PDA

View Full Version : anyone seeing this after the last update in AVG 8?


robinb9
August 2nd, 2008, 04:02 PM
after the last update AVG 8.0 popped up and said there was this Trojan horse Generic11.clr in the files below and one in c:/System Volume Information\_restore,,,,,

c:\windows\system32\spool\drivers\w32x86\3\hpztbu06.exe
and \\(name of machine)\print$\W32X86\3\hpztbu07.exe

Every machine that is connected to my network and using the hp desktjet 5550 is getting the same message from AVG

What triggered it is when i went to print something.

I never saw this before. I have not updated this driver recently and did not install any new software for it.

I ran superantispyware pro and it is coming up clean.

I sent an analysis to AVG- have not heard as of yet

So what gives?

robin

EliteKiller
August 2nd, 2008, 04:13 PM
It's a FP

FWIW it's better to scan a file using virustotal.com or virscan.org than relying on SAS by itself.

robinb9
August 2nd, 2008, 04:19 PM
-{ Quote: "It's a FP

FWIW it's better to scan a file using virustotal.com or virscan.org than relying on SAS by itself." }-

true but i wanted to see if SAS would find anything or anything else. It has never let me down.

btw i went here and it says it is a fp

http://www.bleepingcomputer.com/startups/hpztsb05.exe-2016.html

now all we need is avg to look in here and put an update so avg stops screaming here.

robin

JRViejo
August 2nd, 2008, 04:23 PM
Try their latest update: AVI 270.5.10/ 1587 and see if they have included your FP.

robinb9
August 2nd, 2008, 05:39 PM
Just did a manual update and saw the version you typed.
I restored the 3 files in the virus vault
seems it did
I did a specific scan on windows/system32/ folder and it now comes up clean.

They must have seen my post here or the analysis I sent to them

thanks
robin

JRViejo
August 2nd, 2008, 09:45 PM
robinb9, more than likely AVG saw the analysis you sent them, rather than look in here (they've been too busy lately). Whenever I have sent them a False Positive, AVG has responded with an update within 2 hours or less.

BTW, I use the program's Manual Update every time and I do so by keeping track of AVG updates here: Wilders Update Alerts (http://www.wilderssecurity.com/forumdisplay.php?f=34) since the members & staff do a wonderful job of keeping current on software changes. Just FYI.

hex_614
August 5th, 2008, 09:49 AM
yes AVG is good when it comes to listening to thier client wheather using paid or free versions. ive sent many files to them for analysis and they are replying in the soonest possible time. i did submit a new found trojan which was not yet included in thier database. they are very much thankful to me. the trojan was named Worm/Autoit.BTK. i was the one who submit to them the sample file.

Firecat
August 5th, 2008, 12:41 PM
Heck, AVG even adds samples sent by people who are not users of their product. I really appreciate the quick response from AVG on sample submissions - I have sent a few in the past and they were all added within the next 3 updates. :)