10-26-2017 05:59 PM
I recently ran a Malwarebytes scan of my test system and the Datafinder 2015 .cab file was flagged as spyware. Here are the results from MWB:
---------------------------------
Malwarebytes
www.malwarebytes.com
-Log Details-
Scan Date: 10/25/17
Scan Time: 2:32 PM
Log File: f5771e38-b9cb-11e7-8c0d-00ff88c4a589.json
Administrator: Yes
-Software Information-
Version: 3.2.2.2029
Components Version: 1.0.212
Update Package Version: 1.0.3097
License: Free
-System Information-
OS: Windows 7 Service Pack 1
CPU: x86
File System: NTFS
-Scan Summary-
Spyware.Pony, C:\PROGRAMDATA\NATIONAL INSTRUMENTS\MDF\PRODUCTCACHE\NI DATAFINDER CLIENT 15.0.1 [15.0.16118]\NI-DATAFINDER1.CAB, No Action By User, [70], [450269],1.0.3097
Spyware.Pony, C:\PROGRAMDATA\NATIONAL INSTRUMENTS\MDF\PRODUCTCACHE\NI DATAFINDER CLIENT 15.0.1 [15.0.16118]\NI-DATAFINDER64.CAB, No Action By User, [70], [450269],1.0.3097
---------------------------------
What's going on? Is this real or a false-positive?
10-27-2017 06:41 AM
The NI SEP (Software Engineering Process) includes final virus scanning of all components involved creating the release product from build machines to final installers.
DataFinder Server 2015, DIAdem 2015 (also including that cab) and LabVIEW 2015 DataFinder Toolkit have been scanned using the following engine:
Can you please re-scan the suspicious file(s) using a different scan engine.
10-27-2017 08:43 AM
Hi jrasco,
I have and frequently run DataFinder 2015 and DIAdem 2015, and for years I have frequently scanned with MalwareBytes. I know for a fact that DataFinder 2015 and DIAdem 2015 have been running while I scanned with MalwareBytes on numerous occasions. I have never had MalwareBytes label any version of DIAdem or DataFinder or their components as a potential threat.
I don't know what that means for you in your current situation, but I thought this data point might be useful to you.
Brad Turpin
DIAdem Product Support Engineer
National Instruments
10-27-2017 11:45 AM
The only other program I have access to right now is Windows Defender, which shows no problem (of course.) I have also been running DataFinder + MWB for quite some time on this system and others without incidence. The last scan on 10/12 did not flag this .cab file so this is a recent database signature update on the MWB side.
Unfortunately (for fortunately), this .cab doesn't exist on my other systems so I haven't seen any other quarantine events.
Are there hash sums or PGP signatures for this .cab file that can be verified? I will not attach the file to the forum because I don't want anyone else to download it. I can send it directly to someone in support if that helps.
10-27-2017 05:21 PM
Hi jrasco,
we rechecked all three language versions using a newer version of McAffee and VirusTotal, both returning no issues.
In case you cannot run a virus protection tool on your other machine, I recommend starting over with a fresh installer from our web site.
10-27-2017 05:58 PM
Stefan,
Since the executables weren't flagged, I'm not worried about them and trust their integrity. I quarantined the flagged files since they are only .cab. I'll update this thread if anything happens in the future.
Thanks for your help.