05-08-2012 07:59 AM
Hi, I am a software developer, still working with Powerbuilder 6.5.1. Approx. 1 month ago, NIS 2012 started deleting my software - the reason apparently is SONAR. Up to approx mid. march 2012 everything was ok for years. The software is virus and malware free. Interestingly, it is removed by NIS2012 on Windows XP Home with SP3 only. It stays on Windows XP Professional and Windows 7 - the very same up to date NIS 2012 sees no problem. I know my users can restore file and exclude it from scanning, it works, but the problem is that the whole situation is weird and creates an impression that we introduce a security threat. Application runs fine until a keyboard key is pressed. SONAR as a reason for deleting EXE says something about intercepting a pressed key. We can't digitally sign Powerbuilder EXE because it won't run after signing. What other options do we have?
05-08-2012 08:10 AM
05-08-2012 11:01 AM
You need to submit your file to Symantec to have them add it to the allowed list. Follow the directions to manually submit a file at the bottom of this Symantec knowledge base article.
05-09-2012 02:50 AM
> You need to submit your file to Symantec to have them add it to the allowed list.
> Follow the directions to manually submit a file at the bottom of this Symantec knowledge base article.
The link above refers to NIS2010. NIS2012 does not seem to have 'Submit to Symantec' button as described.
05-09-2012 06:50 AM
Try this article.
It covers reporting false positives. That should get you the links your need to report your files.
05-09-2012 09:28 AM
05-10-2012 03:33 AM
Ok, now I have more details: It seems, that SONAR in NIS2012 on Windows XP HOME with SP3 is preemptively deleting ANY EXE compiled right now with Powerbuilder 6.5.1. This is NOT the case with the same EXEs compiled up to approx. mid-March 2012. Source code is the same, just one compilation was today, original in March. I used different computers and different Powerbuilder applications for compilation, all of them virus and malware free, one computer with up to date NIS2012. When Powerbuilder created EXE is run it works, until a keyboard key is pressed (any key). Then SONAR deletes EXE and says that the reason is (my translation):
Suspicious operation: Event: interception of pressed key
It also says 'Very few users, very new, High threat' - as I say application was just compiled, I wonder then what it would say about NIS2012 right after its compilation:-) Now seriously again, this is happening ONLY on Windows HOME with SP3, it is NOT happening on XP Professional with SP3 and not on Windows 7 64-bit that I am also using for testing. Also, the change to SONAR that affects my Powerbuilder executables has been done by Symantec probably close to April 15. Before everything was fine for many years.
Symantec should try to fix SONAR somehow, because it is doing quite a bad job for everybody with these deletions. Digital signing, fine, file exclusion, fine, but still branding as high threat and deleting ANY EXE created with Powerbuilder 6.5.1 (I don't know about other versions) makes no sense to me at all, no matter how I look at it.
05-10-2012 07:54 AM
azaleski wrote:Ok, now I have more details: It seems, that SONAR in NIS2012 on Windows XP HOME with SP3 is preemptively deleting ANY EXE compiled right now with Powerbuilder 6.5.1. This is NOT the case with the same EXEs compiled up to approx. mid-March 2012. Source code is the same, just one compilation was today, original in March. I used different computers and different Powerbuilder applications for compilation, all of them virus and malware free, one computer with up to date NIS2012. When Powerbuilder created EXE is run it works, until a keyboard key is pressed (any key). Then SONAR deletes EXE and says that the reason is (my translation):
Suspicious operation: Event: interception of pressed key
It also says 'Very few users, very new, High threat' - as I say application was just compiled, I wonder then what it would say about NIS2012 right after its compilation:-) Now seriously again, this is happening ONLY on Windows HOME with SP3, it is NOT happening on XP Professional with SP3 and not on Windows 7 64-bit that I am also using for testing. Also, the change to SONAR that affects my Powerbuilder executables has been done by Symantec probably close to April 15. Before everything was fine for many years.
Symantec should try to fix SONAR somehow, because it is doing quite a bad job for everybody with these deletions. Digital signing, fine, file exclusion, fine, but still branding as high threat and deleting ANY EXE created with Powerbuilder 6.5.1 (I don't know about other versions) makes no sense to me at all, no matter how I look at it.
You mention you have different versions of Powerbuilder on different computers. Is it possible to take the version that is on one of the working computers and install that on the XP Home computer?
The issue seems to be with Sonar and Powerbuilder exe's, but if the other version of Powerbuilder works, then it can help Symantec to find a solution to your problem.
05-10-2012 01:15 PM
The settings for Sonar give an option to have Norton ask you for each detection. Click Settings - Computer - Real Time Protection and click on the setting button beside Remove Risks Automatically. See image below. This will give you control of what to do with a file detected by Sonar.
A Symantec Knowledge Base article on Sonar can be found here.
