When I create a winrar sfx, it's being detected by nod32.
Looks like no matter, if i Use %appdata%, or %userprofile%, or %temp%, or whatever, it's being detected.
with %temp% it's being detected as: RAR/Agent.L trojan
and with %appdata%: RAR/Agent.O trojan
the settings are:
;The comment below contains SFX script commands
Path=%appdata%\settings
Setup=apply.vbs
Silent=1
Overwrite=2