False Positive? DriveCleaner 2006

TVeblen

Building Stuff
Guru
Gold Member
VIP
Local time
11:16 AM
Messages
6,239
Location
In The Woods
Every time I run Spybot S&D it comes out clean except for one entry: DriveCleaner 2006, (SBI $7E4EDB6E) Class Id, located at HKCR > CLSID > InpocServer32(64 bit).

Clicking to "Fix Selected Problems" results in: "Some problems couldn't be fixed; the reason is that the associated files could still be in use (in memory). This could be fixed after a restart."
Restarting does nothing.

The only thing in the InprocServer32 key is:
C:\programs\AutoCad 2010\AdComFolder\watch.dll
> Threading Model: Both

I know DriveCleaner is a nasty piece of business, but I have scoured my system for any evidence of an infection and have found nothing.

I'm just checking to see if anyone here gets this to see if it is a known false positive result.

[FONT=&quot]Thanks[/FONT]
 

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Home Built - Jan 2013
OS
Windows 7 64 Bit Home Premium SP1
CPU
i7-3820
Motherboard
Asus P9X79-PRO - Bios 4608
Memory
GSkill F3-14900CL9Q - 16GB
Graphics Card(s)
EVGA GeForce GTX660 - Driver 352.86
Sound Card
On board Realtek ALC898
Monitor(s) Displays
Acer S271HL
Screen Resolution
1920 x 1080
Hard Drives
#1- Samsung 840 Pro Series
#2- Western Digital WD1002FAEX Sata3 Black
#3- Western Digital WD1002FAEX Sata3 Black
PSU
Corsair CMPSU-850TX-V2 - 850 watt (by Seasonic)
Case
Corsair Obsidian 550D
Cooling
Standard 3 120mm case fans, Cooler Master Hyper 212 EVO
Keyboard
MS KC-0405
Mouse
Intellimouse 5-button
Internet Speed
56 Mbits/Sec (on a good day)
Antivirus
Avast & Malwarebytes
Browser
Firefox
Other Info
Asus DVD - DRW-24B1ST 24X
Did you try scanning with malwarebytes?

Bill
 

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Custom Built
OS
Windows 7 Enterprise x64
CPU
i7-5820K
Motherboard
Asus X99 A
Memory
16GB DDR4
Graphics Card(s)
ASUS 2GB Nvidia 960GTX OC'd
Monitor(s) Displays
24"
Screen Resolution
1920x1080
Hard Drives
Samsung 1TB 840 SSD
Western Digital 1TB Black Drive
Seagate 2TB NAS Drive
PSU
Antec Earthwatts 650w
Case
Antec DF-85
ive faced the same prob only with different string on my reg. CC cleaner failed to delete it and so as other software. i tried manual delete on regedit,failed. last, i just left it there as my system still works normal. As long the dead reg didn't give any problems, i just let it sit silent there
 

My Computer

OS
window's 7
CPU
core 2 quad
Motherboard
gigabyte
Memory
2gb corsair
Graphics Card(s)
ati hd4850
Monitor(s) Displays
lg
Screen Resolution
1600 X 900
Case
power logic
Other Info
none of the spec above is accurate

My Computer

Computer Manufacturer/Model Number
Samsung NP530U4B-S02IN
OS
Windows® 8 Pro (64-bit)
CPU
Intel® Core™ i5 Processor 2467M (1.60GHz, 3MB L3 Cache)
Motherboard
Samsung Electronics
Memory
6GB DDR3 System Memory at 1,333MHz (on BD 4GB + 2GB x 1)
Graphics Card(s)
AMD Radeon™ HD7550M 1GB DDR3 (Ext. Graphic)
Sound Card
Realtek High Definition Audio
Monitor(s) Displays
35.56cm (14.0) SuperBright 300nit HD LED Display
Screen Resolution
1366x768
Hard Drives
1TB S-ATA II Hard Drive (5400RPM) with ExpressCache 16GB SSD
Internet Speed
sucks
Antivirus
Microsoft Security Essentials
Browser
Google Chrome (Sync enabled)
Thing is... I have run many AV's and cleaners and they don't detect anything. Only Spybot. And I have gone down that list of files, folders, and registry keys that are associated with the actual worm with a manual search and none of them show up. And none of the processes associated with DriveCleaner are running. I am pretty sure the system is clean.

I am wondering if Spybot is looking at that watch.dll file and confusing it for DriveCleaner.
 

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Home Built - Jan 2013
OS
Windows 7 64 Bit Home Premium SP1
CPU
i7-3820
Motherboard
Asus P9X79-PRO - Bios 4608
Memory
GSkill F3-14900CL9Q - 16GB
Graphics Card(s)
EVGA GeForce GTX660 - Driver 352.86
Sound Card
On board Realtek ALC898
Monitor(s) Displays
Acer S271HL
Screen Resolution
1920 x 1080
Hard Drives
#1- Samsung 840 Pro Series
#2- Western Digital WD1002FAEX Sata3 Black
#3- Western Digital WD1002FAEX Sata3 Black
PSU
Corsair CMPSU-850TX-V2 - 850 watt (by Seasonic)
Case
Corsair Obsidian 550D
Cooling
Standard 3 120mm case fans, Cooler Master Hyper 212 EVO
Keyboard
MS KC-0405
Mouse
Intellimouse 5-button
Internet Speed
56 Mbits/Sec (on a good day)
Antivirus
Avast & Malwarebytes
Browser
Firefox
Other Info
Asus DVD - DRW-24B1ST 24X
Follow Up

I posted this issue on Safer Networking's "False Positives" forum, including a key description:
"In my HKCR > CLSID > InProcServer32 registry key I do have this:
C:\Programs\AutoCAD 2010\AdComFolder\Watch.dll
Threading Model: Both
Could this be the cause of a false positive for Drive Cleaner 2006?"
[FONT=&quot]
And I got this response:

"[/FONT] hello,

thank you for reporting this issue.
It is quite unexpected to have any legit software with a registry entry at

Code:
HKEY_CLASSES_ROOT\CLSID\InprocServer32

We will regard this as a false positive, it will be corrected with the next detection update scheduled for Wednesday 2010-05-19."
 

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Home Built - Jan 2013
OS
Windows 7 64 Bit Home Premium SP1
CPU
i7-3820
Motherboard
Asus P9X79-PRO - Bios 4608
Memory
GSkill F3-14900CL9Q - 16GB
Graphics Card(s)
EVGA GeForce GTX660 - Driver 352.86
Sound Card
On board Realtek ALC898
Monitor(s) Displays
Acer S271HL
Screen Resolution
1920 x 1080
Hard Drives
#1- Samsung 840 Pro Series
#2- Western Digital WD1002FAEX Sata3 Black
#3- Western Digital WD1002FAEX Sata3 Black
PSU
Corsair CMPSU-850TX-V2 - 850 watt (by Seasonic)
Case
Corsair Obsidian 550D
Cooling
Standard 3 120mm case fans, Cooler Master Hyper 212 EVO
Keyboard
MS KC-0405
Mouse
Intellimouse 5-button
Internet Speed
56 Mbits/Sec (on a good day)
Antivirus
Avast & Malwarebytes
Browser
Firefox
Other Info
Asus DVD - DRW-24B1ST 24X
I posted this issue on Safer Networking's "False Positives" forum, including a key description:
"In my HKCR > CLSID > InProcServer32 registry key I do have this:
C:\Programs\AutoCAD 2010\AdComFolder\Watch.dll
Threading Model: Both
Could this be the cause of a false positive for Drive Cleaner 2006?"
[FONT=&quot]
And I got this response:

"[/FONT] hello,

thank you for reporting this issue.
It is quite unexpected to have any legit software with a registry entry at

Code:
HKEY_CLASSES_ROOT\CLSID\InprocServer32

We will regard this as a false positive, it will be corrected with the next detection update scheduled for Wednesday 2010-05-19."

That was a good reply from them and an appropriate response.
 

My Computer

Computer Manufacturer/Model Number
Home built
OS
Windows 7 Ultimate 32 bit
CPU
Intel(R) Pentium(R) 4 CPU 3.00GHz
Motherboard
ASUS P4P800-VM Motherboard Chipset: Intel 865G + ICH5
Memory
2.50 GB RAM
Graphics Card(s)
NVIDIA GeForce 7600 GS
Sound Card
SoundMax Integrated Digital Audio (Chip)
Monitor(s) Displays
ViewSonic VX 1962 wm
Screen Resolution
1680 X 1050
Hard Drives
Seagate Barracuda 7200.10 80 GB
ST380215A ATA Device 18.6 GB
Western Digital "My Book" external hard drive 750 GB
Cooling
Fan based
Keyboard
Microsoft Comfort Curve Keyboard 2000 v10 USB
Mouse
Logitec optic USB
Internet Speed
3.01 Mb/s download 0.64 Mb/s upload
I have just gone through this exact same thing, until I thankfully came across this thread! HAHAHAHA

...Sevenforums saves the day... AGAIN
 

My Computer

Computer Manufacturer/Model Number
Hewlett-Packard/Pavillion dv6 Notebook PC
OS
64-bit
CPU
Intel(R) Core(TM) 2 Duo T6600 @ 2.20 GHz
Memory
4 GB
It's always best to go to the program's forum and ask! ;)
 

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Bruce ... somewhere in his 40's
OS
Windows 7 Ultimate 32bit SP1
CPU
Intel(R) Core(TM)2 Quad CPU @ 2.40GHz, 2400 MHz
Motherboard
INTEL/D975XBX2
Memory
4 GB
Graphics Card(s)
ATI Radeon HD 2600 Pro
Monitor(s) Displays
Samsung SyncMaster 914v
Screen Resolution
1280 x 1024
Hard Drives
2/500GB each ... ST3500630AS ATA Device.
One is not connected
PSU
Rocketfish 700 W
Case
G.Skill Gigabyte Chassis
Keyboard
Standard PS/2 Keyboard
Mouse
Microsoft PS/2 Mouse
Internet Speed
DSL
Antivirus
Avira Internet Security
Browser
IE 11
Other Info
ATI HDMI Audio
It's always best to go to the program's forum and ask! ;)

Yes it is!
But there are lots of very experienced peeps here, so I felt no reservation in asking!

Thanks to all for looking!
 

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Home Built - Jan 2013
OS
Windows 7 64 Bit Home Premium SP1
CPU
i7-3820
Motherboard
Asus P9X79-PRO - Bios 4608
Memory
GSkill F3-14900CL9Q - 16GB
Graphics Card(s)
EVGA GeForce GTX660 - Driver 352.86
Sound Card
On board Realtek ALC898
Monitor(s) Displays
Acer S271HL
Screen Resolution
1920 x 1080
Hard Drives
#1- Samsung 840 Pro Series
#2- Western Digital WD1002FAEX Sata3 Black
#3- Western Digital WD1002FAEX Sata3 Black
PSU
Corsair CMPSU-850TX-V2 - 850 watt (by Seasonic)
Case
Corsair Obsidian 550D
Cooling
Standard 3 120mm case fans, Cooler Master Hyper 212 EVO
Keyboard
MS KC-0405
Mouse
Intellimouse 5-button
Internet Speed
56 Mbits/Sec (on a good day)
Antivirus
Avast & Malwarebytes
Browser
Firefox
Other Info
Asus DVD - DRW-24B1ST 24X
Back
Top