Slashdot Log In
AVG Virus Scanner Removes Critical Windows File
Posted by
kdawson
on Monday November 10, @07:42PM
from the it-just-acts-like-one dept.
from the it-just-acts-like-one dept.
secmartin writes "The popular virus scanner AVG released an update yesterday that caused their software to mark user32.dll as a virus. Since this is a rather critical file, AVG's suggestion to remove it caused problems for users around the world who are now advised to restore the file through the Windows Recovery Console. AVG just posted an update about this (FAQ item 1574) in the support section of their site. Their forums are full of complaints."
Related Stories
The Fine Print: The following comments are owned by whoever posted them. We are not responsible for them in any way.
Full
Abbreviated
Hidden
Loading... please wait.

Well... (Score:5, Funny)
Reply to This
Re:Well... (Score:5, Funny)
When I read it, I thought the title was "AVG Virus Scanner Removes Critical Windows Flaw" ...
That would have been excellent sales technique. shame the reality is so very different.
Reply to This
Parent
Re:Well... (Score:5, Funny)
shame the reality is so very different.
It is?
Reply to This
Parent
Re:Well... (Score:5, Interesting)
This isn't too far from realistic.
I work for a firm that, through the power of politics, actually pays to use McAfee antivirus and related products. Now, this is a product that can sometimes detect a virus but can't remove it, whatsoever. Yet, it will produce an error message that prompts the end-user to "delete", "remove" or "ignore"... (something to this nature - it really doesn't matter since none of them work except "ignore").
Some of the technicians have resorted to using certain free applications to get rid of the viruses (virii?) when the end-users show up to the help desk, angry as all get. Recently, McAfee started preventing these various freeware packages from being installed - it simply detects them as viruses themselves!
You could say that McAfee is doing its job - it leaves the sales up to the politicians while it prevents the real software from doing the work.
What a hopeless, hopeless situation.
Reply to This
Parent
It's sad... (Score:5, Insightful)
Reply to This
Re:It's sad... (Score:5, Insightful)
Yes, they used to be very good, but they have gone all terrible. First, they started hiding all evidence to their free version from their website (you have to know to go to free.grisoft.com otherwise there is no link from their main website, though it is back up now), misleading licensing, then their version 8 started doing all sort of crap like hogging resources, scanning every weblink and generating massive amount of web traffic (though it can be turned off), and having bugs every week like marking legitimate files as infected and irritatingly requiring a computer restart every time you turn it on (requires a reinstall to fix it).
They have gone all shite, and I'm massively put off by them now, and I will recommend anyone against buying or using their stuff. They are just plain sloppy now, and frankly you don't want your first or second line of defence to be sloppy.
After our current license term expires, my company will be switching away to another vendor.
Reply to This
Parent
Re:It's sad... (Score:5, Informative)
Reply to This
Parent
Re:It's sad... (Score:5, Informative)
Go to the install directory and rename "avgresf.dll" and "afgmwdef_us.mht" (adding a .bak or whatever should work fine). I did this a few days ago and the notification bar is no more, with no apparent problems.
Also, don't tell anyone, to prevent AVG from changing it.
Reply to This
Parent
Re:It's sad... (Score:5, Funny)
"nearly 80% of all websites kill a kitten when you visit with out a spyware blocker?"
It's actually one of the HTTP status codes
463 - NO_MORE_KITTEN
Reply to This
Parent
Re:Arrr! (Score:5, Informative)
Reply to This
Parent
not what it seems (Score:5, Funny)
Reply to This
Should have gone for the gold... (Score:5, Funny)
Reply to This
Re:Should have gone for the gold... (Score:5, Funny)
You haven't used Microsoft software in a while, have you?
Reply to This
Parent
Setting itself apart from other software (Score:5, Interesting)
Damn. This is what I was hoping would never happen to AVG. After reading all the times that McAfee, Norton, and others had removed Office documents, Windows DLLs, and Office DLLs, I always had a smug chuckle available.
But now. Ah, well. Four years, 300 workstations, a dozen or more managed installations and still not a single infection or major problem for me using AVG.
Reply to This
It's done this before.. (Score:5, Funny)
I've been using AVG at customers sites since version 6.. It has, over the years, deleted entire outlook pst's, repeatedly uninstalled VNC servers and radmin, and generally been grumpy for the slightest reason.
I am a sucker for punishment, because I still keep using it. It's just as good as the rest, it's half the price, and noticably faster than all the others I've tried.
I think that, however, the entire concept of antivirus is going to have to fail, and we'll need a whitelist, rather than a blacklist.
There has been quite a bit of discussion about this over the years, and it's going to come true.
Oh. And as an added bonus, Slashdot is screwing up my display. When I load the page, I get the comments page, and then it clears and I get a spammy IBM flash ad of some sort. Serves me right for not installing ABP after a reinstall.
--Rob
Reply to This
We've had our eye on you for sometime now... (Score:5, Funny)
I'd like to share a revelation that I've had during my time here. It came to me when I tried to classify your operating systems and I realized that you're not actually cross platform. Every OS on this planet instinctively develops a natural equilibrium with the surrounding community but you Windows users do not. You move to a hardware manufacturer and you multiply and multiply until every desktop is consumed and the only way you can survive is to spread to another OEM. There is another organism on this planet that follows the same pattern. Do you know what it is? A virus. Windows is a disease, a cancer of this planet.
You're a plague and AVG is the cure.
Reply to This
Re:doh (Score:5, Insightful)
you get what you pay for?
So, those of us who have paid for (what used to be called) the SoHo version, or any of the other versions should just grin and bare it? I dont think so. I'm pissed. It's not all freeware
Reply to This
Parent
Re:doh (Score:5, Funny)
Careful what you bare, you saw how quick it cut off that dll file :D
Reply to This
Parent
Re:doh (Score:5, Funny)
It's just not Kosher, sometimes.
Reply to This
Parent
Re:doh (Score:5, Insightful)
It'd be nice to think that that was true, but based on the number of totally f'ed up McAfee and Norton situations I've seen, it's not even close to safe to conclude that for-pay anti-virus products are reliably more trouble-free than ones that don't cost money for home use.
Reply to This
Parent
Re:doh (Score:5, Interesting)
AVG failed to detect dozens of viruses and malware on my sister's computer that Avast cleared out. Avast isn't perfect, but they're both free, and it's my experience that Avast is more reliable than AVG. As always, YMMV.
Reply to This
Parent
Re:doh (Score:5, Funny)
Actually the free versions always get their updates later than the paid for versions, so it's the paying customers who were affected the most by this.
Reply to This
Parent
Re:doh (Score:5, Funny)
Reply to This
Parent
Re:doh (Score:5, Informative)
McAfee had a similar issue:
http://it.slashdot.org/it/06/03/13/1322215.shtml [slashdot.org]
Reply to This
Parent
Re:I haven't been hit yet... (Score:5, Informative)
If you haven't been hit yet, then you probably won't be either; your AVG quite likely already has the fixed definitions file.
If you -are- hit... guess what? it pops up a warning that it believes it found some sort of trojan in user32.dll . Laymen might just tell it to remove the thing, but I do hope -you- would know better and tell it to stfu and ignore, then fetch the latest update (it will warn you a few more times if you've got the resident shield runnning, as user32.dll gets accessed a lot).
If you -are- hit and it has already removed it... quickly restore it, carry on.
If you are hit, it has removed it, and your machine has already crashed... reboot to a command prompt (safe mode MAY work, but it didn't when I fixed a machine on sunday), restore user32.dll from a cache / restore point. If you can't get it from a cache, get it from the installation CD (if you have one), but keep in mind that it will be missing updates and windows update might not realize that (as everything else on the system tells it hotfixes N-M have been installed - maybe MS will make the update check the MD5 or something of user32.dll, after this problem, just in case).
This was extremely stupid on the end of AVG, but then I'm still baffled why such files can be removed at all; same with ntldr. If you accidentally wipe your root dir, you're all kinds of f'ed.
Reply to This
Parent