accicons.exe

Discussion in 'ESET NOD32 Antivirus' started by fuel666, Apr 19, 2010.

Thread Status:
Not open for further replies.
  1. fuel666

    fuel666 Registered Member

    Joined:
    Apr 19, 2010
    Posts:
    3
    good morning
    Today I encountered the following message:

    C:\WINDOWS\Installer\{90110410-6000-11D3-8CFE-0150048383C9}\accicons.exe contiene probabilmente una variante di Win32/TrojanDownloader.Agent trojan horse.

    but it is no office executable?

    Thank's
     
  2. henktiggelaar

    henktiggelaar Registered Member

    Joined:
    Apr 19, 2010
    Posts:
    8
    I have the same problem since this morning. Getting bombarded with mail alerts like these:

    19-4-2010 10:03:00 - Module Real-time file system protection - Threat Alert triggered on computer FOO: C:\WINDOWS\Installer\{90110413-6000-11D3-8CFE-0150048383C9}\accicons.exe contains probably a variant of Win32/TrojanDownloader.Agent trojan.

    accicons.exe is actually a valid Office 2003 file containing Access icons. Eset, please stop with the false positives, it is becoming annoying.
     
  3. siljaline

    siljaline Former Poster

    Joined:
    Jun 29, 2003
    Posts:
    6,619
    It is in effect a valid Office File as, noted, installed here:
    How to submit to ESET's labs for analysis
     
  4. Marcos

    Marcos Eset Staff Account

    Joined:
    Nov 22, 2002
    Posts:
    14,374
    We're analyzing the file we've received from some of you. The same file we've got here is even whitelisted to prevent it from being detected accidentally.
     
    Last edited: Apr 19, 2010
  5. henktiggelaar

    henktiggelaar Registered Member

    Joined:
    Apr 19, 2010
    Posts:
    8
    I've uploaded the accicons.exe to www.virustotal.com and it definitely is a false positive. My version of accicons.exe is from the dutch version of Office 2003 Pro, SP3 by the way.

    What will Nod32 decide to flag next, ntoskrnl.exe maybe?
     
  6. PhoenixUA

    PhoenixUA Registered Member

    Joined:
    Jul 16, 2008
    Posts:
    13
    +1 with ~70 PCs with false positive detection :mad:
    file sent to samples@eset.com
     
  7. henktiggelaar

    henktiggelaar Registered Member

    Joined:
    Apr 19, 2010
    Posts:
    8
    Fixed here by virus signature database 5041.
     
  8. fuel666

    fuel666 Registered Member

    Joined:
    Apr 19, 2010
    Posts:
    3
    Thanks to everyone for the info

    bye
     
Thread Status:
Not open for further replies.