Norton SONAR engine now flagging Fastkeys.exe

Discussion, questions and support.
Post Reply
nth
Posts: 21
Joined: May 9th, ’14, 18:35

Post by nth » Sep 30th, ’16, 15:21

Logged in this morning to see that Fastkeys was gone!

Got to looking through anti-virus logs and see that after Norton's latest update they now "see" a trojan in Fastkeys.exe.

Can you doublecheck there is nothing lurking in version 3.13?

http://us.norton.com/security_response/ ... 23-4555-99
Info:

Filename: fastkeys.exe
Threat name: SONAR.SuspBeh!gen31Full Path: Not Available

Startup Item
Yes

Launched
Yes

SONAR Protection monitors for suspicious program activity on your computer.

____________________________

fastkeys.exe Threat name: SONAR.SuspBeh!gen31
Locate

Few Users
Fewer than 50 users in the Norton Community have used this file.

New
This file was released 26 days ago.

High
This file risk is high.

___________________________

Source File:
fastkeys.exe

____________________________

File Actions

File: c:\program files (x86)\fastkeys\ fastkeys.exe Threat Removed
File: c:\users\user\appdata\roaming\microsoft\windows\start menu\programs\startup\ fastkeys.lnk Threat Removed

____________________________

System Settings Actions

Event: Process start (Performed by c:\program files (x86)\fastkeys\fastkeys.exe, PID:9600) No action taken
Event: Process start: c:\program files (x86)\fastkeys\ fastkeys.exe, PID:9600 (Performed by c:\program files (x86)\fastkeys\fastkeys.exe, PID:9600) No action taken

____________________________

File Thumbprint - SHA:
Not available
File Thumbprint - MD5:
Not available
User avatar
Marko
Posts: 1718
Joined: Mar 2nd, ’13, 21:02

Post by Marko » Sep 30th, ’16, 15:33

This is a false positive report from Norton. Symantec has already been informed and they confirmed that they will update in few days. Until then, please manually white-list FastKeys from the quarantine.

FastKeys is absolutely safe and clean, as always.
nth
Posts: 21
Joined: May 9th, ’14, 18:35

Post by nth » Sep 30th, ’16, 15:49

Thanks Marko. I figured it was a false positive too, but wanted to be sure, that's why I posted.
Post Reply