Skip to content
This repository has been archived by the owner on Nov 29, 2018. It is now read-only.

Virus warning (Suspicious.Cloud.7.EP) in webdriver-firefox-esr-previous.dll #6120

Closed
lukeis opened this issue Mar 4, 2016 · 4 comments
Closed

Comments

@lukeis
Copy link
Member

lukeis commented Mar 4, 2016

Originally reported on Google Code with ID 6120

Norton Internet Security Reported following this morning:
[ 
Category: Resolved Security Risks
Date & Time,Risk,Activity,Status,Recommended Action
17/08/2013 08:06:02,High,
webdriver-firefox-esr-previous.dll (Suspicious.Cloud.7.EP)
detected by Auto-Protect,Blocked,Resolved - No Action Required
]

While opening FF browser and creating 
c:\Users\username\AppData\Local\Temp\anonymousXXXXXXX.webdriver-profile 
Norton was fired with the this warning ...

I have took file from quarantine and attached it ...

Selenium Web Driver (With c# app)
WebDriver.dll - v2.33.0.0
WebDriver.Support.dll - v2.33.0.0

webdriver-firefox-esr-previous.dll

Password for 7z is: 1234

Did anyone had similar issue or rather what is the reason for this ?


Reported by ingoplayer on 2013-08-17 08:19:59


- _Attachment: [webdriver-firefox-esr-previous.7z](https://storage.googleapis.com/google-code-attachments/selenium/issue-6120/comment-0/webdriver-firefox-esr-previous.7z)_
@lukeis
Copy link
Member Author

lukeis commented Mar 4, 2016

Reported by a.u.savchuk on 2013-08-18 08:35:21

  • Labels added: Browser-Firefox, Component-WebDriver

@lukeis
Copy link
Member Author

lukeis commented Mar 4, 2016

I've checked the attached file with Kaspersky Antivirus -- all is OK.

Norton's Suspicious.Cloud.7.EP heuristics is too alertive, see e.g. [1]

[1] http://answers.microsoft.com/en-us/windows/forum/windows_7-performance/how-do-i-get-rid-of-suspiciouscloud7ep/a430ef94-3aa1-4df1-b7c5-8e95496fef86

Reported by barancev on 2013-08-19 18:25:01

  • Status changed: Invalid
  • Labels removed: Status-Untriaged

@lukeis
Copy link
Member Author

lukeis commented Mar 4, 2016

Received the following wrt Suspicious.Cloud.7.EP warnings in webdriver-firefox-esr-previous.dll
from Symantec.

"Symantec FP Incident Response <falsepositives@symantec.com>
to me

In relation to submission [3320936].

Upon further analysis and investigation we have verified your submission and as such
this detection will be removed from our products.

The updated detection will be distributed in the next set of virus definitions, available
via LiveUpdate or from our website at http://securityresponse.symantec.com/avcenter/defs.download.html"

Reported by Alex.Saputa on 2013-09-24 04:15:26

@lukeis
Copy link
Member Author

lukeis commented Mar 4, 2016

Reported by luke.semerau on 2015-09-17 18:17:47

  • Labels added: Restrict-AddIssueComment-Commit

@lukeis lukeis closed this as completed Mar 4, 2016
@SeleniumHQ SeleniumHQ locked and limited conversation to collaborators Mar 4, 2016
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Projects
None yet
Development

No branches or pull requests

1 participant