Avast Business Pro with the on-premises console.
Program version: 22.4.2699
Pattern file: 220811-4 (or perhaps 3; didn’t check the particular machine)
Any idea why some unknown Avast shield would quarantine:
c:\Windows\System32\spool\drivers\x64\Old\1\PrintConfig.dll
The user is working remotely and uses a local USB (not network) printer.
The user was just upgraded from Windows 10 Pro 64-bit 20H2 to 21H2 prior to this event.
The Avast event message does not say what shield detected this and quarantined it. A manual scan was NOT being run at the time.
I can probably get the file and upload it to Avast for analysis but that will take some work, so does anyone have any thoughts on this before I take the time to do that?
Thanks.