Solved

False Positive : KCSoftwares products (AudioGrail, RAMExpert,...)

  • 28 November 2013
  • 13 replies
  • 85 views

Hello,
 
Software from KC Softwares are tagged as threat.
This is a blatant false positive warning.
Please confirm immediate removal from your blacklist.
 
 http://s28.postimg.org/b8zmzrodp/threats.png
Thanks
icon

Best answer by amcneil 29 November 2013, 07:05

View original

13 replies

Userlevel 7
Hello Kyle_Katarn and welcome to the Webroot Community.
 
The correct way to request reclassification and whitelisting of an item is by submitting a Trouble Ticket.  The Webroot staff that man the Community here officially are off for the U.S. Thanksgiving holiday and will not return until Monday.  The Support Staff, to which Trouble Tickets are delivered, remain at work 24/7 during this time and so your request will be acted on much quicker when submitted in the correct manner.
 
Thank you!
Done !
Thanks !
Userlevel 7
Badge +56
Are you the Vendor? If you are you could be a little nicer about it IMHO.
 
TH
Userlevel 7
Badge +3
It may be that these softwares are being detected as PUAs. Do they have anything else bundled in the installers, which could be classified as adware?
I noticed on the KC Softwares site: "May contain sponsors like Relevant Knowledge and/or PowerPack".  
 
Userlevel 7
@ wrote:
It may be that these softwares are being detected as PUAs. Do they have anything else bundled in the installers, which could be classified as adware?
I noticed on the KC Softwares site: "May contain sponsors like Relevant Knowledge and/or PowerPack".  
 
Yes, I think you have hit on it.  TripleHelix and I were discussing that earlier actually.  WSA, while historically does not detect PUA's, is beginning to.  It will be interesting to see what the Webroot team will decide following a review.
 
Kyle_Katarn, you will have a much better chance of not having any issues if you did not have the 'piggy back' items included in the installers.  Again, WSA has historically not flagged such software, but they are starting to.  Many other AV vendors also detect such items more and more as well.
Userlevel 7
Badge +56
It's possible they have installers with "Sponsors" in other words Adware or PUA's. But they do have installers without PUA's. So be carefull which installer you choose if anyone uses these Apps.
 
Daniel
 
http://www.kcsoftwares.com/?download
 
 


 
Power Pack: http://www.softpublisher.com/
 


 
Relevant Knowledge: http://www.relevantknowledge.com/RKPrivacy.aspx
 

Userlevel 7
I would be curious to know if all installers/versions are being detected, or only the ones that contain the PUA's, and even if the detection was a combination of PUA detection as well as FP on the software that was the intended install.
Userlevel 7
Badge +56
I'm sure one of the Threat Researchers will chime in!
 
Daniel 😉
Hi

Thank you for these answers. it seems that it is done the wrong way since it detect my main exe file.as a threat even if coming from sponsor free installer or portable version

Yes I am the developper of these software, this is obviously worth to be mentioned 🙂
Userlevel 2
Those appear to be heuristic detections and not detections in within the Webroot Threat Intelligence Network.
 
I've quickly researched your application and see your installer drops known PUA applications and has historically installed Relevant Knowledge along-side the application.  It's possible that because of this the installer is being flagged via internal checks.
 
Considering that both the paid and free application are being flagged, and considering that we already block both the PowerPack and RelevantKnowledge installers, I don't see any issue with whitelisting your main .exe files.
 
Be cautious of bundling applications with your software.  The tactics of some vendors could possibly lead to your software being flagged in the future.
 
Happy Thanksgiving!
Thank you !

When will white listing be effective ?
Happy Thanksgiving !
Userlevel 2
Should be immediate -- especially since they were heuristic detections.
 
Try to rescan.
Thank you !

Reply