HenryWilfred
asked on
Can AVG remove these viruses?
I have a computer that is supposed to be protected by AVG Anti-Virus Network Edition 8.5, yet AVG has detected several viruses and worms that it did not automaticaly heal or delete. AVG also did not give any obvious warning that there was a problem - until I looked in the detailed scan history. The email system being used is Thunderbird, and the majority of the infections are in the email.
Questions:
0. Are there other programs than AVG that would clearly warn the user to the infections? Or did AVG not warn of the problem well because the viruses are affecting it?
1. Can AVG remove these viruses (see avg report at the bottom)?
2. Would some other program be better at removing the viruses? Such as Norton Anti-Virus?
3. I see that both AVG and Norton sell special services to remove viruses rather than directing the user to simply download their standard anti-virus programs - so I gather then that neither of there basic anti-virus programs are effective for virus removal? Does anybody recommend the special virus removal services that AVG or Norton offers?
4. I noticed that several viruses in Thunderbird went unnoticed by AVG until I ran IMAPSize to try to convert the emails from mboxtoeml format. Does this mean that AVG is poor at detecting infected emails downloaded via Thunderbird? Is there another anti-virus program that works better with Thunderbird? Or is it best simply to switch to Microsoft Outlook?
HERE ATTACHED IS THE AVG VIRUS INFECTION REPORT - Note that it did not say the files were "Deleted" until after I viewed the detailed scan history and selected "Remove all unhealed infections". At that point it complained that some of the files were too big to remove. Did it really remove them?
"C:\ARCDATA\Users\ehonecke r\Mail\Inb oxold";"Vi rus identified I-Worm/Generic.CBM";"Delet ed"
"C:\ARCDATA\Users\ehonecke r\Mail\Inb oxold:\bod y.zip";"Vi rus identified I-Worm/Mydoom.A";"Deleted"
"C:\ARCDATA\Users\ehonecke r\Mail\Inb oxold:\Cud y.scr";"Vi rus identified I-Worm/Generic.CBM";"Delet ed"
"C:\ARCDATA\Users\ehonecke r\Mail\Inb oxold:\geg en.scr";"V irus identified I-Worm/Generic.CBM";"Delet ed"
"C:\convertedemail\Inbox\C onflicker. B Infection Alert_7801_20100305_115208 _478.eml"; "Trojan horse Generic16.BNVD";"Deleted"
"C:\convertedemail\Inbox\C onflicker. B Infection Alert_7801_20100305_115208 _478.eml:\ open.zip"; "Trojan horse Generic16.BNVD";"Deleted"
"C:\convertedemail\Inbox\C onflicker. B Infection Alert_7801_20100305_115208 _478.eml:\ open.zip:\ open.exe"; "Trojan horse Generic16.BNVD";"Deleted"
"C:\convertedemail\Inbox\C onflicker. B Infection Alert_7805_20100305_115208 _962.eml"; "Trojan horse Downloader.Generic9.AVHI"; "Deleted"
"C:\convertedemail\Inbox\C onflicker. B Infection Alert_7805_20100305_115208 _962.eml:\ open.zip"; "Trojan horse Downloader.Generic9.AVHI"; "Deleted"
"C:\convertedemail\Inbox\C onflicker. B Infection Alert_7805_20100305_115208 _962.eml:\ open.zip:\ open.exe"; "Trojan horse Downloader.Generic9.AVHI"; "Deleted"
"C:\convertedemail\Inbox\C onflicker. B Infection Alert_7812_20100305_115209 _040.eml"; "Virus identified Win32/Cryptor";"Deleted"
"C:\convertedemail\Inbox\C onflicker. B Infection Alert_7812_20100305_115209 _040.eml:\ open.zip"; "Virus identified Win32/Cryptor";"Deleted"
"C:\convertedemail\Inbox\C onflicker. B Infection Alert_7812_20100305_115209 _040.eml:\ open.zip:\ open.exe"; "Virus identified Win32/Cryptor";"Deleted"
"C:\convertedemail\Inbox\C onflicker. B Infection Alert_7824_20100305_115209 _743.eml"; "Virus identified Win32/Cryptor";"Deleted"
"C:\convertedemail\Inbox\C onflicker. B Infection Alert_7824_20100305_115209 _743.eml:\ open.zip"; "Virus identified Win32/Cryptor";"Deleted"
"C:\convertedemail\Inbox\C onflicker. B Infection Alert_7824_20100305_115209 _743.eml:\ open.zip:\ open.exe"; "Virus identified Win32/Cryptor";"Deleted"
"C:\convertedemail\Inbox\C ongratulat ions_6757_ 20100305_1 15034_900. eml";"Troj an horse Generic15.ARXB";"Deleted"
"C:\convertedemail\Inbox\C ongratulat ions_6757_ 20100305_1 15034_900. eml:\winne r.zip";"Tr ojan horse Generic15.ARXB";"Deleted"
"C:\convertedemail\Inbox\C ongratulat ions_6757_ 20100305_1 15034_900. eml:\winne r.zip:\win ner.exe";" Trojan horse Generic15.ARXB";"Deleted"
"C:\convertedemail\Inbox\M icrosoft Outlook Notification for the bhonecker@arcse-mn.org_649 9_20100305 _115004_68 1.eml";"Tr ojan horse SHeur2.BLNK";"Deleted"
"C:\convertedemail\Inbox\M icrosoft Outlook Notification for the bhonecker@arcse-mn.org_649 9_20100305 _115004_68 1.eml:\ins tall.zip"; "Trojan horse SHeur2.BLNK";"Deleted"
"C:\convertedemail\Inbox\M icrosoft Outlook Notification for the bhonecker@arcse-mn.org_649 9_20100305 _115004_68 1.eml:\ins tall.zip:\ install.ex e";"Trojan horse SHeur2.BLNK";"Deleted"
"C:\convertedemail\Inbox\M icrosoft Outlook Notification for the bhonecker@arcse-mn.org_650 0_20100305 _115004_71 2.eml";"Tr ojan horse SHeur2.BLNK";"Deleted"
"C:\convertedemail\Inbox\M icrosoft Outlook Notification for the bhonecker@arcse-mn.org_650 0_20100305 _115004_71 2.eml:\ins tall.zip"; "Trojan horse SHeur2.BLNK";"Deleted"
"C:\convertedemail\Inbox\M icrosoft Outlook Notification for the bhonecker@arcse-mn.org_650 0_20100305 _115004_71 2.eml:\ins tall.zip:\ install.ex e";"Trojan horse SHeur2.BLNK";"Deleted"
"C:\convertedemail\Inbox\M icrosoft Outlook Notification for the bhonecker@arcse-mn.org_650 2_20100305 _115004_80 6.eml";"Tr ojan horse Crypt.ICL";"Deleted"
"C:\convertedemail\Inbox\M icrosoft Outlook Notification for the bhonecker@arcse-mn.org_650 2_20100305 _115004_80 6.eml:\ins tall.zip"; "Trojan horse Crypt.ICL";"Deleted"
"C:\convertedemail\Inbox\M icrosoft Outlook Notification for the bhonecker@arcse-mn.org_650 2_20100305 _115004_80 6.eml:\ins tall.zip:\ install.ex e";"Trojan horse Crypt.ICL";"Deleted"
"C:\convertedemail\Inbox\U PS Invoice 5305325782943_6630_2010030 5_115021_3 21.eml";"T rojan horse Agent2.YLH";"Deleted"
"C:\convertedemail\Inbox\U PS Invoice 5305325782943_6630_2010030 5_115021_3 21.eml:\RE SU8723.zip ";"Trojan horse Agent2.YLH";"Deleted"
"C:\convertedemail\Inbox\U PS Invoice 5305325782943_6630_2010030 5_115021_3 21.eml:\RE SU8723.zip :\RESU8723 .exe";"Tro jan horse Agent2.YLH";"Deleted"
"C:\convertedemail\Inbox\Y our internet access is going to get suspended_7695_20100305_11 5205_134.e ml";"Troja n horse FakeAV.GH";"Deleted"
"C:\convertedemail\Inbox\Y our internet access is going to get suspended_7695_20100305_11 5205_134.e ml:\report .zip";"Tro jan horse FakeAV.GH";"Deleted"
"C:\convertedemail\Inbox\Y our internet access is going to get suspended_7695_20100305_11 5205_134.e ml:\report .zip:\repo rt.exe";"T rojan horse FakeAV.GH";"Deleted"
"C:\convertedemail\Inbox\Y ou've received a postcard_6469_20100305_114 947_290.em l";"Virus found FakeAlert";"Deleted"
"C:\convertedemail\Inbox\Y ou've received a postcard_6469_20100305_114 947_290.em l:\ecard.z ip";"Virus found FakeAlert";"Deleted"
"C:\Documents and Settings\Bethh\Application Data\Thunderbird\Profiles\ 9im1z7cu.d efault\Mai l\mail.arc se-mn.org\ Inboxold"; "Virus identified I-Worm/Generic.CBM";"Delet ed"
"C:\Documents and Settings\Bethh\Application Data\Thunderbird\Profiles\ 9im1z7cu.d efault\Mai l\mail.arc se-mn.org\ Inboxold:\ body.zip"; "Virus identified I-Worm/Mydoom.A";"Deleted"
"C:\Documents and Settings\Bethh\Application Data\Thunderbird\Profiles\ 9im1z7cu.d efault\Mai l\mail.arc se-mn.org\ Inboxold:\ Cudy.scr"; "Virus identified I-Worm/Generic.CBM";"Delet ed"
"C:\Documents and Settings\Bethh\Application Data\Thunderbird\Profiles\ 9im1z7cu.d efault\Mai l\mail.arc se-mn.org\ Inboxold:\ gegen.scr" ;"Virus identified I-Worm/Generic.CBM";"Delet ed"
THE REST OF THE AVG VIRUS REPORT - THE SPYWARE SECTION:
"C:\ARCDATA\Users\efockler \Trash.sbd \Mail\Offi ce People.sbd\Marta";"Potenti ally harmful program Joke.BO";"Deleted"
"C:\ARCDATA\Users\efockler \Trash.sbd \Mail\Offi ce People.sbd\Marta:\INFO.EXE ";"Potenti ally harmful program Joke.BO";"Deleted"
"C:\ARCDATA\Users\efockler 5\News\Tra sh.sbd\Mai l\Office People.sbd\Marta";"Potenti ally harmful program Joke.BO";"Deleted"
"C:\ARCDATA\Users\efockler 5\News\Tra sh.sbd\Mai l\Office People.sbd\Marta:\INFO.EXE ";"Potenti ally harmful program Joke.BO";"Deleted"
"C:\ARCDATA\Users\ehonecke r\Mail\Off ice People.sbd\Marta";"Potenti ally harmful program Joke.BO";"Deleted"
"C:\ARCDATA\Users\ehonecke r\Mail\Off ice People.sbd\Marta:\INFO.EXE ";"Potenti ally harmful program Joke.BO";"Deleted"
"C:\ARCDATA\Users\ehonecke r\Trash.sb d\Mail\Off ice People.sbd\Marta";"Potenti ally harmful program Joke.BO";"Deleted"
"C:\ARCDATA\Users\ehonecke r\Trash.sb d\Mail\Off ice People.sbd\Marta:\INFO.EXE ";"Potenti ally harmful program Joke.BO";"Deleted"
Questions:
0. Are there other programs than AVG that would clearly warn the user to the infections? Or did AVG not warn of the problem well because the viruses are affecting it?
1. Can AVG remove these viruses (see avg report at the bottom)?
2. Would some other program be better at removing the viruses? Such as Norton Anti-Virus?
3. I see that both AVG and Norton sell special services to remove viruses rather than directing the user to simply download their standard anti-virus programs - so I gather then that neither of there basic anti-virus programs are effective for virus removal? Does anybody recommend the special virus removal services that AVG or Norton offers?
4. I noticed that several viruses in Thunderbird went unnoticed by AVG until I ran IMAPSize to try to convert the emails from mboxtoeml format. Does this mean that AVG is poor at detecting infected emails downloaded via Thunderbird? Is there another anti-virus program that works better with Thunderbird? Or is it best simply to switch to Microsoft Outlook?
HERE ATTACHED IS THE AVG VIRUS INFECTION REPORT - Note that it did not say the files were "Deleted" until after I viewed the detailed scan history and selected "Remove all unhealed infections". At that point it complained that some of the files were too big to remove. Did it really remove them?
"C:\ARCDATA\Users\ehonecke
"C:\ARCDATA\Users\ehonecke
"C:\ARCDATA\Users\ehonecke
"C:\ARCDATA\Users\ehonecke
"C:\convertedemail\Inbox\C
"C:\convertedemail\Inbox\C
"C:\convertedemail\Inbox\C
"C:\convertedemail\Inbox\C
"C:\convertedemail\Inbox\C
"C:\convertedemail\Inbox\C
"C:\convertedemail\Inbox\C
"C:\convertedemail\Inbox\C
"C:\convertedemail\Inbox\C
"C:\convertedemail\Inbox\C
"C:\convertedemail\Inbox\C
"C:\convertedemail\Inbox\C
"C:\convertedemail\Inbox\C
"C:\convertedemail\Inbox\C
"C:\convertedemail\Inbox\C
"C:\convertedemail\Inbox\M
"C:\convertedemail\Inbox\M
"C:\convertedemail\Inbox\M
"C:\convertedemail\Inbox\M
"C:\convertedemail\Inbox\M
"C:\convertedemail\Inbox\M
"C:\convertedemail\Inbox\M
"C:\convertedemail\Inbox\M
"C:\convertedemail\Inbox\M
"C:\convertedemail\Inbox\U
"C:\convertedemail\Inbox\U
"C:\convertedemail\Inbox\U
"C:\convertedemail\Inbox\Y
"C:\convertedemail\Inbox\Y
"C:\convertedemail\Inbox\Y
"C:\convertedemail\Inbox\Y
"C:\convertedemail\Inbox\Y
"C:\Documents and Settings\Bethh\Application
"C:\Documents and Settings\Bethh\Application
"C:\Documents and Settings\Bethh\Application
"C:\Documents and Settings\Bethh\Application
THE REST OF THE AVG VIRUS REPORT - THE SPYWARE SECTION:
"C:\ARCDATA\Users\efockler
"C:\ARCDATA\Users\efockler
"C:\ARCDATA\Users\efockler
"C:\ARCDATA\Users\efockler
"C:\ARCDATA\Users\ehonecke
"C:\ARCDATA\Users\ehonecke
"C:\ARCDATA\Users\ehonecke
"C:\ARCDATA\Users\ehonecke
ASKER CERTIFIED SOLUTION
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Ill have to see if I can get on a machine with 8.5 Network Version........
ASKER
I do not see an option to not nofity the user anywhere.