file reputation warning for windowsupdate.com?!

Today avast warned me about what appears to be a file from windows update. I don’t know whether I should block it or not. I’m assuming that this must be some sort of spoof or something designed to just look like it’s from windows update, because why would avast warn me about a real windows update file directly from Microsoft? That’s just crazy. I would guess actual windowsupdate.com files would be on some sort of whitelist and would be ignored.

The avast dialog won’t let me cut and paste the details for some reason (GRRRRRRRRRRR)

File: windows-kb890830-v5.32_aed6c556d7a508c05a3d0acc9468c4760eb1141c.exe
Origin: http://000390-1.l.windowsupdate.com/llnhost_au.download.windowsupdate.com/
Digital signature: Not present
Signed by:
Downloaded by: C:\Windows\System32\svchost.exe

https://forum.avast.com/index.php?topic=177883.msg1262134#msg1262134

Hi Eddy,

I see you found another user with the same problem. I’m not really seeing any helpful info in that thread though (and it ends with an unanswered question).

I probably should have mentioned that I also regularly get these same warnings for the coupons.com coupon printer, which I find almost equally as crazy as that is almost certainly used by a very large number of users as well…

I would like to know:

  1. how can I determine if this is a real windows update file or some sort of spoof that could actually infect my computer?
  2. how do I stop warnings for false positives from windowsupdate.com?
The avast dialog won't let me cut and paste the details for some reason (GRRRRRRRRRRR)
easy soultion is screenshot ;)

file reputation may happen with new files that few use.
there is always the option to upload and test file(s) at www.virustotal.com / www.metascan-online.com
if tested before always click rescan for a fresh result

It is safe. It is Windows Malicious Software Removal Tool.

I see you found another user with the same problem
It is not a problem. It is just a warning that the file (up to that moment) is downloaded by a lot of avast users. Nothing more, nothing less.
I'm not really seeing any helpful info in that thread though
I pointed you to a post from avast member that tells what it is (Jeff).
  1. You can always lookup who owns the domain/IP

  2. It is not a false positive. Nothing malicious is detected.