AVG 8 suddenly reporting a large number of "warnings"

Discussion in 'Malware Help (A Specialist Will Reply)' started by a_hansen, May 13, 2008.

  1. a_hansen

    a_hansen Private E-2

    Hi!

    I kicked out avg 7.5 free and installed avg 8.0 free. Don't know if the new version is being overly sensitive, but scanning the hard drive the updated avg it is finding a variety of threats connected to a number of registry values. Both vundo and virtumonde is called ("adware"), and there is also a number of number of "trojans"/"downloaders".

    None of the threats reported are actual files/executables, only registry entries. After the scan, the conclusion is I have no infections, no spyware but 219 "warnings".

    I am not experiencing very many symptoms of malware. I have noticed that some certain site never showes me the embedded pics, as well as having noticed that spybot never seems to be releasing any updates, which actually has been bugging me for some weeks. Maybe also some lagginess when browsing. Other than that, nothing.

    Besides avg 8, my protection includes zone alarm and spyware blaster. I am regularly scanning with spybot (+immunization) and a2.

    AVG 8 log is included. Please tell me if I should continue with the "Read and run me first".

    Thanks.
     

    Attached Files:

  2. abri

    abri MajorGeek

    Hi a_hansen,
    Welcome to Major Geeks!


    To check the validity of AVG's claims, you may want to go through the READ & RUN ME FIRST and attach the requested logs so we can see if there is any malware showing up that would confirm these findings.

    There have been some issues with AVG's upgrade to 8.0. I recommend going back to 7.5 until they've worked out the problems.

    abri
     
  3. a_hansen

    a_hansen Private E-2

    Hi abri,
    thanks for your reply. I have also considered reverting to avg 7.5 due to the supposedly larger footprint of avg 8.0. What would be your first choice - going back to 7.5 and choose to forget about the lengthy list of trojan warnings or digging in to the read and run me?

    It is past midnight here so I will check back in tomorrow morning.

    Thanks.
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Most if not all of those detections are just AVG8 finding the Active X settings that were put into your registry by Spyware Blaster, Spybot, or similar to block bad active X controls. Thus these Warnings (note they are not infections) are mostly false indications. A few of them could possibly be valid. What really matters is the values of the compatibility flag. If the flag is set to 1000 ( which is 0x400 hex) then the kill bit is set to block. See: http://support.microsoft.com/kb/240797
     
  5. a_hansen

    a_hansen Private E-2

    chaslang,
    thanks for your reply. What you are saying makes sense. I don't understand "the values of the compatibility flag", though.

    Furthermore, all these 219 "warnings" have now been sent to the virus vault. Following your thinking, does that equal inhibiting the spyware blaster/spybot protection? If so, should I restore these items from the vault?
     
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Each Active X CLSID registry key has a subkey named Compatibility Flags and the values of this if set to 1024 will block the active x control. For example from the log you posted the first 4 CLSIDs from that log are:

    {00000001-C003-4A2F-9142-7CB1D78DE6C1}
    {00000049-8F91-4D9C-9573-F016E7626484}
    {00110011-4B0B-44D5-9718-90C88817369B}
    {002AF282-E42D-4B51-9F70-F1570C02FAAD}

    If those keys are looked at with a registry editor and then you look at the Compatibility Flags subkey to see the value then you will see the important information. There will be thousands of CLSIDs under the HKLM\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\ base key.
     
  7. a_hansen

    a_hansen Private E-2

    OK. So examining the keys in regedit would tell us if these are blocks created by spyware blaster. If that is the case, would keeping them in the virus vault inhibit protection? And would the right action be to restore them from the vault?
     
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes unless the programs that put them there automatically put the protection back and I don't think that would be the case for Spyware Blaster unless you run it again and put the protection back in place. You could have other software adding similar protection.

    Yes! Then you could look at the flags to see the values.
     
  9. a_hansen

    a_hansen Private E-2

    I see. Will check this out further tomorrow. It seems the new avg is not meant to be used side by side with additional malware protection. Thanks this far!
     
  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Once we know that those flags are set to 1024 ( 0x400 hex) then we will know if it is just a false warning issue. I suspect it is just a matter of them getting around to updating their program to include these activeX keys and values that they may not know about yet.
     
  11. a_hansen

    a_hansen Private E-2

    The thing is that all of the HKLM entries avg was shouting about are missing the Compatibility Flag all together. Every other key in the long list of HKLM\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\... has a Compatibility Flag subkey set to 1024/0x400, but not these. What does that tell us?
     
  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    It could be an effect of what AVG did in trying to fix the problems. Here is what I suggest, run AVG again and make sure that you choose to fix (i.e., quarantine or delete) the problems that it finds. Then make sure that you empty the AVG quarantine. Now reboot your PC and run another scan after the reboot. What is the result of this last scan?
     
  13. a_hansen

    a_hansen Private E-2

    Will follow your advice tomorrow, it's bedtime over here!
     
  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    No problem! Attach a new log if anything is found by the last scan.
     
  15. a_hansen

    a_hansen Private E-2

    Hi chaslang,
    yes your assumption was correct. There is actually a direct correlation between the active x protection of spyware blaster and the warnings of avg 8. Removing the quarantined objects, disabling all the protection of spyware blaster, restarting the PC and rescanning with avg ended in a clean result. Reenabling spyware blaster made the avg warnings come back.

    For now I would like to revert to AVG 7.5 (or maybe give NOD32 a try). Do you happen to be aware of a trustworthy link to AVG 7.5?

    Many thanks
     
  16. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Not off the top of my head and I don't believe they are going to support updates for it either since version 8 is released.

    Grisoft knows of the problem but their answer is not correct. They need to rewrite their software to look for the value of the flag not the fact that the CLSID is present. See the below:

    http://www.grisoft.com/ww.faq.num-1067

    They do not even detect all of the entries that programs like Spybot and Spyware Blaster put here. So are they also saying that they don't properly detect all of those other activeX issues!!!!

    If this issue does not get resolved, we may need to pull AVG from the recommed antivirus list since it will be quite annoying!!!
     
    Last edited: May 15, 2008
  17. a_hansen

    a_hansen Private E-2

    Right, I will find a link via the avg free forums. Grisoft will support AVG 7.5 with updates all through 2008 it seems.

    I will take this opportunity to express my admiration of the malware forums at majorgeeks. I am actually visiting this place several times a week just to enjoy the way you guys work to find a solution to malware problems. You chaslang has always come through to me as a true artist in this field of work and following your skills is a pleasure.

    Nowadays your procedures have become more standardized, which must be a blessing, but I still have a hard time understanding how you guys find the energy on a daily basis to be present here and still combine this effort with the rest of your daily chores. I mean, you could get paid to do this. Or at least provide the option to donate.

    Enough from me and once more, thank you!

    EDIT: Posted prior to seeing the addition to your post. Agreed, if avg does not fix this it will be very annoying to use.
     
  18. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Thanks for the kudos! :)

    You're welcome and surf safely!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds