1. You are viewing our forum as a guest. For full access please Register. WindowsBBS.com is completely free, paid for by advertisers and donations.

how do I report infected software program .exe file

Discussion in 'Security and Privacy' started by DoubleHUtah, 2010/04/03.

  1. 2010/04/03
    DoubleHUtah

    DoubleHUtah Well-Known Member Thread Starter

    Joined:
    2007/03/27
    Messages:
    44
    Likes Received:
    0
    Is there anyone or anyplace to report an infected .exe file obtained from a vendor via download? Reason for query:

    My employer asked me to install a new version of a paid software program which she routinely uses. The installer file can be downloaded successfully. The program can be installed successfully. However, the .exe file of the new version is instantly deleted when activated. Norton 360 recognizes an Adware.Gen threat and actually deletes the .exe file.

    Via Norton remote assistance, a tech watched the actual file deletion. He added firewall & Norton acceptance of the .exe file. Norton 360 continued to reject it. Norton tech advised that the only method to actively use the program is with autoprotect disabled. We have notified the vendor that the file is infected and are waiting a response.

    I've done some searching and it appears that there is no where or no one to notify, other than the vendor, about the infected file problem. Luckily, the threat was contained, eliminated and subsequent scans indicate that the computer is clean.
     
  2. 2010/04/03
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116

  3. to hide this advert.

  4. 2010/04/03
    DoubleHUtah

    DoubleHUtah Well-Known Member Thread Starter

    Joined:
    2007/03/27
    Messages:
    44
    Likes Received:
    0
    Much thanks. Program is EBookGold - an ebook generator. The file is ebg.exe. Will request security check as suggested.

    If it is a false/positive , any help on how to deal with Norton 360? Or just run the program with autoprotect disabled?
     
  5. 2010/04/03
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    I don't use Norton and I rather stay far away from it, but usually AV programs have some exception setting, where you can put any file, you don't want to be scanned anymore.
     
  6. 2010/04/03
    DoubleHUtah

    DoubleHUtah Well-Known Member Thread Starter

    Joined:
    2007/03/27
    Messages:
    44
    Likes Received:
    0
    Yes, Norton has exceptions for both firewall and program area. The file has been put in both and Norton is still kicking it out. Will wait to see what security check and vendor have to say. Then may try to install the program on a laptop with Avast for comparison. Thanks for your help.
     
  7. 2010/04/03
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    Sure thing :)
     
  8. 2010/04/06
    DoubleHUtah

    DoubleHUtah Well-Known Member Thread Starter

    Joined:
    2007/03/27
    Messages:
    44
    Likes Received:
    0
    www.totalvirus.com confirms Adware.Gen virus in EBookGold .exe file. Norton 360 advises low level threat. Vendor has not responded. Program can be utilized with autoprotect disabled. Not an optimum scenario. Am concerned with definition of "low level threat" -- but how concerned should I be? Is this the same as being a little bit pregnant?
     
  9. 2010/04/06
    TonyT

    TonyT SuperGeek Staff

    Joined:
    2002/01/18
    Messages:
    9,072
    Likes Received:
    400
    IMHO I would seek out different software for generating e-books. EBook Gold generates e-books in .exe format. I don't know about you but even if my dear wife sent me an e-book in .exe format I'd just delete it!

    E-books are simply html files at their most basic. Find one that can generate the e-book as pdf and you'll be set. PDFs can be viewed in Windows, Mac and Linux, thus the e-book becomes available to all readers.
     
  10. 2010/04/06
    DoubleHUtah

    DoubleHUtah Well-Known Member Thread Starter

    Joined:
    2007/03/27
    Messages:
    44
    Likes Received:
    0
    I agree but can only advise employer who bought the program. She is the decision maker. Thanks for your input.
     
  11. 2010/04/06
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    Can you post the log?
    I'd like to see how many engines report the file as a threat.
     
  12. 2010/04/06
    DoubleHUtah

    DoubleHUtah Well-Known Member Thread Starter

    Joined:
    2007/03/27
    Messages:
    44
    Likes Received:
    0
    We didn't print or save the log of the file analyses. I don't work again until Thursday. Will ask employer if she minds taking the time to run them again.
     
  13. 2010/04/06
    DoubleHUtah

    DoubleHUtah Well-Known Member Thread Starter

    Joined:
    2007/03/27
    Messages:
    44
    Likes Received:
    0
    This is the Implix reply to the first email re Adware-Gen:
    The detection name "adware.gen" indicates that it is a generic detection of not a specific virus or spyware, but generic features which could potentially be risky (such as 'lock to one system') only IF the file you are running had malicious intent. I see you are able to run the program with the detection disabled, but if that is not acceptable, you can try running it on a computer that has different security software installed. The ebookgold software is out of development now so we are not able to make any changes to the code, but even doing so would compromise the security features it provides to copy protect your ebook contents.

    This is the Implix reply to the second email:
    Please see the reply sent a short while ago to your last email regarding the 'generic' detection in your Norton 360. This happens due to the copy protect features in ebookgold such as 'lock to one system' and 'check back for verification'. Without the embedded security features, there would be no point in using ebookgold, so you may just need to disable your scanning software or run on a computer that does not have that program.
     
  14. 2010/04/08
    DoubleHUtah

    DoubleHUtah Well-Known Member Thread Starter

    Joined:
    2007/03/27
    Messages:
    44
    Likes Received:
    0
    This can be marked solved. With Implix response to concerns, am pretty sure employer will continue to use the program as it was developed. She purchased it specifically for the features mentioned. Thanks to all who took time to read my posts and provide input. As usual, I can count on this forum for assistance.
     
    Last edited: 2010/04/08
  15. 2010/04/08
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    You're welcome :)
     

Share This Page

  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.