False positive uniextract.exe

Discussion in 'ESET NOD32 Antivirus' started by Fidelius, Feb 26, 2009.

Thread Status:
Not open for further replies.
  1. Fidelius

    Fidelius Registered Member

    Joined:
    Oct 2, 2006
    Posts:
    146
    Today, Nod32 v3.0.669 (def 3893) found that the file UniExtract.exe was infected by the worm Win32/Sohanad.NCB. It comes from ht tp://legroom.net/software/uniextract and I think this is a FP.
    However, when I restore it from quarantine, it is put at once in quarantine by the real time protection. I wish to analyze it by virustotal but I can't.
     
    Last edited by a moderator: Feb 26, 2009
  2. proactivelover

    proactivelover Registered Member

    Joined:
    Apr 7, 2006
    Posts:
    840
    Location:
    Near Wilders Forums
  3. Fidelius

    Fidelius Registered Member

    Joined:
    Oct 2, 2006
    Posts:
    146
    Thank you. The update 3894 fixes this FP.
     
Thread Status:
Not open for further replies.