IMPORTANT NOTIFICATION

This site is an archive of Simon's first blog.
Current writing and commentary is now published at
simonedwards.com.
Showing posts with label dodgy updates. Show all posts
Showing posts with label dodgy updates. Show all posts

Wednesday, 6 February 2013

Kaspersky anti-virus update breaks internet

An update to Kaspersky's anti-virus software broke internet connections for Windows XP users.

The issue came to light on Monday and affected both consumer and business versions of the security software running on Windows XP.

Kaspersky recommended that users disable the "Web AV" component of the software, clear previously-downloaded updates and then update afresh.

The company was quoted in its support forum as adding:
"After the update has been pushed to your workstations, please re-enable your Web AV component in your protection policy. This should resolve the issue."

Thursday, 20 September 2012

Sophos anti-virus kills own updater

Last night anti-virus software from Sophos mistakenly detected its own updating software as being malware.

Additionally it also detected other updater applications as being malicious.

Many well-known anti-virus companies have experienced significant so-called 'false positive' incidents in recent years, but this one was particularly important because the security software quarantined its own updating software.

The usual solution for a serious false positive incident is for the company to issue an update, as quickly as possible, to correct the situation. In this case, though, updates were hard to push out due to the updating software having been disabled.

Sophos issued advice on how to fix the problem.

However, not everyone has found this to be satisfactory. Customer comments on Sophos' website included:
You managed to push out a false positive which flags your own update utility as a trojan and quarantines it, and the solution is... wait for it... to update Sophos using the now-quarantined update binary. Well done.
We were hit with this. I've disabled "on-Access" until it's cleared up, but what do I do with the endpoints that are already quarantined? In the quarantine the only options are "move" and "delete"...
This fiasco has also broken Sage MicroPay and Sage accounts on our customer sites. Payroll for these customers has been severely disrupted as a result. The only resolution we have so far for this is a reinstallation of the affected applications. The suggested fix as posted here to date does nothing but attempt to repair the Sophos environment. The knock on effect for other applications could be huge.
See more cases of 'dodgy updates', including when Avira's software detected itself as Trojan; Microsoft detected Google Chrome as a banking Trojan; McAfee software broke computers, and the company offered financial compensation; while Avast! destroyed some Windows installations.

Tuesday, 31 January 2012

Anti-malware testing: results challenged

When we run anti-malware tests we sometimes find anomalies in how anti-virus products behave when faced with threats.

Sometimes a new beta product from a vendor appears to be less effective than a previous version. In other cases there are differences between corporate and consumer products from the same vendor.

Because we want to recommend good products we find these differences to be interesting, but the vendors themselves seem to find them even more so.

For example, if we discover that a beta version is not up to scratch, the vendor has a chance to fix the problem before releasing the finished product. That is a valuable result of testing in the way that Dennis Technology Labs does.

In one memorable case we found that the corporate version of a product failed to protect against a threat that the related consumer product managed to handle perfectly well. The vendor in question found this result to be unlikely.

When we find a result that surprises a vendor we are challenged to provide evidence. This makes sense because if we are right then a lot of expensive time is going to be spent by the vendor in fixing the problem. Of course, the end result is good for everyone.

In the example above, we provided a report that led the vendor to discover a significant problem with its back-end updates system. A redacted PDF version is available on Dennis Technology Labs' website.

We expect and welcome challenges to our results. They provide vendors with useful information, which means better products (one hopes!) and they ensure that our own procedures are up to scratch.

The end result is better testing, better software and better protection for the user, which is what we care about the most.

Thursday, 27 October 2011

Avira anti-virus detects self


Avira Premium Security Suite detected itself as a spy Trojan yesterday.

More specifically, the anti-malware software generated a false positive on a DLL called aescript.dll, mis-classifying it as TR/Spy.463227.

Avira claims that the problem can be fixed by running an update.

In the last 24 hours the dodgy update affected over 10,000 users (see below).




Monday, 3 October 2011

Microsoft treats competing web browser as banking Trojan

Microsoft's anti-malware software has mistakenly classified Google's Chrome web browser as a 'Severe' banking Trojan.

According to The Register, "On Friday, a faulty signature update for both Microsoft Security Essentials and Microsoft Forefront incorrectly detected the Chrome executable file for Windows as a component of the notorious ZeuS trojan."

While it seems that so far both Google and Microsoft are saying little about the alleged incident, there is an interesting note at the top of Microsoft's Malware Protection Center's Threat Research and Response Encyclopedia:

"NOTICE: September 30, 2011: MMPC has identified an incorrect detection for PWS:Win32/Zbot affecting Google Chrome. Signature version 1.113.672.0 or higher addresses the issue."

Update: 03/10/2011 11:22 Both Microsoft and Google have acknowledged the situation [The Register].

Monday, 26 April 2010

McAfee offers compensation for bad update

McAfee is offering support and, ultimately, cash to put things right with customers who fell foul of last week's dodgy update. In other words, if you've had to spend money to fix your computer then McAfee will reimburse you (within reasonable parameters).

In a statement on its website the company says:

"If you are currently running Windows XP we recommend checking to ensure you have the latest security update.

If you are one of a small percentage of McAfee’s consumer customers who has an inoperable or severely impaired PC as a result of the faulty file released earlier this week, we want to sincerely apologize for the inconvenience. Our immediate priority is to get you back up and running.

Here are the steps you can take.

Step 1 – Locate a local toll free support number for your country. A qualified technician is standing by to diagnose your computer’s current status and determine the fastest way to get you up and running again.

Step 2 – If the technician can’t get your system up and running over the phone, we’ll get you the software to get your system up and running again. We can get you the software in one of two methods. You can either download the software fix from a working PC, or we will express deliver a CD to you.

If you have already incurred costs to repair your PC as a result of this issue, we’re committed to reimbursing reasonable expenses. Steps to process your reimbursement request will be posted in the next few days. Please check back here in a few days.

Because we value our loyal customers, if your PC was rendered inoperable or severely impaired as a result of the faulty file released you are eligible for a two year extension of your existing McAfee subscription free of charge.

We’re committed to getting this issue resolved for all our customers worldwide as quickly as possible."

Thursday, 22 April 2010

McAfee anti-virus update breaks PCs

A recent anti-virus update sent out by McAfee has caused Windows XP systems to fail. The update incorrectly detects a legitimate system file as being a virus, removes it and shuts down the system. The PC is then unable to boot correctly. Networking is disabled after the system is brought back into some form of useful state.

The problem relates to the DAT 5958 update, which detects the svchost.exe file as being a virus called W32/Wecorl.a.

Reports suggest large companies that manage many systems protected by McAfee's software are the worst affected. The Internet Storm Center notes that, "The use of 'ePolicyOrchestrator', which is used to update virus definitions across a network, appears to have lead to a faster spread of the bad DAT file. The ePolicyOrchestrator is used to update 'DAT' files throughout enterprises. It can not be used to undo this bad signature because affected system will lose network connectivity."

McAfee is not alone in making such a mistake. In December last year Alwil (developer of Avast!) dumped a similarly-damaging update on its users and it would be a rare anti-virus company that could claim accurately never to have done the same thing at some stage.

Monday, 7 December 2009

Avast! Broken anti-virus updates ahoy!

Avast!'s CEO Vincent Steckler has made a public apology after the security company released a troublesome update to its anti-virus software. The virus database released early on Thursday caused some users "significant problems". It was sent out by engineers who bypassed the automated testing systems in an effort to fix a problem with the previous update.

In his CEO's Corner blog, Steckler wrote, "I apologize to each and every one of you - I realize that security is fundamentally about trust and you have to trust your security provider. We made a mistake here and it won’t happen again."

The update detected over 50,000 clean file samples as being infected. The result was that some users have reported having to restore their systems from backups or reinstalling Windows. More details are available on this forum post, made by Avast!'s CTO Ondrej Vlcek.