Was sent a file by a colleague (zipped of course) because his av flagged up a warning, being new to such things he didnt know what to do. I scanned the file with my Nod32 and it found nothing, even unzipped it still failed to find anything wrong. An online scan with Dr Web indicated Win32.HLLM.Sahay, and so did Housecall, and also Kaspersky online. I've read up on it and it seems some sort of 'anti-worm' worm that attacks Yaha infected files (I believe) My question is why wasnt it picked up by Nod32? I have also submitted it to Eset for a proper evaluation.