On BNET: 3 worst things about the iPhone 3G S
BNET Business Network:
BNET
TechRepublic
ZDNet

By David Meyer , ZDNet (UK)
Posted on ZDNet News: Dec 21, 2007 6:04:00 AM

Windows Explorer, one of the most crucial components of Microsoft's operating system, was quarantined earlier this week after being falsely identified as malicious code by an antivirus company.

Users of Kaspersky Lab's antivirus products noticed the issue, which Kaspersky claimed lasted two hours, on Wednesday night.

The security company's systems had decided that a virus called Huhk-C was present in the explorer.exe file, leading to its confinement or, in some cases, deletion. As Windows Explorer is the graphical user interface (GUI) for Windows' file system, this made it difficult to perform many common tasks within the operating system, such as finding files.

David Emm, a senior technology consultant at Kaspersky Lab, told ZDNet UK on Friday that the company was still examining its checklist to find out why the false positive "slipped through the net."

"This is classic false-alarm territory," Emm said. "We will check through our systems and see if we can tighten them up so we don't run into this problem in the future. No antivirus company, including ourselves, can say they have never had a false alarm, (but) on all fronts, we do what we can to minimize any potential risk for our customers."

Emm pointed out that Kaspersky adds about 3,000 records per week to its database, demonstrating the "scale of the issue, in terms of testing procedures."

The "offending signature" went out at around 7 p.m. on Wednesday, according to Emm, who claimed that it was pulled two hours later in a "makeshift" attempt to limit the damage while Kaspersky examined the signature.

"We proactively went out to our enterprise customers to make them aware there was this potential issue," Emm said. "Only one corporate customer (in the U.K.) encountered this problem, as well as a handful of home users." He added that users who have not changed their default settings would have found explorer.exe to be only quarantined, rather than deleted.

In March of this year, Kaspersky criticized Microsoft's consumer antivirus product, OneCare, for incorrectly quarantining and, in some cases, deleting Microsoft Outlook files.

David Meyer of ZDNet UK reported from London.

©2007 CNET Networks, Inc. All rights reserved. CNET , CNET.com , and the CNET logo are registered trademarks of CNET Networks, Inc. Used by permission.

SponsoredWhite Papers, Webcasts, and Downloads

  • Talkback
  • Most Recent of 12 Talkback(s)
Actually Internet Explorer is a virus.
No actually Internet Explorer is a virus.

http://www.youtube.com/watch?v=7fh9Ityy8hI

Read the rest)
Posted by: usarcomputertec Posted on: 01/10/08 You are currently: a Guest | | Terms of Use
So what is the difference between an AV package and a virus again?  osreinstall | 12/21/07
Viruses are typically less damaging?  NonZealot | 12/21/07
Oops, that was a reply to osreinstall (nt)  NonZealot | 12/21/07
I figured that.  osreinstall | 12/21/07
Does this work on Ubuntu?  galileon | 12/21/07
Blockbuster like everyone else  josephrot | 12/22/07
RE: Kaspersky inadvertently quarantines Windows Explorer  lkafle | 12/22/07
Norton Challenge  mytetteh | 12/24/07
Take the Norton Challange??  puppadave | 12/24/07
Oops, an AV did it again  Boot_Agnostic | 12/26/07
RE: Kaspersky inadvertently quarantines Windows Explorer  nimd4 | 12/28/07
Actually Internet Explorer is a virus.  usarcomputertec | 01/10/08

What do you think?

advertisement
advertisement

White Papers, Webcasts, and Downloads

SmartPlanet

advertisement
Click Here