Opened Geosetter, which advised me that a new version of exiftool was available (ver 10.21). Clicking ok to install, Norton Security with Backup popped up and quarantined the said tool. It also prompted for a reboot. Since new versions appear almost every other week, I was wondering if this was a false positive. This is the report created:
Filename: exiftool.exe
Threat name: SONAR.Heuristic.142Full Path: Not Available
____________________________
____________________________
On computers as of
30/06/2016 at 7:53:48 PM
Last Used
30/06/2016 at 7:53:48 PM
Startup Item
No
Launched
Yes
SONAR Protection monitors for suspicious program activity on your computer.
____________________________
exiftool.exe Threat name: SONAR.Heuristic.142
Locate
Very Few Users
Fewer than 5 users in the Norton Community have used this file.
Very New
This file was released less than 1 week ago.
High
This file risk is high.
____________________________
Source: External Media
Source File:
exiftool.exe
____________________________
File Actions
File: c:\Users\admin\AppData\Roaming\geosetter\tools\ exiftool.exe Threat Removed
File: c:\users\admin\appdata\local\temp\par-61646d696e\cache-exiftool-10.21\ exiftool.exe No Action Required
Directory: c:\users\admin\appdata\local\temp\ par-61646d696e Removed
Directory: c:\users\admin\appdata\local\temp\par-61646d696e\ cache-exiftool-10.21 Threat Removed
____________________________
System Settings Actions
Event: Process start (Performed by c:\users\admin\appdata\roaming\geosetter\tools\exiftool.exe, PID:5684) No action taken
Event: PE file creation: c:\users\admin\appdata\local\temp\par-61646d696e\cache-exiftool-10.21\ exiftool.exe (Performed by c:\users\admin\appdata\roaming\geosetter\tools\exiftool.exe, PID:5684) No action taken
Event: Process start: c:\Users\admin\AppData\Roaming\geosetter\tools\ exiftool.exe, PID:5684 (Performed by c:\users\admin\appdata\roaming\geosetter\tools\exiftool.exe, PID:5684) No action taken
Event: Process start (Performed by c:\users\admin\appdata\roaming\geosetter\tools\exiftool.exe, PID:3808) No action taken
Event: Process start: c:\Users\admin\AppData\Roaming\geosetter\tools\ exiftool.exe, PID:3808 (Performed by c:\users\admin\appdata\roaming\geosetter\tools\exiftool.exe, PID:3808) No action taken
Event: Process start (Performed by c:\users\admin\appdata\roaming\geosetter\tools\exiftool.exe, PID:9852) No action taken
Event: Process start: c:\Users\admin\AppData\Roaming\geosetter\tools\ exiftool.exe, PID:9852 (Performed by c:\users\admin\appdata\roaming\geosetter\tools\exiftool.exe, PID:9852) No action taken
____________________________
File Thumbprint - SHA:
Not available
File Thumbprint - MD5:
Not available