Please create an account to participate in the Slashdot moderation system

 



Forgot your password?
typodupeerror
×
Bug Technology

Botched Security Update Cripples Thousands of Computers 274

girlmad writes "Thousands of PCs have been crippled by a faulty update from security vendor Malwarebytes that marked legitimate system files as malware code. The update definition meant Malwarebytes' software treated essential Windows.dll and .exe files as malware, stopping them running and thus knocking IT systems and PCs offline, leaving lots of unhappy users and one firm with 80% of its servers offline."
This discussion has been archived. No new comments can be posted.

Botched Security Update Cripples Thousands of Computers

Comments Filter:
  • by Frosty Piss ( 770223 ) * on Thursday April 18, 2013 @12:28AM (#43479735)

    ...is all I use these days.

    Of course since Windows is "out of favor" here, one does not necessarily mention that Microsoft's "Security Essentials" is easily as good as most commercial Windows anti-malware packages, and much more "light weight". And free. And yes, everyone knows that Microsoft purchased the original technology (so what?) ...

  • Doh! (Score:4, Insightful)

    by All_One_Mind ( 945389 ) on Thursday April 18, 2013 @12:30AM (#43479745) Homepage Journal
    For once I'm happy that I'm too lazy to regularly update programs like that.
  • by Anonymous Coward on Thursday April 18, 2013 @12:32AM (#43479757)

    for using microsoft servers

  • by Anonymous Coward on Thursday April 18, 2013 @12:42AM (#43479793)

    I've yet to see an AV that actually can deal with browser add-on attacks.

    The only thing that might help is Malwarebytes because it blocks by IP address.

    If you want protection, use an ad blocker. Ad servers seem to be one of the chief causes, if not the top infection vector these days.

  • 1 in 20 (Score:4, Insightful)

    by tuppe666 ( 904118 ) on Thursday April 18, 2013 @12:44AM (#43479795)

    Maybe I'm doing something wrong, but I haven't seen a virus in a decade.

    ...or maybe as http://eugene.kaspersky.com/2013/03/25/one-in-twenty-is-the-sad-truth/ [kaspersky.com] "Even those who care nothing for their health still get sick – it’s just that the infection goes undiagnosed" as much as you may find it comforting blaming users, 1 in 20 infected machines implies there is something wrong. Its no wonder users are not buying PC's anymore.

  • by Anonymous Coward on Thursday April 18, 2013 @12:48AM (#43479811)
    NO, it hasn't been getting bad reviews, it has had some negative press based on some dodgy tests that try to use essentials for something it isn't really meant for. They throw zero day malware to test its heuristics, which are not wonderful. however in known malware (the stuff 99.9% of people need protection against) it is exceptionally good.
  • by inflex ( 123318 ) on Thursday April 18, 2013 @01:08AM (#43479883) Homepage Journal

    All I use and recommend now as well. Previously good AV suites have become pointlessly (for the consumer) bloated and I'm having a higher occurence of machines being bought in with faults explicitly attributable to the AV suites.

    I'm no fan of Microsoft, but I have to say that MSE does tend to do an acceptable job given that inevitably all AV suites let stuff slip past.

  • by Spikeles ( 972972 ) on Thursday April 18, 2013 @01:40AM (#43479985)

    There is no way to prevent these things from happening

    Sure there is. Kaspersky Anti-Virus Security Center has a Update Verification [kaspersky.com] module built in, that allows a sysadmin to install the update to a known-clean test group and then run a virus scan BEFORE the update is applied to the rest of the machines. If the scan fails(ie, finds anything), the update is aborted and an email is sent to the admin. If Malwarebytes had that kind of thing(or if it did and the sysadmins actually used it), this wouldn't even be an issue.

  • by Anonymous Coward on Thursday April 18, 2013 @01:47AM (#43480015)

    All I use and recommend now as well. Previously good AV suites have become pointlessly (for the consumer) bloated and I'm having a higher occurence of machines being bought in with faults explicitly attributable to the AV suites.

    Which is why, over a year ago, I tried out MSE, found that (at least, back then) it was as good as the usual freebie AV offerings, and installed it on a number of customer PCs and laptops.

    I'm no fan of Microsoft,

    I got a serious amount of stick for going the MSE route, I've cordially detested Microsoft and it's unholy offerings since DOS 3.2

    but I have to say that MSE does tend to do an acceptable job given that inevitably all AV suites let stuff slip past.

    And this is the thing, '..inevitably all AV suites let stuff slip past
    I've had infected machines back to me for disinfection which had been running fully up to date AV suites (both free and commercial).
    In a bout of boredom one week, I set up a test machine running XP c/w patches, ghosted the install, then worked my way through various AV suites, free and commercial.
    The basic test was, fire up eMule, download the obvious virus files, then try to deliberately infect the system by running them.
    Eventually, all the AV suites I tried failed, and the box was duly infected (which lead to part two of the test, how capable various disinfection tools are..oh, what fun).
    MSE fell out of my favour a while back mostly due to detection issues (over a couple of weeks, 10 machines running it became infected with known [to most of the other AV software] variants of a Trojan then doing the rounds) It's hard trying to explain to people that AV software is as fallible as any other software, especially when you initially specified/installed it and are now charging them for repairing the damages caused by it's failure.

  • by Electricity Likes Me ( 1098643 ) on Thursday April 18, 2013 @02:15AM (#43480087)

    Basically "stop doing stupid things with your computer".

    Why a firm needed Malware Bytes on it's servers in the first place is the real question here.

  • by Joce640k ( 829181 ) on Thursday April 18, 2013 @03:32AM (#43480295) Homepage

    Only by those who don't pay attention to current reviews. Like many recent Microsoft products, MSE started off well, but has been in steady decline since its release.

    Face it, they're all shite... the viruses change every single day and no anti-virus of them will protect you from the latest ones. Not one. Virus infection is 100% due to the warm squishy thing between the keyboard and chair, not the flavor of antivirus installed on the machine.

    OTOH, MSE doesn't constantly annoy, slow your PC to a crawl or constantly ask for credit card details just to keep on running.

  • by Joce640k ( 829181 ) on Thursday April 18, 2013 @03:35AM (#43480303) Homepage

    Experience has shown that it makes NO difference what anti-virus I install on people's machines.

  • by Samantha Wright ( 1324923 ) on Thursday April 18, 2013 @03:55AM (#43480385) Homepage Journal

    But if it doesn't slow the computer down to an unusable crawl, how will anyone ever feel safe?!

  • by minus9 ( 106327 ) on Thursday April 18, 2013 @04:08AM (#43480439) Homepage

    If their results can be bought, Microsoft would have bought them.
  • Malwarebytes (Score:4, Insightful)

    by 1s44c ( 552956 ) on Thursday April 18, 2013 @05:13AM (#43480683)

    The clue is in the name.

  • Re:Production (Score:4, Insightful)

    by wonkey_monkey ( 2592601 ) on Thursday April 18, 2013 @06:18AM (#43480885) Homepage
    Yeah, stupid idiots, why didn't they write their own OS from scratch at the start, then they wouldn't have any of these problems.

One man's constant is another man's variable. -- A.J. Perlis

Working...