Reason core security is treated as virus by eset?

roger_m

Level 41
Verified
Top Poster
Content Creator
Dec 4, 2014
3,029
It is being detecting as a potentially unwanted program or PUP, not a virus. ByteFence is a rebrand of Reason Core Security, with a different UI. Unlike Reason it is only available as a paid product. Several scanners detect ByteFence as a PUP because it sometimes come bundled as an unwanted extra with other software.

If you contact ESET they should be able to remove the false positive, so that they continue to detect ByteFence, but no longer detect Reason.
 

budda

Level 2
Thread author
Verified
Feb 13, 2013
89
It is being detecting as a potentially unwanted program or PUP, not a virus. ByteFence is a rebrand of Reason Core Security, with a different UI. Unlike Reason it is only available as a paid product. Several scanners detect ByteFence as a PUP because it sometimes come bundled as an unwanted extra with other software.

If you contact ESET they should be able to remove the false positive, so that they continue to detect ByteFence, but no longer detect Reason.

There is a comment in virus total which raises alarm
Malware adware download setup hXXps://cdn.reasonsecurity.com/resources/installers/reason-core-security-setup_iot.exe

MORE INFO in: Free Automated Malware Analysis Service - powered by Falcon Sandbox - Viewing online file analysis results for 'reason-core-security-setup_iot.exe'

I opened it and found this
Risk Assessment
Remote Access
Contains a remote desktop related string
Reads terminal service related keys (often RDP related)
Spyware
Contains ability to open the clipboard
Contains ability to retrieve keyboard strokes
POSTs files to a webserver
Persistence
Spawns a lot of processes
Writes data to a remote process
Fingerprint
Reads the active computer name
Reads the cryptographic machine GUID
Reads the system/video BIOS version
Reads the windows installation date
Evasive
Possibly checks for the presence of an Antivirus engine
References security related windows services
Tries to sleep for a long time (more than two minutes)
Spreading
Opens the MountPointManager (often used to detect additional infection locations)
Network Behavior
Contacts 10 domains and 8 hosts. View the network section for more details.

so is it a false positive? Can i install it back? I remembered what happened to cc cleaner before so uninstalled it.
 

roger_m

Level 41
Verified
Top Poster
Content Creator
Dec 4, 2014
3,029
Reason's IOT is a different product. But, I'm sure it is safe. That analysis is not saying specifically that it is malicious, it's an overview of some of the things it does. Reason is a trustworthy company.

Edit, it is the usual installer for Reason Core Security. But I'm sure its safe.
 

Atlas147

Level 30
Verified
Honorary Member
Top Poster
Content Creator
Well-known
Jul 28, 2014
1,990
The detection reads as a PUP (potentially unwanted program), which doesn't necessarily mean that it will do your computer harm, just that it might bring you some annoyance if you don't actually mean to install it.

It has been a debate on how to decide if a program is PUP or not, and there are some companies who are sueing because their program got sorted as a PUP (eg Enigma Sues Malwarebytes After PUP Accusations)

For me personally if the detection shows a PUP I would proceed with caution and read every pop up before I click continue or accept. But if the program is as advertised then there is nothing wrong with it. The only thing to look out for is when the installer wants to install other crap on your system like downloadDOTcom does for most of their installers.
 

spaceoctopus

Level 16
Verified
Top Poster
Content Creator
Well-known
Jul 13, 2014
766
At the time i was using Panda IS (last year), when downloading Reason Core Security, Panda always blocked some suspicious links in the background:unsure:
 

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top