AVG 7.5 e 8.0 - Problema com detecção falsa

Dúvidas, problemas, novidades... se tem a ver com Informática, é aqui!
Avatar do Utilizador
Pedro
Administrador
Administrador
Mensagens: 12067
Registado: quarta-feira, 10 novembro 2004 20:07

AVG 7.5 e 8.0 - Problema com detecção falsa

Mensagem por Pedro »

Já me chegaram hoje algumas dúvidas sobre esta questão, pelo que deixo aqui a explicação para não serem apanhados de surpresa. Parece que houve uma asneira na actualização do AVG e ele passou a detectar o user32.dll como vírus (falso positivo). Caso removam o ficheiro ou façam Heal, o Windows deixará de carregar, dado tratar-se de um ficheiro imprescindível ao sistema. Caso isso tenha acontecido com vocês, deixo aqui as instruções que estão no site da Grisoft para resolver a questão. Caso o vosso AVG faça esta detecção, lembrem-se de a ignorar ou vão passar por este problema. É uma falha gravíssima deste anti-vírus, não entendo como este update passou pelo controlo de qualidade... :?
AVG 8.0 - False positive "user32.dll" (DB: 270.9.0/1777)

In case you are not able to run your Windows XP operating system after AVG 8.0 virus definition update, it may be caused by a false positive on a specific "user32.dll" system file. The file was moved to the AVG Virus Vault and deleted. Therefore it is not possible to start Windows. Please follow the steps below to rectify this situation:

In case you do not have Windows XP installation CD with the latest updates, we strongly recommend you to use our fix tool instead. The mentioned fix tool can be found in FAQ 1575.

WARNING! There is a high probability of incompatibility with other system files (for example with winsrv.dll) if the latest installation CD is not used. This can also cause inabitity to start operating system.

1. Please insert the Windows XP installation CD and boot computer from this CD (if you do not have the installation CD please follow steps mentioned in our FAQ 1575).

2. Choose and run Recovery Console.

3. Choose Windows operating system you want to repair.

4. Disable AVG Resident Shield from loading. You can disable loading services/drivers with "disable" command, i.e. you have to type the following commands (some

of them might not be present in all AVG editions):

disable avgMfx86
disable avgMfa86
disable avgldx86
disable avglda86

5. Restore the User32.dll file from the Windows XP installation CD (instead "D:" use letter of your CD-ROM drive):

expand D:\i386\user32.dl_ c:\windows\system32\

In case the command fails, please use the following command to rename original user32.dll and repeat the command above.

ren user32.dll user32.bak

6. Restart computer and boot Windows normally.

7. In order to re-enable the AVG Resident Shield services we recommend that you perform the AVG repair installation as follows:

- Download the latest AVG installation package from the following webpage and save it on your hard disk:

http://www.avg.com/download?prd=aav
(AVG Anti-Virus 8.0)
http://www.avg.com/download?prd=ais
(AVG Internet Security 8.0)
http://www.avg.com/download?prd=avf
(AVG Anti-Virus plus Firewall 8.0)

- When you are prompted, please do not open this file directly from the internet, but click the Save button and choose a location, where the installation

file should be stored. We recommend saving the file to the Desktop.
- Restart your computer.
- Locate the downloaded AVG installation file (it has a four color square icon and its name starts with AVG_...) and launch the installation by double-clicking on it.
- Follow the installation wizard.
- When prompted, please select the Repair installation option.
- Enter your license number when you are asked (we recommend that you use the copy&paste* method to enter this license number into the installation form).
- Restart your computer and update AVG.
In case you are not able to run your Windows XP operating system after AVG 7.5 virus definition update, it may be caused by a false positive on a specific "user32.dll" system file. The file was moved to the AVG Virus Vault and deleted. Therefore it is not possible to start Windows. Please follow the steps below to rectify this situation:

In case you do not have Windows XP installation CD with the latest updates, we strongly recommend you to use our fix tool instead. The mentioned fix tool can be found in FAQ 1580.

WARNING! There is a high probability of incompatibility with other system files (for example with winsrv.dll) if the latest installation CD is not used. This can also cause inabitity to start operating system.

1. Please insert the Windows XP installation CD and boot computer from this CD (if you do not have the installation CD please follow steps mentioned in our FAQ 1580).

2. Choose and run Recovery Console.

3. Choose Windows operating system you want to repair.

4. Disable AVG Resident Shield from loading. You can disable loading services/drivers with "disable" command, i.e. you have to type the following commands (some

of them might not be present in all AVG editions):

disable Avg7Core
disable Avg7RsW
disable AvgClean
disable Avg7RsXP
disable AvgMfx86

5. Restore the User32.dll file from the Windows XP installation CD (instead "D:" use letter of your CD-ROM drive):

expand D:\i386\user32.dl_ c:\windows\system32\

In case the command fails, please use the following command to rename original user32.dll and repeat the command above.

ren user32.dll user32.bak

6. Restart computer and boot Windows normally.

7. In order to re-enable the AVG Resident Shield services we recommend that you perform the AVG repair installation as follows:

- Download the latest AVG installation package (AVG 7.5 for Windows) from the following webpage and save it on your hard disk:

http://www.grisoft.com/doc/downloads?prd=avw
(AVG Anti-Virus)
http://www.grisoft.com/doc/downloads?prd=isw
(AVG Internet Security)
http://www.grisoft.com/doc/downloads?prd=amw
(AVG Anti-Malware)
http://www.grisoft.com/doc/downloads?prd=afw
(AVG Anti-Virus plus Firewall)

- Click on the "AVG 7.5 for Windows" link to download the installation file.

- When you are prompted, please do not open this file directly from the internet, but click the Save button and choose a location, where the installation file should be stored. We recommend saving the file to the Desktop.
- Restart your computer.
- Locate the downloaded AVG installation file (it has a four color square icon and its name starts with AVG75...) and launch the installation by double-clicking on it.
- Follow the installation wizard.
- When prompted, please select the Repair installation option.
- Restart your computer and update AVG.

Avatar do Utilizador
dryden
Veterano
Veterano
Mensagens: 662
Registado: quinta-feira, 25 outubro 2007 13:01

Mensagem por dryden »

Para dizer a verdade nunca gostei muito do AVG desde há muitos anos atrás; Tudo começou quando eu estava nas aulas e ao compilar um programa feito por mim o AVG detectava imediatamente vírus e apagava-o de imediato :shock:
Sabendo eu o que estava no código fonte e que não era vírus, fiquei sempre de pé atrás com ele.

Voltou a repetir-se a situação há cerca de 2 anos atrás mas desta vez em maior escala, na altura tinha um setup meu num site publico, esse programa foi descarregado uns milhares de vezes por vários utilizadores, mas no fórum havia várias pessoas a aconselharem os utilizadores a não descarregarem porque diziam que estava infectado com vírus e que o programador (eu) estava a querer tramar o pessoal. Mais tarde veio-se a descobrir que todos os utilizadores que tinha reportado que era vírus estavam a usar o AVG.

Desde aí nem posso ver o AVG à minha frente...

Na minha opinião, se querem um AV de confiança e grátis fiquem-se pelo Avast, que para mim é o melhor AV Disponível Grátis, se querem pagos então vão para o Norton (come um bocado de recursos mas é excelente) ou para o Kaspersky.