Norton 360 keeps deleting Windower 4.
This happened today. I havent used Windower since Dec 4 2013.
I think I was using WIndower 4.2 (I downloaded the exe after installing 4.1 the conventional way)
I've pasted the Norton message below. Any ideas?
============================================================================================
Filename: windower.exe
Threat name: SONAR.SuspBeh!gen3
Full Path: Not Available
____________________________
Details
Few Users, New, Risk High
Origin
Downloaded from Unknown
Activity
Actions performed: 11
____________________________
On computers as of 1/30/2014 at 10:54:00 PM
Last Used 1/30/2014 at 10:54:00 PM
Startup Item No
Launched Yes
____________________________
Few Users
Fewer than 50 users in the Norton Community have used this file.
New
This file was released more than 7 days 29 days ago.
High
This file risk is high.
SONAR Protection monitors for suspicious program activity on your computer.
____________________________
Source: External Media
Source File:
windower.exe
____________________________
File Actions
File: c:\ffxi-windower 4-1\hook.dllRemoved
File: c:\ffxi-windower 4-1\plugins\autoexec.dllRemoved
File: c:\ffxi-windower 4-1\plugins\timers.dllRemoved
Infected file: c:\ffxi-windower 4-1\windower.exeRemoved
____________________________
Registry Actions
Registry change: HKEY_USERS\S-1-5-21-3826235039-2417536098-1047799240-1000_CLASSES\Local Settings\MuiCache\4C\52C64B7E->LanguageList:..., Registry Hive: 64 bitRepaired
Registry change: HKEY_USERS\S-1-5-21-3826235039-2417536098-1047799240-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\cc-35-40-66-59-40->WpadDetectedUrl, Registry Hive: 64 bitRepaired
____________________________
Network Actions
Event: Network activity (Performed by c:\ffxi-windower 4-1\windower.exe, PID:348)No action taken
____________________________
System Settings Actions
Event: Process start (Performed by c:\ffxi-windower 4-1\windower.exe, PID:348)No action taken
Event: PE file creation: c:\ffxi-windower 4-1\updates\temp\bb0282e9-3534-447d-8269-c69aa9a3eb4e (Performed by c:\ffxi-windower 4-1\windower.exe, PID:348)No action taken
Event: Process start: c:\program files (x86)\playonline\squareenix\playonlineviewer\pol.exe, PID:6512 (Performed by c:\ffxi-windower 4-1\windower.exe, PID:348)No action taken
____________________________
Suspicious Actions
Event: Attempt to start a remote thread in a process address space (Performed by c:\ffxi-windower 4-1\windower.exe, PID:348)No action taken
____________________________
File Thumbprint - SHA:
0bc59cf1e347e09caddd7243a7f8dcfce34930f5259faf03c2ad694fa36a90cd
File Thumbprint - MD5:
Not available