Author Topic: Wmpnetworksvc rootkit?  (Read 3395 times)

0 Members and 1 Guest are viewing this topic.

shotboy

  • Guest
Wmpnetworksvc rootkit?
« on: April 24, 2012, 05:52:19 AM »
Just built a new computer and installed a clean copy of Windows 7 Pro.  When the computer was hooked to the network for the first time, received an error from Avast! that a suspicious object was found, Wmpnetworksvc.  It noted this was a rootkit.  Is this a false positive?

Offline mchain

  • Avast Evangelist
  • Ultra Poster
  • ***
  • Posts: 5633
  • Spartan Warrior
Re: Wmpnetworksvc rootkit?
« Reply #1 on: April 24, 2012, 07:18:56 AM »
Just built a new computer and installed a clean copy of Windows 7 Pro.  When the computer was hooked to the network for the first time, received an error from Avast! that a suspicious object was found, Wmpnetworksvc.  It noted this was a rootkit.  Is this a false positive?
Well, if the object is a running process, then it is a detection in memory, and cannot be uploaded as a file to https://www.virustotal.com/ to be scanned by 42 antivirus scanners.  If you can find the actual file, upload it to virustotal, run the scan, and post the url of the scan in your next reply.

Depending on how Avast! is set up, it will detect some running processes as malicious if that feature to scan memory is selected (not default) prior to the scan being run; a default scan does not scan memory and thus will not produce false positive results.  Unless one knows what one is looking for when running avast! in a non-default configuration, a process can be flagged as malicious when it is in fact, not.  An example would be signatures loaded in memory by Malwarebytes when that is running as an active resident scanner.

Attach a screenshot of the Avast! warning if possible; see attached screenshot below on how to do this.  Just click "Attachments and other options" below the reply text box you are working in and navigate to where you saved your screenshot.

EDIT:  It appears that Wmpnetworksvc is a service process from Microsoft to share your media files.
« Last Edit: April 24, 2012, 07:23:19 AM by mchain »
Windows 10 Home 64-bit 22H2 Avast Premier Security version 24.1.6099 (build 24.1.88821.762)  UI version 1.0.797
 UI version 1.0.788.  Windows 11 Home 23H2 - Windows 11 Pro 23H2 Avast Premier Security version 24.2.6105 (build 24.1.8918.827) UI version 1.0.801