Lots of FPs lately with WSA

Discussion in 'Prevx Releases' started by kdcdq, May 28, 2013.

Thread Status:
Not open for further replies.
  1. kdcdq

    kdcdq Registered Member

    Joined:
    Apr 19, 2002
    Posts:
    815
    Location:
    A Non-Sh*thole State
    Are other people seeing and/or reporting the same thing I am: I have gotten several FPs from WSA in the last couple of weeks on downloads of current programs recently. The FPs occurred on the latest WinZip installer, SUMO installer, BullGuard IS installer, and several less-well-known program installers.

    Inquiring minds want to know.... :cautious:
     
  2. Triple Helix

    Triple Helix Specialist

    Joined:
    Nov 20, 2004
    Posts:
    13,275
    Location:
    Ontario, Canada
    Not here and I have my settings to Max and I have been running the latest WinZip for awhile and all of there files are marked good in my scan log. I would suggest that you Submit a Support Ticket and then they can have a look at your logs.

    TH
     

    Attached Files:

  3. PrevxHelp

    PrevxHelp Former Prevx Moderator

    Joined:
    Sep 14, 2008
    Posts:
    8,242
    Location:
    USA/UK
    One possibility could be a file infector. I would definitely suggest writing into Support to ensure they can take a look at your logs and see if anything is going wrong there.

    Thanks!
     
  4. trjam

    trjam Registered Member

    Joined:
    Aug 18, 2006
    Posts:
    9,102
    Location:
    North Carolina USA
    trust me, if there was a FP issue, I would be yelling the loudest of all. I have had no issues with FPs since I can honestly remember.
     
  5. hogndog

    hogndog Registered Member

    Joined:
    Jun 9, 2007
    Posts:
    632
    Location:
    In His Service
    Could be something interfering with the scanner, are you running any other security applications?
     
  6. PC_Fiddler

    PC_Fiddler Registered Member

    Joined:
    Aug 18, 2012
    Posts:
    167
    Location:
    Yorkshire - UK
    Regarding the Sumo installer: It does add potentially unwanted add-ons though I find it an excellent update program - You can use the version that's basically portable by using the 'zip' icon on the download page, this doesn't install any add-ons but still adds info into the 'C:\ Users' folder so remembers any ignores etc. To update simply delete the Sumo folder & add the new unzipped one (don't know if this is any help or just ramblings) :D
     
  7. kdcdq

    kdcdq Registered Member

    Joined:
    Apr 19, 2002
    Posts:
    815
    Location:
    A Non-Sh*thole State
    Thanks for the suggestions, especially from TH and Joe; looks like it's just me and that is a good thing. :thumb:

    The only additional security I am running besides WSA is Privatefirewall, but I have been running this combo for at least a year now. I have scanned this system with HMP and MBAM; both show no malware found.

    When I have a few minutes, I will open a support ticket and send the fine folks at Webroot my logs.
     
  8. TonyW

    TonyW Registered Member

    Joined:
    Oct 12, 2005
    Posts:
    2,741
    Location:
    UK
    Even easier than that - download the lite version to the right of the zipped installer. The sumo_lite.exe doesn't contain the RK bundle.
     
  9. zfactor

    zfactor Registered Member

    Joined:
    Mar 10, 2005
    Posts:
    6,102
    Location:
    on my zx10-r
    yup no fp's here.. well on a rare occasion and ill submit those. but overall i dont usually see them.
     
  10. Kyle_Katarn

    Kyle_Katarn Developer

    Joined:
    Dec 20, 2007
    Posts:
    3,331
    ... or use NoRK / Lite installers : -http://www.kcsoftwares.com/?download
     
    Last edited by a moderator: Jun 10, 2013
  11. Rompin Raider

    Rompin Raider Registered Member

    Joined:
    May 6, 2010
    Posts:
    1,254
    Location:
    Texas
    No FP's either...feel like the Maytag service man....boring. Maybe trjam could recommend a few sites to get some activity!:argh:
     
  12. BoerenkoolMetWorst

    BoerenkoolMetWorst Registered Member

    Joined:
    Dec 22, 2009
    Posts:
    4,872
    Location:
    Outer space
    Not much FP's here, but I find the URL scanner a bit trigger-happy.
    Btw, Webroot just give a warning on the URL(contains malicious content) provided by Kyle.
     
  13. Triple Helix

    Triple Helix Specialist

    Joined:
    Nov 20, 2004
    Posts:
    13,275
    Location:
    Ontario, Canada
    Yes Kyle's link does show a Web Threat warning info below: Also VT shows 4/39.

    TH

    Capture10-06-2013-11.43.17 AM.jpg

    Capture10-06-2013-11.45.39 AM.jpg
     
  14. TonyW

    TonyW Registered Member

    Joined:
    Oct 12, 2005
    Posts:
    2,741
    Location:
    UK
    The reason those few scanners are showing detections for that installer is the association with Relevant Knowledge. However, that is a topic to debate elsewhere. :)
     
Thread Status:
Not open for further replies.
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.