Secunia CSI7
Advisories
Research
Forums
Create Profile
Our Commitment
PSI
PSI API
CSI
OSI
xSI
Vulnerabilities
Programs
Open Discussions
My Threads
Create Thread
Statistics
About

Forum Thread: Unknown Program: KeePassX 4.x shows installed in PSI

You are currently viewing a forum thread in the Secunia Community Forum. Please note that opinions expressed here are not of Secunia but solely reflect those of the user who wrote it.

This thread was submitted in the following forum:
Open Discussions

This thread has been marked as locked.
joe schmoe Unknown Program: KeePassX 4.x shows installed in PSI
Member 12th Jun, 2011 21:48
Ranking: 38
Posts: 139
User Since: 26th Nov, 2008
System Score: 100%
Location: US
Running XP Home SP3, Secunia PSI 2.0.0.3003.

Secunia rating is 100%, recent updates to Adobe Flash and Java.

Under Scan Results, there is an entry for KeePassX 4.x.

This entry shows that, when expanded to show file path, it is somehow related, or connected to, both LightScribe (a HP file) and Last.fm (a free music internet service).

Path for LightScribe is as follows: C:\Program Files\Common Files\LightScribe\QtCore4.dll, version 4.5.1.0. Last.fm file was the same .dll file, but was reported as a Zombie file. Removed the zombie report by renaming this file to .old in case Last.fm needed this file to run properly.

I do not rightly understand the correlation between KeePassX 4.x and these two other programs (as KeePass is a password security program) and KeePass should be noted alone in its own right in PSI as a program if I had knowingly installed it.

I cannot find an entry anywhere in Add or Remove, nor in Revo Uninstaller. According to these two programs, it does not exist, yet there it is, noted in Secunia PSI. No file version or path for it is listed there as well.

Is this program used by PSI to authenticate SSL transmissions when PSI is opened and run as a program window to allow it to communicate to the Secunia server?

I try, as best is possible, to follow best practices when on the internet.

Internet search via Google does not yield information about the file as listed.

Information or assistance will be appreciated.

Thanks

joe schmoe
XP Home Edition SP3, P4 2.8, 2 GB RAM



--
XP Pro SP3 P4 3.2 HT 2 GB RAM Avast! 9.0.2018 AIS
Win 7 Home Pro SP1 Pentium D 2.8 3 GB RAM Avast 9.0.2018 AIS
Secunia PSI 2.0.0.3003 XP Pro 32-bit & Win 7 H Pro 64-bit

throkr RE: Unknown Program: KeePassX 4.x shows installed in PSI
Member 12th Jun, 2011 22:30
Score: 0
Posts: 16
User Since: 1st May 2010
System Score: N/A
Location: BE
Last edited on 12th Jun, 2011 22:33
Hello joe schmoe,

Running PSI version 2.0.0.3003 on Win 7 Pro SP1x64, I have these items detected (patched) :

- C:\Program Files (x86)\Belgium Identity Card\QtCore4.dll, version 4.5.0.0
- C:\Program Files (x86)\HP\Digital Imaging\bin\QtCore4.dll, version 4.1.0.0

The first one comes with an official card reader program delivered by the Belgian Government to enable securised access to different parts of their official websites to authorized citizens; the second one comes with my HP printer software.
I hadn't these items detected earlier on but they obviously came with the very recent updates of both of the a/m programs.

This explains why I didn't react seeing these new entries.

Just wanted to give some other infos .....
Was this reply relevant?
+1
-0
Maurice Joyce RE: Unknown Program: KeePassX 4.x shows installed in PSI
Handling Contributor 13th Jun, 2011 00:46
Score: 11726
Posts: 8,970
User Since: 4th Jan 2009
System Score: N/A
Location: UK
Last edited on 13th Jun, 2011 01:18
Joe,
I think it is mistaken identity by Secunia.

File qtcore.dll is used by many programmes not least by LightScribe,Adobe Photoshop,OVI Nokia & others as U can see from the post above.

Worth a check that is NOT running other than with LightScribe.

Ensure Lightscribe is closed - then CTRL+ALT+DELETE - Look in Task Manager Processes - it should not be running.

For the reasons stated U will not find an entry in Control Panel>add/remove for Keypass or the dll file.

I have got the same issue - at some stage I might bring it to the attention of Secunia Support but I am content they are asset tracking that file although it is incorrectly named but assigned to LightScribe when U check the path.

Edit: I have just checked another PC without Lightscribe - the Keypass entry is NOT picked up by PSI which somewhat proves my point.

--
Maurice

Windows 7 SP1 64 Bit OS
HP Intel Pentium i7
IE 11 for Windows 7 SP1
16GB RAM
Was this reply relevant?
+2
-0
Skeptia-9 RE: Unknown Program: KeePassX 4.x shows installed in PSI
Member 13th Jun, 2011 10:24
Score: 42
Posts: 23
User Since: 15th Mar 2010
System Score: N/A
Location: US
Hello,

Secunia's PSI Tray Version 2.0.0.3003 claims I have 6 instances of KeePassX 4.x installed on my PC. The version detected, found in the table of scan results, is 4.6.3.0.

I do use a password manager, but not the one claimed by the PSI. KeePassX 4.x is not installed on my machine.

The executable identified by the PSI as belonging to KeePassX 4.x is a DLL--namely, QtCore4.dll. I have listed the 6 instances PSI claims are on my machine below. The first 4 are identified as actual installations. The last 2 are zombies, according to PSI.

VirusTotal scores all 6 DLL's as "Goodware." Team Cymru's Malware Hash Registry agrees. And Malwarebytes' gives my computer a clean bill of health.

Investigation of the six instances of QtCore4.dll, which the PSI identified on my local machine, indicates I should delete none of these files.
_______

C:\Program Files\Acronis\TrueImageHome\OnlineBackupStandalone \QtCore4.dll

1766 KB application extension last modified 09 June, 2010

Properties:
Version 4.6.3.0
Description: C++ application development framework
_______

C:\Program Files\Acronis\TrueImageHome\QtCore4.dll

1766 KB application extension last modified 09 June, 2010

Properties:
Version 4.6.3.0
Description: C++ application development framework
_______

C:\Program Files\Amazon\Kindle For PC\QtCore4.dll

2190 KB application extension last modified 15 April, 2011

Properties:
Version 4.7.1.0
Description: C++ application development framework
_______

C:\Program Files\Calibre2\DLLs\QtCore4.dll

2196 KB application extension last modified 11 May, 2011

Properties:
Version 4.7.3.0
Description: C++ application development framework
_______

C:\Program Files\Stellarium\QtCore4.dll

2484 KB application extension last modified 06 December, 2010

Properties:
Version 4.7.1.0
Description: C++ application development framework
_______

C:\Program Files\WinMHR\QtCore4.dll

2097 KB application extrension last modified 08 June, 2010

Properties:
Version 4.6.3.0
Description: C++ application development framework
_______

I am no computer expert. I hope data from my PC will aid someone more knowledgeable in determining what is going on.

Best regards,

Skeptia-9
WinXP Home SP3, 32-bit
PSI Tray Version 2.0.0.3003
Was this reply relevant?
+2
-0
Maurice Joyce RE: Unknown Program: KeePassX 4.x shows installed in PSI
Handling Contributor 13th Jun, 2011 11:19
Score: 11726
Posts: 8,970
User Since: 4th Jan 2009
System Score: N/A
Location: UK
Last edited on 13th Jun, 2011 12:30
@Skeptia-9

U are correct in not removing anything. This is a new issue for me personally & I am in no doubt that Secunia are in error.

I will contact support & ask them to check their database for this file entry.

EDIT: I have contacted Secunia Support & asked them to comment on this thread when time allows.

--
Maurice

Windows 7 SP1 64 Bit OS
HP Intel Pentium i7
IE 11 for Windows 7 SP1
16GB RAM
Was this reply relevant?
+3
-0
ddmarshall RE: Unknown Program: KeePassX 4.x shows installed in PSI
Dedicated Contributor 13th Jun, 2011 12:39
Score: 1208
Posts: 961
User Since: 8th Nov 2008
System Score: 98%
Location: UK
Qtcore4.dll is part of Qt, an Open Source development framework, so it's not surprising it crops up in a lot of products. KeePassX was originally a Linux version of KeePass which now also has a Windows version.
It definitely looks like Secunia have got something wrong.

--
This answer is provided “as-is.” You bear the risk of using it.
Was this reply relevant?
+2
-0
M.Hansen RE: Unknown Program: KeePassX 4.x shows installed in PSI
Secunia Official 14th Jun, 2011 08:28
Score: 188
Posts: 410
User Since: 26th Jan 2009
System Score: N/A
Location: Copenhagen, DK
Hi

Thank you for reporting the issue.

I've updated our rules and KeePassX should no longer be detected in the qt4.dll is on the system.

You might need to perform a full scan in order for the changes to take effect.
joe schmoe RE: Unknown Program: KeePassX 4.x shows installed in PSI
Member 14th Jun, 2011 10:44
Score: 38
Posts: 139
User Since: 26th Nov 2008
System Score: 100%
Location: US
on 14th Jun, 2011 08:28, M.Hansen wrote:
Hi

Thank you for reporting the issue.

I've updated our rules and KeePassX should no longer be detected in the qt4.dll is on the system.

You might need to perform a full scan in order for the changes to take effect.


Mr. Hansen, et al,

The KeePassx 4x entry does not show in Scan Results anymore. I just did a full scan of my system, and poof!

Thanks to everyone for chiming in; we all need the data to be accurate.

joe schmoe

XP Home Edition SP3, P4 2.8, 2GB RAM

--
XP Pro SP3 P4 3.2 HT 2 GB RAM Avast! 9.0.2018 AIS
Win 7 Home Pro SP1 Pentium D 2.8 3 GB RAM Avast 9.0.2018 AIS
Secunia PSI 2.0.0.3003 XP Pro 32-bit & Win 7 H Pro 64-bit
Was this reply relevant?
+0
-0
throkr RE: Unknown Program: KeePassX 4.x shows installed in PSI
Member 14th Jun, 2011 14:13
Score: 0
Posts: 16
User Since: 1st May 2010
System Score: N/A
Location: BE
Hello,

After a full scan, KeepassX 4.x is not showing up anymore in the scan results.

Thanks !
Was this reply relevant?
+0
-0
M.Rehman RE: Unknown Program: KeePassX 4.x shows installed in PSI
Secunia Official 14th Jun, 2011 14:17
Score: 25
Posts: 41
User Since: 12th May 2011
System Score: N/A
Location: Copenhagen, DK
well, it seems everything is as it should be.
I will lock the thread.

--
Kind regards,

Munib Rehman
Secunia Support

Secunia PSI
http://secunia.com/vulnerability_scanning/personal

This thread has been marked as locked.


 Products Solutions Customers Partner Resources Company
 
 Corporate
Vulnerability Intelligence Manager (VIM)
Corporate Software Inspector (CSI)
Consumer
Personal Software Inspector (PSI)
Online Software Inspector (OSI)
 Industry
Compliance
Technology
Integration
 Customers
Testimonials
 VARS
MSSP
Technology Partners
References
 Reports
Webinars
Events
 About us
Careers
Memberships
Newsroom


 
© 2002-2014 Secunia ApS - Rued Langgaards Vej 8, 4th floor, DK-2300 Copenhagen, Denmark - +45 7020 5144
Terms & Conditions and Copyright - Privacy - Report Vulnerability