Thursday, June 7, 2007

Symantec false positive cripples thousands of Chinese PCs

Virus signature update mistakes critical Windows files for malware

A signature update to Symantec's anti-virus software crippled thousands of Chinese PCs Friday when the security software took two critical Windows .dll files for malware. According to numerous blog entries from Chinese computer users, a virus signature database seeded yesterday mistook two system files of a Chinese edition of Windows XP SP2 as a Trojan horse which Symantec dubs "Backdoor.Haxdoor." via Computerworld

The anti-virus software -- Norton AntiVirus, for example, or the anti-virus component of the Norton 360 or Norton Internet Security suites -- then quarantined the netapi32.dll and lsasrv.dll files."With these files removed, Windows XP will no longer start up, and even the system Safe Mode no longer functions," said one user writing to the alt.comp.anti- virus newsgroup

0 comments: