Page 1 of 1

SONAR.SuspBeh!gen3 in Symantec Internet Security

Posted: 12 Nov 2013 14:39
by zer0
I just wanted to share an unpleasant experience I had this morning where a heuristic signature in Norton Internet Security decided to wipe some of my XYplorer files. Since they were not configuration files, I managed to "fix" things, by re-installing over the top. Here the relevant details:

Code: Select all

Filename: xyplorer_13.20_install.exe
Threat name: SONAR.SuspBeh!gen3
Full Path: Not Available

High
This file risk is high.

SONAR Protection monitors for suspicious program activity on your computer.

____________________________

Source: External Media
____________________________

File Actions

File: c:\users\<username>\appdata\local\temp\wz9c1f\ xyplorer_13.20_install.exe No Action Required

File: c:\program files (x86)\xyplorer\ xyplorer.chm Removed

File: c:\program files (x86)\xyplorer\ readmexy.txt Removed

File: c:\program files (x86)\xyplorer\ licensexy.txt Removed

File: c:\program files (x86)\xyplorer\ tipoftheday.htm Removed

File: c:\programdata\microsoft\windows\start menu\programs\xyplorer\ xyplorer.lnk Removed

File: c:\programdata\microsoft\windows\start menu\programs\xyplorer\ xyplorer help.lnk Removed

File: c:\programdata\microsoft\windows\start menu\programs\xyplorer\ xyplorer homepage.url Removed

File: c:\programdata\microsoft\windows\start menu\programs\xyplorer\ xyplorer uninstall.lnk Removed

File: c:\users\<username>\appdata\roaming\mpc-hc\ default.mpcpl Removed

Directory: c:\users\<username>\appdata\local\temp\ nsnc469.tmp No Action Required
____________________________

Registry Actions

Registry change: HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\ XYplorer->DisplayVersion:13.20, Registry Hive: 64 bit Repaired

Registry change: HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\ XYplorer->NSIS:StartMenuDir:XYplorer, Registry Hive: 64 bit Repaired

Registry change: HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\XYplorer->URLInfoAbout:http://www.xyplorer.com/, Registry Hive: 64 bit Repaired

Registry change: HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\ XYplorer->Publisher:Donald Lessau, Registry Hive: 64 bit Repaired

Registry change: HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\XYplorer->InstallLocation:C:\Program Files (x86)\ XYplorer, Registry Hive: 64 bit Repaired

Registry change: HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\ XYplorer->VersionMajor:13, Registry Hive: 64 bit Repaired

Registry change: HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\ XYplorer->VersionMinor:20, Registry Hive: 64 bit Repaired

Registry change: HKEY_USERS\S-1-5-21-1035394184-3343349579-4230999837-1001_CLASSES\Local Settings\MuiCache\88A\ 52C64B7E->LanguageList:..., Registry Hive: 64 bit Repaired
____________________________

System Settings Actions

Event: Browser process start (Performed by c:\users\<username>\appdata\local\temp\wz9c1f\xyplorer_13.20_install.exe, PID:6536) No action taken

Event: PE file creation: c:\users\<username>\appdata\local\temp\nsnc469.tmp\ userinfo.dll (Performed by c:\users\<username>\appdata\local\temp\wz9c1f\xyplorer_13.20_install.exe, PID:6536) No action taken

Event: PE file creation: c:\users\<username>\appdata\local\temp\nsnc469.tmp\ system.dll (Performed by c:\users\<username>\appdata\local\temp\wz9c1f\xyplorer_13.20_install.exe, PID:6536) No action taken

Event: PE file creation: c:\users\<username>\appdata\local\temp\nsnc469.tmp\ nsdialogs.dll (Performed by c:\users\<username>\appdata\local\temp\wz9c1f\xyplorer_13.20_install.exe, PID:6536) No action taken

Event: PE file creation: c:\users\<username>\appdata\local\temp\nsnc469.tmp\ startmenu.dll (Performed by c:\users\<username>\appdata\local\temp\wz9c1f\xyplorer_13.20_install.exe, PID:6536) No action taken

Event: PE file creation: c:\program files (x86)\XYplorer\ XYplorer.exe (Performed by c:\users\<username>\appdata\local\temp\wz9c1f\xyplorer_13.20_install.exe, PID:6536) No action taken

Event: PE file creation: c:\program files (x86)\XYplorer\ XYcopy.exe (Performed by c:\users\<username>\appdata\local\temp\wz9c1f\xyplorer_13.20_install.exe, PID:6536) No action taken

Event: PE file creation: c:\program files (x86)\XYplorer\ uninstall.exe (Performed by c:\users\<username>\appdata\local\temp\wz9c1f\xyplorer_13.20_install.exe, PID:6536) No action taken

Event: Process start: c:\program files (x86)\XYplorer\ XYplorer.exe, PID:4836 (Performed by c:\users\<username>\appdata\local\temp\wz9c1f\xyplorer_13.20_install.exe, PID:6536) No action taken

Event: Process start: c:\users\<username>\appdata\local\temp\wz9c1f\ xyplorer_13.20_install.exe, PID:6536 (Performed by c:\users\<username>\appdata\local\temp\wz9c1f\xyplorer_13.20_install.exe, PID:6536) No action taken

Event: Process start: c:\program files (x86)\k-lite codec pack\media player classic\ mpc-hc.exe, PID:1508 (Performed by c:\users\<username>\appdata\local\temp\wz9c1f\xyplorer_13.20_install.exe, PID:6536) No action taken
____________________________

Suspicious Actions

Event: Attempt to start a remote thread in a process address space (Performed by c:\users\<username>\appdata\local\temp\wz9c1f\xyplorer_13.20_install.exe, PID:6536) No action taken

Event: Accessibility API usage (Performed by c:\users\<username>\appdata\local\temp\wz9c1f\xyplorer_13.20_install.exe, PID:6536) No action taken
____________________________

Intriguingly, the whole kibosh started when I tried to play a file in MPC. However, it seems that the call to open that process was started by XYplorer's installer in the temp folder. But why would it be there? A temp folder is created when using the installer version, because that's where the temp files are stashed and it is usually removed when I close WinZip.

Re: SONAR.SuspBeh!gen3 in Symantec Internet Security

Posted: 12 Nov 2013 14:40
by admin
Norton... :roll: ... just remove that crap.

Re: SONAR.SuspBeh!gen3 in Symantec Internet Security

Posted: 12 Nov 2013 14:55
by zer0
admin wrote:Norton... :roll: ... just remove that crap.
No single AV product out there is perfect, especially when it comes to heuristics, so it's easy to blame whichever one causes headaches on a given day. I already have excludes for XYplorer.exe and XYcopy.exe.

Re: SONAR.SuspBeh!gen3 in Symantec Internet Security

Posted: 12 Nov 2013 15:22
by armsys
zer0 wrote:No single AV product out there is perfect, especially when it comes to heuristics, so it's easy to blame whichever one causes headaches on a given day. I already have excludes for XYplorer.exe and XYcopy.exe.
Don is factually correct. Try AVG if you really need one.

Re: SONAR.SuspBeh!gen3 in Symantec Internet Security

Posted: 12 Nov 2013 15:58
by zer0
armsys wrote:
zer0 wrote:No single AV product out there is perfect, especially when it comes to heuristics, so it's easy to blame whichever one causes headaches on a given day. I already have excludes for XYplorer.exe and XYcopy.exe.
Don is factually correct. Try AVG if you really need one.
Sorry, not happening. I am not going to change to a different Internet security product simply because of a little hiccup that took less than a minute to fix. Better the devil you know that the devil you don't. FYI, I didn't start this thread to have a bash at an AV product. I just found it curious how various bits and pieces linked together.

Re: SONAR.SuspBeh!gen3 in Symantec Internet Security

Posted: 12 Nov 2013 20:36
by Filehero
I use,

- Windows Defender (after 5 years BitDefender) + SpyBot
- depending on file criticality
+ rolling backups with different generation (1 week and 2 hours)
+ the 1 week backups are again backuped to an external drive that is switched on just for this job
- brain.exe (yes)


Cheers,
Filehero

Re: SONAR.SuspBeh!gen3 in Symantec Internet Security

Posted: 12 Nov 2013 20:44
by zer0
Thanks Filehero, I appreciate the advice. I already have backups to take care of things, but I was still intrigued how seemingly unrelated set of events were connected.

Re: SONAR.SuspBeh!gen3 in Symantec Internet Security

Posted: 12 Nov 2013 21:04
by Filehero
zer0 wrote:... but I was still intrigued how seemingly unrelated set of events were connected.
These sort of "bizarre events" experienced by myself are ultimatively the origin of my backup "strategy" depicted above. Until some years ago I would even never have backuped application settings by weekly means (4 weeks was ok for almost just everything).


Cheers,
Filehero