Slashdot Log In
Anti-Virus Bug Briefly Identified Windows Explorer as Malware
Posted by
Zonk
on Tue Dec 25, 2007 12:23 PM
from the err-oops-pay-no-attention-to-your-OS dept.
from the err-oops-pay-no-attention-to-your-OS dept.
SJ2000 writes "Windows Explorer was quarantined last week by Kaspersky Lab's antivirus software after being falsely identified as malicious code. The security company's systems had decided that a virus called Huhk-C was present in the explorer.exe file, leading to its confinement or, in some cases, deletion. The bug was only live in the wild for two hours, and ended up affecting just one corporate customer and a handful of home users."
Related Stories
This discussion has been archived.
No new comments can be posted.
The Fine Print: The following comments are owned by whoever posted them. We are not responsible for them in any way.
Full
Abbreviated
Hidden
Loading... please wait.
I don't get it... (Score:5, Funny)
Re:I don't get it... (Score:5, Funny)
Because it only identified the explorer component.
Parent
Re:I don't get it... (Score:5, Funny)
Parent
Re: (Score:2)
Re:I don't get it... (Score:4, Funny)
maybe that's why I got laid off...
Parent
Where is the Obligatory Gay Male Coprophilia Porn (Score:4, Funny)
I guess it's just too early still in Seattle... Maybe they will post it later.
Merry Christmas Bill!
Parent
Re: (Score:3, Funny)
Obligatory fixed (Score:4, Funny)
Windows Is Not A Virus! (Score:5, Funny)
Re: (Score:2)
It is a trojan!
jk (Score:4, Funny)
um, don't they test these things before releasing? (Score:5, Insightful)
That's my first reaction, now I'm off to RTFA
Re:um, don't they test these things before releasi (Score:5, Funny)
Oh, you mean Kaspersky Labs
Parent
Re: (Score:2, Funny)
Shouldn't this have been caught by even the simplest test before releasing?
[X] In Soviet Russia, IE tests YOU! ..."
[X] Only old Koreans bother with testing!
[X] "But it IS malware, boss!"
[X] Netcraft confirms it - testing is dead!
[X] I don't run IE, you ignorant clod!
[X] "We tried to test it on Vista, and we will, as soon as its finished booting
O rly? (Score:5, Funny)
And yet it still made the front page of Slashdot.
Re: (Score:2)
Re:O rly? (Score:5, Insightful)
So what does that make people who are stupid enough to mistake Internet Explorer for Windows Explorer?
Parent
Re: (Score:3, Interesting)
Have you even used windows lately? (Score:3, Funny)
It's not a virus, sure. Viruses tend to mature, become more efficient...
But Explorer sure feels like malicious code...
Seen it all before... (Score:3, Interesting)
We've also had Norton 'false positive' on the Windows version of Oolite.
One of these days, a widely used, automatically updated virus scanner is going to detect something like KERNEL32 as malware and kill a whole lot of machines. Wasn't there a problem like this with the Chinese version of Windows earlier this year?
Re: (Score:3, Insightful)
It is not an optional component to install last time I checked so all of their test machines should have had this file. At least some of their test machines should have had exactly that same version of this file
HUHK = Hamburger University of Hong King (Score:3, Funny)
Why things like this happen (Score:5, Insightful)
But how? Don't they test?
Of course they do. AV developers usually have some way to test against the most common software (and a few more software packages) before issuing a new signature. Though, as you can hopefully imagine, that takes time. The "whitelist" box that contains those "known good" files contains literally gigabytes (and soon terabytes) of software. As you can imagine, it takes a LOT of time to scan it all.
Time, though, is of the essence in the malware fight. You NEED that signature out before the proverbial shit hits the fan (i.e. before your customer opens that infected spam mail that was just distributed a few billion times globally). So your sig update has to go out NOW. Preferably it should've been out an hour ago.
How do you solve that quandary?
There are a few strategies. But they all come down to one single problem: Having a current version of every file you want to whitelist. So what most likely happened is this:
MS pushed an update for the file in question, most likely another of their infamous "silent" updates. You know, the ones you don't even notice. Now, if it wasn't a "silent" one, then one should wonder whether Kaspersky was sleeping (because they didn't fit it into their whitelist box in time) or whether it was pushed JUST at that time when they committed that update. Unfortunately such coincidences do happen.
Now, I'm not working at Kaspersky. Rather, I'm working at one of their fiercest competitors. So I should probably rejoice at their blunder (and I'm fairly sure my boss will be in a GOOD mood on Thu, time to ask for a raise, I guess). But it can, did, does and will happen. To anyone in the biz. No matter how good you are and how good your false positive alarms and nets are, it can happen to everyone. If anything, this proves it. Kaspersky IS one of the key players in the business, and they usually know what they're doing.
That's one of the reasons why I do highly recommend that you set your AV tools on "ask me before any action" mode. Yes, it bugs you every now and then, but it also means that things like this won't happen to you should your AV tool manufacturer have a similar problem one day.
Re:Anti-Virus Bug Briefly Identified Windows Explo (Score:5, Funny)
Parent
Re: (Score:3, Insightful)
The point I was making, which should be clear to you, was that there is no merit in making a choice just because it is popular. I can choose to eat food because "everyone else does" and it means nothing; I can choose to eat food becau