<?xml version="1.0"?>
<rss version="2.0">
<channel>
<title>SyMenu - General discussion &amp; questions - Win10 Defender reports Symenu.exe as a trojan - Messages</title>
<link>https://ugmfree.it/forum/messages.aspx?TopicID=442</link>
<description>SyMenu - General discussion &amp; questions - Win10 Defender reports Symenu.exe as a trojan - Messages</description>
<language>en-us</language>
<docs>http://blogs.law.harvard.edu/tech/rss</docs>
<pubDate>Tue, 23 Aug 2016 06:31:42 GMT</pubDate>
<lastBuildDate>Tue, 23 Aug 2016 06:31:42 GMT</lastBuildDate>
<item>
<link>https://ugmfree.it/forum/messages.aspx?TopicID=442</link>
<title>Message from eson</title>
<description><![CDATA[<b>Druuge</b> wrote:<br/><blockquote>Would this response be inappropriate to share on here? I would be interested in reading it even though Symantec isn't necessarily the top authority in this space.</blockquote><br/><br/>No, I can share. I just wanted to avoid feeding the trolls, because the answer I got wasn't very encouraging, <br/>Well, today (after sending a response in pretty harsh terms) I got another responding email about the same issue, where they apparently changed their mind, so I'll just share them both. <br/><br/><br/>First answer 22-08-2014:<br/><blockquote>In relation to submission [3987131].<br/>Upon further analysis and investigation we have determined that the following file(s) meet the necessary criteria to be detected by our products and, as such, the detection(s) cannot be revoked:    <br/>Filename: SyMenu.exe    <br/>MD5: 1E368E21909456F52B8CC7EB3F5B0B6C    <br/>SHA256: 57D16BC4F7A14C788783DB112D73B38F36F4B6A227EF8DDC49C681DFE6336285</blockquote><br/><br/><br/>Second answer 23-08-2014:<br/><blockquote>In relation to submission [3987131].<br/>Upon further analysis and investigation we have verified your submission and, as such, the detection(s) for the following file(s) will be removed from our products:    <br/>Filename: SyMenu.exe    <br/>MD5: 1E368E21909456F52B8CC7EB3F5B0B6C    <br/>SHA256: 57D16BC4F7A14C788783DB112D73B38F36F4B6A227EF8DDC49C681DFE6336285    <br/>Result:     <br/>Whitelisting for above file is available in Rapid Release definitions with a sequence number of 180095 or greater.</blockquote><br/><i>edited by eson on 23/08/2016</i>]]></description>
<pubDate>Tue, 23 Aug 2016 06:31:42 GMT</pubDate>
</item>
<item>
<link>https://ugmfree.it/forum/messages.aspx?TopicID=442</link>
<title>Message from Druuge</title>
<description><![CDATA[IIRC it's triggering alarms for being a "Keylogger". So perhaps there is something to do with the top-level "start search" command or maybe an issue with the search form in the "get new apps" section. Either way, I would wager the fields requiring user-keyboard-input are the root cause that's triggering AVs heuristics.<br/><br/>EDIT: <b>eson</b> wrote:<br/><blockquote>I just received an answer from Symantec. Forwarding it to you. Maybe you can respond from that answer.</blockquote><br/>Would this response be inappropriate to share on here? I would be interested in reading it even though Symantec isn't necessarily the top authority in this space.<br/><i>edited by Druuge on 23/08/2016</i>]]></description>
<pubDate>Tue, 23 Aug 2016 02:42:33 GMT</pubDate>
</item>
<item>
<link>https://ugmfree.it/forum/messages.aspx?TopicID=442</link>
<title>Message from eson</title>
<description><![CDATA[I just received an answer from Symantec. Forwarding it to you. Maybe you can respond from that answer.]]></description>
<pubDate>Mon, 22 Aug 2016 11:58:48 GMT</pubDate>
</item>
<item>
<link>https://ugmfree.it/forum/messages.aspx?TopicID=442</link>
<title>Message from Gianluca</title>
<description><![CDATA[Not at all. <br/>The problem started with version 5.03 and I didn't introduce anything suspect in that version.<br/><br/>I'm enquiring some AV to understand which particular byte sequence is activating the alert. From a byte sequence I can reverse engineer my software to understand which part of the source code is responsible for that. But I strongly doubt that someone will reply.]]></description>
<pubDate>Mon, 22 Aug 2016 11:54:30 GMT</pubDate>
</item>
<item>
<link>https://ugmfree.it/forum/messages.aspx?TopicID=442</link>
<title>Message from eson</title>
<description><![CDATA[I have seen this happen before and I know it is very hard to get rid of a FP. Some years ago I was involved with another "FP take down", and the only way to fix it permanently, is to make the major AV company's fix their signatures. The smaller company's will follow as they are either buying or "borrowing" their signatures from the major ones (or at least watching them closely).<br/>Sure, recompiling will work for a day or two, as you get new hashes for every recompile, but that is hardly the final solution.<br/><br/>Gian, do you have any idea about what component in SyMeny is causing this mess?<br/><i>edited by eson on 22/08/2016</i>]]></description>
<pubDate>Mon, 22 Aug 2016 11:43:37 GMT</pubDate>
</item>
<item>
<link>https://ugmfree.it/forum/messages.aspx?TopicID=442</link>
<title>Message from Gianluca</title>
<description><![CDATA[Hi guys.<br/><br/>This false positive issue is totally crazy.<br/><br/>I've just recompiled the same exactly code for the 5.04 and released it again to the web site and incredibly the VirusTotal report is now completely ok:<br/><br/><a href="https://www.virustotal.com/en/file/ce7738efc9ba1d4a67e0c1d1f4e587278a2576802f739b6ab3c9740157308bf5/analysis/" target="_blank" rel="nofollow">https://www.virustotal.com/en/file/ce7738efc9ba1d4a67e0c1d1f4e587278a2576802f739b6ab3c9740157308bf5/analysis/</a><br/><br/>My guess is that in some days the AV software start again to consider SyMenu the most wanted threat on earth and put it in their blacklists. <br/>Guys it's a problem for conspiracy fans here... or for AV experts. <br/>I've tried to ask for tips to some AV support contacts but it seems they have better things to do. <br/>Indeed me too. <br/>So let's see the next evolution and please give me any suggestion to workaround this problem.<br/><br/>Thanks!]]></description>
<pubDate>Mon, 22 Aug 2016 11:13:25 GMT</pubDate>
</item>
<item>
<link>https://ugmfree.it/forum/messages.aspx?TopicID=442</link>
<title>Message from timrray</title>
<description><![CDATA[I find it strange that only certain builds have this problem. It has happened to me as well before using Avast and Symantec Endpoint Protection. Currently, only the latest build is being detected as a virus. Gianluca, could you try re-compiling it again or something and sending me an updated version? The latest version is consistently being flagged as a virus for me but only when I do the update from 5.03.6014]]></description>
<pubDate>Fri, 19 Aug 2016 20:09:05 GMT</pubDate>
</item>
<item>
<link>https://ugmfree.it/forum/messages.aspx?TopicID=442</link>
<title>Message from lupusbalo</title>
<description><![CDATA[Guys, I have a clue for you:<br/><b><span style="color:FF3300">JUST REMOVE YOUR STUPID AVs </span></b><b><span style="color:FF3300"><img src="images/smilies/sterb1881bq.gif" border="0" alt="Hammer Time" />    <span style="color:000000">(1)</span><br/><br/></span></b><b><span style="color:FF3300">AND INSTALL SYMENU  <img src="images/smilies/knee7rm.gif" border="0" alt="Kneel!" /><br/></span></b><br/><b><span style="color:FF3300">  <img src="images/smilies/13501381245.gif" border="0" alt="ROFLMAO" /></span></b><b><span style="color:FF3300">  <img src="images/smilies/13501381245.gif" border="0" alt="ROFLMAO" /></span></b><b><span style="color:FF3300">  <img src="images/smilies/13501381245.gif" border="0" alt="ROFLMAO" /></span></b><b><span style="color:FF3300">  <img src="images/smilies/13501381245.gif" border="0" alt="ROFLMAO" /></span></b><b><span style="color:FF3300">  <img src="images/smilies/13501381245.gif" border="0" alt="ROFLMAO" /></span></b><br/><br/><span style="color:FF3300"><span style="color:000000">(1) or<span style="color:000000"> add <span style="color:000000">a</span>n exclusion to <span style="color:000000">prevent sy<span style="color:000000">menu from being scanned</span></span></span></span></span><br/><i>edited by lupusbalo on 19/08/2016</i>]]></description>
<pubDate>Fri, 19 Aug 2016 12:07:41 GMT</pubDate>
</item>
<item>
<link>https://ugmfree.it/forum/messages.aspx?TopicID=442</link>
<title>Message from cristov</title>
<description><![CDATA[Seems that also Bitdefender 2016 is blocking SyMenu.exe (says it found Trojan.GenericKD.3472878). Chrome and Edge are blocking access to the <a href="http://www.ugmfree.it/SyMenuDownload.aspx." target="_blank" rel="nofollow">http://www.ugmfree.it/SyMenuDownload.aspx.</a> There is also warning on <a href="http://alternativeto.net/software/symenu/." target="_blank" rel="nofollow">http://alternativeto.net/software/symenu/.</a><br/><i>edited by cristov on 17/08/2016</i>]]></description>
<pubDate>Wed, 17 Aug 2016 18:24:17 GMT</pubDate>
</item>
<item>
<link>https://ugmfree.it/forum/messages.aspx?TopicID=442</link>
<title>Message from KoolPal</title>
<description><![CDATA[Windows Defender removed SyMenu.exe and Chrome does not download a fresh file stating <span style="color:rgb(90, 90, 90)"><span style="font-family:Roboto, "Segoe UI", Tahoma, sans-serif">Failed - Virus detected</span></span><br/><br/>Please review and advise how to use this awesome app!]]></description>
<pubDate>Wed, 17 Aug 2016 16:48:18 GMT</pubDate>
</item>
<item>
<link>https://ugmfree.it/forum/messages.aspx?TopicID=442</link>
<title>Message from Gianluca</title>
<description><![CDATA[Guys if you trust SyMenu please report the false positive to your AV  producers otherwise uninstall SyMenu.<br/>Sorry but I'm unarmed in front of a false positive report.]]></description>
<pubDate>Tue, 02 Aug 2016 22:09:55 GMT</pubDate>
</item>
<item>
<link>https://ugmfree.it/forum/messages.aspx?TopicID=442</link>
<title>Message from otz</title>
<description><![CDATA[Another AV idea`s? Not the same))<br/><a href="https://www.virustotal.com/ru/file/a3fcff6acbd06dd442a888a84e0785707c8f287429da41ff344bdbc9c151a4e5/analysis/" target="_blank" rel="nofollow">https://www.virustotal.com/ru/file/a3fcff6acbd06dd442a888a84e0785707c8f287429da41ff344bdbc9c151a4e5/analysis/</a>]]></description>
<pubDate>Tue, 02 Aug 2016 10:55:04 GMT</pubDate>
</item>
<item>
<link>https://ugmfree.it/forum/messages.aspx?TopicID=442</link>
<title>Message from Gianluca</title>
<description><![CDATA[My idea? False positive.<br/>MS idea's? The same  <img src="images/smilies/smile.gif" border=0 alt="smile" /><br/> <a href="https://www.microsoft.com/en-us/security/portal/submission/SubmissionHistory.aspx?SubmissionId=ad17b39d-947f-43bc-be08-b698e6ac8c62" target="_blank" rel="nofollow">https://www.microsoft.com/en-us/security/portal/submission/SubmissionHistory.aspx?SubmissionId=ad17b39d-947f-43bc-be08-b698e6ac8c62</a>]]></description>
<pubDate>Mon, 01 Aug 2016 10:26:02 GMT</pubDate>
</item>
<item>
<link>https://ugmfree.it/forum/messages.aspx?TopicID=442</link>
<title>Message from Druuge</title>
<description><![CDATA[<b>I downloaded it from a few mirrors (majorgeeks, etc) and got same result:</b><br/><br/><br/><img src="http://i.imgur.com/xWnhL9B.png" border="0"><br/><br/><b>Here's a link to info about the trojan:</b> <a href="https://www.microsoft.com/security/portal/threat/encyclopedia/Entry.aspx?Name=Trojan:Win32/Skeeyah.A!rfn" target="_blank" rel="nofollow">https://www.microsoft.com/security/portal/threat/encyclopedia/Entry.aspx?Name=Trojan:Win32/Skeeyah.A!rfn</a><br/><br/><b>Thoughts? Ideas? Concerns?</b>]]></description>
<pubDate>Mon, 01 Aug 2016 10:13:25 GMT</pubDate>
</item>
</channel>
</rss>
