PUP Guidelines for Detection in G DATA products

This article explains the rules we use to generate PUP (Possibly Unwanted Program) detections

We publish these guidelines to give our Customers and partners the opportunity to determine whether software should be classified as PUP (Possibly Unwanted Program). The G DATA analysts adhere strictly to these guidelines when they classify software that we analyze at G DATA as PUP.

However, the detection is not limited to individual instances of the software itself; it also includes the behavior of the company behind the software. Using software constitutes a contract between two parties: the user and the software developer/provider/distributor, hereinafter referred to in this document as the distributor.

All software functions require time and money for development, testing, and maintenance.

Therefore, it is highly unlikely that commercial software contains unnecessary functions.

Therefore, it must be assumed that all functions found were added for specific purposes.

Nevertheless, mistakes can happen, but it is expected that they will be Resolved, especially when they disadvantage the user. Repeated "mistakes" to the detriment of users are highly unrealistic.

If software violates one or more of the following rules, classification by G DATA as "potentially unwanted" is very likely. Customers who nevertheless want to continue using such software can do so at any time by disabling the detection of "potentially unwanted programs" in the antivirus suites from G DATA.

Fraud

Defined here as "wrongful or criminal deception with the aim of financial or personal gain". Fraud is always intentional; any type of fraud results in a PUP classification or worse.

Examples of fraudulent software behavior:

  • Pretending to be software or a service from Microsoft or another legitimate provider when this is not the case.

  • Displaying a fake countdown for a fake limited-time offer.

  • Registration that turns out to be a purchase or subscription.

  • Exhibiting different behavior in virtual environments than on real hardware.

  • Fake warnings or pop-ups that are not based on facts.

Misleading information

Defined here as "creating a false idea or a false impression". Misleading the user does not necessarily have to be intentional; it can also be the result of poor wording, for example due to a poor translation. However, if we determine that misleading information is intentional, we classify the software as potentially unwanted.

Intent can be difficult to prove, but some examples where information intended to mislead users can be found include

  • The behavior of the software (it claims to optimize your PC, but does not do so)

  • Dialogs and text in the application’s graphical user interface (GUI) that, for example, conceal the fact that the software collects personal data on a large scale

  • History of the distributor or the software

  • Other software from the same vendor and the website/web shop

  • Campaigns limited to, for example:

    • Time

    • Region

    • Software/hardware environment

Purpose and benefit

The purposes of software can be divided into 2 categories: purpose for the benefit of users and purpose for the benefit of the distributor.

For software to be viable, it must provide a benefit to the user; otherwise, no one is willing to use it. On the other hand, the software must provide some benefit to the distributor; otherwise, developing the software was a waste of time and money. In most cases, the software is intended to generate some form of income.

For a fair contract, the benefits for both parties must be balanced.

However, if the balance shifts too strongly in favor of the distributor, it is more likely that this software is potentially unwanted.

  • Software must provide a benefit to the user.

  • Each function should provide a benefit to the user.

  • If a function does not directly benefit the user, it must be justified in writing.

  • The price the user pays must be clear and must not unfairly disadvantage the user.

Advertising

Offers made by the software during/after installation, runtime, or uninstallation are also considered advertising.

Advertising can be divided into 2 categories:

Advertising that promotes the software/service

  • Affiliate marketing generally promotes the software.

    • It is the responsibility of the distributor to keep partners in line; violations of these guidelines by partners also lead to a "potentially unwanted" assessment for the software developer and distributor.

    • Affiliates cannot be used as an excuse for unwanted installations.

    • Affiliates must not violate any of the advertising rules listed in the section for advertising by the software/services below:

  • Self-promotion in other software from the same provider.

Advertising by the software/service

  • The distributor assumes full responsibility for the advertising displayed to the user.

  • The advertising must comply with the law in the user’s region.

  • The ads must not be fraudulent or misleading.

  • The ads must not be offensive.

  • The ads must not be threatening.

  • The ads must not advertise known potentially unwanted applications.

  • The ads must not impede or disrupt the operation of the computer and/or other software.

  • The advertised software must be installable only with the user’s explicit consent.

Monitoring the system environment

Environment detection can be used legitimately to provide the correct language and the correct files for the operating system.

However, it is often used by potentially unwanted software to determine which objectionable behavior can be performed without being detected. This is equivalent to using a defeat device, as in the Volkswagen diesel emissions scandal. If it is detected that the software is running in a test environment, the software behaves differently than on the PCs of potential Customers.

Examples of detected environments:

  • Virtual machine (VMware, VirtualBox, …​)

  • Antivirus software

  • Antispyware

  • Region (geo-IP, language, time of day, …​)

Examples of differing actions

  • Installing a trial version only on real hardware; installing the full version on virtual machines.

  • Displaying advertising only on real hardware; no display on virtual computers.

  • Installing intrusive browser add-ins or other software modules only on real hardware, not on virtual machines

Installation

There are only very few legitimate use cases for the silent installation features of common installers such as Inno Setup. The most common legitimate case is deployment by a network administrator. In this case, however, the EULA of the software in question must explicitly designate the software as intended for business use.

Most of the time, silent installation features are used so that affiliated companies can install the software without the user’s consent.

  • For trial versions, there are no legitimate use cases for a silent installation.

  • For consumer software, there are generally no legitimate use cases for a silent installation.

  • Silent installation overrides consent to all installation dialogs, the EULA, and the privacy policies. Since these are void, there is no legally valid contract between the user and the distributor.

EULA (End User License Agreement)

The EULA (End User License Agreement) must not contain anything surprising or anything that violates the law of the country in which the software is intended to be used. All surprising or inappropriate items are impermissible. Examples of such items include:

  • Use of fake malware to demonstrate malware detection.

  • Use of cryptocurrency miners.

  • Collection and/or trading of personal data

Anything that provides additional benefits to the distributing party must be explicitly declared outside the EULA during the installation process; see examples above

Privacy policies

Certain principles should be observed for privacy policies.

The privacy policy

  • Must be GDPR/DSGVO-compliant if the software is intended to be used in Europe.

  • Must not contain anything surprising.

  • Must not declare personally identifiable information as "pseudonymous" or "anonymous". The use of personally identifiable information must not be concealed.

All impermissible content must be explicitly stated in the installation dialogs. This means that any additional data collection that is not necessary for the application to function must require opt-in (the user must actively enable it) and must be explained in the installation dialog in such a way that anyone can understand it and the resulting consequences. Examples of data collection that should be properly explained if used:

  • Collection and/or trading of PII (personally identifiable information).

  • Collection and/or sharing of hardware information.

  • Collection and/or trading of information about the use/installation of third-party software.

  • Collection and/or trading of visited web pages.

  • Collection and/or trading of sign-in credentials for third-party services

Trial/full versions

The type of software must be made clear during installation. That means it must be explicitly clarified whether it is a full version or a trial version, which features and functions are provided, and which limitations exist.

Trial versions are not entitled to any form of compensation from the user, except for contact information, and they must not be monetized in any way until the user decides to upgrade to the full version.

Startup

Startup entries must be justified and necessary for the application to function.

Examples of possible startup entries include:

  • Startup

  • Service

  • Scheduled task

Examples of legitimate startup entries include:

  • Running an antivirus service

  • Checking for software updates

Examples of not legitimate startup entries:

  • Driver update scan at every system startup.

  • Multiple scheduled tasks to check the registry cleaner.

  • A service installed for a software downloader.

Runtime

During runtime, software must function as promised in order to meet the user’s expectations and provide a benefit. Any functionality that does not meet these goals must be justified.

Examples of justified distributor benefits:

  • Occasional reminder that the software is in the trial phase.

  • Advertising benefit of the full version.

  • Appropriate display of advertising in ad-supported software.

Examples of not justified distributor benefits:

  • Checking for competing software.

  • Displaying ads for third-party providers or other software from the same provider in the trial version.

  • Advertising other software from the same provider disguised as a feature.

Uninstallation

Uninstallation must be easy to find and perform.

  • It must be complete and must not leave any files, startup entries, or Windows Registry manipulations on the system.

  • The default action for uninstallation must be to uninstall.

  • It must not be more difficult than installation

Website/web shop

The website and/or web shop represent the company and the software. It must be truthful and clear and must not obscure/hide information.

Examples of impermissible website/web shop practices:

  • Displaying a product matrix, but all links to the various products lead to the same product.

  • Using fast countdowns to pressure the Customer.

  • Using fake countdowns.

  • The number of remaining units is fabricated (there is no "limited supply" for software downloads).

  • The countdown stops without the offer period ending.

  • The application is always on sale, or the sales "events" are outdated.

  • Adding other products to the shopping cart by default.

Reputation

The history and reputation of a distribution company and its software can provide insight into the current attitude of the distribution company and the behavior of the software.

Depending on its history, a distributor has a different level of credibility.

A provider gains low credibility by:

  • Being a repeat PUP offender.

  • Feigning ignorance of the PUP criteria.

  • "Testing" new violations.

  • Introducing aggressive partner programs.

  • Prioritizing profit over utility.

  • Using very generic product names that may not even include a permanent company name, or advertising the company name at all with the product.

  • Being described by users as misleading or even fraudulent.

  • Communicating in a harsh, threatening, or offensive manner.

  • Attempting to bypass detection.

  • Pretending to be unaware of basic technologies.

Providers are able to gain high credibility within the industry if they …​

  • have Resolved all PUP violations in the past or have never had PUP violations

  • Prioritize the benefit to the user.

  • Complying with standards of the software industry such as the CSA