Welcome to SecurityForumz.com!
FAQFAQ    SearchSearch      ProfileProfile    Private MessagesPrivate Messages   Log inLog in

one_half reported by AVG but not AVP or F-Prot?

 
   Security Forums (Home) -> AVG RSS
Next:  AVG July 4th update  
Author Message
saskee

External


Since: Jul 12, 2003
Posts: 1



(Msg. 1) Posted: Sat Jul 12, 2003 8:41 pm
Post subject: one_half reported by AVG but not AVP or F-Prot?
Archived from groups: alt>comp>virus (more info?)

Yesterday a message popped up on my computer from Norton AV that something
was messing with my boot disk. I scanned with AVG which reported the
presence of one_half, a boot disk virus. When AVG gave no options for
removal or treatment I searched for info. I downloaded and used the trial
versions of F-Prot and AVP and they found no virus. I tried the one_half
specific chk_half.exe and it went into an endless loop accomplishing
nothing. I backed up my data and booted with a clean Win98 boot disk. I
fdisk /mbr 'ed and rebooted the system.

I scanned with AVG and it still reports a virus, one_half.

Has anyone experienced similar problems? Which program is right?

My system is a triple boot, RH8, Win2k, Win98 set up. I use the grub
loader to sort things out on startup.

Any comments, suggestions or ideas appreciated.

Jim












/
/
..

 >> Stay informed about: one_half reported by AVG but not AVP or F-Prot? 
Back to top
Login to vote
Blevins

External


Since: Jul 13, 2003
Posts: 25



(Msg. 2) Posted: Sun Jul 13, 2003 3:15 am
Post subject: Re: one_half reported by AVG but not AVP or F-Prot? [Login to view extended thread Info.]
Imported from groups: per prev. post (more info?)

Back to top
Login to vote
FromTheRafters

External


Since: Sep 19, 2003
Posts: 1207



(Msg. 3) Posted: Sun Jul 13, 2003 7:51 pm
Post subject: Re: one_half reported by AVG but not AVP or F-Prot? [Login to view extended thread Info.]
Archived from groups: per prev. post (more info?)

"saskee" wrote in message
> Yesterday a message popped up on my computer from Norton AV that something
> was messing with my boot disk. I scanned with AVG which reported the
> presence of one_half, a boot disk virus. When AVG gave no options for
> removal or treatment I searched for info. I downloaded and used the trial
> versions of F-Prot and AVP and they found no virus. I tried the one_half
> specific chk_half.exe and it went into an endless loop accomplishing
> nothing. I backed up my data and booted with a clean Win98 boot disk. I
> fdisk /mbr 'ed and rebooted the system.
>
> I scanned with AVG and it still reports a virus, one_half.
>
> Has anyone experienced similar problems? Which program is right?
>
> My system is a triple boot, RH8, Win2k, Win98 set up. I use the grub
> loader to sort things out on startup.
>
> Any comments, suggestions or ideas appreciated.

I think grub writes to the boot sector rather than using
a chainloading scheme. The AV may just be seeing the
write as a BSI. IOW it is probably a false alarm.

Question, how did you get grub back after you Fdisk /mbr'ed?
...or did this not affect that loader?
 >> Stay informed about: one_half reported by AVG but not AVP or F-Prot? 
Back to top
Login to vote
FromTheRafters

External


Since: Sep 19, 2003
Posts: 1207



(Msg. 4) Posted: Sun Jul 13, 2003 10:12 pm
Post subject: Re: one_half reported by AVG but not AVP or F-Prot? [Login to view extended thread Info.]
Archived from groups: per prev. post (more info?)

"saskee" wrote in message
> Yesterday a message popped up on my computer from Norton AV that something
> was messing with my boot disk.

This antiquated feature should be disabled.

> I scanned with AVG which reported the
> presence of one_half, a boot disk virus.

Maybe (pretty likely) a false positive detection.

> When AVG gave no options for
> removal or treatment I searched for info. I downloaded and used the trial
> versions of F-Prot and AVP and they found no virus. I tried the one_half
> specific chk_half.exe and it went into an endless loop accomplishing
> nothing. I backed up my data and booted with a clean Win98 boot disk. I
> fdisk /mbr 'ed and rebooted the system.

This should have now made the system a single boot to Windows
instead of the triple boot mentioned below.

> I scanned with AVG and it still reports a virus, one_half.

It is probably wrong.

> Has anyone experienced similar problems? Which program is right?
>
> My system is a triple boot, RH8, Win2k, Win98 set up. I use the grub
> loader to sort things out on startup.
>
> Any comments, suggestions or ideas appreciated.

I think grub loads the appropriate Windows' loader by making the
chosen Windows partition active and "chain-loading" the loader
from the chosen Windows partition. The grub MBR is not what
these AV programs are expecting to see. Fdisk /mbr should write the
Microsoft standard MBR code back to the boot sector, but maybe
some of the grub code doesn't get overwritten and the AV alerts
on the excess code in the boot sector.
 >> Stay informed about: one_half reported by AVG but not AVP or F-Prot? 
Back to top
Login to vote
Display posts from previous:   
Related Topics:
F-Prot False Positve Alerts on AVG archive/.exe - Hi, I just ran into a problem similar to a problem F-Prot had just a couple of weeks ago w/regard to Sun Java files. F-StopW.exe (F-Prot's RealTime Scanning engine) keeps alerting on my "avg70free_296a409.exe" file and saying it is a securit...

AVG July 4th update - Virus Database 296

AVG update Jul 14th - AVG core 501 / database 299

AVG update July 18th - Program version 6.0.502 Virus database 300

AVG update July 30th - Update AVG 7.0 - AVI 259.9.4 and Update AVG 6.0 - 505 Added detection of BAT/Mosquito, VBS/Mfile, VBS/Nof, I-Worm/Babybear, I-Worm/Jantic, Win32/Casal, Worm/Milcan, Worm/Tofaced, trojan PSW.VB, trojan BackDoor.LH, trojan Dropper.Mimail, trojan..
   Security Forums (Home) -> AVG All times are: Pacific Time (US & Canada)
Page 1 of 1

 
You can post new topics in this forum
You can reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum



[ Contact us | Terms of Service/Privacy Policy ]