Author Topic: Random DLL files being Quarantined by Avast  (Read 2576 times)

0 Members and 1 Guest are viewing this topic.

Offline Minty95

  • Newbie
  • *
  • Posts: 3
Random DLL files being Quarantined by Avast
« on: March 04, 2019, 05:18:02 PM »
Hi all,

Recently Avast has been notifying me of Win32:Malware-gen files that are being stopped and quarantined on multiple machines on our network.

Viewing the files caught in the virus chest I can see the following.



The .dll files are being created in the users c:\windows\temp folder, then removed by Avast.

Event Viewer reports that the following service is being installed just prior to the DLL's being created and Avast Quarantining them.



I have run one of the suspect .dll files through VirusTotal (attached below). Avast, AVG, Malwarebytes and CrowdStrike Falcon have reported the file as Malicious however the other 60+ Anti-Virus products report the file as clean.

I am unsure if the files being quarantined are genuine threats or false positives.

Any help regarding this would be much appreciated.


« Last Edit: March 04, 2019, 05:43:00 PM by Minty95 »

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37532
  • Not a avast user
Re: Random DLL files being Quarantined by Avast
« Reply #1 on: March 04, 2019, 06:04:12 PM »
Quote
I have run one of the suspect .dll files through VirusTotal (attached below). Avast, AVG, Malwarebytes and CrowdStrike Falcon have reported the file as Malicious however the other 60+ Anti-Virus products report the file as clean.
Always post link to scan results as there is lots of extra info we can't  see from a screenshot

Avast lab can then also fetch files from VT when they can see file SHA256 / MD5


Quote
I am unsure if the files being quarantined are genuine threats or false positives.
Best way to answer that is to send samples to avast lab
See my post here on how to report  >>  https://forum.avast.com/index.php?topic=14433.msg1289438#msg1289438



« Last Edit: March 05, 2019, 12:32:02 AM by Pondus »

Offline Minty95

  • Newbie
  • *
  • Posts: 3
Re: Random DLL files being Quarantined by Avast
« Reply #2 on: March 08, 2019, 11:35:44 AM »
Quote
Always post link to scan results as there is lots of extra info we can't  see from a screenshot

Avast lab can then also fetch files from VT when they can see file SHA256 / MD5

Thanks Pondus,

Please find below a link to the scan results.

https://www.virustotal.com/#/file/0383ce989d457cb794099391ca9417194636d0617f4166c37cacaa48b1cc92e8/detection


As advised I have also sent a sample of the file to the Avast Threat Lab.
« Last Edit: March 08, 2019, 11:41:50 AM by Minty95 »