Skip to content
  • Categories
  • Recent
  • Tags
  • Popular
  • World
  • Users
  • Groups
Skins
  • Light
  • Cerulean
  • Cosmo
  • Flatly
  • Journal
  • Litera
  • Lumen
  • Lux
  • Materia
  • Minty
  • Morph
  • Pulse
  • Sandstone
  • Simplex
  • Sketchy
  • Spacelab
  • United
  • Yeti
  • Zephyr
  • Dark
  • Cyborg
  • Darkly
  • Quartz
  • Slate
  • Solar
  • Superhero
  • Vapor

  • Default (No Skin)
  • No Skin
Collapse
Code Project
  1. Home
  2. Other Discussions
  3. Site Bugs / Suggestions
  4. Probably false positive on article download.

Probably false positive on article download.

Scheduled Pinned Locked Moved Site Bugs / Suggestions
c++comquestionlounge
8 Posts 4 Posters 0 Views 1 Watching
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • OriginalGriffO Offline
    OriginalGriffO Offline
    OriginalGriff
    wrote on last edited by
    #1

    XColorSpectrumCtrl - a non-MFC color picker control that displays a color spectrum [^] The download is flagged by Kaspersky (and possibly another AV) as containing a Trojan that wasn't detected until 3 years after the article was written = so it's probably a false positive, but can you look and remove the XColorSpecturmCtrlTest.EXE file from it?

    "I have no idea what I did, but I'm taking full credit for it." - ThisOldTony "Common sense is so rare these days, it should be classified as a super power" - Random T-shirt AntiTwitter: @DalekDave is now a follower!

    "I have no idea what I did, but I'm taking full credit for it." - ThisOldTony
    "Common sense is so rare these days, it should be classified as a super power" - Random T-shirt

    T 0 C 3 Replies Last reply
    0
    • OriginalGriffO OriginalGriff

      XColorSpectrumCtrl - a non-MFC color picker control that displays a color spectrum [^] The download is flagged by Kaspersky (and possibly another AV) as containing a Trojan that wasn't detected until 3 years after the article was written = so it's probably a false positive, but can you look and remove the XColorSpecturmCtrlTest.EXE file from it?

      "I have no idea what I did, but I'm taking full credit for it." - ThisOldTony "Common sense is so rare these days, it should be classified as a super power" - Random T-shirt AntiTwitter: @DalekDave is now a follower!

      T Offline
      T Offline
      Tony Hill
      wrote on last edited by
      #2

      Sophos is also flagging it as infected.

      OriginalGriffO 1 Reply Last reply
      0
      • T Tony Hill

        Sophos is also flagging it as infected.

        OriginalGriffO Offline
        OriginalGriffO Offline
        OriginalGriff
        wrote on last edited by
        #3

        May be legit detection then - but a trojan that escapes detection for three years but gets into a professional developer's EXE download? It's a bit too unlikely for my taste, but deleting the offending file is the best solution, just to be sure.

        "I have no idea what I did, but I'm taking full credit for it." - ThisOldTony "Common sense is so rare these days, it should be classified as a super power" - Random T-shirt AntiTwitter: @DalekDave is now a follower!

        "I have no idea what I did, but I'm taking full credit for it." - ThisOldTony
        "Common sense is so rare these days, it should be classified as a super power" - Random T-shirt

        T 1 Reply Last reply
        0
        • OriginalGriffO OriginalGriff

          May be legit detection then - but a trojan that escapes detection for three years but gets into a professional developer's EXE download? It's a bit too unlikely for my taste, but deleting the offending file is the best solution, just to be sure.

          "I have no idea what I did, but I'm taking full credit for it." - ThisOldTony "Common sense is so rare these days, it should be classified as a super power" - Random T-shirt AntiTwitter: @DalekDave is now a follower!

          T Offline
          T Offline
          Tony Hill
          wrote on last edited by
          #4

          Checked this again on another machine using Avast AV and it reckons its OK.

          1 Reply Last reply
          0
          • OriginalGriffO OriginalGriff

            XColorSpectrumCtrl - a non-MFC color picker control that displays a color spectrum [^] The download is flagged by Kaspersky (and possibly another AV) as containing a Trojan that wasn't detected until 3 years after the article was written = so it's probably a false positive, but can you look and remove the XColorSpecturmCtrlTest.EXE file from it?

            "I have no idea what I did, but I'm taking full credit for it." - ThisOldTony "Common sense is so rare these days, it should be classified as a super power" - Random T-shirt AntiTwitter: @DalekDave is now a follower!

            0 Offline
            0 Offline
            0x01AA
            wrote on last edited by
            #5

            Paloalto Cortex XDR does let it through. Btw. XColorSpectrumCtrlTest.exe is dated on 2008.

            OriginalGriffO 1 Reply Last reply
            0
            • 0 0x01AA

              Paloalto Cortex XDR does let it through. Btw. XColorSpectrumCtrlTest.exe is dated on 2008.

              OriginalGriffO Offline
              OriginalGriffO Offline
              OriginalGriff
              wrote on last edited by
              #6

              And the trojan was detected in 2011 according to Kaspersky.

              "I have no idea what I did, but I'm taking full credit for it." - ThisOldTony "Common sense is so rare these days, it should be classified as a super power" - Random T-shirt AntiTwitter: @DalekDave is now a follower!

              "I have no idea what I did, but I'm taking full credit for it." - ThisOldTony
              "Common sense is so rare these days, it should be classified as a super power" - Random T-shirt

              0 1 Reply Last reply
              0
              • OriginalGriffO OriginalGriff

                And the trojan was detected in 2011 according to Kaspersky.

                "I have no idea what I did, but I'm taking full credit for it." - ThisOldTony "Common sense is so rare these days, it should be classified as a super power" - Random T-shirt AntiTwitter: @DalekDave is now a follower!

                0 Offline
                0 Offline
                0x01AA
                wrote on last edited by
                #7

                Update: Finally I try to run the app (and not only scan it by Cortex) and that is the result:

                Application information:
                Application name: XColorSpectrumCtrlTest Application
                Application version: 1.1.0.1
                Process ID: 3296
                Application location: C:\Users\....\XColorSpectrumCtrlTest.exe
                Command line: "C:\Users\....\XColorSpectrumCtrlTest.exe"
                File origin: Hard drive on this computer

                Prevention information:
                Prevention date: Sonntag, 15. Mai 2022
                Prevention time: 15:37:49
                OS version: 10.0.19043.2.0.0.256.1
                Component: WildFire
                Cortex XDR code: c0400055
                Prevention description: Suspicious executable detected
                Additional information 1: C:\Users\....\XColorSpectrumCtrlTest.exe
                Additional information 2: E6DA91998D5F224CC333A06D8E3EC59AB0F48501E16D5DCE696389D0B2C33C5C
                Additional information 3: E6DA91998D5F224CC333A06D8E3EC59AB0F48501E16D5DCE696389D0B2C33C5C
                Additional information 4:

                [Edit] I did not submit that until now to Paoloalto, maybe I will do it one time. Anyway Cortex gives similar alarms with my own software when I do very low level access to USB devices. I see it relaxed at the moment. [Edit1] After several logins to Paloalto they do not release it.... :confused:

                1 Reply Last reply
                0
                • OriginalGriffO OriginalGriff

                  XColorSpectrumCtrl - a non-MFC color picker control that displays a color spectrum [^] The download is flagged by Kaspersky (and possibly another AV) as containing a Trojan that wasn't detected until 3 years after the article was written = so it's probably a false positive, but can you look and remove the XColorSpecturmCtrlTest.EXE file from it?

                  "I have no idea what I did, but I'm taking full credit for it." - ThisOldTony "Common sense is so rare these days, it should be classified as a super power" - Random T-shirt AntiTwitter: @DalekDave is now a follower!

                  C Offline
                  C Offline
                  Chris Maunder
                  wrote on last edited by
                  #8

                  All I can suggest, other than not using Kaspersky, is to submit it as a false positive to the anti-virus maker and wait. Their algorithms for matching malicious code are (understandably) weighted on false positives rather than false negatives.

                  cheers Chris Maunder

                  1 Reply Last reply
                  0
                  Reply
                  • Reply as topic
                  Log in to reply
                  • Oldest to Newest
                  • Newest to Oldest
                  • Most Votes


                  • Login

                  • Don't have an account? Register

                  • Login or register to search.
                  • First post
                    Last post
                  0
                  • Categories
                  • Recent
                  • Tags
                  • Popular
                  • World
                  • Users
                  • Groups