CastleCops, Internet Crime Fighters
Need help? Click here to register for free! Absolutely zero advertisements on this site!

Donation/Premium
spacer
block bottom
Security Central
spacer
· Home
· PIRT/Fried Phish
· MIRT
· SIRT
· Deutsch
· Wiki
· Newsletter
· O16/ActiveX
· CLSID List
· Contest2007
· Downloads
· Feedback (send)
· Forums
· HijackThis
· Hijacktrend
· LSPs
· My Downloads
· O18
· O20
· O21
· O22
· O23
· O9
· Premium
· Private Messages
· Proxomitron
· Reviews
· Search
· StartupList
· Stories Archive
· Submit News
· WsIRT
· Your Account
· Acceptable Use Policy
block bottom
spacer spacer

AVG 7.5 detects Excel Exploit

 
Post new topic   Reply to topic       All -> FavForums -> Grisoft AVG [del.icio.us!] [digg it!] [reddit!]
View previous topic :: View next topic  
Author Message
Hugh2

Cadet
Cadet


Joined: Nov 15, 2006
Posts: 4
Location: USA

PostPosted: Sun Feb 11, 2007 6:47 pm    Post subject: AVG 7.5 detects Excel Exploit
Reply with quote

My scan today showed 6 Excel files were infected by "Excel Exploit"...this seems to be spread by email attachments. Surprising, since none of the infected files were received via email, and I had not even used them recently. Also, I use hotmail for email, which supposedly scans all attachments.

I sent the files to quarantine, updated AVG again, reran the scan which came back clean.

Anyone else experience this? Is there anything else I should be doing?

Thanks

Back to top
View users profile Send private message
k027

Special Response Team
Guest Forums Host
Guest Forums Host

Joined: Aug 25, 2003
Posts: 8519

1st Responders SRT

PostPosted: Sun Feb 11, 2007 7:14 pm    Post subject:
Reply with quote

I suspect that you are concerned about AVG's detections being possible false positives.

Since you updated AVG, you might try restoring the files from quarantine and then rescanning with the updated AVG. If the files still appear to be contaminated, you can always retest the restored files with other anti-malware programs, like those mentioned here:

http://wiki.castlecops.com/Malware_Removal_and_Prevention:_Overview

Back to top
View users profile Send private message
dp

Microsoft MVP
AVG Host
AVG Host

Joined: Mar 12, 2002
Posts: 416

MVP Premium

PostPosted: Sun Feb 11, 2007 7:22 pm    Post subject:
Reply with quote

From: http://forum.grisoft.cz/freeforum/read.php?4,90494,backpage=2,sv=

At this time we expect them to be false positives... for now leave them in the vault and when Grisoft corrects their definitions you can restore them....

If you suspect a file to be a false positive. Test the file at virusscan.jotti.org and if it is a false positive, archive (zip, arc, tar etc) the file using a password and email a copy to virus@grisoft.com with a brief description as well as the password you used to archive it with.

If it is a false positive , turn off hueristic scanning for the time being. When Grisoft adjusts the virus defintions you can turn it back on. You may have to disable the Resident Shield for this if turning off hueristics doesn't help.

Note: There will be an update out shortly today (AVI 268.17.36/ 681) Restore your Excel findings and re-scan with this new update.


_________________
Microsoft MVP Consumer Security, 2004-2008
Back to top
View users profile Send private message Visit posters website
Hugh2

Cadet
Cadet


Joined: Nov 15, 2006
Posts: 4
Location: USA

PostPosted: Sun Feb 11, 2007 10:21 pm    Post subject:
Reply with quote

Thanks for the info, guys.

I should have thought to check the AVG forum!

Back to top
View users profile Send private message
Display posts from previous:   
Post new topic   Reply to topic       All -> FavForums -> Grisoft AVG All times are GMT
Page 1 of 1

 
Quick Reply:
Username: 

Quote the last message
Attach signature (signatures can be changed in profile)
 
You can post new topics in this forum
You can reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
You can attach files in this forum
You can download files in this forum


Powered by phpBB © 2001 phpBB Group
spacer spacer