Virus detection (False?)

Recently trying to load my old Accounting package NIS found 4 copies of

 

 "Threat name: W95.CIH.remnants

Full Path: e:\util\atc\internet banking\demo32.exe"

 

This software is on a read only CD.

 

I deleted NIS, formatted the hard drive and loaded the software before reloading NIS.  I upgraded the virus signatures and NIS did not find any problems.

 

It seems NIS can do this if software is not popular even though there are no known  issues with the software.

 

Andy Tribe