Kaspersky
Question

False Positive on https://inkforall.com (Windows)

  • 24 January 2021
  • 10 replies
  • 92 views

App from hxxps.//inkforall.com is wrongly flagged by heuristic to contain malware.

HEUR:Trojan.Win32.Silence.gen

 

The submission tool does not work - it says Error: an error occured while sending the object for re-validation. Please try again later.

https://opentip.kaspersky.com/99BCEF2C3E25AE97F6385012E48AF11503B50AB5DF1D0EBBD08D8FCBEED1B3AA/

 

 


10 replies

Userlevel 7
Badge +9

Hello @adridder,

Welcome!

  • If you have a Kaspersky software subscription license, log a case with Kaspersky Technical Support, fill in the Malware, False positive template; zip the .exe file, name the zip archive malware, or infected & protect the zip archive with a password, add the zip archive to the request; add the password to the request; in the problem description provide a detailed history; Support may request Logs & or other system data, they will guide you:

 

 

 

  • After submitting the case, you’ll receive an automated email with an INC+12digits reference number, then, normally, within 5 business days, a Kaspersky Technical Support human will be in touch, also by email, you may continue to engage with the Kaspersky Technical Team via email or by updating the INC in your MyKaspersky account.

Please share the outcome with the Community when it’s available? 

Thank you:pray_tone3:

Flood:whale:+:whale2:

Trojan.Win32.Silence.sb

HEUR:Trojan.Win32.Silence.gen

I don’t have a Kaspersky license. This is affecting my customers who have Kaspersky. I’ve exhausted every support channel and have not gotten anywhere.

Userlevel 7
Badge +9

Hello @adridder

You’re most welcome!

  1. Please provide clear information, when the object was scanned using the Kaspersky Threat Intelligence Portal & the result was displayed, what happened next
  2. Please provide screen images? 
  3. Which “Support channels” have you exhausted? 
  • Note, we’ve been to the site & tried to “get” the exe to test, with no success. 

Thank you:pray_tone3:

Flood:whale:+:whale2:

these images came from our users

 

I tried to submit on this site multiple times, also via the contact form. See the error message above.
https://opentip.kaspersky.com

 

I engaged in chat on Facebook and didn’t get help. The chat person keeps assuming I’m a Kaspersky software user and points me in the wrong direction. 

 

I tweeted at your support team, and I sent LinkedIn messages to people @ Kaspersky.

 

 

  • Note, we’ve been to the site & tried to “get” the exe to test, with no success. 

You can bypass the need to create an INK account by downloading our software directly from this link:
 hxxps.//downloads.seo.app/latest/app.html?platform=windows

(note this is our .exe file that Kaspersky flags as a false positive)

 

When the item was scanned by the portal, it said the same thing … the heuristic treated it like malware.

Then when you click the submit to technical review .. button (right side) I type a message with my email and explanation .. hit the send/submit button and then it spins for a while until showing the error message in my previous post.

Userlevel 7
Badge +9

Hello @adridder

Thank you:ok_hand_tone3:

We’ve submitted the file & a case. 

Please wait for the results. 

Thank you:pray_tone3:

Flood:whale:+:whale2:

Userlevel 7
Badge +5

Hi Flood, can you tell me the inc number, thanks.

Userlevel 7
Badge +9

Hi @Igor Kurzin

PM’d.

Thank you:pray_tone3:

Flood:whale:+:whale2:

Userlevel 7
Badge +9

Advice from Kaspersky Lab, Sent: Tuesday, 26 January 2021 14:58

“ Please be advised that we have received an update from Escalations team: 
Sorry, it was a false detection and will be fixed.
Kindly run a database update on your Kaspersky application and check the issue if it will persist. “ 

On behalf of all the INK SEO Copywriting software community, thank you for correcting this.

Reply