shellm
Posts: 13
Joined: Thu Sep 28, 2017 2:04 pm
Contact: Website

Installer UI test Build Virus

Hello Community,

my Installer gets detected as a Virus by my Symantec Endpoint Protection Small Business Edition (SEP SBE).
However, this only happens when using the test features like "Test Installation UI". When building the Installer and running it afterwards, everything works fine. I might end up just excluding that folder from my SEP SBE, but I wanted to report this behavior anyway.


This is what it says:

Code: Select all

Filename: <myinstaller>.exe
Threat name: Heur.AdvML.BFull Path: c:\users\<myuser>\appdata\local\temp\<myinstaller>.exe

____________________________

____________________________


On computers as of 
12.03.2018 at 11:16:38

Last Used 
12.03.2018 at 11:18:39

Startup Item 
No

Launched 
No

Threat type: Heuristic Virus. Detection of a threat based on malware heuristics.


____________________________

<myinstaller>.exe Threat name: Heur.AdvML.B
Locate


Very Few Users
Fewer than 5 users in the Symantec Community have used this file.

Very New
This file was released less than 1 week  ago.

High
This file risk is high.


____________________________


Source: External Media

Source File:
<myinstaller>.exe

____________________________

File Actions

File: c:\users\<myuser>\appdata\local\temp\<myinstaller>.exe Removed
____________________________


File Thumbprint - SHA:
e013a62aba79c777ed1b0978ee9195e31268d71996c20f480eeb3e060ffe807d
File Thumbprint - MD5:
889fa8789fa83bc90ef4edf7f2927a42
Anyone had this problem before? If needed, I can also send the .aip to Support. I am currently using AI 14.6 Enterprise.
The Installer does nothing but install some fonts and a lot of prerequisites (access runtimes, odbc drivers, crystal reports runtimes...)
Daniel
Posts: 8238
Joined: Mon Apr 02, 2012 1:11 pm
Contact: Website

Re: Installer UI test Build Virus

Hello,

Thank you for your feedback. We can assure you this is a false positive detection. We will investigate this scenario and try to contact the Symantec support team to whitelist this behavior in the future.

In the meantime you should add an exception in your Symantec software for the test setup from the temp folder. Thank you for your understanding.

All the best,
Daniel
Daniel Radu - Advanced Installer Team
Follow us: Twitter - Facebook - YouTube

Return to “Common Problems”