Clever / csvlint

library and command line tool that validates a CSV file
Apache License 2.0
189 stars 20 forks source link

McAfee Endpoint Security 10.7 on Windows 10 says that it is malicious #33

Closed san-r closed 3 years ago

san-r commented 3 years ago

McAfee Endpoint Security 10.7 on Windows 10 prevents it from working saying that it is malicious with threat severity as "Critical". Here's a screenshot:

image

Since the screenshot does not capture full information, here is a copy-paste text version of it:

Adaptive Threat Protection repaired D:\copyNrun\cmdTools\csvlint.exe TargetType, because its reputation (Known Malicious) is below the configured Clean threshold. Analyzer / Detector Product name McAfee Endpoint Security Product version 10.7.0.1929 Feature name Real Protect Cloud

Threat Action taken Clean Threat category Malware Detected Threat event ID 35107 Threat handled Yes Threat name Real Protect-XGPE!D8FF91EB72FC Threat severity Critical Threat timestamp 8/16/2021 2:19 PM Threat type Trojan

Source Source access time 8/16/2021 2:18 PM Source create time 4/12/2018 5:04 AM Source file path C:\WINDOWS\SysWOW64 Source file size 232960 Source hostName DDO-SECTION Source modify time 4/12/2018 5:04 AM Source process name cmd.exe Source user name DDO-SECTION\SECTION-04

Target Target hash d8ff91eb72fcc0f7b029f60c38ddf718 Target host name DDO-SECTION Target name csvlint.exe Target path D:\copyNrun\cmdTools

Other Vector type Local System Detection message Adaptive Threat Protection Detection Detection quarantine ID {9BC8D7C7-FA76-4FDC-968B-1ACCBC7E5689}


Online testing at https://www.virustotal.com/gui/home/upload says that it is clean. That list also includes McAfee-GW-Edition according to which it is clean. The issue only seems to be with McAfee Endpoint Security!

Edit: I've sent an email requesting them to check the file.

san-r commented 3 years ago

I had emailed a check request for the windows executable to McAfee. The problem seems to be resolved now.