Author Topic: MSDEV.exe, infection: Wind32:Malware-gen  (Read 3430 times)

0 Members and 1 Guest are viewing this topic.

adiamond

  • Guest
MSDEV.exe, infection: Wind32:Malware-gen
« on: July 26, 2013, 09:42:00 PM »
Process,c:\windows\system32\rundll32
The MSDEV.EXE is a MS Visual C app.  The full path was D:\Program Files\Microsoft Visual Studio\Common\MSDev98\Bin\MSDEV.EXE so I'm, pretty sure this is a legitimate item and probably not infected....of course I can't prove anything of the sort.

Offline Asyn

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 76033
    • >>>  Avast Forum - Deutschsprachiger Bereich  <<<
Re: MSDEV.exe, infection: Wind32:Malware-gen
« Reply #1 on: July 26, 2013, 09:45:35 PM »
Test it at VT and post the link. -> https://www.virustotal.com/
W8.1 [x64] - Avast Free AV 23.3.8047.BC [UI.757] - Firefox ESR 102.9 [NS/uBO/PB] - Thunderbird 102.9.1
Avast-Tools: Secure Browser 109.0 - Cleanup 23.1 - SecureLine 5.18 - DriverUpdater 23.1 - CCleaner 6.01
Avast Wissenswertes (Downloads, Anleitungen & Infos): https://forum.avast.com/index.php?topic=60523.0

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37600
  • Not a avast user
Re: MSDEV.exe, infection: Wind32:Malware-gen
« Reply #2 on: July 26, 2013, 09:46:04 PM »
and what did avast do With it?
have you tested the file at www.virustotal.com / www.metascan-online.com / www.jotti.org

post link to scan result here

adiamond

  • Guest
Re: MSDEV.exe, infection: Wind32:Malware-gen
« Reply #3 on: July 27, 2013, 06:05:08 PM »
re: virustotal

The file was moved to the chest.  How do I get at it?

Offline DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89279
  • No support PMs thanks
Re: MSDEV.exe, infection: Wind32:Malware-gen
« Reply #4 on: July 27, 2013, 07:33:42 PM »
Create a folder called Suspect in the C:\ drive. Now exclude that folder in the File System Shield, Settings, Exclusions, Add, type (or copy and paste) C:\Suspect\*
That will stop the File System Shield scanning any file you put in that folder.


Now Open the chest - avastUI, Maintenance, Virus Chest - Right click on the file within the chest and select, Extract. From the next window navigate to the newly created C:\Suspect folder and click OK.

A copy of the file will now be in that folder and one remains in the virus chest - now you are good to upload it to virustotal.
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD/ avast! free 24.5.6116 (build 24.5.9153.762) UI 1.0.808/ Firefox, uBlock Origin, uMatrix/ MailWasher Pro/ Avast! Mobile Security

adiamond

  • Guest

Offline Asyn

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 76033
    • >>>  Avast Forum - Deutschsprachiger Bereich  <<<
Re: MSDEV.exe, infection: Wind32:Malware-gen
« Reply #6 on: July 27, 2013, 11:06:20 PM »
You can report a possible FP here: http://www.avast.com/contact-form.php
W8.1 [x64] - Avast Free AV 23.3.8047.BC [UI.757] - Firefox ESR 102.9 [NS/uBO/PB] - Thunderbird 102.9.1
Avast-Tools: Secure Browser 109.0 - Cleanup 23.1 - SecureLine 5.18 - DriverUpdater 23.1 - CCleaner 6.01
Avast Wissenswertes (Downloads, Anleitungen & Infos): https://forum.avast.com/index.php?topic=60523.0

Offline DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89279
  • No support PMs thanks
Re: MSDEV.exe, infection: Wind32:Malware-gen
« Reply #7 on: July 27, 2013, 11:18:42 PM »
The Win32:Malware-gen is a generic detection so is more prone to a false positive, but it isn't unusual for avast to be the only one to detect, but also be correct.

From the avast chest, right click on the file and this time select Submit to virus lab... and periodically scan the file from within the chest. If it was an FP then the signature should be modified and the file will no longer be detected.

- In the meantime (if you accept the risk), add the full path to the file to the exclusions lists (see Note below):
File System Shield, Settings, Exclusions, Add and
avastUI > Settings > Global Exclusions

Restore it to its original location, periodically check it (scan it in the chest), there should still be a copy in the chest even though you restored it to the original location. When it is no longer detected then you can also remove it from the File System Shield and avastUI > Settings > Global Exclusions lists.

Note: When using the Browse button it only goes down to folder level accept that. Now open the entry in the exclusions and change the \* to \file_name.exe where file_name.exe is the file you want to exclude.
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD/ avast! free 24.5.6116 (build 24.5.9153.762) UI 1.0.808/ Firefox, uBlock Origin, uMatrix/ MailWasher Pro/ Avast! Mobile Security