SONAR.SuspBeh!gen3 in Symantec Internet Security
Posted: 12 Nov 2013 14:39
I just wanted to share an unpleasant experience I had this morning where a heuristic signature in Norton Internet Security decided to wipe some of my XYplorer files. Since they were not configuration files, I managed to "fix" things, by re-installing over the top. Here the relevant details:
Intriguingly, the whole kibosh started when I tried to play a file in MPC. However, it seems that the call to open that process was started by XYplorer's installer in the temp folder. But why would it be there? A temp folder is created when using the installer version, because that's where the temp files are stashed and it is usually removed when I close WinZip.
Code: Select all
Filename: xyplorer_13.20_install.exe
Threat name: SONAR.SuspBeh!gen3
Full Path: Not Available
High
This file risk is high.
SONAR Protection monitors for suspicious program activity on your computer.
____________________________
Source: External Media
____________________________
File Actions
File: c:\users\<username>\appdata\local\temp\wz9c1f\ xyplorer_13.20_install.exe No Action Required
File: c:\program files (x86)\xyplorer\ xyplorer.chm Removed
File: c:\program files (x86)\xyplorer\ readmexy.txt Removed
File: c:\program files (x86)\xyplorer\ licensexy.txt Removed
File: c:\program files (x86)\xyplorer\ tipoftheday.htm Removed
File: c:\programdata\microsoft\windows\start menu\programs\xyplorer\ xyplorer.lnk Removed
File: c:\programdata\microsoft\windows\start menu\programs\xyplorer\ xyplorer help.lnk Removed
File: c:\programdata\microsoft\windows\start menu\programs\xyplorer\ xyplorer homepage.url Removed
File: c:\programdata\microsoft\windows\start menu\programs\xyplorer\ xyplorer uninstall.lnk Removed
File: c:\users\<username>\appdata\roaming\mpc-hc\ default.mpcpl Removed
Directory: c:\users\<username>\appdata\local\temp\ nsnc469.tmp No Action Required
____________________________
Registry Actions
Registry change: HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\ XYplorer->DisplayVersion:13.20, Registry Hive: 64 bit Repaired
Registry change: HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\ XYplorer->NSIS:StartMenuDir:XYplorer, Registry Hive: 64 bit Repaired
Registry change: HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\XYplorer->URLInfoAbout:http://www.xyplorer.com/, Registry Hive: 64 bit Repaired
Registry change: HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\ XYplorer->Publisher:Donald Lessau, Registry Hive: 64 bit Repaired
Registry change: HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\XYplorer->InstallLocation:C:\Program Files (x86)\ XYplorer, Registry Hive: 64 bit Repaired
Registry change: HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\ XYplorer->VersionMajor:13, Registry Hive: 64 bit Repaired
Registry change: HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\ XYplorer->VersionMinor:20, Registry Hive: 64 bit Repaired
Registry change: HKEY_USERS\S-1-5-21-1035394184-3343349579-4230999837-1001_CLASSES\Local Settings\MuiCache\88A\ 52C64B7E->LanguageList:..., Registry Hive: 64 bit Repaired
____________________________
System Settings Actions
Event: Browser process start (Performed by c:\users\<username>\appdata\local\temp\wz9c1f\xyplorer_13.20_install.exe, PID:6536) No action taken
Event: PE file creation: c:\users\<username>\appdata\local\temp\nsnc469.tmp\ userinfo.dll (Performed by c:\users\<username>\appdata\local\temp\wz9c1f\xyplorer_13.20_install.exe, PID:6536) No action taken
Event: PE file creation: c:\users\<username>\appdata\local\temp\nsnc469.tmp\ system.dll (Performed by c:\users\<username>\appdata\local\temp\wz9c1f\xyplorer_13.20_install.exe, PID:6536) No action taken
Event: PE file creation: c:\users\<username>\appdata\local\temp\nsnc469.tmp\ nsdialogs.dll (Performed by c:\users\<username>\appdata\local\temp\wz9c1f\xyplorer_13.20_install.exe, PID:6536) No action taken
Event: PE file creation: c:\users\<username>\appdata\local\temp\nsnc469.tmp\ startmenu.dll (Performed by c:\users\<username>\appdata\local\temp\wz9c1f\xyplorer_13.20_install.exe, PID:6536) No action taken
Event: PE file creation: c:\program files (x86)\XYplorer\ XYplorer.exe (Performed by c:\users\<username>\appdata\local\temp\wz9c1f\xyplorer_13.20_install.exe, PID:6536) No action taken
Event: PE file creation: c:\program files (x86)\XYplorer\ XYcopy.exe (Performed by c:\users\<username>\appdata\local\temp\wz9c1f\xyplorer_13.20_install.exe, PID:6536) No action taken
Event: PE file creation: c:\program files (x86)\XYplorer\ uninstall.exe (Performed by c:\users\<username>\appdata\local\temp\wz9c1f\xyplorer_13.20_install.exe, PID:6536) No action taken
Event: Process start: c:\program files (x86)\XYplorer\ XYplorer.exe, PID:4836 (Performed by c:\users\<username>\appdata\local\temp\wz9c1f\xyplorer_13.20_install.exe, PID:6536) No action taken
Event: Process start: c:\users\<username>\appdata\local\temp\wz9c1f\ xyplorer_13.20_install.exe, PID:6536 (Performed by c:\users\<username>\appdata\local\temp\wz9c1f\xyplorer_13.20_install.exe, PID:6536) No action taken
Event: Process start: c:\program files (x86)\k-lite codec pack\media player classic\ mpc-hc.exe, PID:1508 (Performed by c:\users\<username>\appdata\local\temp\wz9c1f\xyplorer_13.20_install.exe, PID:6536) No action taken
____________________________
Suspicious Actions
Event: Attempt to start a remote thread in a process address space (Performed by c:\users\<username>\appdata\local\temp\wz9c1f\xyplorer_13.20_install.exe, PID:6536) No action taken
Event: Accessibility API usage (Performed by c:\users\<username>\appdata\local\temp\wz9c1f\xyplorer_13.20_install.exe, PID:6536) No action taken
____________________________