Pegasus Mail & Mercury

Welcome to the Community for Pegasus Mail and
The Mercury Mail Transport System, the Internet's longest-serving PC e-mail system!
Welcome to Pegasus Mail & Mercury Sign in | Join | Help
in
Home Blogs Forums Downloads Pegasus Mail Overview Mercury Overview

Norton AntiVirus detecting winpm-32.exe as Trjan.Dropper!!!!

Last post 05-18-2007, 23:16 by Peter Strömblad. 85 replies.
Page 4 of 6 (86 items)   « First ... < Previous 2 3 4 5 6 Next >
Sort Posts: Previous Next
  •  05-18-2007, 3:31

    • pbm is not online. Last active: 07-31-2007, 12:27 pbm
    • Top 50 Contributor
    • Joined on 05-17-2007
    • Member
    • Points 500

    Re: Norton AntiVirus detecting winpm-32.exe as Trjan.Dropper!!!!

    Sounds like we've got similar problems.... I've fixed the Norton problem, but can't get the new Pmail install to find the old folders and messages... HELP!

    pbm

  •  05-18-2007, 3:32

    • hbreder is not online. Last active: 05-23-2007, 12:03 hbreder
    • Not Ranked
    • Joined on 05-18-2007
    • Member
    • Points 25

    Re: Norton AntiVirus detecting winpm-32.exe as Trjan.Dropper!!!!

    I got it figured out: I copied most of the old mail into the Admin file, which is a subfolder under Mail; most of it seems to be there although it will need a little resorting and cleaning up.
  •  05-18-2007, 3:34

    • Lex is not online. Last active: 21/08/2008, 7:39 Lex
    • Top 75 Contributor
    • Joined on 03-30-2007
    • New Zealand
    • Member
    • Points 285
    • BetaTeam Moderator

    Re: Norton AntiVirus detecting winpm-32.exe as Trjan.Dropper!!!!

  •  05-18-2007, 4:34

    • jumpcut is not online. Last active: 05-19-2007, 0:05 jumpcut
    • Not Ranked
    • Joined on 05-17-2007
    • Member
    • Points 40

    Re: Norton AntiVirus detecting winpm-32.exe as Trjan.Dropper!!!!

    I have the opposite problem.  I reinstalled Pegasus after disabling Norton A/V and I have all my old files back.  However, I can not send or receive email.  The settings are exactly as they were before the problem started.  Each time I attempt to connect I get "bad address" for POP3 & SMTP.  I have set up an another email account using another address for Outlook Express with the EXACT same setting and that works fine.  I dont have a clue.  Any ideas?

     And of course, all these &^%$# companies ever do is fingerpoint..."Oh its not my problem".

  •  05-18-2007, 4:42

    • mands is not online. Last active: 05-21-2007, 1:32 mands
    • Not Ranked
    • Joined on 05-18-2007
    • Member
    • Points 20

    Re: Norton AntiVirus detecting winpm-32.exe as Trjan.Dropper!!!!

    I have the same problem.  Managed to get back all our old email accounts after reinstalling pmail but now can't download or send anything.  It really frustrating.....  Help...
  •  05-18-2007, 5:03

    • Trader is not online. Last active: 08-17-2008, 6:57 Trader
    • Top 100 Contributor
    • Joined on 05-17-2007
    • Member
    • Points 160

    Re: Norton AntiVirus detecting winpm-32.exe as Trjan.Dropper!!!!

    Hi Barbarab,

    What I was trying to point out in my last posting was for you to determine whether you had XP Pro or XP Home for an operating system.  If you have XP Pro you need to be logged in using an administrator account.  Once your logged in and you bring up Norton Antivirus you should be able to navigate to the settings page.  Do a search on the Norton help file if your not familiar with finding the settings page.  Once your at the settings page you should be able to follow the instructions to restore the winpm-32.exe file.

    If your not logged in as an administrator, the settings page will probably not be available to you.

    I'm not familiar with XP Home so I don't know if there is an administrator account and user account system as is used in XP Pro.  If it is the same, the same rules should apply to administrator or user access to program settings.  

    If you don't have administrator privileges you won't be able to reload Pegasus mail and you won't be able to set the exclusions which will cause Norton to ignore the winpm-32.exe file.

    If your still having problems send me your phone number so I can give you a call.

    Dale

  •  05-18-2007, 5:29

    • jumpcut is not online. Last active: 05-19-2007, 0:05 jumpcut
    • Not Ranked
    • Joined on 05-17-2007
    • Member
    • Points 40

    Re: Norton AntiVirus detecting winpm-32.exe as Trjan.Dropper!!!!

    Thru dumb luck and I do mean dumb luck, I found out that the connection was being blocked by the Norton firewall.  Go to Program Control under personal firewall then set Pegasus to permit all.

    My remaining problem is how to prevent Norton A/V which is disabled from creating the same problem when I reboot in the AM.  I found these instructions: 

    8. Upon completion of the restore process, close the "Security History" window, go back to the main Settings window and select "Virus and Spyware Protection Options" on the bottom of the window.
    9. Select "Scan Exclusions" from the Advanced Options.

    Where is it?  I cant find it in my version. 

  •  05-18-2007, 5:30

    • Trader is not online. Last active: 08-17-2008, 6:57 Trader
    • Top 100 Contributor
    • Joined on 05-17-2007
    • Member
    • Points 160

    Resolution of the Problem: Symantec response with updated definition file address.

    Good news is at hand,

     

    I received the following email this evening (17 May) regarding the False Positive (FP)  situation from Symantec.

     

     

    We were able to confirm the FP and the solution will be in Rapid Release Sequence 68629 or greater.
     
    You can find Rapid Release virus definitions here:
    ftp://ftp.symantec.com/AVDEFS/norton_antivirus_corp/rapidrelease/sequence/
     
    Please download the file "symrapidreleasedefsx86.exe" from within the folder with that sequence number and run it to install a new set of virus definitions that will correct the issue.
    We are also planning another LiveUpdate this evening to resolve the issue. This will be broadcast globally. I am sorry but I do not have an ETA on the LiveUpdate.
     
    Thanks again for the submission, and sorry for the inconvenience.
     
    Brandon

     
    Brandon Noble

    Security Response Liaison

    Symantec Corporation

    www.symantec.com

     

     

    I've downloaded the update file, run the update and will post the results, positive or negative within the next few minutes.   Currently its 9:29 PM Mountain Standard Time 

    The updated definition file has resolved the situation.  See the posting below for further info. 

  •  05-18-2007, 5:39

    • Trader is not online. Last active: 08-17-2008, 6:57 Trader
    • Top 100 Contributor
    • Joined on 05-17-2007
    • Member
    • Points 160

    Re: Norton AntiVirus detecting winpm-32.exe as Trjan.Dropper!!!!

    Within the settings page there should be several subsections with "Additional Options" as one of these.  Under "Additional Options" you should be able to find "Virus and Spyware Protection Options", and under that you should be able to find "Advanced Options" and under that, you should find "Scan Exclusions".  There you can set the winpm-32.exe exclusions. 

     

    If you still having problems finding it within your version, have a look at the help file and search for "scan exclusions." 

     

    Alternatively, you can download the Symantec Rapid Update and cure the problem once and for all.  I've included the email that I received from Symantec in a previous posting. 

  •  05-18-2007, 5:54

    Re: Norton AntiVirus detecting winpm-32.exe as Trjan.Dropper!!!!

    I will try the rapid release thingie.  While I was able to fix the problem on my XP-based work computer by restoring the WINPM-32.EXE from "quarantine", I've wasted the entire evening at home trying to get Norton Internet Security to tolerate WINPM-32.EXE.  I tried restoring from quarantine -- as soon as I do that, it detects the trojan and immediately removes it again.  I tried excluding "security risk.dropper" in ADVANCED OPTIONS: Signature Exclusions, and it has no effect.  I tried adding both the path to WINPM-32.EXE and the directory that contains WINPM-32.EXE to ADVANCED OPTIONS: Scan Exclusions without success -- Norton still removes the file.  I tried reinstalling, and NAV kills the file during the install, and Pegasus says the installation is corrupted.  The only way I can get Pegasus Mail to work at all is to disable auto-protect, reinstall PMAIL, and run it.  If I re-enable auto-protect, after a while it finds it, tries to remove it, can't, tells me to exit the program, and if I don't do that, eventually PMAIL is just killed and Norton demands I reboot.

    One important difference: I'm running Vista, but this is the Vista version of Norton Internet Security 2007.

    Anyway, I'm done with Norton -- after this waste of time, and two denied rebates last year (turned out my son took advantage of the same offer from Fry's for his computer without me knowing it, and it was one per household -- this was a regular rebate and an upgrade rebate), this will be the last Norton product I buy.

    I hear Trend Micro's antivirus is pretty good and less of a resource hog, and Vista doesn't really need a separate firewall (I have a hardware firewall anyway).  I also hear the Microsoft antivirus is terrible.  Any other suggestions?

      

     

     

     

  •  05-18-2007, 6:03

    Re: Norton AntiVirus detecting winpm-32.exe as Trjan.Dropper!!!!

    Ok... I tried the 68638 version of symrapidreleasedefsx86.exe but when I try to run it, it says

               This package has passed the initial signature check, but failed at launching the embedded package.

     Pressing OK closes the program.

     Another Vista incompatibility, I suspect.

     

     

  •  05-18-2007, 6:08

    • rjowsey is not online. Last active: 05-18-2007, 22:58 rjowsey
    • Not Ranked
    • Joined on 05-18-2007
    • Member
    • Points 5

    Re: Norton AntiVirus detecting winpm-32.exe as Trjan.Dropper!!!!

    FWIW, I highly recommend NOD32 from www.eset.com, having tried most of the others. I've seen only one false positive (with heuristic scanning set to "aggressive") in the past 12 months. Disclaimer: the NZ distributor (Chillisoft.co.nz) is a business partner. I'm not making any money from this, but I reckon NOD32 is about the best A/V product out there. Virus Bulletin seems to agree...

    Hope that helps!

     

    Filed under:
  •  05-18-2007, 6:12

    • Trader is not online. Last active: 08-17-2008, 6:57 Trader
    • Top 100 Contributor
    • Joined on 05-17-2007
    • Member
    • Points 160

    Re: Resolution of the Problem: Symantec response with updated definition file address.

    I'm running XP Pro 32 bit.  I removed the file exclusions from Norton Antivirus, and ran a scan of the Pegasus Mail folder.  The scan ran normally, and did not generate a false positive as it did earlier today.  Following that I ran a test with Pegasus mail, sending and receiving, which ran normally, without any problems generated by Norton Antivirus.   It would appear that the issue has been solved, at least for XP Pro 32 bit.

     

    I wonder if the x86 version is incorrect for the Windows Vista update.  The version info in the update folder on the Symantec FTP site doesn't indicate which file to use for the Vista Operating system.  In any event this should be solved by tomorrow with a normal global update from Symantec.  

     

    Time: 10:12 PM MST 

  •  05-18-2007, 6:40

    • repartie is not online. Last active: 05-18-2007, 13:44 repartie
    • Not Ranked
    • Joined on 05-17-2007
    • Member
    • Points 0

    Re: Resolution of the Problem: Symantec response with updated definition file address.

    This does seem to resolve the problem. This machine is running XP Pro... I don't know if the problem still exists on Vista platforms. For anyone just coming to the forum this works. I tried a variety of different things over the past hours, but this makes Pegasus and Norton play together again:

    1) download the "symrapidreleasedefsx86.exe" file to your computer from the latest relevant folder in ftp://ftp.symantec.com/AVDEFS/norton_antivirus_corp/rapidrelease/sequence/

    2) run that file. If there are problems, I'd try downloading a different version. I used the one out of the 63638 folder and it worked without problems.

    3) backup your pmail folder somewhere else under a different name, just in case.

    4) reinstall Pegasus. Download a fresh copy if you have errors. During install, you should be able to point to the original folder and it will give you the option to "update installation". This option will restore any missing files, but won't wreck your old mail or settings. Alternatively, all that seems to be needed is a current copy of winpm-32.exe put back into the PMAIL directory (your old shortcuts will tell you where it was supposed to be if you right-click and select "properties" on the shortcut). Old backups work for that, if Norton didn't *kindly* remove them, too.

    5) if you have problems not being able to download mail, make sure your firewall settings didn't get changed to block Pegasus from internet access. With Norton Internet Security 2007, open NIS 2007 and select settings->personal firewall->configure->program control and then select "Allow" under the "Access" column next to the Pegasus entry.


    BTW, I would suggest that as many of us as possible send notices to Norton to advise them that, while accidents do happen, a program as old and well-known as Pegasus Mail shouldn't get shut down like this. Kudos to the techies who got the signatures updated, finally.

    Also, for anyone so inclined, PandaSoftware has some nice, solid security software offerings. I prefer the configurability of platinum, but titanium is good too.

  •  05-18-2007, 6:49

    • tbartlem is not online. Last active: 05-18-2007, 6:49 tbartlem
    • Not Ranked
    • Joined on 05-17-2007
    • Member
    • Points 5

    Re: Norton AntiVirus detecting winpm-32.exe as Trjan.Dropper!!!!

    Take a good look at Trend, especially if you are supporting SMB sites.  I started moving all my clients off Symantec CE to TrendMicro about two years ago because Symantec programs became too invasive,prices got boosted to the stars and support went SOUTH (figuratively & literally).  Appears that Symantec needed to squeeze all the juice out of its AV users to support its foray into storage security.  When renewal prices went past $50-$60 per user I said goodbye....and haven't regretted it a minute since.  TrendMicro pricing for corporate licenses is a half to a third less than Symantec, especially if you go for a two year license upfront.  I've never had a single problem with virus definition file botches with Trend.  Symantec's AV support used to be run out of Eugene OR and they were good folks to deal with.  Those days are LONG GONE and you can see the kind of garbage support you get today.  Try TrendMicro...highly recommended.
Page 4 of 6 (86 items)   « First ... < Previous 2 3 4 5 6 Next >
View as RSS news feed in XML

Copyright © 2007 David Harris / Peter Strömblad. All Rights Reserved. | Terms of Use | Privacy Statement
Questions/Problems with community.pmail.com? | Visit our Hoster: PraktIT | Pegasus Mail Home Page