Sign in to follow this  
BWarriner

FraudTool.Win32.AVSoft(v) - ERDNT.exe Fals Positive?

Recommended Posts

The latest build (11614?) caught this .exe which I believe is part of the ERUNT backup registry tool.

Skipped items:
Description: c:\windows\erdnt\4-5-2011\erdnt.exe Family Name: FraudTool.Win32.AVSoft (v) Engine: 3 Clean status: Success Item ID: 1 Family ID: 0 MD5: 89afdd29832aa923926bdd4b5f5243d5

Share this post


Link to post
Share on other sites
Hi akcan,

Many files can be reported as FraudTool.Win32.AVSoft(v) and only a few are false positives. Please, follow the guide http://www.lavasoftsupport.com/index.php?showtopic=18033 to give Lavasoft all the information they need to be able to investigate if it is a false positive in your case.

Share this post


Link to post
Share on other sites
HI!
Unfortunately i have already removed the file. It seems to be rather complicated to send the information to Lavasoft.
Why not just dubbelclic the Ad-Awareicon on the clipboard and then go to "quarantine"?

Share this post


Link to post
Share on other sites
[quote name='BWarriner' timestamp='1331057680' post='133484']
Cecilia, can you respond to my original query please?
[/quote]Sorry BWarriner, I don't do malware research. I have not seen LS Andy in the forum this week, he probably has missed your post and I will send him an email.

Share this post


Link to post
Share on other sites
Hi BWarriner,

Thanks for your report. This was a false positive and will no longer be detected by Ad-Aware. Please update your definition file.

Regards,

Andy
Lavasoft Malware Labs

Share this post


Link to post
Share on other sites
Sign in to follow this