Computer Help and Spyware Removal Computer Help and Spyware Removal Computer Help and Spyware Removal Computer Help Forums Windows Startup Programs Database Spyware and Malware Removal Guides Computer Tutorials Uninstall Database File Database Computer Glossary Computer Resources
 

Welcome Guest ( Log In | Click here to Register a free account now! )



Register a free account to unlock additional features at BleepingComputer.com
Welcome to Bleeping Computer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.
Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

 
Reply to this topicStart new topic
> Avg Free Edition Anti-virus Scan, Test Results - Clarification?
Anonix
post Jan 22 2008, 03:52 PM
Post #1


New Member
*

Group: Members
Posts: 13
Joined: 22-January 08
Member No.: 185,322



Using Mozilla browser, I ran an AVG scan of my computer and in 'test result' (under the virus results tab) the following appears:

listed as 'object':
c:\windows\systems32\shell32.dll
c:\windows\system32\drivers\etc\hosts

next to each object, the "result" is listed as "change"
next to "result" column, the status is listed as "changed"

i have been seeing these "objects" for awhile now in the scans (a few weeks), but did not know how to read it. i thought 'change' meant that AVG had fixed it.

on the latest scan, i was asked if i wanted to accept the (i think) registry changes. i accepted them.

where do i go from here?

thanks in advance.
Go to the top of the page
 
+Quote Post
garmanma
post Jan 22 2008, 04:10 PM
Post #2


Computer Masochist
******

Group: Moderator
Posts: 10,660
Joined: 27-January 07
From: Cleveland, Ohio
Member No.: 108,618



Is the icon by it red or green? If you right-click on the object of concern it should give you more detailed results
Mark

This post has been edited by garmanma: Jan 22 2008, 04:11 PM


--------------------
Mark

why won't my laptop work?

Having grandkids is God's way of giving you a 2nd chance because you were too busy working your butt off the 1st time around
Avatar by Handplane
Go to the top of the page
 
+Quote Post
Anonix
post Jan 22 2008, 04:22 PM
Post #3


New Member
*

Group: Members
Posts: 13
Joined: 22-January 08
Member No.: 185,322



QUOTE(garmanma @ Jan 22 2008, 01:10 PM) *
Is the icon by it red or green? If you right-click on the object of concern it should give you more detailed results
Mark


When I right click these virus results, it describes the paths (listed above) and the 'result' as 'change'. There is no other detail.

While in the virus results tab view, the only icon visible is a blue "I" icon -- nothing red or green -- immediately to the left of the "object' path names.

If I am in 'results overview' tab view, then two green arrows point to "general properties" and "object summary".

The test results do not report any 'threats', but these two objects repeatedly show up in the 'virus results' tab.

Thoughts?
Go to the top of the page
 
+Quote Post
usasma
post Jan 22 2008, 04:31 PM
Post #4


Still visually handicapped, new avatar :0)
******

Group: Global Moderator
Posts: 15,531
Joined: 2-October 05
From: Southeastern CT, USA
Member No.: 35,824



Something is changing your shell32.dll and your HOSTS file - do you have any tweaking programs or custom security programs that could be doing this to protect you?


--------------------
- John
**If you need a more detailed explanation, please ask for it. I have the Knack. **
BTW - the avatar pic is a camel as it looks back at me while I'm in the saddle (and he wasn't happy!)
Go to the top of the page
 
+Quote Post
Anonix
post Jan 22 2008, 04:51 PM
Post #5


New Member
*

Group: Members
Posts: 13
Joined: 22-January 08
Member No.: 185,322



QUOTE(usasma @ Jan 22 2008, 01:31 PM) *
Something is changing your shell32.dll and your HOSTS file - do you have any tweaking programs or custom security programs that could be doing this to protect you?


I have SpyBot S&D and AVG AntiVirus installed (WinXP Pro). Recently added AVG's rootkit detector. I occasionally run other security software if it looks to be of use, although I also usually delete any files when done. My router has a good firewall. Have the latest browser versions, keep MSFT updated, etc. No 'custom' security programs that I know of. I will take a look at add/remove programs to see if I can find anything unusual. I will also check all program files to look for anything unrecognizeable. AVG's calling these viruses, but I'm not convinced. They are not showing up as 'threats' in the test results. One of those objects is related to the system restore function, which I should be able to reset to MSFT's default setting. Not sure about the 'hosts' file.
Go to the top of the page
 
+Quote Post
usasma
post Jan 22 2008, 04:58 PM
Post #6


Still visually handicapped, new avatar :0)
******

Group: Global Moderator
Posts: 15,531
Joined: 2-October 05
From: Southeastern CT, USA
Member No.: 35,824



I suspect that SpyBot Search and Destroy is doing this. But, to be safe, I'd perform a free, online scan to verify that nothing has gotten past your current protection software. Try these:

http://safety.live.com (requires IE)
http://housecall.trendmicro.com

If they come up clean, then I'd suspect that the results were normal and would just keep an eye on them.


--------------------
- John
**If you need a more detailed explanation, please ask for it. I have the Knack. **
BTW - the avatar pic is a camel as it looks back at me while I'm in the saddle (and he wasn't happy!)
Go to the top of the page
 
+Quote Post
Anonix
post Jan 22 2008, 05:14 PM
Post #7


New Member
*

Group: Members
Posts: 13
Joined: 22-January 08
Member No.: 185,322



QUOTE(usasma @ Jan 22 2008, 01:58 PM) *
I suspect that SpyBot Search and Destroy is doing this. But, to be safe, I'd perform a free, online scan to verify that nothing has gotten past your current protection software. Try these:

http://safety.live.com (requires IE)
http://housecall.trendmicro.com

If they come up clean, then I'd suspect that the results were normal and would just keep an eye on them.


Thanks. I've run a bunch of tests (housecall among them) and am coming up clean. Here's what someone else had to say in a Yahoo forum. I think it's by some updates or install/uninstalls (which I do a fair amount of). I'm not going to worry about it. But will keep an eye on program files, etc.

Hi Northman
Dont fret thats normal... its detected a chnage since it last did a check, but if you installed or removed anything or updated anything then of course it will change, there normally 2 or 3 it finds, but this is basically to warn you thats these files have changed.
As the person aboves says it good and its free, but if you want the best, then its kapersky AV or NOD32 or similar, but these will cost around 25-35 each for one year. If you not happy with AVG (i use it myself) then try Avast its also free, just google avast, but its not as simple to use (in my opinion).
Hope this helps.... Good Luck
Go to the top of the page
 
+Quote Post
ruby1
post Jan 22 2008, 05:16 PM
Post #8


a forum member
******

Group: Members
Posts: 2,360
Joined: 27-August 07
Member No.: 153,171



a long -shot but....have you ever knowingly been to

http://www.mvps.org/winhelp2002/hosts.htm
and downloaded the Hosts file to your computer ?
Go to the top of the page
 
+Quote Post
Dialer
post Jan 22 2008, 07:04 PM
Post #9


Distinguished Member
*****

Group: Members
Posts: 642
Joined: 4-November 07
From: The Great State of Disarray
Member No.: 167,506



QUOTE(usasma @ Jan 22 2008, 02:58 PM) *
I suspect that SpyBot Search and Destroy is doing this.

I think you you might be right about this, usasma. Wendy K. Walker made mention of the same thing in this recent thread:

http://www.bleepingcomputer.com/forums/topic126343.html


--------------------
Go to the top of the page
 
+Quote Post
Softix
post Jan 23 2008, 12:14 AM
Post #10


New Member
*

Group: Members
Posts: 5
Joined: 22-January 08
Member No.: 185,419



QUOTE(usasma @ Jan 22 2008, 04:58 PM) *
I suspect that SpyBot Search and Destroy is doing this. But, to be safe, I'd perform a free, online scan to verify that nothing has gotten past your current protection software. Try these:

http://safety.live.com (requires IE)
http://housecall.trendmicro.com

If they come up clean, then I'd suspect that the results were normal and would just keep an eye on them.



HI I would like to asked if this type of program is applicable in any times of OS?. I am running AVG as well and might as well try it out too to see if my system is clean .


--------------------
Go to the top of the page
 
+Quote Post

Reply to this topicStart new topic
1 User(s) are reading this topic (1 Guests and 0 Anonymous Users)
0 Members:

 



Lo-Fi Version Time is now: 9th January 2009 - 04:24 AM


Advertise   |   About Us   |   Terms of Use   |   Privacy Policy   |   Contact Us   |   Site Map   |   Chat   |   Tutorials   |   Uninstall List
Discussion Forums   |   The Computer Glossary   |   Resources   |   RSS Feeds   |   Startups   |   The File Database   |   Malware Removal Guides

© 2003-2008 All Rights Reserved Bleeping Computer LLC.