Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[Prometheus Bug]: NSI Fails to run Java detection script with Antivirus installed. #202

Open
3 tasks
willgoerzen opened this issue Jun 22, 2023 · 2 comments
Open
3 tasks
Assignees
Labels
bug Something isn't working Prometheus

Comments

@willgoerzen
Copy link

Contact Details

No response

What happened?

When installing Prometheus (and I assume other apps), Trellix (McAfee) blocks the detection script from running due to a suspicious double filename extension.

Looking at the NSI script, the temp name generated includes a .tmp extension, then when the script adds a .bat to the end of this, it ends up being [tempname].tmp.bat, which my antivirus doesn't seem to like.

Version

(Dev) 2021.12.03

What version of Windows are you seeing the problem on?

Windows 10 64-bit

Relevant log output

McAfee/Trellix Log: 
2023-06-22 17:24:06.110Z    |Activity|ApBl                |mfeesp                   |      9084|     27224|BOPAP               |XModuleEvents.cpp(851)                  | [DOMAINUSER] ran C:\Users\[DOMAINUSER]\Prometheus_2021.12.03.exe, which tried to access the file C:\Users\[DOMAINUSER]\AppData\Local\Temp\nsrA95F.tmp.bat, violating the rule "Suspicious Double File Extension Execution", and was blocked. For information about how to respond to this event, see KB85494.

Approvals Process

  • Testing For Issue
  • Executive Approval
  • Merge
@spydmobile
Copy link
Collaborator

@RobBryce I co-assigned this for your review.

@spydmobile
Copy link
Collaborator

@willgoerzen thank you for reporting this!

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
bug Something isn't working Prometheus
Projects
None yet
Development

No branches or pull requests

3 participants