AVG Virus Scanner Accidentally Removes Critical Windows Component
Short story is a bad definition that affected both AVG 7.5 and 8 caused the file user32.dll, a critical Windows component to be deleted.
AVG Virus Scanner Accidentally Removes Critical Windows Component
Started by AdvancedSetup, Feb 05 2009 08:56 PM
#2
Posted 05 February 2009 - 09:16 PM
That's old news. Caused a lot of problems.
False positives is a serious issue for av companies.
On the other hand, users must be careful too, especially with system files, something that its not easy for users without experience.
False positives is a serious issue for av companies.
On the other hand, users must be careful too, especially with system files, something that its not easy for users without experience.
#3
Posted 05 February 2009 - 10:10 PM
Yes, it's old news but I wanted to share it here since we've had a couple recent users think that MBAM is the only one around that has removed a valid file by accident.
Even the biggest AV Companies out there have run into this issue and removed valid files before.
Even the biggest AV Companies out there have run into this issue and removed valid files before.
#4
Posted 06 February 2009 - 06:38 AM
Kaspersky removed Explorer.exe a while back. That was serious and they took a lot of heat for it.
Kaspersky false alarm quarantines Windows Explorer
Kaspersky false alarm quarantines Windows Explorer
#5
Posted 06 February 2009 - 06:59 AM
Quote
Registry Data Items Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Userinit (Trojan.Agent) -> Data: c:\winnt\system32\userinit.exe -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Userinit (Trojan.Agent) -> Data: system32\userinit.exe -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Userinit (Trojan.Agent) -> Data: c:\winnt\system32\userinit.exe -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Userinit (Trojan.Agent) -> Data: system32\userinit.exe -> Quarantined and deleted successfully.
cureit from safe mode killed this computer
Quote
Infected copy of c:\windows\system32\userinit.exe was found and disinfected
Restored copy from - c:\windows\$NtServicePackUninstall$\userinit.exe
Restored copy from - c:\windows\$NtServicePackUninstall$\userinit.exe
combofix seems to handle it
Regards
Chewy the wild wookie
Chewy the wild wookie
#6
Posted 06 February 2009 - 10:04 AM
MBAM DOES NOT remove this file. It says it does, but it doesn't it's there as a marker for Experts to see and know it's infected and needs attention.
Combofix can potentially correct it IF there is a valid clean version it can locate on the drive. Sometimes there isn't or the Malware prevents access to it.
Combofix can potentially correct it IF there is a valid clean version it can locate on the drive. Sometimes there isn't or the Malware prevents access to it.
#7
Posted 06 February 2009 - 01:14 PM
MBAM only removed the offending key in the registry
Cureit deleted the infected system file
Quote
Dr Cureit... it found one: userinit.exe in WINT/System32... I told it to cure all and saw the status of it and showed it was deleted.
Cureit deleted the infected system file
Regards
Chewy the wild wookie
Chewy the wild wookie
#8
Posted 06 February 2009 - 09:14 PM
Well I would assume that Dr Web only removed it because like Combofix it found another valid copy on the system. If that file was removed and another not put in it's place the computer would not boot up and allow you to logon.
#9
Posted 06 February 2009 - 11:11 PM
Quote
If that file was removed and another not put in it's place the computer would not boot up and allow you to logon.
That's what the user claimed happened
Regards
Chewy the wild wookie
Chewy the wild wookie
#10
Posted 06 February 2009 - 11:40 PM
No problem. Some time when you're bored and have some extra time. Boot up with some type of WinPE disk and move or change the name of that file and make sure there is no other copy of it in a cache folder or elsewhere and then restart the PC and see if you can logon now.
#11
Posted 08 February 2009 - 04:34 PM
What safeguards does the MBAM team use to avoid a critical Windows component being flagged?
#12
Posted 08 February 2009 - 07:27 PM
An internal whitelist is just one stage of avoiding critical files.
#13
Posted 08 February 2009 - 10:48 PM
#14
Posted 09 February 2009 - 12:13 AM
Jamin4u said:
Would it be safe to say that most false positives happen during heuristic scanning?
At least two thirds of our database is heuristics, so yes, false positives are due to an error in heuristics. The research team fixes them as soon as they hear about them.
Quote
For we wrestle not against flesh and blood, but against principalities, against powers, and against the worldly governors, the princes of the darkness of this world...
#15
Posted 09 February 2009 - 12:32 AM
Thank you Marcin and Arthur for your time in answering my questions.
I think the team does an excellent job of responding to false positives.
Please allow me to ask one more question regarding false positives.
Does the team use test computers with various operating systems to test each database version before release?
I think the team does an excellent job of responding to false positives.
Please allow me to ask one more question regarding false positives.
Does the team use test computers with various operating systems to test each database version before release?
#16
Posted 12 February 2009 - 04:42 PM
Jamin4u said:
Does the team use test computers with various operating systems to test each database version before release?
That I don't know. Bruce didn't answer that question when I asked him.
I do know that the research team does not all use the same version of Windows. They do their research on both Windows XP and Windows Vista, and I would believe some of them use 2000 as well. I assume they have to test the database to make sure that each addition does remove what they expect it to remove, but I do not know any specifics about the testing that they do.
Quote
For we wrestle not against flesh and blood, but against principalities, against powers, and against the worldly governors, the princes of the darkness of this world...
#17
Posted 15 February 2009 - 08:36 PM
szgr, on Feb 5 2009, 10:16 PM, said:
False positives is a serious issue for av companies.
http://kb.bitdefender.com/KB519-en--Faulty...nlogon.exe.html
#18
Posted 15 February 2009 - 09:18 PM
No action required by the user as long as they did not reboot during that time. Otherwise it would be a big problem.
#19
Posted 26 May 2009 - 11:05 PM
Thank you for posting this, I had no idea.
I am an AVG user and I hope this hasn't happened to my system.
Do you know if there is a way to tell?
I am an AVG user and I hope this hasn't happened to my system.
Do you know if there is a way to tell?
AdvancedSetup, on Feb 5 2009, 03:56 PM, said:
AVG Virus Scanner Accidentally Removes Critical Windows Component
Short story is a bad definition that affected both AVG 7.5 and 8 caused the file user32.dll, a critical Windows component to be deleted.
Short story is a bad definition that affected both AVG 7.5 and 8 caused the file user32.dll, a critical Windows component to be deleted.
#20
Posted 26 May 2009 - 11:07 PM
You would know right away with an AV or AM scan. This is quite old now and was fixed I think the same day it happened so unless you happen to have had that version on that day and never updated again you won't have this issue.
1 user(s) are reading this topic
0 members, 1 guests, 0 anonymous users
Sign In
Create Account
This topic is locked


Back to top









