Avast threat pop-up: aspnet_compiler.exe

Hello,

I just got an Avast threat pop-up informing me threats had been detected and moved to the chest:

1:
Threat Name: Win32:Malware-gen Infected file: aspnet_compiler.exe
Original location: C:\Windows\SoftwareDistribution\Download\3bbe913523b063ccd6f178f733c3e742\amd64_Microsoft-Windows-NetFx3-OnDemand-PackageAMD6410.0.16299.15\x86_aspnet_compiler_b03f5f7f11d50a3a_10.0.16299.15_none_33dac4e0b5d00f53

2:
Threat Name: Win32:Malware-gen Infected file: aspnet_compiler.exe
Original location: C:$WINDOWS.~BT\NewOS\Windows\Microsoft.NET\Framework\v2.0.50727

I’m not very IT savvy, so I hoped someone would be able to help me in figuring out a) do I need to worry about these? b) if so, what should I do?

Thanks!

Hello,
send us the detected files using https://www.avast.com/false-positive-file-form.php
Files should be in the avast’s virus chest if you are using default settings.

Milos

Any update on this? Over the weekend 6 dozen PC’s for multiple customer’s had…

Object Name: C:\Windows\SoftwareDistribution\Download\4621457ada0167559a83d8fa537a53ad\x86_Microsoft-Windows-NetFx3-OnDemand-Package~~X86~~10.0.16299.15\x86_aspnet_compiler_b03f5f7f11d50a3a_10.0.16299.15_none_33dac4e0b5d00f53\aspnet_compiler.exe

…and…

Object Name: C:\$WINDOWS.~BT\NewOS\Windows\Microsoft.NET\Framework\v2.0.50727\aspnet_compiler.exe

…flagged as viruses.

Same here, I have about 7 machines on my network with the same alert. False positive??

Have anyone sendt file (s) to avast lab? … see post from Milos above

Hi,

Same here. And I ´m upgrading as we speak win 10…

Submitted aspnet_compiler.exe to the form link Milos provided.

https://www.virustotal.com/#/file/2720106d61861b3c91575fa92309f6c677da04c48e70ecf0675ffeb9e90253e7/

Well I’ve fallen at the first hurdle, because I can’t work out the location of the chest in order to upload those files to that form…

I’m also more confused now though…because the reply said to send this as a false positive, however the link in the other reply about aspnet_compiler.exe says it’s very harmful malware…how can I tell which it is?!

Well I've fallen at the first hurdle, because I can't work out the location of the chest in order to upload those files to that form....
https://forum.avast.com/index.php?topic=14433.msg1289438#msg1289438

Hey guys, had these two pop up as well today.

One happened without a scan, the other happened in a scan.

Any idea if this is a real threat or a FP?

Thank you. This is a False positive and should be fixed now.

Milos

Hello,

So, I finally managed to do a full system scan rather than the smart one (it took 3 hours…is that normal or do I just have a lot of junk on my laptop?! LOL). It found a third item with the same aspnet_compiler.exe:

Threat Name: Win32:Malware-gen Infected file: aspnet_compiler.exe
Original location: C:$WINDOWS.~BT\NewOS\Windows\WinSxS\x86_aspnet_compiler_b03f5f7f11d50a3a_10.0.16299.15_none_33dac4e0b5d00f53

I still can’t figure out how to use that submit false positive form, I can’t find the files in the file browser (the only folder named ‘chest’ I navigate to is empty). So instead I’ve submitted them as a false positive using the feature in the Avast interface, however it says that there won’t be a response, so I’m unsure how to proceed from here?

Thanks!

I still can't figure out how to use that submit false positive form, I can't find the files in the file browser (the only folder named 'chest' I navigate to is empty). So instead I've submitted them as a false positive using the feature in the Avast interface, however it says that there won't be a response, so I'm unsure how to proceed from here?
You can't browse to the chest/quarantine, it is a protected area. You have to restore (to orginal location, avast may detect again) or extract (to a new folder) the file before you can use the form

-Create a new folder on your desktop and name it … false positive ( you can name it anything)
-exlude that folder from avast scan
-extract file to that folder

Hi Pondus,

Sorry, still struggling!

If I right click on the file/files in the chest (like the walkthrough says), nothing happens, it doesn’t give me any options.

The only things I can do with the files in the chest in the Avast interface are ‘delete’ ‘restore’ or ‘send for analysis’ (which I’ve already done).

My Avast updated last month, maybe the extraction option was changed or removed?

I appreciate your help.

My Avast updated last month, maybe the extraction option was changed or removed?
Hmmm ... maybe, I don't use it anymore so don't know

Same here, Its in the virus chest also.

Interesting note I cant do the win10 update, it wont finish and reverest back, I’m wondering if this is a FP? Any updates?

Hellos,
send us the detected file, please (https://www.avast.com/false-positive-file-form.php). Or post a Virustotal link of the scanned file (or its sha256).

Milos