Fredfish Posted December 26, 2014 Posted December 26, 2014 LOOT 6 just reported that there was a new version of LOOT 6.01 I downloaded the archive, extracted it and scanned it. all fine so far so I installed it. On running LOOT my anti virus detected a trojan (SONAR.Heuristic.120) and deleted LOOT.exe http://www.symantec.com/security_response/writeup.jsp?docid=2014-011016-0119-99 Can anyone else confirm this?
Alpia Posted December 26, 2014 Posted December 26, 2014 virustotal scan is 1 of 56 antivir programs reported something https://www.virustotal.com/en/file/0ed54bb8c3245e3db4d23f6e1ab39522d53a27a99d63f3da3d2385f6e312cfea/analysis/1419597558/ Symantec is the only program that reported something so I doubt that Symantec WS.Reputation.1 20141226 The .rar version of the download has 0 of 56 reports so no just no also there is absolutly no reason why they should pack in something into loot. https://www.virustotal.com/en/file/3553794d16138c4c5c2de238802498712977e8741c4a6ec481b1271afa8fbf12/analysis/1419597822/
germanicus Posted December 26, 2014 Posted December 26, 2014 I checked new Loot 6.01, with two anti virus programs and two AntiSpyware programs, and had no single report about being infected.
Slorm Posted December 26, 2014 Posted December 26, 2014 I've seen this before and it's usually poor or malicious reporting by Symantec users (the so called "wisdom of the crowd"), it does not mean that any virus has been detected at all. In short it's just hearsay and not based on concrete evidence Better off dumping Symantec and it's bloatware and invest in a better virus scanner From the Symantec Website Updated: February 15, 2012 3:15:47 PM Type: Other Risk Impact: High Systems Affected: Windows 2000, Windows NT, Windows Server 2003, Windows Server 2008, Windows Vista, Windows XP BehaviorWS.Reputation.1 is a detection for files that have a low reputation score based on analyzing data from Symantec’s community of users and therefore are likely to be security risks. Detections of this type are based on Symantec’s reputation-based security technology. Because this detection is based on a reputation score, it does not represent a specific class of threat like adware or spyware, but instead applies to all threat categories.The reputation-based system uses "the wisdom of crowds" (Symantec’s tens of millions of end users) connected to cloud-based intelligence to compute a reputation score for an application, and in the process identify malicious software in an entirely new way beyond traditional signatures and behavior-based detection techniques.
CGi Posted December 26, 2014 Posted December 26, 2014 As the name says: "SONAR.Heuristic.120". And heuristic means simmilar to/could be. if you use a paranoid AV, set it up to ask for user input on the action to take, instead of automaticly deleting a file. As for Symantec WS.Reputation.1: What Slorm wrote. Rules about heuristic apply there.
Fredfish Posted January 16, 2015 Author Posted January 16, 2015 Rescanned the original file after the usual Norton updates and the threat message has been removed
Recommended Posts
Archived
This topic is now archived and is closed to further replies.