False positive: Win32:IRCBot-ECU [Trj]

Avast! Free Antivirus with latest virus definitions wrongly detects a part of my scanner driver as infected with Win32:IRCBot-ECU [Trj]. The module in question is gtwatch.exe.
You can download the driver for Mustek Bearpaw 2400CS Plus scanner at http://www.mustek.de/11/index.php/en/service-a-drivers-2/treiber-a-software/269-downloads/170
You can successfully install this driver package on a system without a scanner (tested on Windows XP only). That will unpack gtwatch.exe into your %WINDIR%
Otherwise, you can download gtwatch.exe here: http://rghost.ru/35859786
Virustotal.com detection ratio for this module is 2/40: http://www.virustotal.com/file-scan/report.html?id=18d18e136d7c251fed2caaca28a41f46b44631243b990f5008e346f07fbfd92b-1324469078
Please take a look at this, Avast! team.

the scan you post is from 20/12 - 2011… always post latest :wink:
https://new.virustotal.com/file/18d18e136d7c251fed2caaca28a41f46b44631243b990f5008e346f07fbfd92b/analysis/1326312061/

seems to be an old file
First seen: 2009-06-10 07:11:13
Last seen : 2011-12-21 12:04:38

will upload to avast lab

Old file indeed :slight_smile:

http://systemexplorer.net/filereviews.php?fid=471066

avast lab

Hello, thank you for sending sample. False positive will be fixed in next VPS update. Sorry for any inconvenience.

OT: Does the lab send replies now…??

OT: Does the lab send replies now..??
Sometimes i get lucky....i think this is nr 3 or 4 i have recived....

maybe they have started with something new, since it is a new year ;D

Hopefully, as it would be great to receive answers. :slight_smile: