Symantec endpoint is flagging cwm_recovery_en.exe as a trojan and I believed it to be a false positive and reported it as such. The results came back informing me that I was wrong.
I find this hard to believe. I have had cwm...exe in my downloads folder for over a year and it didn't get flagged and deleted until today even though the report from symantec states theyve known it as a threat for over a year. The file itself comes from xda-developers.com which isn't exactly a shady site by any means. I downloaded it from http://forum.xda-developers.com/devdb/project/dl/?... and it still gets flagged.
I'm fairly certain this is a mistake based on symantec thinking because the file creates new processes in the background and whatnot that it may fit an algorithm for a suspect file, but that nobody has actually checked the contents to see there is nothing harmful. This is a pretty standard file for any android developer or user that wishes to 'root' their phone.
Here's the report I got back after submitting false positive report: (sorry about the formatting but thats how symantec formatted the pdf of the report....wouldn't it be easier/safer to just reply with an html report in the e-mail?):
Submission number: 39356619
Date submitted: August 28, 2015
Date closed: August 28, 2015 Contact details:XXXXXXXXX
Customer comments: I downloaded this from [http://]forum.xda-developers.com/devdb/project/dl/?id=5098 It says it hasnt been updated since spring 2014 which is around the time I last rooted my phone so the version symantec deleted may have been older but this is likely it.
Number of files in submission: 1
File name Determination MD5 CWM_Recovery_en.exe Trojan.Gen.X 2e35b4f5b751204d55bb5b01b837d565 File details: CWM_Recovery_en.exe Determination: Trojan.Gen.X
Reputation: Not Trusted There are many indications that this file is untrustworthy. Many users This file has been seen by hundreds of users . Mature Symantec has known about this file for more than 1 year. File Information MD5: 2e35b4f5b751204d55bb5b01b837d565 Size: 9075.77 KB
Type: 196608:rYNiXeuk60YeTMUYuRcj4Oj4aPCeA0JboKBhF0j+qjnyoCcFi5XcfRGlYY:U7ukktUTULPM0JsK3wjyVcFiCfIlYY Aliases: Information is unavailableSymptoms Presence of the following file(s):
%Temp%\RarSFX0\nul %Temp%\RarSFX0\recovery\AdbWinUsbApi.dll ( 5f23f2f936bdfac90bb0a4970ad365cf )
%Temp%\RarSFX0\recovery\adb.exe ( 2c25a39086b640b2f83bebc82050b8fc )
%Temp%\RarSFX0\recovery\recovery.img ( b69e557139780cbf8d155b734c56e4cb ) %Temp%\RarSFX0\recovery\AdbWinApi.dll ( 47a6ee3f186b2c2f5057028906bac0c6 )
%Temp%\RarSFX0\recovery\fastboot.exe ( a730a3c0507f718a10917ce510f1ef5b )
%Temp%\RarSFX0\__tmp_rar_sfx_access_check_573094 %Temp%\RarSFX0\recovery
%Temp%\RarSFX0\Recovery.bat %Temp%\RarSFX0\Recovery.bat ( a809a41fb453a7373e719abc9cd0801f )
%Temp%\RarSFX1\recovery\adb.exe ( 2c25a39086b640b2f83bebc82050b8fc )
%Temp%\RarSFX1\recovery\AdbWinApi.dll ( 47a6ee3f186b2c2f5057028906bac0c6 )
%Temp%\RarSFX1\recovery\AdbWinUsbApi.dll ( 5f23f2f936bdfac90bb0a4970ad365cf ) %Temp%\RarSFX1\Recovery.bat ( a809a41fb453a7373e719abc9cd0801f )
%Temp%\RarSFX1\recovery\fastboot.exe ( a730a3c0507f718a10917ce510f1ef5b ) %Temp%\RarSFX1\recovery\recovery.img ( b69e557139780cbf8d155b734c56e4cb )Presence of the following folder(s): %WORKINGDIRECTORY% Technical Description When executed, the threat performs the following functions.
Creates the following file(s): %Temp%\RarSFX0\nul
%Temp%\RarSFX0\recovery\AdbWinUsbApi.dll ( 5f23f2f936bdfac90bb0a4970ad365cf )
%Temp%\RarSFX0\recovery\adb.exe ( 2c25a39086b640b2f83bebc82050b8fc )
%Temp%\RarSFX0\recovery\recovery.img ( b69e557139780cbf8d155b734c56e4cb )
%Temp%\RarSFX0\recovery\AdbWinApi.dll ( 47a6ee3f186b2c2f5057028906bac0c6 )
%Temp%\RarSFX0\recovery\fastboot.exe ( a730a3c0507f718a10917ce510f1ef5b )
%Temp%\RarSFX0\__tmp_rar_sfx_access_check_573094 %Temp%\RarSFX0\recovery
%Temp%\RarSFX0\Recovery.bat ( a809a41fb453a7373e719abc9cd0801f )
%Temp%\RarSFX1\recovery\adb.exe ( 2c25a39086b640b2f83bebc82050b8fc )
%Temp%\RarSFX1\recovery\AdbWinApi.dll ( 47a6ee3f186b2c2f5057028906bac0c6 )
%Temp%\RarSFX1\recovery\AdbWinUsbApi.dll ( 5f23f2f936bdfac90bb0a4970ad365cf )
%Temp%\RarSFX1\Recovery.bat ( a809a41fb453a7373e719abc9cd0801f )
%Temp%\RarSFX1\recovery\fastboot.exe ( a730a3c0507f718a10917ce510f1ef5b )
%Temp%\RarSFX1\recovery\recovery.img ( b69e557139780cbf8d155b734c56e4cb )Deletes the following file(s): %Temp%\RarSFX0\__tmp_rar_sfx_access_check_573094
Creates the following folder(s): %WORKINGDIRECTORY%
Anyone care to download this file linked above to check it out and-- hopefully-- verify its harmless; then help remove this from endpoints definitions?