I'm getting a false positive on the main executable for "Call of Duty 4: Modern Warfare" (the original Modern Warfare "1," not the new one.) The file is iw3sp.exe, and the detection is "Trojan-Spy.Win32.KeyLogger.cxh." 3 other engines on VirusTotal.com list similar results, but there is consensus on the web that these are false positives (the MD5 checksum confirms that this is the "real" file.) This is one of the main files for "Call of Duty 4: Modern Warfare" (the original "Modern Warfare") -- the game cannot work without this file. I am NOT using a crack -- COD4: MW was installed via a purchased CD.
I sent the file to newvirus at Kaspersky dot com as per the instructions here, but the problem is that I cannot get ZAES to ignore the file during an On-demand scan. I added it to the exception list in both categories -- both the "On Access scan" and the "Trusted Process." I also removed it from the "target" list. This prevented it from being quarantined by simply looking at it, but it continues to be quarantined during on-demand scans. Am I missing something about excluding the file from scans? Is ZAES not able to exclude files from On-Demand scans like it can with On-Access scans? Or... is this actually malware disguised as the MW exe file? This seems unlikely given the other reactions on the web, as well as the low virustotal report (4 of 41), but I have no way to tell for sure.
Note that unlike some other files, this one does not give me the post-scan option to "ignore always." ZAES simply quarantines it without asking.