Skip to content
DataMiner DoJo

More results...

Generic selectors
Exact matches only
Search in title
Search in content
Post Type Selectors
Search in posts
Search in pages
Search in posts
Search in pages
Log in
Menu
  • Updates & Insights
  • Questions
  • Learning
    • E-learning Courses
    • Empower Replay: Limited Edition
    • Tutorials
    • Open Classroom Training
    • Certification
      • DataMiner Fundamentals
      • DataMiner Configurator
      • DataMiner Automation
      • Scripts & Connectors Developer: HTTP Basics
      • Scripts & Connectors Developer: SNMP Basics
      • Visual Overview – Level 1
      • Verify a certificate
    • Video Library
    • Books We Like
    • >> Go to DataMiner Docs
  • Expert Center
    • Solutions & Use Cases
      • Solutions
      • Use Case Library
    • Markets & Industries
      • Media production
      • Government & defense
      • Content distribution
      • Service providers
      • Partners
      • OSS/BSS
    • Agile
      • Agile Webspace
      • Everything Agile
        • The Agile Manifesto
        • Best Practices
        • Retro Recipes
      • Methodologies
        • The Scrum Framework
        • Kanban
        • Extreme Programming
      • Roles
        • The Product Owner
        • The Agile Coach
        • The Quality & UX Coach (QX)
    • DataMiner DevOps Professional Program
      • About the DevOps Program
      • DataMiner DevOps Support
  • Downloads
  • More
    • DataMiner Releases & Updates
    • Feature Suggestions
    • Climb the leaderboard!
    • Swag Shop
    • Contact
    • Global Feedback Survey
  • PARTNERS
    • All Partners
    • Technology Partners
    • Strategic Partner Program
    • Deal Registration
  • >> Go to dataminer.services

Antivirus false positives on SLSpiHost.exe

Solved1.25K views17th November 2022antivirus Dataminer Release
2
Brecht Deconinck [SLC] [DevOps Member]1.20K 16th November 2022 0 Comments

The installation file: DataMiner 10.2.11.0-12373 Full Upgrade\Update\Files\SLSpiHost.exe seems to be triggering some av-engines, see: https://www.virustotal.com/gui/file/4f4a838983b209bc7ae6172c1ea77de0d26a1a8eba2b002c5d1a2a7bd4363757/detection

It looks like false positives, but can this be confirmed and are all installation packages scanned before published?

Simo Hallikainen Answered question 17th November 2022

2 Answers

  • Active
  • Voted
  • Newest
  • Oldest
6
Bert Vandenberghe [SLC] [DevOps Enabler]8.29K Posted 16th November 2022 0 Comments

I can confirm this indeed concerns false positives and we do scan each package we make available.

It looks like more people are affected by this MSILHeracles false positive, hopefully those engines will soon have updated definitions to avoid this false positive.

Ben Vandenberghe [SLC] [DevOps Enabler] Selected answer as best 16th November 2022
0
Simo Hallikainen25 Posted 17th November 2022 2 Comments

Hi, I sure do hope that mentioned file gets whitelisted soon, meanwhile this prevents us from updating our system. As a suggestion, maybe a broader variation of av-engines could be used before publishing to avoid these kind of issues? Meanwhile, I would not state this case as solved..

BR,

Simo

Bert Vandenberghe [SLC] [DevOps Enabler] Posted new comment 17th November 2022
Bert Vandenberghe [SLC] [DevOps Enabler] commented 17th November 2022

Hi Simo, as definition files of these av-engines get continuous updates, these false positive can happen at any moment of time and this is also out of our control even if yesterday everything was still green. We do continue to follow up on this case and we are able to avoid the false positive by commenting out one method we call from the Win32 API. Strangely enough, this method is also used in other processes which are currently not flagged as a false positive today. But, as I mentioned, this can change any time with definition updates… We are currently investigating if we can make a new release without this line of code very soon now. Unless the av-engines would get an update in meantime which fixes this problem.
Anyhow, I do also want to reemphasize that it is perfectly safe to continue to install this release as it is today. It is a false positive, there is nothing wrong with this process, only a few av-engines are a bit too enthusiastic in their detections.

Bert Vandenberghe [SLC] [DevOps Enabler] commented 17th November 2022

I just heard from our QA Director that the releases of tomorrow (10.2.12 and 10.2 CU9) would have that one line of code removed to avoid this false positive…

Please login to be able to comment or post an answer.

My DevOps rank

DevOps Members get more insights on their profile page.

My user earnings

0 Dojo credits

Spend your credits in our swag shop.

0 Reputation points

Boost your reputation, climb the leaderboard.

Promo banner DataMiner DevOps Professiona Program
DataMiner Integration Studio (DIS)
Empower Katas
Privacy Policy • Terms & Conditions • Contact

© 2025 Skyline Communications. All rights reserved.

DOJO Q&A widget

Can't find what you need?

? Explore the Q&A DataMiner Docs