Possible false positive on Weather alert app

  • 22 November 2013
  • 10 replies
  • 55 views

Hi,
 
We are facing an issue with one of our client installer.
 
To reproduce the problem, download and install the file from <http://s3.amazonaws.com/severeweatheralerts/swa1_23.exe> 
 
Threat Name: Pua.Search.Results
Your Product details :- Webroot SecureAnywhere
Product version :- 8.0.4.17
 
We have tested it at our end and found nothing malicious either with the file or with the URL.  But  'Pua.Search.Results' threat was detected while downloading the setup, by your product. 
 
Can you please re-investigate and fix this issue.
 
Thank you.

10 replies

Userlevel 7
Hello,
 
Thank you for the information, I have tested the file and have reveresed the determination. Please note a number of vendors mark this file as PUA. I ran the installer and it didnt get any junkware. 
Userlevel 7
Badge +56
Hello @ and Welcome to the Webroot Community Forums.


 
I see that you still have version 8.0.4.17 and the newest build is v8.0.4.24 please see here: https://community.webroot.com/t5/Release-Notes/PC-Release-Notes-8-0-4-24/td-p/64707#.Uo-FcOLZG_o you can Right Click on the Webroot Tray Icon by the Clock and Check for Updates and if it continues to say it's up to date please download the Installer Here and install over top and reboot and you should be all set with v8.0.4.24.
 
Cheers,
 
Daniel ;)
 
 
Hi Rakanisheu,
 
I am still getting the same alert from webroot for this file. I am using the updated version 8.0.4.24.
 
Seeems the detection is still there.
 
Thanks
Sameer
Userlevel 7
That file is good in our database and I have tested it on two PC`s and I am not getting any detection. Are you sure its the same file that you posted in your original post (MD5 -> D18C6EDB768E000117EEEEA3D5FC89BE)?
Hi Rakanisheu,
 
Yes, its the same file with MD5 --> d18c6edb768e000117eeeea3d5fc89be , SHA1--> 775ceb1bd0d24df850773b5b57ea588983aa18d2.
 
We are getting this threat , when we install the file.
 
Can you please check it again.
 
Thanks
Sameer
Userlevel 7
Confirmed its not being detected by our client, right click scan -> File good (See below)
 
[g] c:documents and settingsadministratordesktopswa1_23.exe [MD5: D18C6EDB768E000117EEEEA3D5FC89BE] 
 
I am not sure if you have modified the WSA defaults or have set the file be manually blocked
 
I would advise doing an un/re of WSA to see if it helps.
Hi Rakanisheu,
 
Thanks for your timely response.
 
I am still getting it on my system, can you please let me know, how can i check the file status on my system. 
 
The WSA is having the default setting.
 
Thanks
Sameer 
 
 
Userlevel 7
Hello,
 
Can you right click on the webroot icon down on the your taskbar and select the option "Save a scan log" Save the scan log to your desktop and upload the file to Filedropper (Shown below)
 
1. Visit <a href="http://www.filedropper.com/" target="_blank">www.filedropper.com</a>.
2. Click Upload File.
3. Select the file you want to upload and click Open.
4. After the file has finished uploading, a page appears with a link labeled "Link To Share This File With Anyone". Right-click the link and select Copy.
5. Please paste this link into a message to us. Once you have sent the message, this link will allow Webroot access the file you just uploaded.
 
 
Hi,
 
Please find the details of the scan log : http://www.filedropper.com/webrootscanlog
 
Please do let me know, if you need any other details.
 
Thanks
Sameer
Userlevel 7
Hello,
 
Can you submit a support ticket? One of my colleagues has alerted me to something in regard to the software.

Reply