1452 McAfee False Positive Detections of SD MSI Files

Prev Next

Issue:

McAfee AV may report a Trojan detection of SecureDoc_32.msi and SecureDoc_64.msi files on both SD 6.2 and 6.5 installation packages. It's deleting these files from clients' servers and client devices.

Symptoms:
The device may blue screen or BSOD during SD installation.

Product Version Affected:
SD 6.2 and 6.5 installation packages

Environment:

Windows OS and Devices
McAfee enterprise v8.8
Scan engine 5700.7163
Dat file is from Feb 1st 2015
v7699

Virus Scan detection:
Response_Name: Virus Detection Alerts
Detecting_Product: VIRUSCAN8800
Threat_Category: Malware detected
Threat_Type: Trojan
Threat_Names: Trojan-FFQA!058631A1A00A
Affected_Computer_IP_Address: 10.8.0.95
Affected_Computer_Name: MIL-SESMS-SD01
Affected_User_Name: SYSTEM
Affected_Ojbect: d:\Program Files (x86)\WinMagic\SDDB-NT\RemotePackage\WINMAGIC_SES\Test - No Customizations\SecureDoc_32.msi\ISChainPackageData.Pkg1._182CC3B9F5E3B28BF25BB3C6D922DA6F\Data1.cab\cmp_server.exe.52E3DC56_4AF1_446C_A8E4_9EA3D6F51B4D
Event_Description: file infected.  Undetermined clean error, deleted successfully
Action_Taken: deleted
Event_ID: 1280
Source_Computer: _
Detection_Time: 02/02/15 04:16:47 UTC
Notification_Email_Time: 02/02/15 04:22:57 UTC

Resolutions:
1. Open a case with McAfee support.
Asked if these SecureDoc_32.msi and SecureDoc_64.msi are false positives or not.
2. White-listing the files and obtaining updated virus definitions from AV support