Stories
Slash Boxes
Comments

News for nerds, stuff that matters

Slashdot Log In

Log In

Create Account  |  Retrieve Password

Anti-Virus Bug Briefly Identified Windows Explorer as Malware

Posted by Zonk on Tue Dec 25, 2007 11:23 AM
from the err-oops-pay-no-attention-to-your-OS dept.
SJ2000 writes "Windows Explorer was quarantined last week by Kaspersky Lab's antivirus software after being falsely identified as malicious code. The security company's systems had decided that a virus called Huhk-C was present in the explorer.exe file, leading to its confinement or, in some cases, deletion. The bug was only live in the wild for two hours, and ended up affecting just one corporate customer and a handful of home users."
+ -
story

Related Stories

This discussion has been archived. No new comments can be posted.
The Fine Print: The following comments are owned by whoever posted them. We are not responsible for them in any way.
 Full
 Abbreviated
 Hidden
More
Loading... please wait.
  • by Anonymous Coward on Tuesday December 25 2007, @11:25AM (#21815044)
    Windows identified as malware... why is this a bug?
  • by Anonymous Coward on Tuesday December 25 2007, @11:25AM (#21815048)
    Anti-Virus Bug "Correctly" Identified Windows Explorer as Malware
  • by filesiteguy (695431) <kai@perfectreign.com> on Tuesday December 25 2007, @11:30AM (#21815076) Homepage
    Viruses are small and efficient.
    • You are correct!

      It is a trojan!
      • Nope. Trojans are being streamlined to hide better from the user's eye, usually have a fairly small footprint (less than 100k normally, and few are bigger than 500k), get updated at the very least every other week, are tested and tried until they are bug free and will never ever blow up in the user's face.

        Windows is not a trojan.

        It is a bug.
  • jk (Score:4, Funny)

    by wizardforce (1005805) on Tuesday December 25 2007, @11:32AM (#21815090) Journal
    that's not a bug, it's a feature
  • by Anonymous Coward on Tuesday December 25 2007, @11:33AM (#21815094)
    Shouldn't this have been caught by even the simplest test before releasing?

    That's my first reaction, now I'm off to RTFA
    • by ubrgeek (679399) on Tuesday December 25 2007, @11:35AM (#21815114)
      You're right. But sometimes MS is in a hurry to get their product out.

      Oh, you mean Kaspersky Labs ...
    • Re: (Score:2, Funny)

      by Anonymous Coward

      Shouldn't this have been caught by even the simplest test before releasing?

      [X] In Soviet Russia, IE tests YOU!
      [X] Only old Koreans bother with testing!
      [X] "But it IS malware, boss!"
      [X] Netcraft confirms it - testing is dead!
      [X] I don't run IE, you ignorant clod!
      [X] "We tried to test it on Vista, and we will, as soon as its finished booting ..."

        • Netcraft is dead... Netcraft confirmed it!

          Also, always good to see another Vista user. Now I'll have someone to get my back when I defend Vista against haters. ;)

  • O rly? (Score:5, Funny)

    by Dunbal (464142) on Tuesday December 25 2007, @11:52AM (#21815218)
    The bug was only live in the wild for two hours, and ended up affecting just one corporate customer and a handful of home users.

          And yet it still made the front page of Slashdot.
      • I use IE7 (due to policies and ) at work and FF at home. Why am I stupid ?
        • Re: (Score:2, Informative)

          "I use IE7 (due to policies and ) at work and FF at home. Why am I stupid ?" For starters your sentence should have been typed like this: "I use IE7 (due to job-related policies) at work and FF at home. Why am I stupid?"
      • Re:O rly? (Score:5, Insightful)

        by rhizome (115711) on Tuesday December 25 2007, @01:02PM (#21815650) Homepage
        It made the front page of Slashdot because a corporate user shouldn't be stupid enough to use Microsoft Explorer over a real browser.

        So what does that make people who are stupid enough to mistake Internet Explorer for Windows Explorer?
      • Re: (Score:3, Interesting)

        I was under the impression that explorer.exe was the MSWindows file manager. As a file manager, it actually is quite nice and has some interesting (good, or at least different) properties compared to nautilus. Such as copying a folder with the same name as a folder in the target will perform a merge of the two folder contents rather than deleting the original contents or the target.
        • The idea of merging is cool, but if a merge is the most intuitive outcome of a folder copy for you, it sure isn't for me. Hopefully the user is notified about the proposed merge? else it's housekeeping time for me when i get back to work.
          • I'm not sure if it is more intuitive or not. Presumably MSFT has good usability lab to figure that out. It is less destructive, though.

            It's been a while since I got burnt by it in nautilus. Does nautilus warn you if it's about to delete the entire contents of a folder because another folder with the same name is being copied over it?

            I know that at at least until a year ago, on filesystems that are case retentive but not case sensitive (ie: fat32 and ntfs), nautilus aborts without any warning if it copies
          • Hopefully the user is notified about the proposed merge? else it's housekeeping time for me when i get back to work.
            You get a "Confirm Folder Replace" dialogue [lowendmac.com].

            BTW, is pressing "ctrl-z" ( / edit -> undo) really that much housekeeping work?
  • by pcgabe (712924) on Tuesday December 25 2007, @12:53PM (#21815596) Homepage Journal

    "Windows Explorer was quarantined last week by Kaspersky Lab's antivirus software after being
    falsely identified as malicious code.
    "Falsely?"

    It's not a virus, sure. Viruses tend to mature, become more efficient...

    But Explorer sure feels like malicious code...
  • by Anonymous Coward
    From TFA:

    As Windows Explorer is the graphical user interface for Windows' file system, this made it difficult to perform many common tasks within the operating system, such as finding files.

    Gee, makes it sound like losing explorer.exe is only mildly inconvenient.
  • Very slow news day.
  • by Alioth (221270) <no@spam> on Tuesday December 25 2007, @01:17PM (#21815748) Journal
    ...last year, when Symantec flagged part of the Windows Server 2003 resource kit as a trojan. That one stayed in 'the wild' much longer, probably because the resource kit in particular wasn't a widely installed piece of software.

    We've also had Norton 'false positive' on the Windows version of Oolite.

    One of these days, a widely used, automatically updated virus scanner is going to detect something like KERNEL32 as malware and kill a whole lot of machines. Wasn't there a problem like this with the Chinese version of Windows earlier this year?
    • Re: (Score:3, Insightful)

      Both of the items you mention I can just about understand making it through a software testing process. It is feasible that none of the test machines had the two peices of software you mention installed. But if you can find me a windows box without explorer.exe I will show you a borked installation.

      It is not an optional component to install last time I checked so all of their test machines should have had this file. At least some of their test machines should have had exactly that same version of this file
  • by SlappyBastard (961143) on Tuesday December 25 2007, @01:33PM (#21815854) Homepage
    http://www.huhk.com/intro_background.html [huhk.com] Hmmm... Truly viral marketing.
  • So what does that mean? are we all fucked?
  • by Opportunist (166417) on Tuesday December 25 2007, @05:54PM (#21817228)
    Now, of course they should not. Never. But they do. A few years ago, McAfee found MS Excel as malware (and acted accordingly, including detention or deletion, just like Kaspersky did with explorer now).

    But how? Don't they test?

    Of course they do. AV developers usually have some way to test against the most common software (and a few more software packages) before issuing a new signature. Though, as you can hopefully imagine, that takes time. The "whitelist" box that contains those "known good" files contains literally gigabytes (and soon terabytes) of software. As you can imagine, it takes a LOT of time to scan it all.

    Time, though, is of the essence in the malware fight. You NEED that signature out before the proverbial shit hits the fan (i.e. before your customer opens that infected spam mail that was just distributed a few billion times globally). So your sig update has to go out NOW. Preferably it should've been out an hour ago.

    How do you solve that quandary?

    There are a few strategies. But they all come down to one single problem: Having a current version of every file you want to whitelist. So what most likely happened is this:

    MS pushed an update for the file in question, most likely another of their infamous "silent" updates. You know, the ones you don't even notice. Now, if it wasn't a "silent" one, then one should wonder whether Kaspersky was sleeping (because they didn't fit it into their whitelist box in time) or whether it was pushed JUST at that time when they committed that update. Unfortunately such coincidences do happen.

    Now, I'm not working at Kaspersky. Rather, I'm working at one of their fiercest competitors. So I should probably rejoice at their blunder (and I'm fairly sure my boss will be in a GOOD mood on Thu, time to ask for a raise, I guess). But it can, did, does and will happen. To anyone in the biz. No matter how good you are and how good your false positive alarms and nets are, it can happen to everyone. If anything, this proves it. Kaspersky IS one of the key players in the business, and they usually know what they're doing.

    That's one of the reasons why I do highly recommend that you set your AV tools on "ask me before any action" mode. Yes, it bugs you every now and then, but it also means that things like this won't happen to you should your AV tool manufacturer have a similar problem one day.
    • Can I ask where you work? Because Mcafee does not impress me at the moment. You can send me an e-mail.. smkatz@gmail.com if you would prefer not to say so publicly. (I'm not worried about spam, because Gmail filters it.)
  • Yesterday, AVG Free identified Quake4.exe as a trojan on my machine. I had to disable AVG and run the Quake 4 update to get it running again.
    • Building fail-safes would make sense and might work.
    • "Why not have the music player, upon detection of a track, check for a Microsoft digital signature in the WMA, and maybe behave differently in this situation? Might just save a few systems in the future from incorrect signatures. I can't see this change in logic being beneficial to song writers as they won't have a Microsoft signature, and if they can somehow change the music playing program to check for digital signatures against a different public key, you are already liberated."

      Just an analogy to the w

      • That doesn't make sense at all as an analogy. This idea assumes that all Microsoft-signed binaries are clean and that any virus signatures found in those files should be ignored. It's not an extra layer of security, it's a way to prevent the annoyance of false-positives in an existing layer. I can't think of a direct analogy involving DRM; it would have to involve exempting files meeting certain criteria from restriction.

        If an AV scanner decides to let all MS-signed binaries go, they might also consider
    • What's funny is, if I saw that explorer was missing on my system, by the time I reloaded the OS (cause *obviously* it's infected/broken/normal operating procedure), I never would've known the cause. It was pulled by the time I would've finished installing.

      You'd reload Windows because explorer.exe is missing? Holy crap, is that ever overkill.

      Run WinUBCD, change the shell to cmd.exe, reboot, and run sfc. That would fix you right up, in about 10 minutes. And it would also give you the opportunity to figu

              • Re: (Score:3, Insightful)

                I never stated a thing about being "fulfilled": I just stated people are wise to use something that IS the most used, so they are ready for it in the workplace, so they can get paid. Job requirements & training for them is what running Windows @ home does for most folks.

                The point I was making, which should be clear to you, was that there is no merit in making a choice just because it is popular. I can choose to eat food because "everyone else does" and it means nothing; I can choose to eat food becau