It's doing so because they classify it as a PUP. The VirusTotal scan shows that F-Secure/WithSecure identifies it as PotentialRisk.PUA/KerishDoctor.A. This is nothing to worry about as, PUPs/PUAs and Kerish PC Doctor specifically, are not malicious.f-secure blocked "AppData\Local\Temp\is-DF1SS.tmp" and "AppData\Local\Temp\is-HKMQ7.tmp" when installing Kerish Doctor.