Avast WEBforum

Consumer Products => Avast Free Antivirus / Premium Security (legacy Pro Antivirus, Internet Security, Premier) => Topic started by: David_E on April 09, 2013, 07:17:22 PM

Title: MS Patch Tuesday updates
Post by: David_E on April 09, 2013, 07:17:22 PM
I just tried installing MS Patch Tuesday updates and Avast! 8 popped up warnings and quarantined several files.
Is anyone else seeing this issue with the MS updates?
Title: Re: MS Patch Tuesday updates
Post by: DavidR on April 09, 2013, 07:30:14 PM
The file names, location and malware name will help us to determine what action to take.
Title: Re: MS Patch Tuesday updates
Post by: schmidthouse on April 09, 2013, 07:47:47 PM
I just tried installing MS Patch Tuesday updates and Avast! 8 popped up warnings and quarantined several files.
Is anyone else seeing this issue with the MS updates?

Have had 'no issues' here with 8 Security Updates on Windows 8 Pro today ;)
Title: Re: MS Patch Tuesday updates
Post by: midnight on April 09, 2013, 07:52:24 PM
7 Security Updates on Windows 7 today.
Title: Re: MS Patch Tuesday updates
Post by: abruptum on April 09, 2013, 07:56:22 PM
Also 7 Windows Updates today.

Malicious Software Removal Tool
Update for IE10 Windows 7 SP1
Update for Windows 7
4 Security Updates for Windows 7
Title: Re: MS Patch Tuesday updates
Post by: David_E on April 09, 2013, 07:58:24 PM
The file names, location and malware name will help us to determine what action to take.

I'll get the requested info asap.
I re-booted the PC with an OS using MSSE and updates install without issues.
I believe I got 10 updates today on the Win 7 x86 OS with Avast! 8.
Title: Re: MS Patch Tuesday updates
Post by: tkt on April 09, 2013, 08:00:04 PM
avast detected windows update as virus??????
Title: Re: MS Patch Tuesday updates
Post by: wolfhound1747 on April 09, 2013, 08:17:10 PM
Had the same problem as David_E, when running Windows Update on W7 SP1 (32bit).   

Avast placed a total of 6 downloaded files relating to KB2813170 into Virus Chest, including csrsrv.dll citing Win32:Aluroot-B (Rtk).  Probably a false positive, but can anyone confirm?
Title: Re: MS Patch Tuesday updates
Post by: David_E on April 09, 2013, 08:19:26 PM
The file names, location and malware name will help us to determine what action to take.

I'll get the requested info asap.
I re-booted the PC with an OS using MSSE and updates install without issues.
I believe I got 10 updates today on the Win 7 x86 OS with Avast! 8.

I attached a screen print of the Virus Chest.
Is this enough info?
I cancelled the Windows update when I started getting the alerts, so I don't know if there might have been more files with issues that.
Title: Re: MS Patch Tuesday updates
Post by: abruptum on April 09, 2013, 08:34:44 PM
Update KB2813170 was successfully  installed.
Virus Chest is empty.
Title: Re: MS Patch Tuesday updates
Post by: David_E on April 09, 2013, 08:40:49 PM
Maybe it has been fixed with a Streaming Update?
I just installed the other 9 updates without issues.
I didn't retry KB2813170 yet.
Title: Re: MS Patch Tuesday updates
Post by: wolfhound1747 on April 09, 2013, 08:53:32 PM
Confirm issue now resolved, in that KB2813170 install sucessfully - my last streaming update was 19.43 BST which, presumably contained the fix.
Title: Re: MS Patch Tuesday updates
Post by: DavidR on April 09, 2013, 09:41:47 PM
The file names, location and malware name will help us to determine what action to take.

I'll get the requested info asap.
I re-booted the PC with an OS using MSSE and updates install without issues.
I believe I got 10 updates today on the Win 7 x86 OS with Avast! 8.

I attached a screen print of the Virus Chest.
Is this enough info?
I cancelled the Windows update when I started getting the alerts, so I don't know if there might have been more files with issues that.


I think that this is down to the way the updates are applied. I think that after the windows update these files would normally be removed. After windows reboots I don't think avast will find anything.
Title: Re: MS Patch Tuesday updates
Post by: David_E on April 09, 2013, 10:05:09 PM
The file names, location and malware name will help us to determine what action to take.

I'll get the requested info asap.
I re-booted the PC with an OS using MSSE and updates install without issues.
I believe I got 10 updates today on the Win 7 x86 OS with Avast! 8.

I attached a screen print of the Virus Chest.
Is this enough info?
I cancelled the Windows update when I started getting the alerts, so I don't know if there might have been more files with issues that.


I think that this is down to the way the updates are applied. I think that after the windows update these files would normally be removed. After windows reboots I don't think avast will find anything.

I don't think so.
The first attempt at applying KB2813170 failed.
The second attempt succeeded, but there were streaming updates installed after the first attempt.
I'm just guessing here, but seems to me the definitions were fixed for a FP...
Title: Re: MS Patch Tuesday updates
Post by: lilidurhone on April 09, 2013, 10:12:07 PM
Hi

Just confirmed false positive detection has been fixed  :D
Title: Re: MS Patch Tuesday updates
Post by: DavidR on April 09, 2013, 10:21:37 PM
I had no failures or detections during the win7 updates I got including the one you mentioned. So I'm not sure why as I can't recall what VPS version I had at the time.
Title: Re: MS Patch Tuesday updates
Post by: David_E on April 09, 2013, 10:31:11 PM
I'm not sure what VPS version I had when the update failed.
It would be nice if Avast! could confirm if there was a FP that was fixed.
My Update History shows the failed update when Avast! quarantined the files during the first update attempt...


 
Title: Re: MS Patch Tuesday updates
Post by: lilidurhone on April 09, 2013, 10:36:44 PM
I'm not sure what VPS version I had when the update failed.
It would be nice if Avast! could confirm if there was a FP that was fixed.
My Update History shows the failed update when Avast! quarantined the files during the first update attempt...


 

Yes i confirm this false positive has been fixed not detection after one windows update
Title: Re: MS Patch Tuesday updates
Post by: dertb on April 10, 2013, 10:00:01 AM
I had the same issue yesterday:

Win32:Aluroot-B [Rtk] detected in files for KB2813170.

Code: [Select]
09.04.2013 19:50:56 C:\Windows\SoftwareDistribution\Download\34040f093a63a8239849e531dfa4b587\x86_microsoft-windows-csrsrv_31bf3856ad364e35_6.1.7601.18113_none_cb8d824703a0c682\csrsrv.dll [L] Win32:Aluroot-B [Rtk] (0)
Datei erfolgreich in Container verschoben...
09.04.2013 19:51:01 C:\Windows\SoftwareDistribution\Download\34040f093a63a8239849e531dfa4b587\$dpx$.tmp\2602d68417a12c478775c5cd02e68dd1.tmp [L] Win32:Aluroot-B [Rtk] (0)
Datei erfolgreich in Container verschoben...
09.04.2013 19:51:12 C:\Windows\SoftwareDistribution\Download\34040f093a63a8239849e531dfa4b587\x86_microsoft-windows-csrsrv_31bf3856ad364e35_6.1.7601.22280_none_cbc86ec01cf9ddde\csrsrv.dll [L] Win32:Aluroot-B [Rtk] (0)
Datei erfolgreich in Container verschoben...
09.04.2013 19:51:14 C:\Windows\SoftwareDistribution\Download\34040f093a63a8239849e531dfa4b587\$dpx$.tmp\4e6ca47c954dfa44b4f7c10cc4e15225.tmp [L] Win32:Aluroot-B [Rtk] (0)
Datei erfolgreich in Container verschoben...
09.04.2013 19:51:30 C:\Windows\SoftwareDistribution\Download\34040f093a63a8239849e531dfa4b587\x86_microsoft-windows-csrsrv_31bf3856ad364e35_6.1.7600.21490_none_c9d741ce1fdb8de3\csrsrv.dll [L] Win32:Aluroot-B [Rtk] (0)
Datei erfolgreich in Container verschoben...
09.04.2013 19:51:30 C:\Windows\SoftwareDistribution\Download\34040f093a63a8239849e531dfa4b587\$dpx$.tmp\703ca74b26cabe4f9bf20f3d69c78ec1.tmp [L] Win32:Aluroot-B [Rtk] (0)
Datei erfolgreich in Container verschoben...

Files were put in chest, now avast says no virus after new check in virus chest.

Is this really a false positive confirmed by avast?

thank you and br

Title: Re: MS Patch Tuesday updates
Post by: lilidurhone on April 10, 2013, 01:21:51 PM
I had the same issue yesterday:

Win32:Aluroot-B [Rtk] detected in files for KB2813170.

Code: [Select]
09.04.2013 19:50:56 C:\Windows\SoftwareDistribution\Download\34040f093a63a8239849e531dfa4b587\x86_microsoft-windows-csrsrv_31bf3856ad364e35_6.1.7601.18113_none_cb8d824703a0c682\csrsrv.dll [L] Win32:Aluroot-B [Rtk] (0)
Datei erfolgreich in Container verschoben...
09.04.2013 19:51:01 C:\Windows\SoftwareDistribution\Download\34040f093a63a8239849e531dfa4b587\$dpx$.tmp\2602d68417a12c478775c5cd02e68dd1.tmp [L] Win32:Aluroot-B [Rtk] (0)
Datei erfolgreich in Container verschoben...
09.04.2013 19:51:12 C:\Windows\SoftwareDistribution\Download\34040f093a63a8239849e531dfa4b587\x86_microsoft-windows-csrsrv_31bf3856ad364e35_6.1.7601.22280_none_cbc86ec01cf9ddde\csrsrv.dll [L] Win32:Aluroot-B [Rtk] (0)
Datei erfolgreich in Container verschoben...
09.04.2013 19:51:14 C:\Windows\SoftwareDistribution\Download\34040f093a63a8239849e531dfa4b587\$dpx$.tmp\4e6ca47c954dfa44b4f7c10cc4e15225.tmp [L] Win32:Aluroot-B [Rtk] (0)
Datei erfolgreich in Container verschoben...
09.04.2013 19:51:30 C:\Windows\SoftwareDistribution\Download\34040f093a63a8239849e531dfa4b587\x86_microsoft-windows-csrsrv_31bf3856ad364e35_6.1.7600.21490_none_c9d741ce1fdb8de3\csrsrv.dll [L] Win32:Aluroot-B [Rtk] (0)
Datei erfolgreich in Container verschoben...
09.04.2013 19:51:30 C:\Windows\SoftwareDistribution\Download\34040f093a63a8239849e531dfa4b587\$dpx$.tmp\703ca74b26cabe4f9bf20f3d69c78ec1.tmp [L] Win32:Aluroot-B [Rtk] (0)
Datei erfolgreich in Container verschoben...

Files were put in chest, now avast says no virus after new check in virus chest.

Is this really a false positive confirmed by avast?

thank you and br



Yes it's a false positive
Avast has been fixed
Title: Re: MS Patch Tuesday updates
Post by: dertb on April 10, 2013, 04:13:58 PM
Confirmed by you or avast? Sorry, just want ot be sure.

BR