ESET detecting printer driver as Trojan ( Win32/Ponmocup.AA.Gen )

Discussion in 'ESET NOD32 Antivirus' started by pnorm, Feb 3, 2012.

Thread Status:
Not open for further replies.
  1. pnorm

    pnorm Registered Member

    Joined:
    Feb 3, 2012
    Posts:
    3
    Location:
    US
    Since the latest definitions update ESET is seeing my printer driver as a Trojan.

    LOG:
    2/3/2012 3:47:10 PM Real-time file system protection file C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\DLHSMCzd.dll Win32/Ponmocup.AA.Gen trojan cleaned by deleting - quarantined D9RPJTK1-PHILN\Phil Norman Event occurred during an attempt to access the file by the application: C:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE.

    When I reload the drivers from a DVD ESET stops the install.

    Anyone have any ideas?
     
  2. Cudni

    Cudni Global Moderator

    Joined:
    May 24, 2009
    Posts:
    6,956
    Location:
    Somethingshire
  3. olydrh

    olydrh Registered Member

    Joined:
    Feb 3, 2012
    Posts:
    4
    Location:
    USA
    Re: ESET detecting printer driver as Trojan

    Cudni,
    Can you contact top level support and advise them definitions 6855 are bad. This needs to be fixed ASAP. I fear a black eye for Eset if not.
    You know have 3 reports of different DLL's being flagged as Win32/Ponmocup.AA.Gen trojan.
    This Printer driver
    Nero
    RingCentral's Call Controler. RCSPSKSPVISTA.DLL
    Get this sorted out quick.
    Regards,
    Dave
     
  4. pnorm

    pnorm Registered Member

    Joined:
    Feb 3, 2012
    Posts:
    3
    Location:
    US
    Re: ESET detecting printer driver as Trojan

    I have submitted the false positive.
    I do not want to add exceptions to scanning, this would seem to open up some holes in scanning.

    Hopefully Eset can fix the virus signature database error quickly.

    Thanks for the heads up on where to submit!
     
  5. agoretsky

    agoretsky Eset Staff Account

    Joined:
    Apr 4, 2006
    Posts:
    4,032
    Location:
    California
    Hello,

    Issue is under investigation. Thank you for your report.

    Regards,

    Aryeh Goretsky
     
  6. agoretsky

    agoretsky Eset Staff Account

    Joined:
    Apr 4, 2006
    Posts:
    4,032
    Location:
    California
    Hello,

    This has been resolved in virus signature database 6856. Can you please confirm?

    Can you tell me which printer the report occurred with?

    Regards,

    Aryeh Goretsky
     
  7. pnorm

    pnorm Registered Member

    Joined:
    Feb 3, 2012
    Posts:
    3
    Location:
    US
    The updated signatures solved the issue.
    Dell 1350cnw printer.
     
  8. siljaline

    siljaline Former Poster

    Joined:
    Jun 29, 2003
    Posts:
    6,619
    The behaviours of this Trojan are detailed here
     
Thread Status:
Not open for further replies.