false positive

boclean has given me a malware notification on an svc for shadow protect by storagecraft. this is a disk imaging software. a definite false positive.

i did the malware update list for sep 09 and the notification did not reoccur. perhaps the problem has already been fixed or was just an anomaly. i looked at the list of malware and did see 3 entries that began with shadow.

Hi leobull :slight_smile:

Thank you for keeping a sharp eye on BOClean :slight_smile: It was most likely a false positive that has been fixed by the Malware Research boys :wink:

Greetz, Red.

I also have a false positive on shadowprotectsvc.exe wich is call BKDR-SDBOT.sru malware (or something like that)!!!

The update I have is : 2008-09-09 15:29:38 wich appears to be the latest update when manually checking for update???

Thanks,
Atomas31

Hi Atomas31.

Can you please email the file to: malwaresubmit [ at ] comodo.com .
Specify in the subject line " BOClean False Positive ? ".
Zip and password protect it with " infected " and include that information in the body.

If the file is too big to email, provide a download link in the email. For the time being you can exlude the file in BOClean if you are 100% sure it is indeed a false positive :slight_smile:

Greetz, Red.

Hello atomas31 and leobull,

It was a FP and has been fixed already. Please let us know if you are still facing a problem.

Regards,
Baskar.