| Hello and Welcome to Tech Support Team! Before you can start posting and answering questions, you'll have to register. Registration is fast, simple and absolutely free! Feel free to browse through existing questions by choosing the forum you want to visit below. | | |  | | 
13th August 2008, 06:32 PM
|  | TST Expert | | Join Date: Aug 2008, 776 posts. Reputation:  | | | AVG 8 FREE Question
AVG 8 FREE works great. Even better now that the activex entries from
Spybot immunize feature has been eliminated.
Anyway, I do have an item of interest...
Any manual scan always turns up an adware.virusburst warning in the
WZCSVC folder of windows xp registry. That HKLM hive ends with ControlFlags.
I know that folder controls wzcsvc.dll for my wireless network so I can't just remove it.
When I vault this item, it always rewrites back into my reg.
No other malware online or off-line scans show this particular item.
I am not having any symptoms of being infected with adware.virusburst at all.
My HJT log is clean as a whistle.
I believe it to be a false positive hit.
Can anyone confirm or add to this? 
Thanks. | 
13th August 2008, 06:33 PM
|  | TST Oracle | | Join Date: Jul 2008, 8,171 posts. Location: UK Norfolk ..... Reputation:  | | |
Have you reported it Gunner to Avg ??
VirusBurst is considered to be one of a rogue antispyware. It displays fake warnings and tricks computer users to purchase all available software to remove infections.
__________________ Life should NOT be a journey to the grave with the intention of arriving safely in an attractive and well preserved body, but rather to skid in sideways, chocolate in one hand, wine in the other, body thoroughly used up, totally worn out and screaming...
Damn, What a ride!! | 
13th August 2008, 07:01 PM
|  | TST Expert | | Join Date: Aug 2008, 776 posts. Reputation:  | |
No I haven't reported it mainly because I'm too lazy to google an address. 
I have googled the symptoms you describe but, as I said, I have no indications
at all other than the avg scan warning.
Eset or Malbytes, SAS or any others do not show this as a warning or threat at all.
I will try and find an AVG trouble report link.
Thanks. | 
13th August 2008, 07:04 PM
|  | TST Oracle | | Join Date: Jul 2008, 8,171 posts. Location: UK Norfolk ..... Reputation:  | | |
It is a just a warning then i would ignore it
__________________ Life should NOT be a journey to the grave with the intention of arriving safely in an attractive and well preserved body, but rather to skid in sideways, chocolate in one hand, wine in the other, body thoroughly used up, totally worn out and screaming...
Damn, What a ride!! | 
14th August 2008, 12:33 AM
|  | TST Master | | Join Date: Dec 2007, 2,107 posts. Location: England Reputation:  | |
Please visit one of the following:
( Multiple sites are given in case one is not working)
(If more than one file needs scanned they must be done separately) Copy the file path to the suspect file into notepad.
At the upload site, click once inside the window next to Browse. - Press Ctrl+V on the keyboard (both at the same time) to paste the file path in the window.
- Next click Send File/Submit/Upload (depending on the site)
- Your file will possibly be entered into a queue which normally takes less than a minute to clear.
- This will perform a scan across multiple different virus scanning engines.
- Please wait for all of the scanning engines to complete.
see if you get the same warning or not.
__________________
__________________ "If at first you do not succeed, sit down, have a coffee, have a smoke, and think for a bit. If that still doesn't work, post it on TST". | 
14th August 2008, 12:59 AM
|  | TST Expert | | Join Date: Aug 2008, 776 posts. Reputation:  | |
Rik, it's not a file that's getting this warning but a registry entry...
HKLM\software\microsoft\WZCSVC\parameters\interfac es\{bunch of numbers and
letters}}\controlflags
I tried several times to send this string to AVG Virus Lab but it won't go...failed.
No other malware scanner errors on this entry. Has to be an AVG prob...I think.
But, then again, that's why I'm asking. 
Thanks. | 
14th August 2008, 08:14 AM
|  | TST Oracle | | Join Date: Dec 2007, 8,001 posts. Location: Market Haemorrhoids, Middle England Reputation:  | | |
I should ignore it and treat it as a false positive.
__________________ Confuse and Prosper. | 
14th August 2008, 08:29 AM
|  | TST Oracle | | Join Date: Jul 2008, 8,171 posts. Location: UK Norfolk ..... Reputation:  | | |
If it was flagged as a warning yes ignore
If it was flagged as a threat thats different and it would have been quarantined
__________________ Life should NOT be a journey to the grave with the intention of arriving safely in an attractive and well preserved body, but rather to skid in sideways, chocolate in one hand, wine in the other, body thoroughly used up, totally worn out and screaming...
Damn, What a ride!! | 
14th August 2008, 08:33 AM
|  | TST Oracle | | Join Date: Dec 2007, 8,001 posts. Location: Market Haemorrhoids, Middle England Reputation:  | | |
Sounds like AVG has got it wrong here and is hitting a perfectly innocent registry entry as sinister.
__________________ Confuse and Prosper. | 
14th August 2008, 09:08 AM
|  | TST Master | | Join Date: Dec 2007, 2,107 posts. Location: England Reputation:  | |
Are you comfortable with using regedit? If so, make a backup of your registry with the export button then delete the entry manually.
If you see no problems after that then all is well. If you do see any problems then use import to restore the registry.
A reboot will be required after each regedit use.
If you wish to give my suggestion a try but are not too sure about regedit then let me know and i will do you some detailed instructions.
__________________ "If at first you do not succeed, sit down, have a coffee, have a smoke, and think for a bit. If that still doesn't work, post it on TST". | 
14th August 2008, 01:22 PM
|  | TST Member | | Join Date: Jan 2008, 139 posts. Reputation:  | | |
i think gunner that it is a false positive because if nothing else is picking it up then i would ignore it.
__________________
James aka Nesbitt -> the only welsh irishman
| 
14th August 2008, 03:27 PM
|  | TST Expert | | Join Date: Aug 2008, 776 posts. Reputation:  | | Quote:
Originally Posted by Rik Are you comfortable with using regedit? If so, make a backup of your registry with the export button then delete the entry manually.
If you see no problems after that then all is well. If you do see any problems then use import to restore the registry.
A reboot will be required after each regedit use.
If you wish to give my suggestion a try but are not too sure about regedit then let me know and i will do you some detailed instructions.  | Yes, I'm very comfortable in the reg.
I already exported the string and then deleted the reg entry but it recreates
after a reboot. I'm pretty sure windows\system32\wzcsvc.dll is doing the restore
and I can't remove/rename that dll without killing my wireless network.
But, just to reiterate, removing that string (and do not reboot), AVG will not hit
on any warning or threat.
I can vault the warnings but it's restored anyway so useless.
I appreciate all the advice and suggestions. I don't feel it's a real threat for I have
no indications of any problems at all.
Misery loves company so mainly trying to see if this happened to anyone else.
When avg 8 first came out it hit on warnings if running spywareblaster but
found out it was really hitting on spybot immunize items falsely. AVG corrected
that.
I have this posted in an avg forum and will update this thread if I find anything
of interest.
Thanks again. | 
14th August 2008, 03:52 PM
|  | TST Oracle | | Join Date: Dec 2007, 8,001 posts. Location: Market Haemorrhoids, Middle England Reputation:  | | |
Gunner - have you tried scanning with hijackthis to see if it finds anything? If it scans clear then I would consider the case closed!
__________________ Confuse and Prosper. | 
14th August 2008, 06:34 PM
|  | TST Expert | | Join Date: Aug 2008, 776 posts. Reputation:  | | Quote:
Originally Posted by Albert Lionheart Gunner - have you tried scanning with hijackthis to see if it finds anything? If it scans clear then I would consider the case closed! | Yes, HJT is clean.
I'll leave this post open for a while in case later info becomes available.
Thanks again, ALL!!  (That includes you too, Al.  A little levity.)
| 
14th August 2008, 06:57 PM
|  | TST Member | | Join Date: Jan 2008, 165 posts. Location: Tampa FL Reputation:  | | |
What was the value of that key? did you check it?
Under
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Servic es\WZCSVC\Parameters\Interfaces
There are GUIDs (bunch of letters and numbers) for each of the installed adapters. For each adapter entry, there is a registry value called 'ControlFlags'.
If bit 0x8000 of the ControlFlags value is set, then Wzc is enabled for that adapter, if it's cleared, then Wzc is disable for that adapter. <- That is the 4th bit of the hex code for the value on that key
I believe all it is doing is telling your system to purge any previous wireless
cached connection credentials to force the you to re-authenticate
Last edited by Blind Dragon; 14th August 2008 at 06:59 PM.
| 
14th August 2008, 08:09 PM
|  | TST Expert | | Join Date: Aug 2008, 776 posts. Reputation:  | |
There are 3 GUID entries.
2 read the same controlflags values...reg_dword 0x03918002
1 (with the threat warning) has a value of...........0x03818002
I don't know enough about it to see the diff between 1 bit in 2 hex numbers.
59867138 vs 58818562 
I'll search.
Thanks.
P.S.
Windows XP Embedded SP2 Feature Pack 2007
Primitive: Wzcsvc
The Primitive: Wzcsvc component provides support for Wired Equivalency Privacy
(WEP). WEP provides data encryption for wireless networks.
Even though I use WAP and not WEP, I can not delete wzcsvc.dll.
| 
9th April 2009, 06:59 PM
|  | TST Expert | | Join Date: Aug 2008, 776 posts. Reputation:  | |
AVG resolved this problem long ago but I failed to update this thread.
AVG 8 Free Edition does not show any false positives. Actually 7.5 had been fixed also.
It's great!!!:thumbsup : (No comments, Albert.  )
| 
9th April 2009, 08:19 PM
|  | TST Oracle | | Join Date: Dec 2007, 8,001 posts. Location: Market Haemorrhoids, Middle England Reputation:  | | |
AVG must be getting cross with me because I had an email from them this week offering a free copy to try and prove me wrong. I turned it down!
__________________ Confuse and Prosper. | 
9th April 2009, 09:10 PM
|  | TST Expert | | Join Date: Aug 2008, 776 posts. Reputation:  | | Quote:
Originally Posted by Albert Lionheart AVG must be getting cross with me because I had
an email from them this week offering a free copy to try and prove me wrong. I turned it down! | A free copy of a paid version? And you turned it down WHY?
I really can't see AVG paid version being too much better than the FREE one.
I'm sure it does something extra but too lazy to search....too content also. | 
10th April 2009, 03:44 PM
|  | Community Moderator | | Join Date: Dec 2007, 4,345 posts. Location: Oxford, UK Reputation:   | | Quote:
Originally Posted by Gunner2 you turned it down WHY?
I really can't see AVG paid version being too much better than the FREE one. | You answered your own question mate.
__________________
Numberwang!
A little air on the earth.
|  | | Only registered members can participate in forum threads. You must register or log in to contribute. All times are GMT. The time now is 11:45 AM.
| |
|