Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

SONAR.Cryptlck!g134 warning from Norton #146

Closed
Dopplizzle opened this issue Feb 12, 2017 · 10 comments
Closed

SONAR.Cryptlck!g134 warning from Norton #146

Dopplizzle opened this issue Feb 12, 2017 · 10 comments
Labels
Important Important issues Question Issue which are questions

Comments

@Dopplizzle
Copy link

Just a heads up. Norton Security is firing off a heuristics detection warning of "SONAR.Cryptlck!g134" trojan virus for soundswitch.exe. Re-downloading and reinstalling from your github immediately fired it again upon running the executable. This hasn't happened before, so not sure why it's tripping the alert now, but it is (Norton tends to err on the side of caution). It's a little unsettling, even when I'm sure it's a false positive...

@Belphemur Belphemur added the Question Issue which are questions label Feb 13, 2017
@Belphemur
Copy link
Owner

Belphemur commented Feb 13, 2017

Hello @Dopplizzle

It's not the first time Norton is annoying with the installer.
It must be because this last version includes the debugging symbols (pdb) that would help me debug the program if it crashed.

I ran a virus total with the download link:
Url
File itself

As you can see, there is nothing dangerous into the installer (hence neither in the application itself).

@Dopplizzle
Copy link
Author

Yep, I had already run those checks, mostly posted here so others could google it. Thanks for double checking. Closing the issue.

@Belphemur
Copy link
Owner

I submitted the false positive report to Symantec.
We'll see where it goes...

I'll keep this open for transparency purpose.

@Belphemur Belphemur reopened this Feb 13, 2017
@Belphemur Belphemur added the Important Important issues label Feb 13, 2017
Belphemur pushed a commit that referenced this issue Feb 14, 2017
Surely causing the issue #146
@Belphemur
Copy link
Owner

I got an answer from Symantec, they can't reproduce the issue. Can you give me the exact name of the product you're using and it's version?

It would help greatly!

@Dopplizzle
Copy link
Author

I am using Norton Security version 22.9.0.68. with Windows 10 64-bit. Oh, and the latest version of SoundSwitch v3.12.8.37187 doesn't seem to cause the alert...

@CrippleZero
Copy link

CrippleZero commented Feb 15, 2017

I am on a corporate machine and the same happened to me. Our company is running Symantec Endpoint Protection 12.1.6 (12.1 RU6 MP5) build 7004 (12.1.7004.6500). I am running Windows 7 64bit with the latest release of SoundSwitch.

Even though I "recover" the executable for SoundSwitch, it immediately gets put back in to Quarantine once I attempt to run it.

This did not happen with the previous version of SS.

EDIT: My fault - I was running v3.12.6.23652; I didn't see that you had updated to .8.37187. It works!

@Belphemur
Copy link
Owner

Belphemur commented Feb 15, 2017

Symantec confirmed the False Positive, it should take around 72h to propagate to all their products.
I'll keep the issue open for 72 hours.

Exerpt of the email response:

In relation to submission 18472.

Upon further analysis and investigation we have verified your submission and, as such, the detection(s) for the following file(s) will be removed from our products:

File name: 0128f3091762d1aefd4af9d01f52cd33c1bdd378179530937b01757c549396f8
MD5: 76b30cdde516c2b6d5e23cf097ed13dd
SHA256: 0128f3091762d1aefd4af9d01f52cd33c1bdd378179530937b01757c549396f8
Note: Whitelisting may take up to 72 hours to take effect via Live Update

In relation to submission 18239.

Upon further analysis and investigation we have verified your submission and, as such, the detection(s) > for the following file(s) will be removed from our products:

File name: SoundSwitch_v3.12.6.23652_Release_Installer.exe
MD5: 1c34e1b837db11121bd2f99d577c551d
SHA256: 15fd5b65dc7661422d6883c06a038f2e45e46727c0f75f073cfa0450f53c5166
Note: Whitelisting may take up to 72 hours to take effect via Live Update

@arosendaal
Copy link

Good to read this: I had the same issue, probably after the update on 13/2. Symantec Endpoint Protection.

SoundSwitch version 3.12.7.38751. Win 7 Enterprise 64-bit

@uvcshelp
Copy link

My organization is continuing to have issues with Symantec Endpoint Protection disabling SoundSwitch, despite Symantec having by now released a number of updates for its malware definitions.

SoundSwitch version 3.12.8.37187
Windows 10 Education version 1607 build 14393.693
Symantec Endpoint Protection managed client version 12.1.6 (12.1 RU6 MP6) build 7061 (12.1.7061.6600)
SEP definitions current as at 2017-02-20 11:00 PST

@arosendaal
Copy link

arosendaal commented Feb 22, 2017 via email

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Important Important issues Question Issue which are questions
Projects
None yet
Development

No branches or pull requests

5 participants