Ticket T558591
Visible to All Users

McAfee identifies a Trojan in a DevExpress file

created 8 years ago (modified 8 years ago)

Hello,

A file copied by devexpress has been identified as a Trojan by McAfee at one of our clients's sites (see below).
It is confirmed by virustotal (see attachment)

Can you do something about it ?

Thanks,
Martin

----------------------------------------------------------------------------------------------------------------------

Subject: "Malware detected and not handled" events received
Importance: High
ePolicy Orchestrator Notification
Analyzer Method: OAS
Threat Type: Trojan
Threat Severity: Alert
Threat Action Taken: deleted

Response Name: Malware detected and not handled Event Type Name: Threat Defined at: My Organization System Location:
Description: Sends an e-mail notification when "Malware detected and not handled" events are received.

Number of events: 1
Source IPV6 addresses:
Source IPV4 addresses:
Threat Names: GenericRXCT-AM!FF526CA867DC Threat Process Name:
Detecting Product Names: VirusScan Enterprise Target File Name: C:\Users\Public\Documents\DevExpress Demos 15.2\Components\WinForms\Bin\PivotGridOlapBrowser.exe

Show previous comments (5)
Stan (DevExpress Support) 8 years ago

    Hello,

    I have finally managed to reproduce this false positive issue on the VirusTotal website. So far we have the following list of files that I were reported as infected:

    15.2.10 - PivotGridOlapBrowser.exe; Size:108 KB (111,104 bytes); MD5:ff526ca867dc26ef348d9645ed18eeed -testing results (indicated by TrendMicro)
    16.1.8 - PivotGridOlapBrowser.exe; Size: 108 KB (111,104 bytes); MD5:220ca8765141d05c4ae9b014c2a578b0 -testing results (already clean)
    16.2.4 - PivotGridOlapBrowser.exe; Size:108 KB (111,104 bytes); MD5:0b6cc218d66d8de94311f7fc4ff07c48 -testing results  (already clean)
    17.1.6 - PivotGridOlapBrowser.exe; Size:108 KB (111,104 bytes); MD5:5fe657f170b638ebbf823e284c7fb9fc) -testing results (indicated by SentinelOne)

    We are will contact the corresponding vendors and do our best to resolve this odd issue as soon as possible. I will keep you informed about any results we receive.

    In the meantime, I suggest you white list these applications, because I am sure that this is a false positive. Particularly, we have tried to build the same demo application from source code in debug mode (it is included in the installation) and received the same alarm. I believe that this alarm will disappear in a couple of days.

    Thanks,
    Stan

    Stan (DevExpress Support) 7 years ago

      Just a follow-up. We have contacted both vendors - TrendMicro and SentinelOne but have not received any response yet. I hope that this weird issue will be addressed in a few days. I will let you know when these files will be whitelisted.

      I would like to note that PivotGridOlapBrowser is a sample project that is built from the source code shipped with the installation. The source code is placed in the neighbor folder - "C:\Users\Public\Documents\DevExpress YYYY.X Demos\Components\WinForms\CS\PivotGridOlapBrowser". Technically, you can delete this file without any risk and rebuild it from the source code.

      Should you have any additional questions in this regard, just drop me a line.

      Serge (DevExpress Support) 7 years ago

        Hello guys,
        Just a quick follow up while Stan is out of the office…
        TrendMicro seems to have updated their definitions. PivotGridOlapBrowser.exe of version 15.2.10 is no longer detected: VirusTotal report. However, the file from version 17.1.6 is still detected by SentinelOne. We're awaiting a response from them.

        Disclaimer: The information provided on DevExpress.com and affiliated web properties (including the DevExpress Support Center) is provided "as is" without warranty of any kind. Developer Express Inc disclaims all warranties, either express or implied, including the warranties of merchantability and fitness for a particular purpose. Please refer to the DevExpress.com Website Terms of Use for more information in this regard.

        Confidential Information: Developer Express Inc does not wish to receive, will not act to procure, nor will it solicit, confidential or proprietary materials and information from you through the DevExpress Support Center or its web properties. Any and all materials or information divulged during chats, email communications, online discussions, Support Center tickets, or made available to Developer Express Inc in any manner will be deemed NOT to be confidential by Developer Express Inc. Please refer to the DevExpress.com Website Terms of Use for more information in this regard.