be ok

Now one other thing, why did file for flash player not get checked by Download insight???

 

 

This use to happen to any .exe downloads.  Try downloading the .exe of your favorite files and you will see Norton reporting the URL as offending.  I think this is due to the fact that downloading the exe is mistaken for the download of malware, which also use a similiar tatic to download .exes.

so its all cool?

 

what about 

why did file for flash player not get checked by Download insight???

 

 

 

 


Calls wrote:

what about 

why did file for flash player not get checked by Download insight??


I downloaded this file as well, using Firefox, and I did get the Download Intelligence popup saying the file was safe.  I'm not sure why your experience may have been different, although there have been some descrepancies with Download Insight that have been reported here.  I am running NIS 2011 so perhaps it has something to do with the version, although more likely it was just a glitch,

 

Sorry, I didn't phrase m question well.

I was wondering why NIS 2010 Download Insight didi not seem to scan

Flash10l.ocx file upon download.

 

It scanned the flash player uninstaller exe file, but not the Flash10i.ocx file

Does download insight not check on ocx files?

The Flash Player installer and uninstaller files are ,exe files.  You wouldn't download Flash10l.ocx separately.  Auto-protect would take a look when Flash10l.ocx was written to disk.

it looks like downlod insight did NOT scan the flash player installer just the uninstaller. Is that something to be concerned about?

SendOfJive already answered this.  Insight does not scan every file coming into your machine.  It scans executables.  ocx files are considered to be a form of active x control and are components to be used by the executable file, which was checked.  Auto-protect scans everything.

 

It is perfectly normal.

i've had this problem before. the in browser install app can set norton off. even give you a warning if it's too new of a file. you have nothing to worry about as long as you know you installed that app and not someone else, ie a website you've gone too did that in the background with out you knowing. if your really scared you can run the file in question by virustotal.

 

it's because of problems like this that I use the manual installer for adobe so I can scan it first to besafe, a bit of a pain but it doesn't upset norton.

 

http://kb2.adobe.com/cps/191/tn_19166.html#main_ManualInstaller

OK

I just thought that SoJ said there was an installer.exe  and that is what I'm saying I DO NOT see scanned

I thought you said originally that the .exe was scanned and you wanted to know why the other wasn't. So which is it????

 

"Sorry, I didn't phrase m question well.

I was wondering why NIS 2010 Download Insight didi not seem to scan

Flash10l.ocx file upon download.

 

It scanned the flash player uninstaller exe file, but not the Flash10i.ocx file"

The uninstaller exe was scanned. But I do not see that the installer exe was scanned.

NIS 2010    17.8.0.5

Vista Home Premium 32 bit, Vista SP2

 

OK I know I have posted before about IPS Detection issues, but this one may be  a little different

 

Description   IPS Detection Statistical Submission

Signature ID: 23318

 

Local or Remote Attacker: 1  (Does 1 mean local or remore???)

 

Application Name: \DEVICE|HARDDISKVOLUME1\PROGRAMFILES\INTERNET EXPLORER\IEXPLORE.EXE

 

Offending URL:   ie.conduit-download.com/6/264/CT2642706/Downloads/IE/Releases/6.2.3.0/10-11-14-17.56.02.676/

                               TranslatorBar_5.exe

Status: Waiting

Recommended  Action: No Action Required

So does this mean this item downloaded on my computer?

I checked everywhere and I do not see TranslatorBar_5.exe

Checked applications Raiting from Norton GUI and this item was NOT shown there

Does it mean it tried to download and was stopped??

  

 

At thsi point is there anything I need to do?

Ran malewarebytes scan-CLEAN

Rand NORTON Quick Scan-CLEAN

 

 

just wondering if this is saying something tried to intrude

Hi Calls,

 

Please refer back to your earlier thread:

 

http://community.norton.com/t5/Norton-Internet-Security-Norton/Offending-URL-from-Flash-player-uninstaller-exe/m-p/322044/highlight/true#M133988

 

[Edit: Threads are now merged]

I understand that most of these if they say no action required, but this one throws me

 

Went to malwarebytes.org to download a clean install of malwarebytes

 

it takes me to the cnet download site for malwarebytes

ok

but then my security history shows this

IPS Statistical submission

Offending url:  software-files-l.cnet.com/s/software/11/65/78/91/mbamsetup1.50.0.0.exe  then a bunch of numbers and letters

 

so is this safe to download malwarebytes from?

 

also when I get to the download site at cnet, there are so many things on the page, hard to see which is the mbam download


Calls wrote:

I understand that most of these if they say no action required, but this one throws me

 

Went to malwarebytes.org to download a clean install of malwarebytes

 

it takes me to the cnet download site for malwarebytes

ok

but then my security history shows this

IPS Statistical submission

Offending url:  software-files-l.cnet.com/s/software/11/65/78/91/mbamsetup1.50.0.0.exe  then a bunch of numbers and letters

 

so is this safe to download malwarebytes from?

 

also when I get to the download site at cnet, there are so many things on the page, hard to see which is the mbam download


HI Calls,

 

This is perfectly normal and nothing to worry about. I don't see a lot of things on the CNET site. The MalwareBytes download button is on the upper left hand side and has MalwareBytes identified in the download button itself.

 

You should also see a Download Insight event which clearly states that the file is safe.

 

Best wishes.

Allen

Hi Calls,

 

I agree with AllenM that there is no reason for concern.

 

I believe SendOfJive and others have explained this before.  Undoubtedly what you are experiencing is the result of a new test signature.  Please see this post by Reese Anschultz.

 

If it's any comfort, I updated Malwarebytes today and have a similar IPS Submission entry:

...Offending URL: data-cdn.mbamupdates.com/v0/program/data/mbam-setup...