ncs2dmix.dll Win32:Dropper-gen [Drp] F/P

Avast! quick scan VPS 140317-0 and 140317-1 detected:

C:\WINDOWS\system32[b]ncs2dmix.dll[/b]
C:\i386[b]ncs2dmix.dll[/b]

as Win32:Dropper-gen[Drp] in my system. The only analyzers in Virus Total to detect this file are avast! and GData:
https://www.virustotal.com/en/file/0dfd548157dbf7cdeb6ffbac851bb1ac3ecc5df3f57dd2437c20dceeb654fcfe/analysis/1395095829/

This file belogs to Intel Proset for Windows Device Manager so I am pretty sure it is a F/P. File was sent to avast! lab for verification.

Nada yet. Vps 140318-0 and 140318-01 still detect de file. Worst, it is detecting it in system restore now with File System Shield >:(

Hey avast! you are usually fast at fixing these F/P, or is it because is and old XP file and no one else is reporting it ?

BTW no answer in e-mail confirming it is not a F/P.

when I sending a file to be added to the detection
sometimes get some response
but this is difficult

I will try to solve your problem

Reporting to virus analyst

Hola Jefferson.

Yes I could have sent to Milos, but I thought it might be better to post it here for others to see. Usually avast! lab is fast at fixing F/P.

Thanks

I do not know what’s going on
because a week ago I sent a file and so far nothing
maybe virus lab not received.

Already fixed in VPS 140319-1 update.

When you say this is fixed, does that mean this file is ok to use? I just ran Avast boot scan last night, 3/20/2014, and it was moved to the chest. Should I restore it, assuming I know how to restore?

Nick Geti

hello

exactly, open the virus chest
click on restore options and add exclusions
it is still being detected
send the file to virus@avast.com, put “False positive” to email subject,compressed in ZIP or RAR.

Why did you run a Boot Time scan? It’s not needed unless Avast! found something in the FullScan.

Not quite. It was fixed with 140320-0 or 20-1. Sorry for my late answer. I’ve been busy, and thanks to avast! to resolve this F/P.

Hi Nick.

It was fixed with VPS 140320-0. That means that avast! is not detecting that file as a Dropper; However, there are several versions of the file. Some are signed others not. Some are more uptodate than others, mine was old an unknown. May be the one you have is another version and avast! is still detecting it.

Do as Santiago said and send it to avast! lab. After you have it restored send it to Virus Total for analysis. Let see what it finds. Report results.