Symantec automated Malware analyzer FAILED in detecting a proven malware submission!

Duis mollis, est non commodo luctus, nisi erat porttitor ligula, eget lacinia odio sem nec elit. Sed posuere consectetur est at lobortis. Vestibulum id ligula porta felis euismod semper. Donec ullamcorper nulla non metus auctor fringilla. Aenean lacinia bibendum nulla sed consectetur. Cras justo odio, dapibus ac facilisis in, egestas eget quam. Cras mattis consectetur purus sit amet fermentum. Morbi leo risus, porta ac consectetur ac, vestibulum at eros. Sed posuere consectetur est at lobortis. Etiam porta sem malesuada magna mollis euismod. Cum sociis natoque penatibus et magnis dis parturient montes, nascetur ridiculus mus. Duis mollis, est non commodo luctus, nisi erat porttitor ligula, eget lacinia odio sem nec elit. Cras justo odio, dapibus ac facilisis in, egestas eget quam. Aenean eu leo quam. Pellentesque ornare sem lacinia quam venenatis vestibulum. Curabitur blandit tempus porttitor. Sed posuere consectetur est at lobortis.

i’m sorry .i supposed to post it in the 360 section:smileyvery-happy:

here's another example i sent it 2 days ago a backdoor!!!....i lost my trust with symantec security analysis:mansad:

www.virustotal.com/analisis/3c6685363fef8e81beec05a6c2d600f2

 

Tracking #9710371

We have analyzed your submission. The following is a report of our
findings for each file you have submitted:

filename: info.exe
machine: Machine
result: See the developer notes

Developer notes:
 info.exe Our automation was unable to identify any malicious content in this submission.
 The file will be stored for further human analysis

As a matter of fact I had the Virtumonde adware on my machine while running N360 v2 . It was not found by N 360, not even on full system scans . Since I make automated back ups with Ghost I went back 3 days and got rid of it that way.  Spybot found it tho but could not get rid of it quick enough to my taste. The story  with N360 v2 continues

i hope Tony Weiss will comment on this thread also :smileytongue:

so, shall i continue posting examples of undetected malwares?:robotmad:.i received new another 2  different submitted malwares that symantec saying are clean…where other vendors approved that the files are 100% infected  :smileysurprised:

 i should better get over …and let symantec be as it is …

Could you confirm the dates and anything else of reference of the reports back from Symantec on those two incidents.

 

I've never had to report stuff not detected so I don't know how that works with the Symantec system but does it select the specific file to submit or do you?

 

I'm not querying your veracity but just interested in how it works. I see Grumpster has had a similar problem.

 

I've flagged this thread for a Norton Staffer and will watch how it develops but I'm a volunteer here and can't do more than that unless I have experience to share which I don't.

I apologize for any delay; I have contacted the security response team to look into this issue further. From the Symantec site, the following information is available regarding VirtuMonde, which Symantec identifies as Adware:

 

http://www.symantec.com/security_response/writeup.jsp?docid=2003-120914-4108-99

 

This thread also looks very similar to the following thread:

 

http://community.norton.com/norton/board/message?board.id=nis_feedback&message.id=2736#M2736

 

Is your product up-to-date? What version of Norton 360 v2 are you running? Thank you for your patience while we address the problem.

 

thank u Tony&huwyngr  for reply..:smileyhappy:

 

norton 360 v2 is up to date and vrrus signature always updated and product version (2.3.0.9)...norton didn't includ the threats even to the comminuty watch submitted catagory..

here is another

Below is a status update on your virus submission:  

[CLOSING]: Symantec Security Response Automation: Tracking #9711043

Date: June 23, 2008

We have analyzed your submission. The following is a report of our
findings for each file you have submitted:

filename: WUPH.exe
machine: Machine
result: See the developer notes

 WUPH.exe Our automation was unable to identify any malicious content in this submission.
 The file will be stored for further human analysis This file is contained by Desktop.rar

 

 

Ok lets analyize what's going on here:


cystatinC wrote:

i got infected with a Trojan Virtumonde which norton 360 v2 didn't detect it about 2 weeks ago !!.becose norton 360 doesn't have the option to quarantine and send suspected malware directly to symantec so i sent it to symantec submission site 2 times the infected malware...and each time symantec reply me with same message a 4 days later that the file is clean and not infected..but when i checked it at virustotal..the file is defiantly a proven Malware:18/33 (54.55%)


so you send the file to virustotal and out of 33 scanners running at that site only half (roughly) thought the file was malware.  So this could be a new varient of something.....   but we don't know if this one file submitted was really the right file, or if it was part of several originally...


cystatinC wrote:

filename: Spyware.exe


 

but i guess submitting the file with whatever name it had was out not possible, which may have been part of the problem with detection of a known threat.  I doubt the filename was spyware.exe when you got infected... after all how obvious is that?   

 

but wait.... we don't even know what file you actually submitted to get this result...  after all the name appear to have been changed along the way...    but whatever was sent in

 


cystatinC wrote:

The file will be stored for further human analysis


 

will get analized by more than a machine.

 


now lets move to your next post:

 


cystatinC wrote:

here's another example i sent it 2 days ago a backdoor!!!....i lost my trust with symantec security analysis:mansad:


wow.....  you got infected by a second so soon?   Or do you just keep various files around to submit to places to see what happens?

 


 

cystatinC wrote:

so, shall i continue posting examples of undetected malwares?:robotmad:.i received new another 2  different submitted malwares that symantec saying are clean...where other vendors approved that the files are 100% infected  :smileysurprised:

 i should better get over ..and let symantec be as it is ...


wow..... how many do you have?   do you just collect these to submit?   

 

 

I really find it hard to believe you are constantly getting infected... submitting files...  and then coming here to post about it to:


cystatinC wrote:

So the reason why I’m posting that back. is ..I’m trying to give feedback in this issue. for to improve analyzing for future :manhappy:


 

 

Message Edited by 4runner on 06-25-2008 10:09 AM

hii 4runner

thanx for reply…

I’ll answer to all your comments ::smileyhappy:

1.  {so you send the file to virustotal and out of 33 scanners running at that site only half (roughly) thought the file was malware.  So this could be a new varient of something…   but we don’t know if this one file submitted was really the right file, or if it was part of several originally…}

 

this is  totally the original file…i supplied the tracking number’s u can re-analyze it again if u don’t believe me…because the file is saved at symantec  " stored for further human analysis"  u can refer to the tracking number and re-analyze it…and see who is right:smileyhappy:…and i sent the same file to Kaspersky even before getting the result yet from symantec. .because kaspersky replied me in 2 hours. they confirm it as 100% malware …if u want i can send it to u again to your email…

by the way…i rechecked the same file today on virustotal…symantec just released update for the same file. which is sign that they reanalyze it again…

http://www.virustotal.com/analisis/37243c8758ed51ce02560819ef19e4f7

2.{wow… how many do you have?   do you just collect these to submit?}+{wow…  you got infected by a second so soon?   Or do you just keep various files around to submit to places to see what happens?}

i just been infected by the Trojan vertmonde(spyware.exe) only the  1st one not more…i learned my lesson!. all the rest been just suspected. so i just sent it to more than 1 vendor(symantec and kaspersky and avira) to be cretin…symantec said its CLEAN… all others said INFECTED.to whom i should believe?

 

about how many do i have??..i’m downloading everyday various files…like many others…so I’m sending just every occasionally downloaded suspicious file to me to symantec after checking it 1st at Virustotal !!..i just like to contribute to Symantec to get a better detection rate. helping in the fight against malwares…however symantec …saying they are safety clean applications :smileytongue:… seems I’m wrong in trying to help !!!

by the way most of them appreciate my work…by trying to help…Symantec Seems not appreciating… they are too confident :smileywink:

 The Symantec Security Response team has updated me on the status of these submissions:

 

9710371 - identified as Infostealer
9665065 - identified as Trojan.Dropper (that drops Trojan.Vundo)

 

We have recently created malware definitions for these items, and they are currently available here: 

http://securityresponse.symantec.com/avcenter/rapidrelease.download.html

 

Additionally, the threats found in 9711043 have malware definitions that will be available later today. Thank you for your help; this is a great example of how important our customers are in the detection of recent malware.

thank you very much Tony:smileyhappy:

finally i found somebody belive me....:smileyhappy:

glad everything ok now..

 

 


cystatinC wrote:

thank you very much Tony:smileyhappy:

finally i found somebody belive me....:smileyhappy:

glad everything ok now..

 

 


 

I'm glad you have a solution now.

 

Please not the difference in the way people's names appear in the Author column -- not everyone here works for Symantec! If you see a name in red, like Tony Weiss's, that indicates that they are Norton Staff. Other names can be specific volunteers, as I am, or just posters with a problem who stick around.

 

If you take a moment to scan through the messages here you will see indeed that Norton do care and that in fact they set up this Forums. I've been around computers a long long time and I can tell you I have not seen participation and feedback to this extent since the days when manufacturers used to run their own forums on Compuserve !

 

It's a breath of fresh air.

 

Keep in touch -- there's a lot going on.

thank u huwyngr :smileyhappy:

u r right..i didn't notice that...admins r in red :smileytongue:

glad to have u here huwyngr and all supporting members like u:manhappy:

 

take care &keep in touch

You’re welcome – keep coming back!

Message moved to its own thread for better exposure.