Skip to main content
Solved

False Positive : KCSoftwares products (AudioGrail, RAMExpert,...)

  • November 28, 2013
  • 13 replies
  • 112 views

Hello,
 
Software from KC Softwares are tagged as threat.
This is a blatant false positive warning.
Please confirm immediate removal from your blacklist.
 
 http://s28.postimg.org/b8zmzrodp/threats.png
Thanks

Best answer by amcneil

Those appear to be heuristic detections and not detections in within the Webroot Threat Intelligence Network.
 
I've quickly researched your application and see your installer drops known PUA applications and has historically installed Relevant Knowledge along-side the application.  It's possible that because of this the installer is being flagged via internal checks.
 
Considering that both the paid and free application are being flagged, and considering that we already block both the PowerPack and RelevantKnowledge installers, I don't see any issue with whitelisting your main .exe files.
 
Be cautious of bundling applications with your software.  The tactics of some vendors could possibly lead to your software being flagged in the future.
 
Happy Thanksgiving!

13 replies

shorTcircuiT
Gold VIP
  • Gold VIP
  • November 28, 2013
Hello Kyle_Katarn and welcome to the Webroot Community.
 
The correct way to request reclassification and whitelisting of an item is by submitting a Trouble Ticket.  The Webroot staff that man the Community here officially are off for the U.S. Thanksgiving holiday and will not return until Monday.  The Support Staff, to which Trouble Tickets are delivered, remain at work 24/7 during this time and so your request will be acted on much quicker when submitted in the correct manner.
 
Thank you!

  • Author
  • New Voice
  • November 28, 2013
Done !
Thanks !

DAGOLAG
Gold VIP
Forum|alt.badge.img+57
  • Gold VIP
  • November 28, 2013
Are you the Vendor? If you are you could be a little nicer about it IMHO.
 
TH

Dermot7
Gold VIP
Forum|alt.badge.img+3
  • Gold VIP
  • November 29, 2013
It may be that these softwares are being detected as PUAs. Do they have anything else bundled in the installers, which could be classified as adware?
I noticed on the KC Softwares site: "May contain sponsors like Relevant Knowledge and/or PowerPack".  
 

shorTcircuiT
Gold VIP
  • Gold VIP
  • November 29, 2013
@ wrote:
It may be that these softwares are being detected as PUAs. Do they have anything else bundled in the installers, which could be classified as adware?
I noticed on the KC Softwares site: "May contain sponsors like Relevant Knowledge and/or PowerPack".  
 
Yes, I think you have hit on it.  TripleHelix and I were discussing that earlier actually.  WSA, while historically does not detect PUA's, is beginning to.  It will be interesting to see what the Webroot team will decide following a review.
 
Kyle_Katarn, you will have a much better chance of not having any issues if you did not have the 'piggy back' items included in the installers.  Again, WSA has historically not flagged such software, but they are starting to.  Many other AV vendors also detect such items more and more as well.

DAGOLAG
Gold VIP
Forum|alt.badge.img+57
  • Gold VIP
  • November 29, 2013
It's possible they have installers with "Sponsors" in other words Adware or PUA's. But they do have installers without PUA's. So be carefull which installer you choose if anyone uses these Apps.
 
Daniel
 
http://www.kcsoftwares.com/?download
 
 


 
Power Pack: http://www.softpublisher.com/
 


 
Relevant Knowledge: http://www.relevantknowledge.com/RKPrivacy.aspx
 


shorTcircuiT
Gold VIP
  • Gold VIP
  • November 29, 2013
I would be curious to know if all installers/versions are being detected, or only the ones that contain the PUA's, and even if the detection was a combination of PUA detection as well as FP on the software that was the intended install.

DAGOLAG
Gold VIP
Forum|alt.badge.img+57
  • Gold VIP
  • November 29, 2013
I'm sure one of the Threat Researchers will chime in!
 
Daniel 😉

  • Author
  • New Voice
  • November 29, 2013
Hi

Thank you for these answers. it seems that it is done the wrong way since it detect my main exe file.as a threat even if coming from sponsor free installer or portable version

Yes I am the developper of these software, this is obviously worth to be mentioned 🙂

  • Retired Webrooter
  • Answer
  • November 29, 2013
Those appear to be heuristic detections and not detections in within the Webroot Threat Intelligence Network.
 
I've quickly researched your application and see your installer drops known PUA applications and has historically installed Relevant Knowledge along-side the application.  It's possible that because of this the installer is being flagged via internal checks.
 
Considering that both the paid and free application are being flagged, and considering that we already block both the PowerPack and RelevantKnowledge installers, I don't see any issue with whitelisting your main .exe files.
 
Be cautious of bundling applications with your software.  The tactics of some vendors could possibly lead to your software being flagged in the future.
 
Happy Thanksgiving!

  • Author
  • New Voice
  • November 29, 2013
Thank you !

When will white listing be effective ?
Happy Thanksgiving !

  • Retired Webrooter
  • November 29, 2013
Should be immediate -- especially since they were heuristic detections.
 
Try to rescan.

  • Author
  • New Voice
  • November 30, 2013
Thank you !