Norton blocking Roon due to IDP.generic infection message (ref#2XXWYP)

What’s happening?

· Other

How can we help?

· None of the above

Other options

· My Roon software won't start up

Describe the issue

Norton is blocking Roon after update. Roonappliance.exe infected with IDP.generic is the message

Describe your network setup

wifi

Please read:

Hello @Rob_Langstraat,

The issue you’re encountering is due to a false positive detection by Norton Antivirus. The IDP.Generic flag is a generic heuristic used by Norton and other antivirus software to identify potentially suspicious behavior, but it does not necessarily mean the file is malicious.

In this case, RoonAppliance.exe from Roon version 2.51, build 1534 is safe, and this detection is a mistake. The Roon team regularly scans all releases for malware before distribution. We’ve seen similar reports in the past with other antivirus software as well, especially when new builds are released.


What you can do:

  1. Restore the file from quarantine in Norton.
  2. Add an exception in Norton for RoonAppliance.exe or the entire Roon installation folder.
  3. Report it as a false positive to Norton via their official False Positive Submission Form.

Hello Vadim,

Solved!

Many thanks,

Rob

Hello @Rob_Langstraat,

Thank you for the update. We are glad to hear that the issue is solved. Enjoy your music!

For security reason, can you please remove the “IDP.Generic” threat from your application instead we accept it and restore from quarantine in Norton? Thanks!

Hi @mak.lixian,

There is nothing to remove, there is no threat within Roon, it’s a false flag (incorrect conclusion) from Norton.

Typically once reported antivirus software vendors take action and update their generic heuristic algorithms so the file is no longer flagged.

In this case you can report it to Norton via

https://submit.norton.com/

If you are still concerned, I recommend scanning the file with an alternative antivirus software.

IIRC there are some site that allow uploading of files for analysis but multiple systems and report back the results.

I have reported it to Norton.

1 Like

This topic was automatically closed 24 hours after the last reply. New replies are no longer allowed.