Re: Latest XP update aborted with virus warning

Tech-Archive recommends: Repair Windows Errors & Optimize Windows Performance



On Mon, 20 Apr 2009 14:36:01 -0700, sgopus
<sgopus@xxxxxxxxxxxxxxxxxxxxxxxxx> wrote:

ZA has nothing to do with antivirus, it's strictly a firewall software.


Bear in mind that although ZA started out strictly as a firewall
program, it no longer is limited to that. ZA now has several packages
and security suites for sale, including an anti-virus program. See
http://www.zonealarm.com/security/en-us/compare-anti-virus-spyware-software.htm
or http://tinyurl.com/8xmd6f



"Anthony Buckland" wrote:

Yup, I trust Windows Update. I use Zone Alarm. The file
in question turns out to be an essential Windows service,
so I suppose the multiple copies represent an attempt
by Windows to regenerate a file it found was missing?
Anyway, everything else seems to be working ok, and I
can live for a while with ZA and Windows carrying on a
minor war with one another. Thanks for your prompt
replies.

"sgopus" <sgopus@xxxxxxxxxxxxxxxxxxxxxxxxx> wrote in message
news:55D408C3-F4E6-4CF4-87FA-A709E3858396@xxxxxxxxxxxxxxxx
Windows update is safe as far as virus goes, messing up your system I
couldn't make a statement about, many updates have been known to cause
problems.

it's been known in the past that some windows updates have been
indentified
as false positives as far as anti virus software goes, unless you got it
from
a different site than microsoft I wouldn't even consider for a moment it
was
a virus. I know I recently downloaded the same update, no virus for me,
what
are you using for virus software?




"Anthony Buckland" wrote:

Could be, I suppose. This thing is regenerating itself: seven
copies have been quarantined so far today. If the patch
generated a file that is going to be identified as a virus,
would it really help to turn off the antivirus during the patch
and then leave the detection to be done later? And if it
were _not_ a false positive, wouldn't that leave a window
in which the virus could do harm? Anyhow, I'll see if I can
find out what the named file does for a living, and I remain
curious as to whether other people are getting the same
result.

I notice that the Windows update was a single item this
time, which leads me to wonder if it was an unusually high
priority fix. And I suppose I have to consider that the virus
detection might have occurred just after the patch as a
matter of coincidence.

"sgopus" <sgopus@xxxxxxxxxxxxxxxxxxxxxxxxx> wrote in message
news:391D1086-D2D1-470E-A081-984B09D19948@xxxxxxxxxxxxxxxx
you should always disable virus software when applying updates, I would
suggest it's a false positive.

"Anthony Buckland" wrote:

I just responded to a Windows update, KB956572, by asking to
have it downloaded (no problem) and then installed (big problem,
for the first time in my memory (such as it is) an update failed
to install). Then I got an immediate virus warning concerning
wmiprvse.exe in windows\system32\dllcache
the virus is identified as backdoor.win32.agent.afqs
and was quarantined.

Are others running into this?










--
Ken Blake, Microsoft MVP - Windows Desktop Experience
Please Reply to the Newsgroup
.



Relevant Pages

  • Bobax.C
    ... Other files containing the virus have been ... W32.Bobax.C is a worm that exploits both the LSASS ... While this threat may execute on Windows 95/98/Me/Server ... Virus Definitions * ...
    (microsoft.public.windowsxp.security_admin)
  • Re: Installing a MS Patch killed my computer
    ... Best bet would've been to remove the worm before trying to install the ... patch - you're trying to lock the barn door after the cows have gotten out. ... Windows XP, Windows 2000, Windows Server 2003, Windows NT ... Symptoms of the virus: Some customer may not notice any symptoms at all. ...
    (microsoft.public.win2000.security)
  • Re: Need help... may be a virus!
    ... a virus cannot cause physical ... Before that, however, if you can get into Windows ... try to turn off the automatic reboot (Right-click My Computer> ... > to get a patch with it from a site. ...
    (microsoft.public.windowsxp.security_admin)
  • Re: Pixelsrvr.exe wont load on bootup
    ... Sounds like you got yourself a virus,. ... Adds the following line to the [windows] section of the Win.ini file: ... antivirus products, including the Symantec AntiVirus and Norton AntiVirus ... Disabling System Restore ...
    (microsoft.public.windowsxp.video)
  • Re: HELP ON XP RE-INSTALLATION...
    ... > IF I REINSTALL XP ON MY COMPUTER HELP IF I HAVE A VIRUS THAT I CANT ... Don't have an AntiVirus software? ... There are more applications you may need to run to completely clean your ... It will probably save you time and effort in re-installing Windows XP ...
    (microsoft.public.windowsxp.general)