FDM unins000.exe detected as trojan - False Positive

Discussion in 'ESET NOD32 Antivirus' started by GreenWhite, Nov 9, 2008.

Thread Status:
Not open for further replies.
  1. GreenWhite

    GreenWhite Registered Member

    Joined:
    Nov 23, 2004
    Posts:
    110
    Just want to inform that Free Download Manager ( FDM ) unins000.exe has been detected as a win32/trojan downloader/agent trojan. I highly think its a false positive.
     
  2. proactivelover

    proactivelover Registered Member

    Joined:
    Apr 7, 2006
    Posts:
    840
    Location:
    Near Wilders Forums
    i have sent unins000.exe to eset lab they will fix this FP
    C:\Program Files\Your Uninstaller 2008\unins000.exe - probably a variant of Win32/TrojanDownloader.Agent trojan
    C:\Program Files\Go Go Gourmet Chef Of The Year\ReflexiveArcade\unins000.exe - probably a variant of Win32/TrojanDownloader.Agent trojan
     
  3. DooGie

    DooGie Registered Member

    Joined:
    Jul 1, 2006
    Posts:
    112
    I got 4 false positives this morning all related to uninstaller files.
    C:\Andy\CD Stuff\nLite\unins000.exe - probably a variant of Win32/TrojanDownloader.Agent trojan
    C:\Andy\Registry\Registrar Registry Manager\unins000.exe - probably a variant of Win32/TrojanDownloader.Agent trojan
    C:\Andy\Utilities\Driver Sweeper\unins000.exe - probably a variant of Win32/TrojanDownloader.Agent trojan
    C:\Andy\Diagnostics\PhysX_FluidMark_v1.0.0\unins000.exe - probably a variant of Win32/TrojanDownloader.Agent trojan
    A bad definition update I feel.
     
    Last edited: Nov 9, 2008
  4. auchkoenig

    auchkoenig Registered Member

    Joined:
    Nov 17, 2006
    Posts:
    3
    I have the same fp too. Here is the log

    9/11/2008 8:45:29 PM Real-time file system protection file C:\Program Files (x86)\Driver Sweeper\unins000.exe probably a variant of Win32/TrojanDownloader.Agent trojan unable to clean Event occurred during an attempt to access the file by the application: C:\Program Files (x86)\WinRAR\RarExtLoader.exe.

    9/11/2008 7:38:49 PM Real-time file system protection file C:\Program Files (x86)\oZone3D\Benchmarks\FurMark_v1.4.0\unins000.exe probably a variant of Win32/TrojanDownloader.Agent trojan unable to clean Event occurred during an attempt to access the file by the application: C:\Program Files (x86)\Symantec\Norton AntiBot\agent\Bin\NABAgent.exe.
     
  5. Gene Benson

    Gene Benson Registered Member

    Joined:
    Apr 19, 2003
    Posts:
    26
    D:\Program Files\MailWasher Pro\unins000.exe - probably a variant of Win32/TrojanDownloader.Agent trojan - cleaned by deleting - quarantined [1]

    Got this yesterday. I'm sure it's a fp as well.
     
  6. proactivelover

    proactivelover Registered Member

    Joined:
    Apr 7, 2006
    Posts:
    840
    Location:
    Near Wilders Forums
    FP is fix in letest update 3598
     
  7. Gene Benson

    Gene Benson Registered Member

    Joined:
    Apr 19, 2003
    Posts:
    26
    Confirmed.

    D:\Program Files\MailWasher Pro\unins000.exe - probably a variant of Win32/TrojanDownloader.Agent trojan - cleaned by deleting - quarantined [1]

    Scanned today and not a peep from Nod. Nice work Eset.
     
Thread Status:
Not open for further replies.