Quantcast
Viewing all articles
Browse latest Browse all 11462

False positive? gen trojan cwm_recovery_en.exe (android dev tool)

Non, je n'ai pas besoin d'une solution (je partage des informations seulement)

Symantec endpoint is flagging cwm_recovery_en.exe as a trojan and I believed it to be a false positive and reported it as such. The results came back informing me that I was wrong. 

I find this hard to believe. I have had cwm...exe in my downloads folder for over a year and it didn't get flagged and deleted until today even though the report from symantec states theyve known it as a threat for over a year. The file itself comes from xda-developers.com which isn't exactly a shady site by any means.  I downloaded it from http://forum.xda-developers.com/devdb/project/dl/?... and it still gets flagged.

I'm fairly certain this is a mistake based on symantec thinking because the file creates new processes in the background and whatnot that it may fit an algorithm for a suspect file, but that nobody has actually checked the contents to see there is nothing harmful. This is a pretty standard file for any android developer or user that wishes to 'root' their phone. 

Here's the report I got back after submitting false positive report:  (sorry about the formatting but thats how symantec formatted the pdf of the report....wouldn't it be easier/safer to just reply with an html report in the e-mail?):

Submission number: 39356619
Date submitted: August 28, 2015
Date closed: August 28, 2015 Contact details:XXXXXXXXX
Customer comments: I downloaded this from [http://]forum.xda-developers.com/devdb/project/dl/?id=5098 It says it hasnt been updated since spring 2014 which is around the time I last rooted my phone so the version symantec deleted may have been older but this is likely it.
Number of files in submission: 1
File name Determination MD5 CWM_Recovery_en.exe Trojan.Gen.X 2e35b4f5b751204d55bb5b01b837d565 File details: CWM_Recovery_en.exe Determination: Trojan.Gen.X
Reputation: Not Trusted There are many indications that this file is untrustworthy. Many users This file has been seen by hundreds of users . Mature Symantec has known about this file for more than 1 year. File Information MD5: 2e35b4f5b751204d55bb5b01b837d565 Size: 9075.77 KB
Type: 196608:rYNiXeuk60YeTMUYuRcj4Oj4aPCeA0JboKBhF0j+qjnyoCcFi5XcfRGlYY:U7ukktUTULPM0JsK3wjyVcFiCfIlYY Aliases: Information is unavailable

Symptoms Presence of the following file(s):
%Temp%\RarSFX0\nul %Temp%\RarSFX0\recovery\AdbWinUsbApi.dll ( 5f23f2f936bdfac90bb0a4970ad365cf )
%Temp%\RarSFX0\recovery\adb.exe ( 2c25a39086b640b2f83bebc82050b8fc )
%Temp%\RarSFX0\recovery\recovery.img ( b69e557139780cbf8d155b734c56e4cb ) %Temp%\RarSFX0\recovery\AdbWinApi.dll ( 47a6ee3f186b2c2f5057028906bac0c6 )
%Temp%\RarSFX0\recovery\fastboot.exe ( a730a3c0507f718a10917ce510f1ef5b )
%Temp%\RarSFX0\__tmp_rar_sfx_access_check_573094 %Temp%\RarSFX0\recovery
%Temp%\RarSFX0\Recovery.bat %Temp%\RarSFX0\Recovery.bat ( a809a41fb453a7373e719abc9cd0801f )
%Temp%\RarSFX1\recovery\adb.exe ( 2c25a39086b640b2f83bebc82050b8fc )
%Temp%\RarSFX1\recovery\AdbWinApi.dll ( 47a6ee3f186b2c2f5057028906bac0c6 )
%Temp%\RarSFX1\recovery\AdbWinUsbApi.dll ( 5f23f2f936bdfac90bb0a4970ad365cf ) %Temp%\RarSFX1\Recovery.bat ( a809a41fb453a7373e719abc9cd0801f )
%Temp%\RarSFX1\recovery\fastboot.exe ( a730a3c0507f718a10917ce510f1ef5b ) %Temp%\RarSFX1\recovery\recovery.img ( b69e557139780cbf8d155b734c56e4cb )

Presence of the following folder(s): %WORKINGDIRECTORY% Technical Description When executed, the threat performs the following functions.

Creates the following file(s): %Temp%\RarSFX0\nul
%Temp%\RarSFX0\recovery\AdbWinUsbApi.dll ( 5f23f2f936bdfac90bb0a4970ad365cf )
%Temp%\RarSFX0\recovery\adb.exe ( 2c25a39086b640b2f83bebc82050b8fc )
%Temp%\RarSFX0\recovery\recovery.img ( b69e557139780cbf8d155b734c56e4cb )
%Temp%\RarSFX0\recovery\AdbWinApi.dll ( 47a6ee3f186b2c2f5057028906bac0c6 )
%Temp%\RarSFX0\recovery\fastboot.exe ( a730a3c0507f718a10917ce510f1ef5b )
%Temp%\RarSFX0\__tmp_rar_sfx_access_check_573094 %Temp%\RarSFX0\recovery
%Temp%\RarSFX0\Recovery.bat ( a809a41fb453a7373e719abc9cd0801f )
%Temp%\RarSFX1\recovery\adb.exe ( 2c25a39086b640b2f83bebc82050b8fc )
%Temp%\RarSFX1\recovery\AdbWinApi.dll ( 47a6ee3f186b2c2f5057028906bac0c6 )
%Temp%\RarSFX1\recovery\AdbWinUsbApi.dll ( 5f23f2f936bdfac90bb0a4970ad365cf )
%Temp%\RarSFX1\Recovery.bat ( a809a41fb453a7373e719abc9cd0801f )
%Temp%\RarSFX1\recovery\fastboot.exe ( a730a3c0507f718a10917ce510f1ef5b )
%Temp%\RarSFX1\recovery\recovery.img ( b69e557139780cbf8d155b734c56e4cb )

Deletes the following file(s): %Temp%\RarSFX0\__tmp_rar_sfx_access_check_573094

Creates the following folder(s): %WORKINGDIRECTORY% 

Anyone care to download this file linked above to check it out and-- hopefully-- verify its harmless; then help remove this from endpoints definitions?


Viewing all articles
Browse latest Browse all 11462

Trending Articles