Windows NCPA agent files detected as possible malware

This support forum board is for support questions relating to Nagios XI, our flagship commercial network monitoring solution.
Locked
alipoglavsek
Posts: 13
Joined: Fri Nov 13, 2020 6:37 am

Windows NCPA agent files detected as possible malware

Post by alipoglavsek »

Hi.

We have F-Secure antivirus and yesterday some files from Windows NCPA agents (version 2.2.2) werer identified as possible malware code.

For now these 2 files were found:
ObjectName (custom) C:\Program Files (x86)\Nagios\NCPA\library.zip\[518] py_compile.pyc
ObjectName (custom) C:\Program Files (x86)\Nagios\NCPA\library.zip\[599] sysconfig.pyc

Is this actually has to do something with malware or are these false positives and we can white liste these files?

Thank you for your help.

Best regards, Aljaž
ssax
Dreams In Code
Posts: 7682
Joined: Wed Feb 11, 2015 12:54 pm

Re: Windows NCPA agent files detected as possible malware

Post by ssax »

This is the first I've seen this, that library.zip file contains those files on my system as well and is distributed with NCPA (it's essentially the python libraries need for NCPA).

Can you 7zip that C:\Program Files (x86)\Nagios\NCPA\library.zip file and PM it to me so that I can analyze it?

EDIT: I installed f-secure safe and scanned it and it did not get flagged with NCPA 2.2.2 or NCPA 2.3.1.
alipoglavsek
Posts: 13
Joined: Fri Nov 13, 2020 6:37 am

Re: Windows NCPA agent files detected as possible malware

Post by alipoglavsek »

Hi,

you have files on PM.
Thank you.

BRA
ssax
Dreams In Code
Posts: 7682
Joined: Wed Feb 11, 2015 12:54 pm

Re: Windows NCPA agent files detected as possible malware

Post by ssax »

Thank you, the file hash matches and it looks like it is a false positive. We don't get into recommending AV/malware exclusions by policy but you should reach out to F-Secure and see what options you have for this in their product.
Locked