Norton Categorizes FE update as Unsafe and Removes it From My Computer

I have FE bata version 0.915.001 and I tried to update to version 0.915.002. I downloaded the FallenEnchantress_0.915_update_setup.exe to my downloads folder. As soon as the download ended Norton 360 informed me that the file was a threat to my system and that it, Norton, had removed it, without my permission, for my protection.

>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>

>>>>>

This next part if from the clipboard

>>>>>

Full Path: c:\users\joshua\downloads\tempmrmod\fe\fallenenchantress_0.915_update_setup.exe
Threat: WS.Reputation.1
____________________________
____________________________
On computers as of Not Available
Last Used 7/15/2012 at 8:52:34 AM
Startup Item No
Launched No
____________________________
____________________________
Unknown
Number of users in the Norton Community that have used this file: Unknown
____________________________
Unknown
This file release is currently not known.
____________________________
Medium
This file risk is medium.
____________________________
Threat Details
Threat type: Insight Network Threat. There are many indications that this file is untrustworthy and therefore not safe
____________________________
https://stardock.cachefly.net/Protected/expiretime=1342531798;badurl=aHR0cDovL3NkYzEuc3RhcmRvY2suY29tL2N1c3RvbWVycm9ycy80MDQuaHRt/b92becc0aa58d61426824f7c92c5a852/setup/FallenEnchantress_0.915_update_setup.exe Downloaded File fallenenchantress_0.915_update_setup.exe
Threat name:
WS.Reputation.1 from
cachefly.net
____________________________
File Actions
File: c:\users\joshua\downloads\tempmrmod\fe\fallenenchantress_0.915_update_setup.exe
Removed
____________________________
File Thumbprint - SHA:
ef5ae3110c80a65d5b86d31a0b0edd6f92084b5db41f87396ddd483aef3820f3
____________________________
File Thumbprint - MD5:
29f22727ba446fd04919cd0f0d4e0b88
____________________________

>>>>>>

One I though Stardock would like to know.

Two I would like the update.

12,561 views 17 replies
Reply #1 Top

You could close out of Norton prior to beginning the download, then launch it again after you've finished installing it.

Reply #2 Top

Quoting Tohron, reply 1
You could close out of Norton prior to beginning the download, then launch it again after you've finished installing it.
End of Tohron's quote

I turned off Norton Firewall and downloaded it. Norton still removed the file after download so it wasn't the firewall.

I then dug deeper into Norton's directories and found something called "Download Intelligence". I turned that off and downloaded again. It worked this time.

Reply #3 Top

This is becoming more and more of a problem for software developers.

Antivirus apps should not imply something is a threat simply because they do not know anything about it and the download intelligence feature of Norton appears to be fundamentally flawed.

I think the only way Norton will get the message is if people decline to renew their AV subscription and move to an AV package thats less stupid.

Reply #4 Top

WS.Reputation.1

http://www.symantec.com/security_response/writeup.jsp?docid=2010-051308-1854-99

WS.Reputation.1 is a detection for files that have a low reputation score based on analyzing data from Symantec’s community of users and therefore are likely to be security risks. Detections of this type are based on Symantec’s reputation-based security technology. Because this detection is based on a reputation score, it does not represent a specific class of threat like adware or spyware, but instead applies to all threat categories.

The reputation-based system uses "the wisdom of crowds" (Symantec’s tens of millions of end users) connected to cloud-based intelligence to compute a reputation score for an application, and in the process identify malicious software in an entirely new way beyond traditional signatures and behavior-based detection techniques.

End of quote

 If I'm reading this right, one of their users flagged the file? It didn't actually detect a threat?

Reply #5 Top


Did this issue just develope today? I have Norton, re-downloaded the game like 3-4 days ago, and had no problem. 

Reply #6 Top

Hm, this post reminds me I never got to finding an antivirus program... ^^
Never had any trouble though.

Sincerely
~ Kongdej

Reply #7 Top

Quoting Heavenfall, reply 5
WS.Reputation.1

http://www.symantec.com/security_response/writeup.jsp?docid=2010-051308-1854-99

WS.Reputation.1 is a detection for files that have a low reputation score based on analyzing data from Symantec’s community of users and therefore are likely to be security risks. Detections of this type are based on Symantec’s reputation-based security technology. Because this detection is based on a reputation score, it does not represent a specific class of threat like adware or spyware, but instead applies to all threat categories.

The reputation-based system uses "the wisdom of crowds" (Symantec’s tens of millions of end users) connected to cloud-based intelligence to compute a reputation score for an application, and in the process identify malicious software in an entirely new way beyond traditional signatures and behavior-based detection techniques.


 If I'm reading this right, one of their users flagged the file? It didn't actually detect a threat?
End of Heavenfall's quote

I understand it is actually worse, they decided it was a threat because they knew nothing about the file.

Reply #8 Top

Quoting Heavenfall, reply 5
WS.Reputation.1

http://www.symantec.com/security_response/writeup.jsp?docid=2010-051308-1854-99


WS.Reputation.1 is a detection for files that have a low reputation score based on analyzing data from Symantec’s community of users and therefore are likely to be security risks. Detections of this type are based on Symantec’s reputation-based security technology. Because this detection is based on a reputation score, it does not represent a specific class of threat like adware or spyware, but instead applies to all threat categories.

The reputation-based system uses "the wisdom of crowds" (Symantec’s tens of millions of end users) connected to cloud-based intelligence to compute a reputation score for an application, and in the process identify malicious software in an entirely new way beyond traditional signatures and behavior-based detection techniques.


 If I'm reading this right, one of their users flagged the file? It didn't actually detect a threat?
End of Heavenfall's quote

Odd way to decide if software is a threat. I mean if anyone who has Norton can flag any software download as being a threat what is to stop competitors from voting software as a threat for their own reasons? Such a means of determining a threat must rely on the honesty of those flagging software downloads as a threat. Trusting unknown individuals to honestly evaluate the threat level of software downloads, especially when they may have reasons not to be honest, seems unwise.

That aside I did get it downloaded after turning "Download Intelligence" off. So if anyone else runs into the same problem they know what to do.

However I would think that Stardock might want to fallow up on this and ask Norton why they did this. After all flagging a Stardock software download as a threat and then removing the software download in question, without the users permission, implies to all Norton users that Stardock is not trust worthy and is unsafe for their computers. I happen to trust Stardock more the Norton as can be seen by my willingness to ignore and turn Norton off but for new Stardock users who have not yet come to trust Stardock from experience.... Again they may want to follow up on this. Especially if it may effect any future updates or downloads that Stardock offers its paying customers.

Reply #9 Top


Norton is unsafe.

Try use a program that virus' aren't attracted to.

I have done tests: 2 machines....one with Norton and the other without.

I then proceed to view questionably safe sites....the same time....on both machines. Sure enough, the Norton machine picked up the virus and has trouble fighting it; the non-norton machine I virus scan afterwards an no virus? Coincidence? I think not.

 

Reply #10 Top

I'm not entirely sure about unsafe, but it's definitely intrusive, bulky (in terms of system resources), unfriendly and generally poorly developed.  I would suggest ANY OTHER virus program out there, free or paid, would outperform it in every way.

 

You should categorize Norton as unsafe, and remove it from your computer.

Reply #11 Top

There are several excellent security products offered free of charge for personal, non-commercial use. The trade press reviews and ranks them periodically - do a search. Ad-Aware, AVG, Avast, even Microsoft Security Essentials does a pretty good job. I'm not opposed to paying for security software but I expect better performance and less obtrusive operation compared to the free products

Reply #12 Top

Stay clear of AVG everyone I know who uses it get a virus - do yourself a favor pay for AV.  Now in terms of this application problem, there should be away to omit the FE directory - but obviously that opens you up to some other issues so be careful about doing this.  I would just sent a note to Norton about this.

Reply #13 Top

I have Norton's too and this is the most annoying feature. It's happened to me on more than one occasion with other game downloads. What is most frustrating is that it just deletes it without confirmation or warning and you can't change it. It is either on or off. Not fun when you download a 8GB file you trust only to have it erased immediately.  I don't find this functionality of "Norton Intelligence" intelligent at all.

 

Reply #14 Top

Quoting SteelFin, reply 14
I have Norton's too and this is the most annoying feature. It's happened to me on more than one occasion with other game downloads. What is most frustrating is that it just deletes it without confirmation or warning and you can't change it. It is either on or off. Not fun when you download a 8GB file you trust only to have it erased immediately.  I don't find this functionality of "Norton Intelligence" intelligent at all.

 
End of SteelFin's quote

It could be a good feature for some types of users who rarely if ever download anything and need maximum security on the computer.  BUT!!  Norton needs to document this option better and make sure users are fully aware of how this works and what the consequences can be to enabling it.

Reply #15 Top

Uninstall Norton- it's  worse malware then most viruses.

 

Reply #17 Top

Quoting Alstein, reply 16
Uninstall Norton- it's  worse malware then most viruses.

 
End of Alstein's quote

AAAAAMEN, brother!