Status: Fixed
Summary
On 9 October 2026, WithSecure Elements Endpoint Protection and the Business Suite products Client Security and Server Security began detecting the file msp-ufa-tppatch-install.exe as malicious (HEUR/APC.misc). The product blocks and disinfects the file, and then prompts the user to restart the computer.
Details
- The file is an update installer for N-able N-sight.
- WithSecure Labs is analyzing the file as a top priority to determine whether this detection is a false positive.
- Because of the type of detection, it is not possible to create an exclusion for this file.
Resolution:
WithSecure Labs analysis of the file is complete and the file was determined to be clean. The rating for the file has been updated and the file will no longer be detected as malicious. We apologize for the inconvenience may have caused.