DriveCleaner.Net False Positive? (MSIL/IRCBot.A)

Discussion in 'ESET NOD32 Antivirus' started by SaphireX, Aug 27, 2008.

Thread Status:
Not open for further replies.
  1. SaphireX

    SaphireX Registered Member

    Joined:
    Jul 29, 2004
    Posts:
    84
  2. Marcos

    Marcos Eset Staff Account

    Joined:
    Nov 22, 2002
    Posts:
    14,374
    Re: DriveCleaner.Net False Positive?

    Please compress the files with WinRAR, protect the archive with the password "infected" and send it to samples[at]eset.com with this thread's url enclosed.
     
  3. Hurin

    Hurin Registered Member

    Joined:
    Aug 27, 2008
    Posts:
    1
    Re: DriveCleaner.Net False Positive?

    I noticed the same thing. Ironically, I had just re-downloaded and reinstalled Drivercleaner.net yesterday. Early this morning, I suddenly starting getting reports that all its files were infected with MSIL/IRCBot.A Trojan. Even the originally downloaded ZIP file came up as infected.

    The good news is that the issue already appears to be fixed. The newest definitions appear to no longer cause the false positive. I just re-downloaded the DC.net and scanned it with no problems.
     
  4. SaphireX

    SaphireX Registered Member

    Joined:
    Jul 29, 2004
    Posts:
    84
    Yup ....concur --- the latest update definitions/files that came after I made this post earlier no longer detect DriveCleaner.Net as a threat :D
    As once I removed the DriveCleaner directory from the exclusion list I ran an On-Demand scan to check the status again as a potential threat and can confirm that vis a vis NOD32 they are no longer a threat...

    Thanks Marcos & ESET for the update and debug!

    SaphireX

    http://img.photobucket.com/albums/v242/Saphirex/8-27-20081-59-24PM.jpg
     

    Attached Files:

Thread Status:
Not open for further replies.