Windows 10: Has anyone ever had a file from Microsoft.com get flagged as malicious? Is it safe?

Discus and support Has anyone ever had a file from Microsoft.com get flagged as malicious? Is it safe? in Windows 10 Software and Apps to solve the problem; Our firewall is identifying the file being downloaded from here... Discussion in 'Windows 10 Software and Apps' started by Dan B. Richardson, Dec 7, 2023.

  1. Has anyone ever had a file from Microsoft.com get flagged as malicious? Is it safe?


    Our firewall is identifying the file being downloaded from here 2.tlu.dl.delivery.mp.microsoft.com/filestreamingservice/files/3d3c4265-57fd-450e-9bda-9fb5f4612029?P1=1701954557&P2=404&P3=2&P4=McNpfOQj9mJNU0C3bPFht%2Brb6MQzXlXxM%2B6VlcZzMBgwIP8/k1abbXViSBH14culRunGhGVgsX7bgLiUEKCLKQ%3D%3D as being malicious. I have tried running the location and file through other malware tools for verification, but they come back as inconclusive. Based on my investigation, it appears that the traffic may be getting initiated though delivery optimization.

    :)
     
    Dan B. Richardson, Dec 7, 2023
    #1
  2. useruh Win User

    OneDriveUpdateTask.exe being flagged as malicious

    Hello, my PC is constantly executing the file "OneDriveUpdateTask.exe", which is creating temporary files that are being flagged as malicious by my antivirus software. I'm not sure if these are actually malicious or false flagged. Thank you for your time.
     
    useruh, Dec 7, 2023
    #2
  3. CuriousPC Win User
    system32 DLLs flagged as malicious

    I downloaded Autoruns to help me identify malware on my computer. My computer is experiencing incoming and outgoing connections to IPs that are flagged as malicious by Virustotal and/or AbuseIPDB. In addition to dropped connections.

    Initially 14 microsoft files were flagged as malicious by Virustotal.

    Msiexec.exe. Trojan.generic.c1.70. sangfor engine zero.

    ipsecsvc.dll.malicious

    Rasmans.dll. malicious. SecureAge

    Scardsvr.dll. malicious

    Schedsvc.dll.malicious

    Sessenv.dll. malicious

    umrdp.dll. malicious

    Workfoldersshell.dll. malicious

    gatherNetworkInfo.vbs. McAfee-GW-edition. BehavesLike.VBS.backdoor.mp.

    Appxdeploymentservrr.dll. malicious

    Bcastdvruserservice.dll. malicious

    dcsvc.dll. malicious

    ngccredprov.dll. malicious

    Updatepolicy.dll. malicious

    Here is the interesting part. I did a reformat and windows 10 pro 21H2 install. 9 of the above had no detections post install. gathernetworkinfo.vbc, ipsecsvc.dll, ngccredprov.dll were malicious. Three new dlls were flagged: installservicetasks.fll, smsroutersvc.dll, & xblauthmanager.dll. dcsvc.dll disappeared. I forgot to check updatepolicy.dll. I thought this is great progress. I discovered 21H2 19044.1288 was

    not the latest so I upgraded in place to 22H2. I thought after this upgrade there would be no more detections.

    After updates my current version is 22H2 19045.3208. Here is the bad news. 9 dlls that had no detections now have detections. Sessenv.dll still has no detection. Smsroutersvc.dll, xblauthmanager.dll, and installservicetasks.dll no longer have any detections. Updatepolicy.dll has no detection. Gathernetworkinfo.vbs , ipsecsvc.dll, and ngccredprov.dll still have detections. These results seem to rule out false positive.

    I need clean versions of the dlls. There may be more dlls that are malicious.

    I downloaded from www.microsoft.com/en-us/software-download/windows10

    Thanks
     
    CuriousPC, Dec 7, 2023
    #3
  4. InVasMani Win User

    Has anyone ever had a file from Microsoft.com get flagged as malicious? Is it safe?

    13 Major Vulnerabilities Discovered in AMD Zen Architecture, Including Backdoors

    It makes me think that Microsoft should just patch the OS itself to prevent all .bios files from being flashed w/o 2-step authentication first to safe guard against these malicious attacks. Something that important should be better guarded against for these kinds of exploits.
     
    InVasMani, Dec 7, 2023
    #4
Thema:

Has anyone ever had a file from Microsoft.com get flagged as malicious? Is it safe?

Loading...
  1. Has anyone ever had a file from Microsoft.com get flagged as malicious? Is it safe? - Similar Threads - Has anyone ever

  2. Has anyone ever had a file from Microsoft.com get flagged as malicious? Is it safe?

    in Windows 10 Gaming
    Has anyone ever had a file from Microsoft.com get flagged as malicious? Is it safe?: Our firewall is identifying the file being downloaded from here...
  3. Has anyone ever had a file from Microsoft.com get flagged as malicious? Is it safe?

    in AntiVirus, Firewalls and System Security
    Has anyone ever had a file from Microsoft.com get flagged as malicious? Is it safe?: Our firewall is identifying the file being downloaded from here...
  4. system32 DLLs flagged as malicious

    in Windows 10 Gaming
    system32 DLLs flagged as malicious: I downloaded Autoruns to help me identify malware on my computer. My computer is experiencing incoming and outgoing connections to IPs that are flagged as malicious by Virustotal and/or AbuseIPDB. In addition to dropped connections.Initially 14 microsoft files were flagged as...
  5. OneDriveUpdateTask.exe being flagged as malicious

    in Windows 10 Gaming
    OneDriveUpdateTask.exe being flagged as malicious: Hello, my PC is constantly executing the file "OneDriveUpdateTask.exe", which is creating temporary files that are being flagged as malicious by my antivirus software. I'm not sure if these are actually malicious or false flagged. Thank you for your time....
  6. Has anyone ever had this problem ? It also happens in the windows menu

    in Windows 10 Ask Insider
    Has anyone ever had this problem ? It also happens in the windows menu: [ATTACH] submitted by /u/IBeYaZ [link] [comments] https://www.reddit.com/r/Windows10/comments/wet2aq/has_anyone_ever_had_this_problem_it_also_happens/
  7. Malicious flag for Microsoft Official Website

    in AntiVirus, Firewalls and System Security
    Malicious flag for Microsoft Official Website: Why did one of the vendor Quttera flag MALICIOUS for Microsoft's Official Website in VirusTotal? https://answers.microsoft.com/en-us/protect/forum/all/malicious-flag-for-microsoft-official-website/17744723-e845-448c-8caf-bf35d42aed90
  8. Has anyone ever had this problem?

    in Windows 10 Ask Insider
    Has anyone ever had this problem?: [ATTACH] My work laptop is docked and has a i7-4700MQ and when I start it up after being powered off the max speed I can get is around 2.5GHz. It will stay like this until I put it to sleep and wake it up. The it'll run at 3.4GHz like it's suppose to. Has anyone had this...
  9. Microsoft Defender flags hosts files with Microsoft server redirects as malicious

    in Windows 10 News
    Microsoft Defender flags hosts files with Microsoft server redirects as malicious: The native antivirus client of the Windows 10 operating system, Microsoft Defender, has started to flag the hosts file on the system as malicious if it contains redirects for certain Microsoft servers. The hosts file is a simple plain text designed to redirect connections....
  10. Domain has been flagged as malicious

    in AntiVirus, Firewalls and System Security
    Domain has been flagged as malicious: The domain central-compliance.com was falsely reported by Microsoft in regards to being a phishing attack. These domains belong to a SaaS platform, PhishingBox. PhishingBox provides tools to generate simulated phishing campaigns for authorized clientele. We do not collect any...