Possible false positive alerts with MythicSoft File Locator Pro

I'm getting alert messages for recurring activity in the temp folder. After investigation, I suspect that this is caused by the program "FileLocator Pro" by MythicSoft.  The activity appears to correlate with FileLocator Pro indexing and activity, and this program apparently uses the temp folder. Separately I've been running multiple different checks for any indications of malware infection with no actual evidence identified.  

See the discussion here, https://qa.mythicsoft.com/13669/how-important-are-the-files-appdata-local-temp-flf99c0-tmp-dir

(OS is Windows 10, Norton, fully updated)

Examples of Norton Logs/Alerts I'm seeing: 

Filename: Flt_e16f039262d1ec40912fb57b05f7011f.tmp [note the naming convention is generally Flt_XXXXXXXXXXXXXXXXXXXXX.tmp] with the exact filenames changing. For example: 
Threat name: Trojan HorseFull Path: C:\Users\[username]\AppData\Local\Temp\Flf2908.tmp.dir\Flt_e16f039262d1ec40912fb57b05f7011f.tmp

1/20/2024 12:04:54 PM,High,Flt_e16f039262d1ec40912fb57b05f7011f.tmp (Trojan Horse) detected by Auto-Protect,Blocked,Resolved - No Action Required, Actions performed: 0
1/20/2024 12:04:54 PM,High,Flt_1a7fd78c559ea54e9ec5a69b80ad9c78.tmp.utf8 (Trojan Horse) detected by Auto-Protect,Blocked,Resolved - No Action Required, Actions performed: 0
1/19/2024 12:04:58 PM,High,Flt_2100f4c7694f864aa8297743e80d2994.tmp (Trojan Horse) detected by Auto-Protect,Blocked,Resolved - No Action Required, Actions performed: 0
1/19/2024 12:04:58 PM,High,Flt_2424592612f2f040975bcc593bb73caf.tmp.utf8 (Trojan Horse) detected by Auto-Protect,Blocked,Resolved - No Action Required, Actions performed: 0
1/18/2024 12:06:15 PM,High,Flt_46351d15e6a3fb4cadb88f852aadbed8.tmp (Trojan Horse) detected by Auto-Protect,Blocked,Resolved - No Action Required, Actions performed: 0

 

 

RandomlyGeneratedString:

Final comment- Norton does not have a straightforward mechanism for reporting and resolving this sort of thing. 

You mean other than....links posted earlier. 

Report a suspected incorrect detection to Norton
https://support.norton.com/sp/en/us/home/current/solutions/v126152382

Submit a file or URL to Norton
https://support.norton.com/sp/en/us/home/current/solutions/kb20090602171902EN

Respond to incorrect Norton alerts that a file is infected or a program or website is suspicious
https://support.norton.com/sp/en/us/home/current/solutions/kb20100222230832EN

Issue resolved, thanks to communication and assistance with Dave from MythicSoft support and my continued review of internal logs. This was a false positive for a unique use case. Norton was alerting on temp files generated by MythicSoft's File Locator Pro created during the scheduled indexing. Norton was alerting on IOC content from indexed files ( my collection of cybersecurity industry reports describing malicious activity that had technical IOCs and yara rules). Although Norton did not alert on the original files, likely Norton alerted because the IOCs were appearing in files being dropped into the Temp folder, which is a usual place to check for malicious activity. 

Final comment- Norton does not have a straightforward mechanism for reporting and resolving this sort of thing. I spent a reasonable time looking for that and could not find one except the chat, which was always busy with long waits. 

 

Will you be reporting suspected incorrect detections to Norton?
I've installed Professional Trial.  I'm running search for File name: Norton
My Norton 360 remains quiet.  

This is a highly granular file indexing and search tool.  Once installed, I'd recommend having a batch of test documents to index.  You'll have to set up and build an index (pretty easy to do with a few clicks) and I'm also adding the advanced options for OCR indexing. 

IDK

Thanks for the quick response. You can try replicating it; FileLocator Pro is available for download here and has full functionality for the trial period. https://www.mythicsoft.com/filelocatorpro/download/

This is a highly granular file indexing and search tool.  Once installed, I'd recommend having a batch of test documents to index.  You'll have to set up and build an index (pretty easy to do with a few clicks) and I'm also adding the advanced options for OCR indexing. 

Apparently, from my recent communication with MythicSoft technical support, the program does utilize the temp folder during search and indexing; this was also discussed in the forum post link I posted.  

RandomlyGeneratedString:

I'm getting alert messages for recurring activity in the temp folder. After investigation, I suspect that this is caused by the program "FileLocator Pro" by MythicSoft.  The activity appears to correlate with FileLocator Pro indexing and activity, and this program apparently uses the temp folder. 

Can I easily reproduce Norton detections with Professional Trial?  or Lite (free)? 
I've not familiar with FileLocator Pro. 

Report a suspected incorrect detection to Norton
https://support.norton.com/sp/en/us/home/current/solutions/v126152382

Submit a file or URL to Norton
https://support.norton.com/sp/en/us/home/current/solutions/kb20090602171902EN

Respond to incorrect Norton alerts that a file is infected or a program or website is suspicious
https://support.norton.com/sp/en/us/home/current/solutions/kb20100222230832EN


Please tell us what Norton is telling you regarding this event.
For information regarding this event > from Norton pop-up > View Details > Copy to Clipboard &or from Norton history > More Options > Copy to Clipboard > paste here.

For second opinion choose File &/or Search hash at VirusTotal 


Act on quarantined risks or threats
https://support.norton.com/sp/en/us/home/current/solutions/v6200305

Turn off or turn on Download Intelligence
https://support.norton.com/sp/en/us/norton-security/current/solutions/v23920640

Exclude files and folders from Norton scans
https://support.norton.com/sp/en/us/home/current/solutions/v3672136

Norton detects a file or program as a threat even after you exclude it from scan
https://support.norton.com/sp/en/us/home/current/solutions/v115455517

Configure Exclusions/Low Risks settings
https://support.norton.com/sp/en/us/norton-360/home/solutions/v15457075

Exclude files with low-risk signatures from Norton scans
https://support.norton.com/sp/en/us/home/current/solutions/v15463085