PDA

View Full Version : FDM unins000.exe detected as trojan - False Positive


GreenWhite
November 9th, 2008, 01:08 AM
Just want to inform that Free Download Manager ( FDM ) unins000.exe has been detected as a win32/trojan downloader/agent trojan. I highly think its a false positive.

proactivelover
November 9th, 2008, 09:49 AM
i have sent unins000.exe to eset lab they will fix this FP
C:\Program Files\Your Uninstaller 2008\unins000.exe - probably a variant of Win32/TrojanDownloader.Agent trojan
C:\Program Files\Go Go Gourmet Chef Of The Year\ReflexiveArcade\unins000.exe - probably a variant of Win32/TrojanDownloader.Agent trojan

DooGie
November 9th, 2008, 01:24 PM
I got 4 false positives this morning all related to uninstaller files.
C:\Andy\CD Stuff\nLite\unins000.exe - probably a variant of Win32/TrojanDownloader.Agent trojan
C:\Andy\Registry\Registrar Registry Manager\unins000.exe - probably a variant of Win32/TrojanDownloader.Agent trojan
C:\Andy\Utilities\Driver Sweeper\unins000.exe - probably a variant of Win32/TrojanDownloader.Agent trojan
C:\Andy\Diagnostics\PhysX_FluidMark_v1.0.0\unins000.exe - probably a variant of Win32/TrojanDownloader.Agent trojan
A bad definition update I feel.

auchkoenig
November 9th, 2008, 02:47 PM
I have the same fp too. Here is the log

9/11/2008 8:45:29 PM Real-time file system protection file C:\Program Files (x86)\Driver Sweeper\unins000.exe probably a variant of Win32/TrojanDownloader.Agent trojan unable to clean Event occurred during an attempt to access the file by the application: C:\Program Files (x86)\WinRAR\RarExtLoader.exe.

9/11/2008 7:38:49 PM Real-time file system protection file C:\Program Files (x86)\oZone3D\Benchmarks\FurMark_v1.4.0\unins000.exe probably a variant of Win32/TrojanDownloader.Agent trojan unable to clean Event occurred during an attempt to access the file by the application: C:\Program Files (x86)\Symantec\Norton AntiBot\agent\Bin\NABAgent.exe.

Gene Benson
November 9th, 2008, 09:38 PM
D:\Program Files\MailWasher Pro\unins000.exe - probably a variant of Win32/TrojanDownloader.Agent trojan - cleaned by deleting - quarantined [1]

Got this yesterday. I'm sure it's a fp as well.

proactivelover
November 9th, 2008, 11:52 PM
FP is fix in letest update 3598

Gene Benson
November 10th, 2008, 09:47 PM
{QUOTE-> FP is fix in letest update 3598 <-QUOTE}
Confirmed.

D:\Program Files\MailWasher Pro\unins000.exe - probably a variant of Win32/TrojanDownloader.Agent trojan - cleaned by deleting - quarantined [1]

Scanned today and not a peep from Nod. Nice work Eset.