There really have been some weird detections with Kelihos-S with multiple files, especially when they are detections in memory.
I feel I have been banging my head against a brick wall in trying to report this to support, but they just keep asking for samples, despite telling them they are detections in memory, so you can't send memory blocks for analysis. Made worse when the file on the hard disk isn't detected.
The problem being I'm using the conventional email reporting of a false positive without an attachment, and they insist they need an attachment/sample in order to be able to analyse it, colour me totally frustrated in trying to resolve this.
So save all the grief and don't scan memory.