Autoback.exe, a file contained in the Erunt program.
This file has been deemed safe. It popped up again today when I booted my machine.
Current DB 4942
CIS 4.0.141842.828
Heuristics set on High
WinXP Pro SP3
The password for the .zip file is: infected

Website: http://www.larshederer.homepage.t-online.de/erunt

I submitted it through the online submit page as well.

Hello L.A.R. Grizzly,

Thank you for letting us know about this. We’ll check this and get back to you soon.

This detection seems to come and go. I can go for a month or so without a single warning and then CAV seems to detect it again. It isn’t detected with a manual scan. Curious behavior.

Well, it’s been a couple of days now and the detection of Autoback.exe returned today when I booted my machine! The pop-up alert was the same as mentioned before. ???