nodejs / node

Node.js JavaScript runtime ✨🐢🚀✨
https://nodejs.org
Other
107.37k stars 29.49k forks source link

Symantec false positve on x64 installer #1303

Closed dougalcampbell closed 9 years ago

dougalcampbell commented 9 years ago

Trying to install iojs (1.6.3) on a Win 7 Enterprise 64-bit machine (work computer). On launching the MSI installer, it silently deletes itself. Whaaaa?

piscisaureus commented 9 years ago

On launching the MSI installer, it silently deletes itself. Whaaaa?

Huh, seriously. Maybe get an antivirus solution (or get rid of it)?

silverwind commented 9 years ago

At least it's not an AV false positive:

https://www.virustotal.com/en/file/19afdc050d960526080559dbbdeb778e322238d6d28ed62ec5d92380439b4b02/analysis/1427830237/

@dougalcampbell I suggest running procmon to find out what's actually deleting it:

https://technet.microsoft.com/en-us/sysinternals/bb896645

dougalcampbell commented 9 years ago

Since it's a work computer, it could very well be some Enterprise-level system protection kicking in (though I do, theoretically, have admin permissions on this laptop). It's just odd that there's no error indication at all. No installation or error dialog appears. I just double-click the .msi in the file explorer, and a few seconds later, it simply disappears (and it's not in the Recycle Bin).

silverwind commented 9 years ago

That really sounds like some sort of protection software. I don't think the installer even has routines to delete itself.

dougalcampbell commented 9 years ago

As best as I can tell, I think Symantec Endpoint Protection is jumping in.

dougalcampbell commented 9 years ago

Confirmed: SEP quarantined the file as possible malware with risk classification "WS.Reputation.1". It does the same with both the 32-bit and 64-bit installers.

silverwind commented 9 years ago

@dougalcampbell care to submit a false positive here?: https://submit.symantec.com/false_positive/

silverwind commented 9 years ago

Submitted a report. if you can do too, it might help get it noticed faster.

dougalcampbell commented 9 years ago

@silverwind Submitted. Thanks. Going go go ahead and close this.

silverwind commented 9 years ago

Got an reply from Symantec saying they removed the binary from detection. Hopefully this will also apply to future releases.

dougalcampbell commented 9 years ago

"In relation to submission [3758605].

Upon further analysis and investigation we have verified your submission and as such this detection will be removed from our products."