SONAR.AM.C!g9 Norton's?

Moderator: Ken Berry

Post Reply
brucefl
Posts: 431
Joined: Tue Apr 12, 2005 2:38 pm
operating_system: Windows 10
System_Drive: C
32bit or 64bit: 64 Bit
motherboard: I7 3770
processor: 3-4 Gig
ram: 12gb
Video Card: NT Geoforce 640
Hard_Drive_Capacity: 2 T
Corel programs: VS21 VS18thru21 and more PIX13
Location: Millinocket, Maine

SONAR.AM.C!g9 Norton's?

Post by brucefl »

Not sure why it came up now, but Norton's said SONAR.AM.C!g9 was suspicious and I should remove it?
It was low lever and comes from VS exe?
Anyone else seen this? Thanks Bruce
User avatar
Ken Berry
Site Admin
Posts: 22481
Joined: Fri Dec 10, 2004 9:36 pm
operating_system: Windows 11
System_Drive: C
32bit or 64bit: 64 Bit
motherboard: Gigabyte B550M DS3H AC
processor: AMD Ryzen 9 5900X
ram: 32 GB DDR4
Video Card: AMD RX 6600 XT
Hard_Drive_Capacity: 1 TB SSD + 2 TB HDD
Monitor/Display Make & Model: Kogan 32" 4K 3840 x 2160
Corel programs: VS2022; PSP2023; DRAW2021; Painter 2022
Location: Levin, New Zealand

Re: SONAR.AM.C!g9 Norton's?

Post by Ken Berry »

I've never received it myself, but then again I use McAfee... But I also have never seen anyone else ever reporting this -- although there have been other very isolated cases of false positives in the past, including IIRC with PSP as well as VS.

I assume your "low lever" was a typo for "low level"...

Does VS still open and function properly?
Ken Berry
greyguru
Posts: 4
Joined: Mon Sep 22, 2014 5:48 pm
operating_system: Windows 10
System_Drive: C
32bit or 64bit: 64 Bit
processor: Intel Core i9 10900
ram: 32GB
Video Card: NVIDIA GeForce RTX 2060 SUPER
Hard_Drive_Capacity: 5 TB total
Monitor/Display Make & Model: Dell U3219 (landscape), Dell S2722QC (portrait)
Corel programs: PaintShop Pro 2023
Contact:

Re: SONAR.AM.C!g9 Norton's?

Post by greyguru »

I just downloaded Videostudio Ultimate 10.5 and I got a similar message on Fast Flick and on screen capture. Possibly I will get this on any other part I open too. Here's the "suspicious activity" it recorded:

Filename: MWizard.exe
Threat name: SONAR.AM.C!g9Full Path: d:\program files\corel\corel videostudio x10\mwizard.exe

____________________________

____________________________


On computers as of 
28-Aug-17 at 9:51:12 PM

Last Used 
28-Aug-17 at 9:51:12 PM

Startup Item 
No

Launched 
Yes

SONAR Protection monitors for suspicious program activity on your computer.


____________________________


MWizard.exe Threat name: SONAR.AM.C!g9
Locate


Few Users
Hundreds of users in the Norton Community have used this file.

New
This file was released more than 7 days  ago.

High
This file risk is high.


____________________________


Source: External Media

Source File:
mwizard.exe

____________________________

System Settings Actions

Event: Process start (Performed by d:\program files\corel\corel videostudio x10\mwizard.exe, PID:4784) No fix attempted
\REGISTRY\USER\S-1-5-21-3333716158-4089654070-4278953749-1001\SOFTWARE\Corel\PCU:HFIv2 (Performed by d:\program files\corel\corel videostudio x10\mwizard.exe, PID:4784) No fix attempted
c:\Users\David\AppData\Local\Temp\ PCULog3.txt (Performed by d:\program files\corel\corel videostudio x10\mwizard.exe, PID:4784) No fix attempted
\REGISTRY\USER\S-1-5-21-3333716158-4089654070-4278953749-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings:ProxyEnable (Performed by d:\program files\corel\corel videostudio x10\mwizard.exe, PID:4784) No fix attempted
\REGISTRY\USER\S-1-5-21-3333716158-4089654070-4278953749-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings:ProxyOverride (Performed by d:\program files\corel\corel videostudio x10\mwizard.exe, PID:4784) No fix attempted
\REGISTRY\USER\S-1-5-21-3333716158-4089654070-4278953749-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections:SavedLegacySettings (Performed by d:\program files\corel\corel videostudio x10\mwizard.exe, PID:4784) No fix attempted
\REGISTRY\USER\S-1-5-21-3333716158-4089654070-4278953749-1001\SOFTWARE\Corel\VSPro\Version20\CCC\ServerData:pcuversion (Performed by d:\program files\corel\corel videostudio x10\mwizard.exe, PID:4784) No fix attempted
c:\Users\David\AppData\Local\Temp\ _tmp540225004 (Performed by d:\program files\corel\corel videostudio x10\mwizard.exe, PID:4784) No fix attempted
\REGISTRY\USER\S-1-5-21-3333716158-4089654070-4278953749-1001\SOFTWARE\Corel\VSPro\Version20\msgsys:Launches (Performed by d:\program files\corel\corel videostudio x10\mwizard.exe, PID:4784) No fix attempted
\REGISTRY\USER\S-1-5-21-3333716158-4089654070-4278953749-1001\SOFTWARE\Corel\VSPro\Version20\msg:LastLaunchCount (Performed by d:\program files\corel\corel videostudio x10\mwizard.exe, PID:4784) No fix attempted
\REGISTRY\USER\S-1-5-21-3333716158-4089654070-4278953749-1001\SOFTWARE\Corel\VSPro\Version20\msg:Schedule (Performed by d:\program files\corel\corel videostudio x10\mwizard.exe, PID:4784) No fix attempted
\REGISTRY\USER\S-1-5-21-3333716158-4089654070-4278953749-1001\SOFTWARE\Corel\VSPro\Version20\msg:StartDate (Performed by d:\program files\corel\corel videostudio x10\mwizard.exe, PID:4784) No fix attempted
\REGISTRY\USER\S-1-5-21-3333716158-4089654070-4278953749-1001\SOFTWARE\Corel\VSPro\Version20\msg:LastLaunchTime (Performed by d:\program files\corel\corel videostudio x10\mwizard.exe, PID:4784) No fix attempted
\REGISTRY\USER\S-1-5-21-3333716158-4089654070-4278953749-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content:CachePrefix (Performed by d:\program files\corel\corel videostudio x10\mwizard.exe, PID:4784) No fix attempted
\REGISTRY\USER\S-1-5-21-3333716158-4089654070-4278953749-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies:CachePrefix (Performed by d:\program files\corel\corel videostudio x10\mwizard.exe, PID:4784) No fix attempted
\REGISTRY\USER\S-1-5-21-3333716158-4089654070-4278953749-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History:CachePrefix (Performed by d:\program files\corel\corel videostudio x10\mwizard.exe, PID:4784) No fix attempted
\REGISTRY\USER\S-1-5-21-3333716158-4089654070-4278953749-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings:EnableAutodial (Performed by d:\program files\corel\corel videostudio x10\mwizard.exe, PID:4784) No fix attempted
c:\Users\David\AppData\Local\Temp\ trkcfg.ini (Performed by d:\program files\corel\corel videostudio x10\mwizard.exe, PID:4784) No fix attempted
\REGISTRY\USER\S-1-5-21-3333716158-4089654070-4278953749-1001\SOFTWARE\Corel\VSPro\Version20:totallaunchcount (Performed by d:\program files\corel\corel videostudio x10\mwizard.exe, PID:4784) No fix attempted
c:\Users\David\AppData\Local\microsoft\Windows\inetcookies\ rgd6k2z8.cookie (Performed by d:\program files\corel\corel videostudio x10\mwizard.exe, PID:4784) No fix attempted
c:\users\david\appdata\local\temp\ srvdbcf.tmp (Performed by d:\program files\corel\corel videostudio x10\mwizard.exe, PID:4784) No fix attempted
c:\Users\David\AppData\Local\microsoft\Windows\inetcache\IE\RGFWMGGX\ mcsatellite[4].xml (Performed by d:\program files\corel\corel videostudio x10\mwizard.exe, PID:4784) No fix attempted
c:\users\david\appdata\local\temp\ srvdff7.tmp (Performed by d:\program files\corel\corel videostudio x10\mwizard.exe, PID:4784) No fix attempted
c:\Users\David\AppData\Roaming\Corel\Messages\540225004_807001\en\messagecache1\Messages\ Messages.xml (Performed by d:\program files\corel\corel videostudio x10\mwizard.exe, PID:4784) No fix attempted
c:\Users\David\AppData\Roaming\ulead systems\corel videostudio mw (x64)\ 20.0 (Performed by d:\program files\corel\corel videostudio x10\mwizard.exe, PID:4784) No fix attempted
c:\Users\David\AppData\Roaming\ulead systems\corel videostudio mw (x64)\20.0\ en-US (Performed by d:\program files\corel\corel videostudio x10\mwizard.exe, PID:4784) No fix attempted
\REGISTRY\USER\S-1-5-21-3333716158-4089654070-4278953749-1001\SOFTWARE\Microsoft\Windows NT\CurrentVersion\DRIVERS32:vidc.i420 (Performed by d:\program files\corel\corel videostudio x10\mwizard.exe, PID:4784) No fix attempted
\REGISTRY\USER\S-1-5-21-3333716158-4089654070-4278953749-1001\SOFTWARE\Ulead Systems\Corel VideoStudio MW\20.0 (Performed by d:\program files\corel\corel videostudio x10\mwizard.exe, PID:4784) No fix attempted
\REGISTRY\USER\S-1-5-21-3333716158-4089654070-4278953749-1001\SOFTWARE\Ulead Systems\Corel VideoStudio MW\20.0\VIO (Performed by d:\program files\corel\corel videostudio x10\mwizard.exe, PID:4784) No fix attempted
\REGISTRY\USER\S-1-5-21-3333716158-4089654070-4278953749-1001\SOFTWARE\Ulead Systems\Corel VideoStudio MW\20.0\VIO\AVI (Performed by d:\program files\corel\corel videostudio x10\mwizard.exe, PID:4784) No fix attempted
\REGISTRY\USER\S-1-5-21-3333716158-4089654070-4278953749-1001\SOFTWARE\Ulead Systems\Corel VideoStudio MW\20.0\VIO\AVI:EnableGlobalDivX (Performed by d:\program files\corel\corel videostudio x10\mwizard.exe, PID:4784) No fix attempted
\REGISTRY\USER\S-1-5-21-3333716158-4089654070-4278953749-1001\SOFTWARE\Ulead Systems\Corel VideoStudio MW\20.0\VIO:RemoveCriticalSection (Performed by d:\program files\corel\corel videostudio x10\mwizard.exe, PID:4784) No fix attempted
Event: Process start (Performed by d:\program files\corel\corel videostudio x10\mwizard.exe, PID:2592) No fix attempted
Event: Process start: d:\program files\Corel\corel videostudio x10\ MWizard.exe, PID:2592 (Performed by d:\program files\corel\corel videostudio x10\mwizard.exe, PID:2592) No fix attempted
\REGISTRY\USER\S-1-5-21-3333716158-4089654070-4278953749-1001\SOFTWARE\Microsoft\Multimedia\ActiveMovie Filters\MPEG Decoder:AudioFreqDivider (Performed by d:\program files\corel\corel videostudio x10\mwizard.exe, PID:4784) No fix attempted
\REGISTRY\USER\S-1-5-21-3333716158-4089654070-4278953749-1001\SOFTWARE\MainConcept\DirectShow\MPEGVideoDecoder:MPEG2Only (Performed by d:\program files\corel\corel videostudio x10\mwizard.exe, PID:4784) No fix attempted
\REGISTRY\USER\S-1-5-21-3333716158-4089654070-4278953749-1001\SOFTWARE\MainConcept\DirectShow\MPEGVideoDecoder:ForceOverlayMixer2 (Performed by d:\program files\corel\corel videostudio x10\mwizard.exe, PID:4784) No fix attempted
Event: Process start: d:\program files\Corel\corel videostudio x10\x86\ qtbridge32.exe, PID:9820 (Performed by d:\program files\corel\corel videostudio x10\mwizard.exe, PID:4784) No fix attempted
c:\Users\David\AppData\Roaming\ulead systems\corel videostudio mw (x64)\20.0\en-US\ U32BASE.CFG (Performed by d:\program files\corel\corel videostudio x10\mwizard.exe, PID:4784) No fix attempted
c:\Users\David\AppData\Roaming\ulead systems\corel videostudio mw (x64)\20.0\en-US\ GG_App.ini (Performed by d:\program files\corel\corel videostudio x10\mwizard.exe, PID:4784) No fix attempted
____________________________


File Thumbprint - SHA:
70f72752aceddb2b9d2b0680be2f4f819e4535d5f158b14cab7265fefafe16aa
File Thumbprint - MD5:
Not available
User avatar
RobertOZ
Advisor
Posts: 2426
Joined: Tue Jun 26, 2012 12:50 am
operating_system: Windows 10
System_Drive: C
32bit or 64bit: 64 Bit
motherboard: Asus Prime B550M-A WI-FI AM4 mATX
processor: AMD Ryzen 5 3600 3 6 GHz
ram: 16GB
Video Card: Asus Geforce GTX 1650 GDDR6 Driver 551 23
sound_card: Realtek High Definition Audio
Hard_Drive_Capacity: 7 TB
Monitor/Display Make & Model: Philips 32" IPS LED, Samsung 28" 3840x2160 UHD 4K
Corel programs: VS2018/21/22/23 & MS 3D, MCC XL
Location: Mornington, Vic. Australia

Re: SONAR.AM.C!g9 Norton's?

Post by RobertOZ »

Ignore the threat, it is a false positive, if you purchased the product from Corel then what you download will be perfectly safe to install and use, MWizard .exe appears to be related to the FastFlick component of the program and will not present any problems for you
Tear out my hair
Posts: 1
Joined: Tue Sep 19, 2017 2:47 am
operating_system: Windows 10
System_Drive: C
32bit or 64bit: 64 Bit
motherboard: +++++
processor: +++++
ram: 12 GB
Video Card: +++++
sound_card: +++++
Hard_Drive_Capacity: 1TB
Monitor/Display Make & Model: Dell
Corel programs: Video Studio X10 Ultimate

Re: SONAR.AM.C!g9 Norton's?

Post by Tear out my hair »

I have been the frequent recipient of a similar message from Norton regarding suspicious vstudio.exe file behavior (sonar.am.c!g9) The TS person I called at Norton had apparently never heard of Corel and was sorry for my inconvenience, The phone support person at Corel determined that it is a tech support (which would e-mail me soon) problem a bit over two weeks ago and I have heard zip, zero, nada since. The chat person at Corel I chatted with today was also sorry for my inconvenience but chatted, emphatically, that I will hear from TS and essentially hung up. I D/L'd the program from Corel. I would be delighted if Corel were to say that this file's behavior too is a false positive but neither Corel nor Norton seem willing to commit to reassuring their customers with any resolution to this very worrying issue.
Post Reply