Rotate Sushi
A Windows program that does nothing but spin a 3D model of a sushi roll against a blue screen. It is built the same way as a DirectX 9 sample (the DirectX SDK tutorial "Meshes"), with only the model swapped for a sushi roll I made myself.
Recreation
The actual screen from back then survives in a YouTube video of Sushi.exe running. Separately, the animation below is an imagined recreation redrawn by AI, using the rendering conditions read out of the distributed exe and model (it is not the actual screen).

- The model sits away from the origin, so the sushi does not spin in place but sweeps a wide circle across the screen
- One turn takes about 6.3 seconds (1 radian per second)
- Lighting is ambient only, so there is no shading and the texture colors come through as-is
The time Norton deleted it
On the day I started handing it out, this 10KB program that does nothing but spin a sushi roll was deleted by Norton AntiVirus as a virus. It was a false positive, of course. The fun part: renaming the file, without changing a single byte, changed the verdict. I no longer distribute the program, so what follows is a record of what happened then.
Norton first warned me when the file was downloaded. The reasons it listed were three: "very few users", "very new", and "unproven".

When run, it was stopped for "suspicious behavior" and deleted.

So I checked, in this order:
- A program that only shows a message box, built under the name
Sushi.exe, was also flagged as suspicious - The real sushi program, compiled under the name
DxTest4.exe, was not flagged - Copying that and renaming it to
Sushi.exegot it detected as a virus - The files in 2 and 3 had the same MD5 (a fingerprint-like value computed from a file's contents)

At the time I figured several "suspicious" conditions had lined up: an unknown download source, very few users worldwide, a name different from the one it was compiled under, and maybe a past virus named sushi.exe (that last one was a guess even then, and I could not confirm it this time either). Three other antivirus products I tried on the same file said nothing.
Reading it again now, one thing remains unexplained. Norton's reputation-based judgment (Norton Insight1) tells files apart by a hash of their contents and by how many people use them. By that logic two files with identical contents should get the same reputation, yet the name split the result. Perhaps something besides reputation was also using the name as a clue. Back then I wrote that being too strict does no harm and was impressed, while also noting it might be a harsh spec for individual developers. I had renamed the file in the first place because the compiled name looked lame.
Introduced in Norton 2010. It collects SHA-256 hashes of files and treats those that appear on most users' computers as safe. Norton Insight (Wikipedia) ↩︎
🤖 This English version is machine-translated by AI.