• There seems to be an uptick in Political comments in recent months. Those of us who are long time members of the site know that Political and Religious content has been banned for years. Nothing has changed. Please leave all political and religious comments out of the forums.

    If you recently joined the forums you were not presented with this restriction in the terms of service. This was due to a conversion error when we went from vBulletin to Xenforo. We have updated our terms of service to reflect these corrections.

    Please note any post refering to a politician will be considered political even if it is intended to be humor. Our experience is these topics have a way of dividing the forums and causing deep resentment among members. It is a poison to the community. We appreciate compliance with the rules.

    The Staff of SOH

  • Server side Maintenance is done. We still have an update to the forum software to run but that one will have to wait for a better time.

AVG users BEWARE

dominique

Charter Member
My wife's laptop just got hit by this false positive which brings AVG to wrongly isolate a file needed to start up XP :censored:.

AVG virus scanner removes critical Windows file

Nov.10, 2008 in News
An update for the AVG virus scanner released yesterday contained an incorrect virus signature, which led it to think user32.dll contained the Trojan Horses PSW.Banker4.APSA or Generic9TBN. AVG then recommended deleting this file; this causes the affected systems to either stop booting or go into a continuous reboot cycle. So far, the problem only appears to affect Windows XP, but there is no guarantee that other versions of Windows don’t have the same issue.
avg_user32_dll.png

Both AVG 7.5 and AVG 8.0 were affected by the update; a revised signature database has just been published that corrects this issue. People that have removed the user32.dll can either boot from their original Windows CD and choose the repair option, or use another CD to boot from and restore the file from C:\Windows\System32\dllcache. If you happen to need a bootable CD: my personal favorite is the Ultimate Boot CD (mirror of UBCD 4.1.1 ISO).
AVG claims to have approximately 80 million users worldwide; there is no official reaction on the AVG website yet, but FAQ item 1574 in their support section covers a “False positive user32.dll” and offers some advice on restoring your system using the Windows Recovery Console.
AVG’s popularity stems mainly from the free version they offer for home users; if you’re looking for an alternative free virus scanner for Windows I highly recommend Avast!. ClamWin is another alternative; it’s a Windows port of the popular Linux scanner ClamAV.
Update:AVG has responded on their forum, but there is no press release or other info on their main website yet, other than the info in their FAQ. The response in the forum:
Unfortunately, the previous virus database might have detected the
mentioned virus on legitimate files. We can confirm that it was a
false alarm. We have immediately released a new virus update
(270.9.0/1778) that removes the false positive detection on this file.
Please update your AVG and check your files again.
[...]
We are sorry for the inconvenience and thank you for your help.
Update 2: According to comments at ghacks, users of AVG version 7.5 might have an easier alternative: reboot in safe mode and disable the scanner, then update to the latest version.
Update 3: A reader suggested Avira as another alternative free virus scanner; I’ve never heard of it, but you can check it out here. And of course, if your virus scanner should ever detect a file that looks to you like a false positive, head over to virustotal.com and submit it to all major virus scanners at once!
 
Yikes! That's a pretty awesome screw-up!

I have it on my laptop, but have not booted in to windows for a few days, so it blew past me. Thank goodness!
 
I used it until recently and had that same warning a lot,but would never let it delete the file.Got rid of it and downloaded Avast,much better program.
 
i think i was spared b.c i cancelled the virus scan this morning as i was doing homework (im serious dont laugh :p) and the scan slows my pc down... sooo will i be safe for tomorow? have they released an update to fix this yet? hmm my scan starts at 8 am EST:isadizzy:
 
No problem so far with 8.0 Free. I had a Trojan that SpySweeper found the other day but it was unrelated to the win32 Trojan.
 
According to AVG only the updates for the following languages were affected: French, Dutch, Italian, Portuguese en Spanish. The English version was not affected. PCs with Vista or with XP SP3 were not affected as well.

Huub
 
According to AVG only the updates for the following languages were affected: French, Dutch, Italian, Portuguese en Spanish. The English version was not affected. PCs with Vista or with XP SP3 were not affected as well.

Huub

My wife's laptop which was affected uses the English version with XP SP2 (XP being the French version though). And my deskstop using this english version showed the false positive too...

The alert is now over anyway as AVG has changed the database. I JUST have to reinsert the dll in a puter which doesn't boot :icon_lol:. I keep AVG stiil, as it has served me well otherwise for the past few years.
 
Back
Top