Avast WEBforum

Other => Viruses and worms => Topic started by: Minty95 on March 04, 2019, 05:18:02 PM

Title: Random DLL files being Quarantined by Avast
Post by: Minty95 on March 04, 2019, 05:18:02 PM
Hi all,

Recently Avast has been notifying me of Win32:Malware-gen files that are being stopped and quarantined on multiple machines on our network.

Viewing the files caught in the virus chest I can see the following.

(http://i68.tinypic.com/2rhw6z4.jpg)

The .dll files are being created in the users c:\windows\temp folder, then removed by Avast.

Event Viewer reports that the following service is being installed just prior to the DLL's being created and Avast Quarantining them.

(http://i63.tinypic.com/1q60ao.jpg)

I have run one of the suspect .dll files through VirusTotal (attached below). Avast, AVG, Malwarebytes and CrowdStrike Falcon have reported the file as Malicious however the other 60+ Anti-Virus products report the file as clean.

I am unsure if the files being quarantined are genuine threats or false positives.

Any help regarding this would be much appreciated.


Title: Re: Random DLL files being Quarantined by Avast
Post by: Pondus on March 04, 2019, 06:04:12 PM
Quote
I have run one of the suspect .dll files through VirusTotal (attached below). Avast, AVG, Malwarebytes and CrowdStrike Falcon have reported the file as Malicious however the other 60+ Anti-Virus products report the file as clean.
Always post link to scan results as there is lots of extra info we can't  see from a screenshot

Avast lab can then also fetch files from VT when they can see file SHA256 / MD5


Quote
I am unsure if the files being quarantined are genuine threats or false positives.
Best way to answer that is to send samples to avast lab
See my post here on how to report  >>  https://forum.avast.com/index.php?topic=14433.msg1289438#msg1289438



Title: Re: Random DLL files being Quarantined by Avast
Post by: Minty95 on March 08, 2019, 11:35:44 AM
Quote
Always post link to scan results as there is lots of extra info we can't  see from a screenshot

Avast lab can then also fetch files from VT when they can see file SHA256 / MD5

Thanks Pondus,

Please find below a link to the scan results.

https://www.virustotal.com/#/file/0383ce989d457cb794099391ca9417194636d0617f4166c37cacaa48b1cc92e8/detection


As advised I have also sent a sample of the file to the Avast Threat Lab.