Reply
Contributor
SmileyMike
Posts: 66
Registered: ‎04-14-2011
Accepted Solution

Sonar Pick Up!!

HI There,

 

I am trying to un-install a coffeecup program thru programs and feature and Sonar picked up a problem.  I trust programs from coffeecup.com. I am un-installing a program to install a new version of the same program from coffeecup.com.

 

 Go into "Programs and Features". Soon I clicked to un-install Direct FTP. Click continue and then a little window popped up bottom right of screen saying a program was acting suspicious and was removed. Was in /temp/. Did it 2 times and had 2 different numbers. _uninstall4700 and different number after that.

 

Coffeecup.com is a trusted and safe company. What should I do to stop this from going on. Send a clipboard copy or what it doing or restore  or turn off to finish un-install the program. coffeecup.com been around since 1996 by the way.

 

HAVE A GREAT DAY.

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Bike Mike
2002 Olympic Torchbearer
Multiple Sclerosis Cyclist since 1990

IBM Desktop ThinkCentre, Vista SP2, 32bit, IE 8, FF 3.6, Norton 360 v5.1.0.29, Chrome 11.0.696.68, Paint Shop Pro 12.50 and Adobe 10, 3 GB memory
Symantec Employee
HarryP
Posts: 737
Registered: ‎07-23-2010

Re: Sonar Pick Up!!

Hi Mike,

 

The uninstaller may be creating files in the /temp/ folder with different numbers during the uninstallation process and by some means SONAR detects that file as malicious. Since the file name would be different each time, restoring from quarantine won't be much help. It would be good if you can disconnect from the Internet, then turn off AutoProtect & SONAR temporarily (for 15mins or so) and then perform the uninstall. You can turn on AutoProtect & SONAR once you complete the uninstall process, then reconnect back to the Internet.

 

It would be good, if you can provide more information like the version and name of coffeecup program you are trying to install, threat detection information from the Security History for the SONAR etc. This would help us to verify the problem from our end as well.

 

Thanks,

HarryP

Contributor
SmileyMike
Posts: 66
Registered: ‎04-14-2011

Re: Sonar Pick Up!!

[ Edited ]

HI........ I un-installed the old Direct FTP program from coffeecup.com and then installed the new Direct FTP  program from coffeecup.com. I trust coffeecup.com 100%. Just wondering why Sonar was picking it up when I was trying to un-install the old Direct FTP early this week. Wierd!

 

Anyway . . . .  Before coming here. I tried 3 times to un-install Direct FTP from PROGRAMS and FEATURES with no luck. The first time it said this file ........  /temp/_uninstall4700 from Norton Sonar ..... Then tried a second time and Norton Sonar said _uninstall5368 abd then tried one more time to un-install 5308.

 

Then tried when you said. To disconnect from the net . . . . . Then turn off antivirus and then un-install again. That time it worked.

 

Here is a copy from the first one to give you Norton the idea. I think it false positive.

~~~~~~~~~~~~~

 

Full Path: Not Available

____________________________

____________________________

On computers as of 5/21/2012 at 5:58:30 PM

Last Used 5/21/2012 at 5:58:50 PM

Startup Item No

Launched Yes

____________________________

____________________________

Very Few Users

Fewer than 5 users in the Norton Community have used this file.

____________________________

Very New

This file was released less than 1 week ago.

____________________________

High

This file risk is high.

____________________________

Threat Details

SONAR Protection monitors for suspicious program activity on your computer.

____________________________

Source File:

_uninstall4700

____________________________

File Actions

File: c:\users\bike mike\appdata\local\temp\_uninstall4700 Removed

____________________________

Registry Actions

Registry change: HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Session Manager\Environment->BitRock

No Action Required

____________________________

File Thumbprint - SHA:

Not Available

____________________________

File Thumbprint - MD5:

Not Available

____________________________

 

 

 

~~~~~~~~~~~~~~~~~~~~~~~~~~

This to show you what it said when it happened . . . I already done the action you said HarryP. I am just showing what it did and it re-peated for the 2 other times. . . . Okay!

 

 I am using the newest version of Norton 360 V 6.0 on a Vista Business Pro 32bit system.. . . . Browser  is IE9.

 

HAVE A  GREAT UP COMING WEEKEND TO ALL READING THIS!!!

 

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Bike Mike
2002 Olympic Torchbearer
Multiple Sclerosis Cyclist since 1990

IBM Desktop ThinkCentre, Vista SP2, 32bit, IE 8, FF 3.6, Norton 360 v5.1.0.29, Chrome 11.0.696.68, Paint Shop Pro 12.50 and Adobe 10, 3 GB memory
Contributor
SmileyMike
Posts: 66
Registered: ‎04-14-2011

Re: Sonar Pick Up!!

HI HARRYP,

 

. . . . EXTRA STUFF . . . .



I did what you said . . . Unistall what you typed.

 

So you know . . . The prgram I tried to un-install . . . . . Direct FTP verssion 6.7 Build 1772 . . . . and it was the one that would not let me un-install by Norton Sonar . . . . . It is now gone . . . . . I put in the NEW Direct FTP. . . .  after what you said HarryP.

 

CoffeeCup Software is a great website for sure. Trusted this place and all it software since the late 1990s. Very trusted indeed. coffeecup.com for webmaster or people that like to build websites!!!!

 

HAPPY HOLIDAY WEEKEND TO ALL . . . . The un-offical start to summer begins and un-offical end of summer is Labor Day weekend in September.

 

 

HAPPY SUMMER TO ALL.!!!!

 

Bike Mike is on the air!!!!

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Bike Mike
2002 Olympic Torchbearer
Multiple Sclerosis Cyclist since 1990

IBM Desktop ThinkCentre, Vista SP2, 32bit, IE 8, FF 3.6, Norton 360 v5.1.0.29, Chrome 11.0.696.68, Paint Shop Pro 12.50 and Adobe 10, 3 GB memory