We previously posted a message regarding an issue we were seeing with the AVG Free and we have since collected a lot more information! We have posted in the AVG forums but no one seems to care so we'll keep blogging as we get more info gathered.
Computer: Dell Inspiron 600m
OS: Windows XP Pro SP2 (fully licensed, used on 50 + computers and loaded from the original Windows CD)
We installed the OS on our clients laptop on Feb 15, 2009. We installed the drivers downloaded from the Dell website and then started in on the back up files. We had previously scanned the external drive for malware and viruses, nothing was found. We had scanned it with AVG which was installed on one of our desktop computers with the database from Feb 14, 2009.
We then proceeded to download AVG Free. It was retrieved from Download.com (where we always go for this download as Grisoft doesn't host their own download). The version that was available at that time was 8.0.233. We also downloaded and installed Malwarebytes from download.com as well. That was the full extent of our online surfing. We then ran Malwarebytes and all hell broke loose. Every file it touched, AVG indicated it was infected and removed it.
Here is an example of the files that were detected as "threats"....
Virus found Win32/Virut";"C:\WINDOWS\Installer\{90280409-6000-11D3-8CFE-0050048383C9}\xlicons.exe";"Infected";"2/17/2009, 2:11:47 PM";"File";"C:\Program Files\AVG\AVG8\avgui.exe"
"Virus found Win32/Virut";"C:\WINDOWS\explorer.exe";"Object is in whitelist";"2/17/2009, 2:11:46 PM";"File";"C:\Program Files\AVG\AVG8\avgui.exe"
"Virus found Win32/Virut";"C:\WINDOWS\system32\notepad.exe";"Object is in whitelist";"2/17/2009, 2:09:49 PM";"File";"C:\WINDOWS\explorer.exe"
"Virus found Win32/Virut";"C:\WINDOWS\explorer.exe";"Object is in whitelist";"2/17/2009, 2:09:04 PM";"File";"C:\Program Files\AVG\AVG8\avgui.exe"
"Virus found Win32/Virut";"C:\WINDOWS\system32\dllcache\inetwiz.exe";"Infected";"2/17/2009, 2:08:47 PM";"File";"C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe"
Please not that the first file on that list is associated with AVG itself! We have since installed avg_free_stf_en_8_233a1415.exe (57.2mb) which was downloaded Feb 16, 2009 and is running on the work PC this message is being posted with; it works fine and we have run Malwarebytes and nothing has been detected by AVG at all.
Today we went back to the issue of the laptop and downloaded the version available today which is avg_free_stf_eng_8_237a1428.exe (58.1mb) and very obviously a DIFFERENT FILE form what we got yesterday. It once again began giving false positives and deleted uninfected Windows system files.
Tuesday, February 17, 2009
Subscribe to:
Post Comments (Atom)
No comments:
Post a Comment