Install of ADX 904 blocked by Webroot

Add-in Express™ Support Service
That's what is more important than anything else

Install of ADX 904 blocked by Webroot
 
Lars Black




Posts: 8
Joined: 2013-04-10
I am not able to install ADX 904 because Webroot flags is as a W32.Trojan.Gen

I found an old thread about this https://www.add-in-express.com/forum/read.php?FID=5&TID=14961 (from 2018) but it is obviously still a problem.

What are you doing during install that still makes Webroot think ADX is a trojan?

Cheers
Lars
Posted 07 Sep, 2019 18:24:12 Top
Andrei Smolin


Add-in Express team


Posts: 18825
Joined: 2006-05-11
Hello Lars,

Lars Black writes:
What are you doing during install that still makes Webroot think ADX is a trojan?


We suppose this is a WebRoot issue: we do not receive similar reports from other antivirus products.

For me to provide them with detailed info please answer these questions.
What WebRoot version do you use? Is it updated regularly?
What is the exact message?
What is the exact file name blocked?
What is the file name of the .MSI included in the Add-in Express download package?


Andrei Smolin
Add-in Express Team Leader
Posted 09 Sep, 2019 05:17:32 Top
Lars Black




Posts: 8
Joined: 2013-04-10
We use newest Webroot (9.0.26.61) corporate edition with daily updates.

The MSI is adxnet-v904-b4644-vs-pre.msi, dated June 20th

Here is the message from the scan log:
Infection detected: C:\Users\lcb\AppData\Local\Temp\MSIEE78.tmp [SHA256:14FAFBB3BB93803B5E5BDED2A54CB5FEE5665EA460E7E3788B669D3F3E3A2993] [MD5: 24DB1042C57BABF2F7C617C222AB2E91] [3/08081000] [W32.Trojan.Gen]

File blocked in realtime: C:\Users\lcb\AppData\Local\Temp\MSIEE78.tmp [UniqueID: B3FBFA14, MD5: 24DB1042C57BABF2F7C617C222AB2E91, Size: 840256 bytes] [134746112/00000003] [W32.Trojan.Gen]

File blocked in realtime: C:\Users\lcb\AppData\Local\Temp\MSIEE78.tmp [UniqueID: B3FBFA14, MD5: 24DB1042C57BABF2F7C617C222AB2E91, Size: 840256 bytes] [134746112/00000003] [W32.Trojan.Gen]

Determination flags modified: C:\Users\lcb\AppData\Local\Temp\MSIEE78.tmp - UniqueID: B3FBFA14, MD5: 24DB1042C57BABF2F7C617C222AB2E91, Size: 840256 bytes, Flags: 00000020
Posted 09 Sep, 2019 06:19:16 Top
Andrei Smolin


Add-in Express team


Posts: 18825
Joined: 2006-05-11
Hello Lars,

Thank you for this info. It allows us to identify the file that WebRoot marks as a virus: this is ActivateKey.exe; see https://www.virustotal.com/gui/file/14fafbb3bb93803b5e5bded2a54cb5fee5665ea460e7e3788b669d3f3e3a2993/detection. I will contact them and ask them to confirm that the issue is a false positive. Will post their response here.


Andrei Smolin
Add-in Express Team Leader
Posted 09 Sep, 2019 08:10:40 Top
Andrei Smolin


Add-in Express team


Posts: 18825
Joined: 2006-05-11
Hello Lars,

I've submitted the file to http://snup.webrootcloudav.com/SkyStoreFileUploader/upload.aspx#file and found that they won't let me know about their results.


Andrei Smolin
Add-in Express Team Leader
Posted 09 Sep, 2019 08:17:44 Top