Devinco
July 26th, 2004, 05:14 PM
Hi Everyone,
I'm a proud new licensee of NOD32 for one of my systems.
So far it seems to be working well, except for a couple of problems.
I have the new beta version 2.011 and configured as per BlackSpear's excellent extra settings thread. I also have Insight Software Solutions Macro Express 3 (http://www.macros.com/) (a useful macro utility).
MacroExpress3 has a resident component (MacExp.exe) that NOD32 flags with the following message at boot:
D:\Program Files\Macro Express3\MacExp.exe is infected with probably unknown NewHeur_PE virus. Details merely say probably unknown NewHeur_PE virus.
I also get a message like this:
NewHeur_PE virus found in operating memory. Suggested action is deletion as the file most probably consists only of viral code (if not applicable, choose leave or terminate) No action can be taken on a memory infiltration.
I am a licensee for MacroExpress3 and I also scanned it (prior to NOD32 installation) with NAV2003 and TDS-3 (latest sigs) so I am pretty sure it is not viral.
I added the whole directory D:\Program Files\Macro Express3 (including parsing subdir) to exclusion list in AMON, but still it pops up.
I looked in the NOD32 on demand scanner as well, but there is no exclusion list there.
I understand that if the heuristics thinks it walks like a duck and quacks like a duck, it must be a duck, but this is just a macro utility.
How can I resolve this possible "false positive"?
Also, the alert said "No action can be taken on a memory infiltration".
Why can't NOD32 take any action? Isn't that part of its job?
Thank you
I'm a proud new licensee of NOD32 for one of my systems.
So far it seems to be working well, except for a couple of problems.
I have the new beta version 2.011 and configured as per BlackSpear's excellent extra settings thread. I also have Insight Software Solutions Macro Express 3 (http://www.macros.com/) (a useful macro utility).
MacroExpress3 has a resident component (MacExp.exe) that NOD32 flags with the following message at boot:
D:\Program Files\Macro Express3\MacExp.exe is infected with probably unknown NewHeur_PE virus. Details merely say probably unknown NewHeur_PE virus.
I also get a message like this:
NewHeur_PE virus found in operating memory. Suggested action is deletion as the file most probably consists only of viral code (if not applicable, choose leave or terminate) No action can be taken on a memory infiltration.
I am a licensee for MacroExpress3 and I also scanned it (prior to NOD32 installation) with NAV2003 and TDS-3 (latest sigs) so I am pretty sure it is not viral.
I added the whole directory D:\Program Files\Macro Express3 (including parsing subdir) to exclusion list in AMON, but still it pops up.
I looked in the NOD32 on demand scanner as well, but there is no exclusion list there.
I understand that if the heuristics thinks it walks like a duck and quacks like a duck, it must be a duck, but this is just a macro utility.
How can I resolve this possible "false positive"?
Also, the alert said "No action can be taken on a memory infiltration".
Why can't NOD32 take any action? Isn't that part of its job?
Thank you