Avast WEBforum

Consumer Products => Avast Free Antivirus / Premium Security (legacy Pro Antivirus, Internet Security, Premier) => Topic started by: ZoneMaster60 on January 19, 2011, 01:37:27 AM

Title: network framework - win32/malware-gen FP's since 1/18/11 update 10:37a
Post by: ZoneMaster60 on January 19, 2011, 01:37:27 AM
I have been getting these all day since the update this morning at 10:37am. I never had this problem in the past, and even went as far as running ComboFix for Windows 7 and that didn't seem to solve anything (apparently they must be false positives maybe? not sure). Below are links from Virustotal for all the files I had analyzed. The files originate from C:\Users\UserName\AppData\Local\Temp and are randomly named DLL's that are associated with the process Network Framework 2.0 CSC.exe.

There are 5 sometimes 6 scanners that detect a problem, and always the same ones for any of the files I submitted.

http://www.virustotal.com/file-scan/report.html?id=f922a5b3bcc943a62d5651e7cfc79d803bb6e452735481a8aaea264da9854537-1295396891 (http://www.virustotal.com/file-scan/report.html?id=f922a5b3bcc943a62d5651e7cfc79d803bb6e452735481a8aaea264da9854537-1295396891)

http://www.virustotal.com/file-scan/report.html?id=82016d64f2a1cbc1a7984fe0721d468b89dc874c22624fcdf2da50a9ca676b33-1295397165 (http://www.virustotal.com/file-scan/report.html?id=82016d64f2a1cbc1a7984fe0721d468b89dc874c22624fcdf2da50a9ca676b33-1295397165)

one more:

http://www.virustotal.com/file-scan/report.html?id=153974ef7bab9fa330480a8b96c46fd74f2d5857801af200b3b79bffaba2db2f-1295397402 (http://www.virustotal.com/file-scan/report.html?id=153974ef7bab9fa330480a8b96c46fd74f2d5857801af200b3b79bffaba2db2f-1295397402)

There were more than this but I think this may give you a good idea. Hope this isn't something too serious.

Title: Re: network framework - win32/malware-gen FP's since 1/18/11 update 10:37a
Post by: dweaver on January 19, 2011, 02:50:38 AM
I am also having files get tagged throughout the day since the update this morning. Is this the case of a false positive or do I have an actual virus fully infected on my machine? I also used one of the scanner services with the same results as the OP.
Title: Re: network framework - win32/malware-gen FP's since 1/18/11 update 10:37a
Post by: Oblarg on January 19, 2011, 02:55:58 AM
Yeah, I registered to ask the same thing - I've been having the same messages all day.

I'm thinking a false positive is likely given three people have all had the same thing start popping up after the same update, but who knows?  I'm running a full scan now to be sure as I'm not really doing much else.
Title: Re: network framework - win32/malware-gen FP's since 1/18/11 update 10:37a
Post by: Dalrain on January 19, 2011, 02:56:29 AM
As much as I hate to say "me too," I had to sign up to say "me too." Same symptoms.

Edit: I guess I should clarify that I don't know enough to declare this a FP.  I think that's possible, but I don't want to call it that based on my limited knowledge.
Title: Re: network framework - win32/malware-gen FP's since 1/18/11 update 10:37a
Post by: Dalrain on January 19, 2011, 03:36:05 AM
Did any of you try applying a "games for windows" update from windows update?  We just ended up doing that (on accident) and the avast popup isn't occurring now.  Very strange.

Edit: Looks like my error was related to this: http://forum.avast.com/index.php?topic=69660.0

I think the VPS update actually was what "fixed" it.
Title: Re: network framework - win32/malware-gen FP's since 1/18/11 update 10:37a
Post by: Milos on January 19, 2011, 11:11:56 AM
Hello,
it should be fixed in next vps update.

Milos
Title: Re: network framework - win32/malware-gen FP's since 1/18/11 update 10:37a
Post by: ZoneMaster60 on January 19, 2011, 03:27:32 PM
Apparently they were false positives, NO problems as of the update this morning. If anything does happen to arise I will post here again, let's hope not... LOL

Thanks! :)