PDA

View Full Version : Switch from ewido (paid) to AVG 7.5 Anti-Spyware


Okanagan
October 13th, 2006, 12:27 AM
Before I switch to the new AVG 7.5 Anti-Spyware, could someone please tell
me what is the procedure of three quarantined files, that are still in ewido?

C:\WINDOWS\Setup1.exe (infected with) Backdor.Agobot.xb
C:Documents and Settings\ (My name)\Desktop\Incoming\sprint32.exe
(infected with) Backdoor.Agobot.xb
C:\Documents and Settings\(My name)\Desktop\Incoming\ptclpvue-setup.exe

This happened on Jul. 28 -06, PC is running OK so far.
Your answers are always appreciated, thank you.

karl.ewido
October 13th, 2006, 05:25 AM
Please send us copies of these quarantined files:
http://www.ewido.net/en/malware/

Okanagan
October 13th, 2006, 12:50 PM
Done.

Okanagan
October 13th, 2006, 11:34 PM
Done.
What I meant, is, I sent the report to ewido.

I still haven't got a clue what to do???

karl.ewido
October 16th, 2006, 09:53 AM
Did you send us only the quarantined Setup1.exe or also the other files? Please try to send us also the other files (sprint32.exe and ptclpvue-setup.exe). Thanks

Okanagan
October 18th, 2006, 12:17 AM
Dear User,

please restore the Setup1.exe file because this is not a Backdoor. This
false positive will be fixed with the next updates.

.ca wrote:
> C:WINDOWS\Setup1.exe Backdoor.Agobot.xb Risk: High 7/28/06
>
> C:Documents and Settings\Richard Golda\
> Desktop\INCOMING\sprint32.exe
> Backdoor.Agobot.xb Risk: High 7\28\06
>
> C:Documents and Settings\Richard Golda\
> Desktop\INCOMING\ptclpvue-setup.exe
> Backdoor.Agobot.xb Risk: High 7/28/06 All these are quarantined, PC is running OK

This is what ewido answered me. I have not restored the C:WINDOWS\
Setup1.exe file so far.Still wondering about the other two files before changing anything.
Please inform me of any additional changes. Thank you.

karl.ewido
October 18th, 2006, 07:09 AM
Please send us also the other quarantined files (sprint32.exe and ptclpvue-setup.exe)

Okanagan
October 18th, 2006, 12:37 PM
ewido anti-spyware-Scan Report
+ created at: 10:42:29 AM 7/28/2006
+ Scan result"

C:\Documents and Settings\Richard Golda\Desktop\INCOMING\ptclpv-
setup.exe/PTClpVue.CAB/SETUP1.EXE->Backdoor.Agobot.xb :Cleaned with
backup (quarantined)

C:Documents and Settings\Richard Golda\Desktop\INCOMING\sprint32.exe/
SreenPrint32.CAB/SETUP1.EXE->Backdoor.Agobot.xb :Cleaned with with
backup (quarantined)

Report end