Licensing

Licensing

When installing ANSYS Fluids on a Windows system, the corporate malware monitoring triggered the following warning: Cisco AMP for Endpoints found a total of 1 events matching your subscription named Cybersecurity Threat Detected since 2018-04-13 17:21:05 UTC. * Event Type: Threat Detected * Computer: computer_name * Hostname: Hostname * IP: 123.45.6.789 * User: abc@company * Detection: Win.Trojan.Generic.in10.talos * File: testWaitFileNormally.exe * File path: \?C:Program FilesANSYS Incv190fensapicebintestWaitFileNormally.exe * Detection SHA-256: bf641e32413277ed6867ffe4978ea958c7c57034c5a113cfe99a80b239aa0b5f * By Application: 7z.exe * Application SHA-256:81c9bac9522487fa14205f7f310bd61177b7809b86a6fe238097ef9196997bf * Timestamp: 2018-04-13 17:32:55 +0000 UTC

    • FAQFAQ
      Participant

      This is a false positive. This small executable is a small utility used in scripts to detect if a file exists. It’s a small code, we have the source and built it. The file did not change for many releases (same md5sum), and we never got a report on this. Scanned it with VirusTotal: https://www.virustotal.com/#/file/bf641e32413277ed6867ffe4978ea958c7c57034c5a113cfe99a80b239aa0b5f/detection 62 scans are clean and those include the big name AVs: Avast, Microsoft, ESET, Symantec, Sophos, Avira, Kaspersky, McAfee, Panda, Trend Micro 2 flagged as a potential threat: Qihoo is a Chinese AV; CrowdStrike Falcon This categorizes it as a false positive. For the record, two items which are factors in the probability of false positives here: – This is a 32 bit app – It contains some amount of unused libraries (cgns, cfx io libraries, etc.) ANSYS 19.2 they will be migrating to build this file with a 64-bit utility so this pop up will no longer occur.