Jump to content

False positive? software RG Supervision, PDM trojan generic.


Recommended Posts

Hello, 

 

I have a customer where we have installed Kaspersky Internet Security on more than 5 laptops, and they all have the same detection of a Trojan. It seems that this file is created by powershell, and comes from the software RG Supervision. So it’s not a virus, but even when I place the folder rgsupv in the exclusion list, it keeps alerting about Powershell creating a file (test.ps1)

How can I tell the software it’s not a virus ? 

Thanks for your help. 

 

Link to comment
Share on other sites

@Gemini2039 Welcome.

Please submit the object here https://opentip.kaspersky.com/  and request a reanalyze.
 

 

 

 

Also : ⚠ ​ Only if you trust the object  ⚠

Link to comment
Share on other sites

Hello,

Does this powershell script have a remote download file api (.DownloadFile() ) or network connect api ( .connect() ) or have a  sleep process (Start-Sleep -m $sleep;) or bypass uac script  (Start-Process -WindowStyle hidden -FilePath ‘eventvwr.exe’;) ?

if you have or you don’t know which script trigger PDM detection. You should follow @Berny advice, or you recommand your user add a exclusion rule for your powsershell script.

Regards.

Link to comment
Share on other sites

  • 1 month later...
Guest
This topic is now closed to further replies.


×
×
  • Create New...