Symantec doesn't like latest MLV

Questions specific to Megalogviewer

Moderator: LT401Vette

Post Reply
elaw
Super MS/Extra'er
Posts: 2926
Joined: Fri Oct 16, 2009 6:20 am
Location: Wilmington, MA

Symantec doesn't like latest MLV

Post by elaw »

So... yesterday I let MLV auto-update to the latest version.

And today, Symantec endpoint protection decided that MegaLogViewer.exe is infected with the Trojan.Gen.SMH virus!

I assume this is a false positive, but what's the best way to deal with it?

Update: I fixed the immediate issue by excluding the EFI Analytics program folder in Symantec, and also submitted the file to them as a false positive.
Eric Law
1990 Audi 80 quattro with AAN turbo engine: happily running on MS3+MS3X
2012 Audi A4 quattro, desperately in need of tweaking

Be alert! America needs more lerts.
LT401Vette
Super MS/Extra'er
Posts: 12731
Joined: Sat Jul 16, 2005 8:07 am
Location: Moorseville, NC
Contact:

Re: Symantec doesn't like latest MLV

Post by LT401Vette »

Update: I fixed the immediate issue by excluding the EFI Analytics program folder in Symantec, and also submitted the file to them as a false positive.
Submitting the false positive is what generally needs to be done. False positives do come up some times.
Keep me posted on there response or any further action needs to be taken.
Phil Tobin
EFI Analytics, helping to simplify EFI
Next Generation tuning software.
Supporting all MegaSquirt versions and firmwares.
http://www.TunerStudio.com
http://www.efiAnalytics.com/MegaLogViewer/
Support the firmware running your engine:
http://www.msextra.com/doc/donations.html
elaw
Super MS/Extra'er
Posts: 2926
Joined: Fri Oct 16, 2009 6:20 am
Location: Wilmington, MA

Re: Symantec doesn't like latest MLV

Post by elaw »

Response from Symantec this morning:
In relation to submission [3705946].

Upon further analysis and investigation we have verified your submission and, as such, the detection(s) for the following file(s) will be removed from our products:

3688F713A59654A464AF9D7FA2ACC9BF - megalogviewer.exe
Looks like we win!
Eric Law
1990 Audi 80 quattro with AAN turbo engine: happily running on MS3+MS3X
2012 Audi A4 quattro, desperately in need of tweaking

Be alert! America needs more lerts.
LT401Vette
Super MS/Extra'er
Posts: 12731
Joined: Sat Jul 16, 2005 8:07 am
Location: Moorseville, NC
Contact:

Re: Symantec doesn't like latest MLV

Post by LT401Vette »

:D

They did that quick too.
Phil Tobin
EFI Analytics, helping to simplify EFI
Next Generation tuning software.
Supporting all MegaSquirt versions and firmwares.
http://www.TunerStudio.com
http://www.efiAnalytics.com/MegaLogViewer/
Support the firmware running your engine:
http://www.msextra.com/doc/donations.html
whittlebeast
Super MS/Extra'er
Posts: 2221
Joined: Tue May 04, 2004 8:20 pm
Location: St Louis
Contact:

Re: Symantec doesn't like latest MLV

Post by whittlebeast »

Mine Is still misbehaving.
LT401Vette
Super MS/Extra'er
Posts: 12731
Joined: Sat Jul 16, 2005 8:07 am
Location: Moorseville, NC
Contact:

Re: Symantec doesn't like latest MLV

Post by LT401Vette »

whittlebeast wrote:Mine Is still misbehaving.
It will take until the next definition file update by Symantec is put out.

Also the HD edition may take another change as it is a difference, but almost identical exe. Hopefully they get back on that soon.

I think I really need to start digitally signing my installers and executables, the world it becoming much more sensitive to unsigned apps.
Phil Tobin
EFI Analytics, helping to simplify EFI
Next Generation tuning software.
Supporting all MegaSquirt versions and firmwares.
http://www.TunerStudio.com
http://www.efiAnalytics.com/MegaLogViewer/
Support the firmware running your engine:
http://www.msextra.com/doc/donations.html
elaw
Super MS/Extra'er
Posts: 2926
Joined: Fri Oct 16, 2009 6:20 am
Location: Wilmington, MA

Re: Symantec doesn't like latest MLV

Post by elaw »

whittlebeast wrote:Mine Is still misbehaving.
I fixed it on my machine by telling Symantec to exclude the MLV program folder.

I tried to exclude just the executable itself, but as soon as I selected it in the "exclude" dialog, Symantec auto-protect would kick in and quarantine the file, and then setting the exclusion would fail because the .exe was no longer present. Typical Symantec stupidity. :(
Eric Law
1990 Audi 80 quattro with AAN turbo engine: happily running on MS3+MS3X
2012 Audi A4 quattro, desperately in need of tweaking

Be alert! America needs more lerts.
LT401Vette
Super MS/Extra'er
Posts: 12731
Joined: Sat Jul 16, 2005 8:07 am
Location: Moorseville, NC
Contact:

Re: Symantec doesn't like latest MLV

Post by LT401Vette »

I fixed it on my machine by telling Symantec to exclude the MLV program folder.
I think maybe what they don't like here is that the exe really just kicks off the javaw.exe in the runtime/bin subdir.
Phil Tobin
EFI Analytics, helping to simplify EFI
Next Generation tuning software.
Supporting all MegaSquirt versions and firmwares.
http://www.TunerStudio.com
http://www.efiAnalytics.com/MegaLogViewer/
Support the firmware running your engine:
http://www.msextra.com/doc/donations.html
Post Reply