Endpoint Protection

 View Only
Expand all | Collapse all

Adobe Gamma Loader.exe Detected as Trojan.Gen.X

ℬrίαη

ℬrίαηSep 21, 2012 09:48 PM

ℬrίαη

ℬrίαηSep 21, 2012 10:56 PM

Migration User

Migration UserSep 24, 2012 12:36 PM

  • 1.  Adobe Gamma Loader.exe Detected as Trojan.Gen.X

    Posted Sep 21, 2012 02:46 PM

    This morning we had a fair number of machines that detected Trojan.Gen.X for the Adobe Gamma Loader.exe (file path on XP:  C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe).  I think the systems are all running Adobe CS 3 but am not 100% positive on this.  Is this a legitimate detection or a false positive?

    Thanks!



  • 2.  RE: Adobe Gamma Loader.exe Detected as Trojan.Gen.X

    Posted Sep 21, 2012 02:52 PM

    On Google + others running different versions of CS or other Adobe products are getting this as well.



  • 3.  RE: Adobe Gamma Loader.exe Detected as Trojan.Gen.X

    Posted Sep 21, 2012 04:34 PM

    https://www-secure.symantec.com/connect/forums/adobe-gamma-loaderexe-alerts-today

    Please submit the file to Symantec security response.



  • 4.  RE: Adobe Gamma Loader.exe Detected as Trojan.Gen.X

    Posted Sep 21, 2012 06:39 PM

    Prachand, I will try to do this if I can get it.  SEP Policies have been deleting it on a lot of machines, though we may have some different groups with different policies.



  • 5.  RE: Adobe Gamma Loader.exe Detected as Trojan.Gen.X

    Posted Sep 21, 2012 06:40 PM

    Submitted to Symantec.

    We are getting quite a few machines reporting this.  Some running CS3, CS5 and some running Adobe PS Elements !

    It is part of the Adobe screen gamma calibration tool.



  • 6.  RE: Adobe Gamma Loader.exe Detected as Trojan.Gen.X

    Posted Sep 21, 2012 06:58 PM

    I added it to the centralized exception policy, then restored the file backup in the quarantine.  Submitted the file to Symnatec support, and here is the result.

    Will leave in my exception policy until I can get word from Symantec that the detection issue is resolved.

     

    Submission Summary
    Files Submitted
    # Filename MD5 Determination Signature Protection Name RR Seq#
    1 adobe gamma loader.exe C2FF17734176CD15221C10044EF0BA1A

    Developer Notes:
    adobe gamma loader.exe is a clean file.

    Assessment File1:  adobe gamma loader.exe (113664 bytes)
    MD5:  C2FF17734176CD15221C10044EF0BA1A
    SHA-1:  C5B97DCD1EF1DD4A0FB5D7CE13E85FE1820CEF47
    SHA-256:  B0D83215E105E2CC88AAA556B1DF380B2E67500A21077F83447199DB8E8CB7BD
    Machine: Machine
    Determination: Clean
    Determination Detail:  This file is clean.

      

    This message was generated by Symantec Security Response automation.

    Should you have any questions about your submission, please contact our regional technical support from the Symantec Web site, and give them the tracking number included in this message.



  • 7.  RE: Adobe Gamma Loader.exe Detected as Trojan.Gen.X

    Posted Sep 21, 2012 07:13 PM

    Can you  open a case with Symantec and ask it be relooked.



  • 8.  RE: Adobe Gamma Loader.exe Detected as Trojan.Gen.X

    Posted Sep 21, 2012 07:31 PM

    Hi,
    Adobe has always been and will always be vulnerable.
    If possible swap if you do not just put the SEP always on alert with adobe
    There are vulnerabilities and exploits that are created to always attack with this type of application.
    take care



  • 9.  RE: Adobe Gamma Loader.exe Detected as Trojan.Gen.X

    Posted Sep 21, 2012 07:32 PM

    Done

    Support indicates the fix should be in defs r17 from today, or in tomorrow's base certified release.

    Hope that helps you out.

    I'm leaving my centralized exception entry in until Monday to be sure.

     

     



  • 10.  RE: Adobe Gamma Loader.exe Detected as Trojan.Gen.X

    Posted Sep 21, 2012 09:48 PM

    So this is a confirmed false positive?



  • 11.  RE: Adobe Gamma Loader.exe Detected as Trojan.Gen.X

    Posted Sep 21, 2012 10:52 PM

    Hi Brian.. Yes it's confirmed by Symantec support as a false positive.



  • 12.  RE: Adobe Gamma Loader.exe Detected as Trojan.Gen.X

    Posted Sep 21, 2012 10:56 PM

    Great, thanks for updating.



  • 13.  RE: Adobe Gamma Loader.exe Detected as Trojan.Gen.X

    Posted Sep 22, 2012 06:30 AM

    I have a home copy of SEP provided by my employer. it detected adobe gamma loader.exe as trojan.gen.x yesterday evening. I deleted it and ran a full msanual system scan.

    SEP found another file that it identified as trojan.gen.x:

    A0098343.exe

    Is this a coincidence, or has SEP found two real trojans?

    Not being very versed in these deep computer detail, might it be a restore version of the same adobe file?

     

     

    Action Risk Type Original Location
    Cleaned by deletion File c:\System Volume Information\_restore{CCBD9007-8833-4453-B61E-BB22C73B8EBD}\RP774\
     

     



  • 14.  RE: Adobe Gamma Loader.exe Detected as Trojan.Gen.X

    Broadcom Employee
    Posted Sep 22, 2012 06:40 AM

    is the system updated with the latest definition?

    can you open a support ticket?



  • 15.  RE: Adobe Gamma Loader.exe Detected as Trojan.Gen.X

    Posted Sep 22, 2012 02:48 PM

    Have you updated to latest revision? Any detections?



  • 16.  RE: Adobe Gamma Loader.exe Detected as Trojan.Gen.X
    Best Answer

    Trusted Advisor
    Posted Sep 24, 2012 08:57 AM

    Hello,

    Symantec have received multiple reports of a file named Adobe Gamma Loader.exe being detected as Trojan.Gen.X. It is confirmed this was a False Positive.

    It was resolved as of definition Version: 20120921.003.

    It is recommended to make sure you are running the Latest version of Virus Definitions on the Symantec Endpoint Protection clients.

    Similar Thread: https://www-secure.symantec.com/connect/forums/adobe-gamma-loaderexe-alerts-today

    Hope that helps!!



  • 17.  RE: Adobe Gamma Loader.exe Detected as Trojan.Gen.X

    Posted Sep 24, 2012 09:00 AM

    Hello ragenkagen,

    Please see this thread:

    https://www-secure.symantec.com/connect/forums/adobe-gamma-loaderexe-alerts-today

    There was a recent False Positive with a file of this name, but that has now been corrected.



  • 18.  RE: Adobe Gamma Loader.exe Detected as Trojan.Gen.X

    Posted Sep 24, 2012 12:30 PM

    Thanks all for helping out in determining that this was a false positive.



  • 19.  RE: Adobe Gamma Loader.exe Detected as Trojan.Gen.X

    Posted Sep 24, 2012 12:36 PM

    Thank you all!