SONAR.SuspBeh!gen3 in Symantec Internet Security

Please check the FAQ (https://www.xyplorer.com/faq.php) before posting a question...
Post Reply
zer0
Posts: 2676
Joined: 19 Jan 2009 20:11

SONAR.SuspBeh!gen3 in Symantec Internet Security

Post by zer0 »

I just wanted to share an unpleasant experience I had this morning where a heuristic signature in Norton Internet Security decided to wipe some of my XYplorer files. Since they were not configuration files, I managed to "fix" things, by re-installing over the top. Here the relevant details:

Code: Select all

Filename: xyplorer_13.20_install.exe
Threat name: SONAR.SuspBeh!gen3
Full Path: Not Available

High
This file risk is high.

SONAR Protection monitors for suspicious program activity on your computer.

____________________________

Source: External Media
____________________________

File Actions

File: c:\users\<username>\appdata\local\temp\wz9c1f\ xyplorer_13.20_install.exe No Action Required

File: c:\program files (x86)\xyplorer\ xyplorer.chm Removed

File: c:\program files (x86)\xyplorer\ readmexy.txt Removed

File: c:\program files (x86)\xyplorer\ licensexy.txt Removed

File: c:\program files (x86)\xyplorer\ tipoftheday.htm Removed

File: c:\programdata\microsoft\windows\start menu\programs\xyplorer\ xyplorer.lnk Removed

File: c:\programdata\microsoft\windows\start menu\programs\xyplorer\ xyplorer help.lnk Removed

File: c:\programdata\microsoft\windows\start menu\programs\xyplorer\ xyplorer homepage.url Removed

File: c:\programdata\microsoft\windows\start menu\programs\xyplorer\ xyplorer uninstall.lnk Removed

File: c:\users\<username>\appdata\roaming\mpc-hc\ default.mpcpl Removed

Directory: c:\users\<username>\appdata\local\temp\ nsnc469.tmp No Action Required
____________________________

Registry Actions

Registry change: HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\ XYplorer->DisplayVersion:13.20, Registry Hive: 64 bit Repaired

Registry change: HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\ XYplorer->NSIS:StartMenuDir:XYplorer, Registry Hive: 64 bit Repaired

Registry change: HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\XYplorer->URLInfoAbout:http://www.xyplorer.com/, Registry Hive: 64 bit Repaired

Registry change: HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\ XYplorer->Publisher:Donald Lessau, Registry Hive: 64 bit Repaired

Registry change: HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\XYplorer->InstallLocation:C:\Program Files (x86)\ XYplorer, Registry Hive: 64 bit Repaired

Registry change: HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\ XYplorer->VersionMajor:13, Registry Hive: 64 bit Repaired

Registry change: HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\ XYplorer->VersionMinor:20, Registry Hive: 64 bit Repaired

Registry change: HKEY_USERS\S-1-5-21-1035394184-3343349579-4230999837-1001_CLASSES\Local Settings\MuiCache\88A\ 52C64B7E->LanguageList:..., Registry Hive: 64 bit Repaired
____________________________

System Settings Actions

Event: Browser process start (Performed by c:\users\<username>\appdata\local\temp\wz9c1f\xyplorer_13.20_install.exe, PID:6536) No action taken

Event: PE file creation: c:\users\<username>\appdata\local\temp\nsnc469.tmp\ userinfo.dll (Performed by c:\users\<username>\appdata\local\temp\wz9c1f\xyplorer_13.20_install.exe, PID:6536) No action taken

Event: PE file creation: c:\users\<username>\appdata\local\temp\nsnc469.tmp\ system.dll (Performed by c:\users\<username>\appdata\local\temp\wz9c1f\xyplorer_13.20_install.exe, PID:6536) No action taken

Event: PE file creation: c:\users\<username>\appdata\local\temp\nsnc469.tmp\ nsdialogs.dll (Performed by c:\users\<username>\appdata\local\temp\wz9c1f\xyplorer_13.20_install.exe, PID:6536) No action taken

Event: PE file creation: c:\users\<username>\appdata\local\temp\nsnc469.tmp\ startmenu.dll (Performed by c:\users\<username>\appdata\local\temp\wz9c1f\xyplorer_13.20_install.exe, PID:6536) No action taken

Event: PE file creation: c:\program files (x86)\XYplorer\ XYplorer.exe (Performed by c:\users\<username>\appdata\local\temp\wz9c1f\xyplorer_13.20_install.exe, PID:6536) No action taken

Event: PE file creation: c:\program files (x86)\XYplorer\ XYcopy.exe (Performed by c:\users\<username>\appdata\local\temp\wz9c1f\xyplorer_13.20_install.exe, PID:6536) No action taken

Event: PE file creation: c:\program files (x86)\XYplorer\ uninstall.exe (Performed by c:\users\<username>\appdata\local\temp\wz9c1f\xyplorer_13.20_install.exe, PID:6536) No action taken

Event: Process start: c:\program files (x86)\XYplorer\ XYplorer.exe, PID:4836 (Performed by c:\users\<username>\appdata\local\temp\wz9c1f\xyplorer_13.20_install.exe, PID:6536) No action taken

Event: Process start: c:\users\<username>\appdata\local\temp\wz9c1f\ xyplorer_13.20_install.exe, PID:6536 (Performed by c:\users\<username>\appdata\local\temp\wz9c1f\xyplorer_13.20_install.exe, PID:6536) No action taken

Event: Process start: c:\program files (x86)\k-lite codec pack\media player classic\ mpc-hc.exe, PID:1508 (Performed by c:\users\<username>\appdata\local\temp\wz9c1f\xyplorer_13.20_install.exe, PID:6536) No action taken
____________________________

Suspicious Actions

Event: Attempt to start a remote thread in a process address space (Performed by c:\users\<username>\appdata\local\temp\wz9c1f\xyplorer_13.20_install.exe, PID:6536) No action taken

Event: Accessibility API usage (Performed by c:\users\<username>\appdata\local\temp\wz9c1f\xyplorer_13.20_install.exe, PID:6536) No action taken
____________________________

Intriguingly, the whole kibosh started when I tried to play a file in MPC. However, it seems that the call to open that process was started by XYplorer's installer in the temp folder. But why would it be there? A temp folder is created when using the installer version, because that's where the temp files are stashed and it is usually removed when I close WinZip.
Reporting a bug? Have a wish? Got a question? Use search - View roadmap - FAQs: Forum + XY site
Windows 7/10
Always using the latest stable two-decimal build

admin
Site Admin
Posts: 66813
Joined: 22 May 2004 16:48
Location: Win8.1, Win10, Win11, all @100%
Contact:

Re: SONAR.SuspBeh!gen3 in Symantec Internet Security

Post by admin »

Norton... :roll: ... just remove that crap.

zer0
Posts: 2676
Joined: 19 Jan 2009 20:11

Re: SONAR.SuspBeh!gen3 in Symantec Internet Security

Post by zer0 »

admin wrote:Norton... :roll: ... just remove that crap.
No single AV product out there is perfect, especially when it comes to heuristics, so it's easy to blame whichever one causes headaches on a given day. I already have excludes for XYplorer.exe and XYcopy.exe.
Reporting a bug? Have a wish? Got a question? Use search - View roadmap - FAQs: Forum + XY site
Windows 7/10
Always using the latest stable two-decimal build

armsys
Posts: 557
Joined: 10 Mar 2012 12:40
Location: Hong Kong

Re: SONAR.SuspBeh!gen3 in Symantec Internet Security

Post by armsys »

zer0 wrote:No single AV product out there is perfect, especially when it comes to heuristics, so it's easy to blame whichever one causes headaches on a given day. I already have excludes for XYplorer.exe and XYcopy.exe.
Don is factually correct. Try AVG if you really need one.

zer0
Posts: 2676
Joined: 19 Jan 2009 20:11

Re: SONAR.SuspBeh!gen3 in Symantec Internet Security

Post by zer0 »

armsys wrote:
zer0 wrote:No single AV product out there is perfect, especially when it comes to heuristics, so it's easy to blame whichever one causes headaches on a given day. I already have excludes for XYplorer.exe and XYcopy.exe.
Don is factually correct. Try AVG if you really need one.
Sorry, not happening. I am not going to change to a different Internet security product simply because of a little hiccup that took less than a minute to fix. Better the devil you know that the devil you don't. FYI, I didn't start this thread to have a bash at an AV product. I just found it curious how various bits and pieces linked together.
Reporting a bug? Have a wish? Got a question? Use search - View roadmap - FAQs: Forum + XY site
Windows 7/10
Always using the latest stable two-decimal build

Filehero
Posts: 2734
Joined: 27 Feb 2012 18:50
Location: Windows 11@100%

Re: SONAR.SuspBeh!gen3 in Symantec Internet Security

Post by Filehero »

I use,

- Windows Defender (after 5 years BitDefender) + SpyBot
- depending on file criticality
+ rolling backups with different generation (1 week and 2 hours)
+ the 1 week backups are again backuped to an external drive that is switched on just for this job
- brain.exe (yes)


Cheers,
Filehero

zer0
Posts: 2676
Joined: 19 Jan 2009 20:11

Re: SONAR.SuspBeh!gen3 in Symantec Internet Security

Post by zer0 »

Thanks Filehero, I appreciate the advice. I already have backups to take care of things, but I was still intrigued how seemingly unrelated set of events were connected.
Reporting a bug? Have a wish? Got a question? Use search - View roadmap - FAQs: Forum + XY site
Windows 7/10
Always using the latest stable two-decimal build

Filehero
Posts: 2734
Joined: 27 Feb 2012 18:50
Location: Windows 11@100%

Re: SONAR.SuspBeh!gen3 in Symantec Internet Security

Post by Filehero »

zer0 wrote:... but I was still intrigued how seemingly unrelated set of events were connected.
These sort of "bizarre events" experienced by myself are ultimatively the origin of my backup "strategy" depicted above. Until some years ago I would even never have backuped application settings by weekly means (4 weeks was ok for almost just everything).


Cheers,
Filehero

Post Reply