Home   News  Product reviews  Website reviews  Forums   Competitions  Subscribe 

Security >> Security help
 |  Print Topic
Jump to first unread post. Pages: 1
cromwell1230
regular


Reg'd: Mon
Posts: 127
Loc: UK
AVG today detected I-Worm/Brontok.KO...how to deal with it?
      #399084 - Tue Jul 01 2008 09:35 AM

Scheduled scan by my AVG 7.5 Free Antivirus today detected I-Worm/Brontok.KO which was automatically healed by AVG. The file C:\Windows\$NtServicePackUninstall$\msconfig.exe has been deleted by AVG though a backup file copy remains in my Virus Vault. Can anyone(I know there are AVG experts here ) advise me on how to deal with this detection?

--------------------
Philips MT2700,Windows XP MCE(SP3),IE7 & FireFox3(default),AVG Free 8,CCleaner,SUPERAntispyware,F-Secure BlackLight AntiRootKit,ZoneAlarm Free 7.0.483


Post Extras: Print Post   Remind Me!   Notify Moderator  
heidi
regular


Reg'd: Sun
Posts: 273
Re: AVG today detected I-Worm/Brontok.KO...how to deal with it? [Re: cromwell1230]
      #399142 - Wed Jul 02 2008 01:41 AM

Early indications are that it's a false positive
http://www.autopatcher.com/forums/index.php?showtopic=645&pid=3609&st=0&#entry3609

http://virscan.org/report/67eef16a86ad0e262087befc15b8e8ea.html (red entry)

Maybe check back to official AVG Free Forum to see if any more enlightening tomorrow?
http://freeforum.avg.com/read.php?4,134859,backpage=,sv=

--------------------
ask4help.org.uk


Post Extras: Print Post   Remind Me!   Notify Moderator  
greystsModerator
regular


Reg'd: Thu
Posts: 17744
Loc: Colchester
Re: AVG today detected I-Worm/Brontok.KO...how to deal with it? [Re: cromwell1230]
      #399155 - Wed Jul 02 2008 10:45 AM

Perhaps if you upgraded to AVG 8.0 the problem would go away.

--------------------


Do you know that we're all in line for succession to the throne? Really?
Well, if forty-eight million, two hundred thousand, seven hundred and one people died I'd be Queen.


Post Extras: Print Post   Remind Me!   Notify Moderator  
cromwell1230
regular


Reg'd: Mon
Posts: 127
Loc: UK
Re: AVG today detected I-Worm/Brontok.KO...how to deal with it? [Re: greysts]
      #399173 - Wed Jul 02 2008 03:14 PM

I clicked "restore file" under Action in the AVG Virus Vault dialog box(after being convinced by my readings that it's a FP) but there wasn't any indication/confirmation from my AVG that the file msconfig.exe has really been restored. I was at least expecting a dialog box saying "file restored" before I empty my Virus Vault...otherwise I'd have the misery of not having the msconfig.exe file in my pc anymore. How can I be sure that indeed the msconfig.exe file that was deleted( in the process of automatic healing) by AVG has been restored properly? There was no detection by AVG in my pc today but I'm thinking it could be because:
1. I don't have the msconfig.exe file anymore or
2. I have already gotten(yesterday) the AVG virus DB update 1528

Thanks heidi for pointing me to the right direction! And yes greysts I'd upgrade to AVG8 after this. Can I install on top or do I have to uninstall AVG7.5 first? I have the McAfee SiteAdvisor and Finjan Secure Browsing add-ons in my Firefox...will I need the LinkScanner or maybe...what's best to have?

--------------------
Philips MT2700,Windows XP MCE(SP3),IE7 & FireFox3(default),AVG Free 8,CCleaner,SUPERAntispyware,F-Secure BlackLight AntiRootKit,ZoneAlarm Free 7.0.483


Post Extras: Print Post   Remind Me!   Notify Moderator  
heidi
regular


Reg'd: Sun
Posts: 273
Re: AVG today detected I-Worm/Brontok.KO...how to deal with it? [Re: cromwell1230]
      #399224 - Thu Jul 03 2008 01:16 AM

Sorry, my omission in not noting you were on version 7.5.
It's simple and a few seconds to remove AVG 7.5 via add/remove programs in Control Panel. As for the Linkscanner, it appears to be causing a few problems, Re installing without the Linkscanner see
http://free.avg.com/ww.faq.num-1241

If you're prefering not to use the Linkscanner, you might also consider whether to install the AVG Security Toolbar either, since the two work hand in hand
http://free.avg.com/ww.faq.num-1241

If you're going to upgrade you might want to consider your use of potentially conflicting programs (those with an immunise feature), such as Spywareblaster/Spybot. It's not that they won't work at all together, but AVG will pick up some ActiveX nasties that appear to relate to the afore-mentioned programs and their immunise feature. Then you need to be able to differentiate betwen real/not real problems. You might want to have a read of the following thread
http://www.webuser.co.uk/forums/showflat.php/Cat/0/Number/397207/an/0/page/0#397207

--------------------
ask4help.org.uk


Post Extras: Print Post   Remind Me!   Notify Moderator  
Pages: 1

Rate this topic

Jump to


Extra information
0 registered and 20 anonymous users are browsing this forum.

Moderator:  AndrewC, putasolutions, Joe_London, greysts, bricat, John_McKenna, Hello_There, Mouse, Nanook, TheFatControlleR, Noviciate 


Print Topic

Forum Permissions
      You cannot start new topics
      You cannot reply to topics
      HTML is disabled
      Mark-up is enabled

Rating:
Topic views: 0

Contact Us | Privacy statement Main website
Hitwise Top 10 Award Winner - Jan-Mar 2005

About us | Contact us | Link to us | Terms & Conditions | Privacy Policy
© Copyright IPC Media Limited, All rights reserved