On last.fm: Exclusive Lightspeed Champion Interview
BNET Business Network:
BNET
TechRepublic
ZDNet

By Aaron Tan, News.com
Posted on ZDNet News: May 24, 2007 2:44:00 PM

A Symantec antivirus signature update mistakenly quarantined two critical system files in the Simplified Chinese version of Windows XP last week, crippling PCs throughout China.

According to the Chinese Internet Security Response Team (CISRT), users of Norton Antivirus, Norton Internet Security 2007 and Norton 360 who installed an antivirus signature update released by Symantec on May 17 could not reboot their PCs. The update reportedly mistook two Windows system files--"netapi32.dll" and "lsasrv.dll"--as the Backdoor.Haxdoo Trojan horse. The two files were subsequently quarantined.

CISRT said the flawed Symantec update affects only users of the Simplified Chinese version of Windows XP Service Pack 2 who have been patched with a particular Microsoft software fix available since November 2006. CISRT noted that this issue has been "huge."

According to CCTV.com, which is part of China's largest national TV network, the problem has affected millions of PCs and was not completely resolved as of Wednesday.

A representative at Symantec Asia-Pacific and Japan confirmed the incident earlier this week, but declined to reveal the number of Chinese Norton customers who were affected. According to Symantec, the problem was caused when Symantec made a change to the automated process used by the company's security response team to detect malicious software.

Symantec said the false detection was immediately removed from the virus signature definitions. Symantec security experts then initiated a LiveUpdate--the company's automated software update process--posting to include the updated definitions. This LiveUpdate became publicly available on May 17, about four and a half hours after Symantec was notified of the issue.

According to Symantec China's Web site, affected customers can resolve the problem by initiating another LiveUpdate, if they have not restarted their PCs after installing the flawed update. Systems that have already been restarted can be returned to the previous state by recovering the two system files from the Windows XP disc.

Aaron Tan of ZDNet Asia reported from Singapore.

  • Talkback
  • Most Recent of 11 Talkback(s)
No matter how you slice it, Symantec just plain sucks...
Take a look at:
http://windowssecrets.com/comp/070517/#story1

Perhaps:
Read the rest)
Posted by: shawkins Posted on: 05/27/07 You are currently: Logged In | Log out
Told ya so! Confused by religion   | 05/24/07
Bloatware Mr Roboto   | 05/24/07
Symantec is junk skeptic tank   | 05/24/07
People still use symantec? kraterz   | 05/24/07
Totally agree! MGP2   | 05/25/07
Removing Norton bluelinex@...   | 05/26/07
Removing Norton DNSB   | 05/26/07
Norton AV is Bad 4 U jwinkler2083233   | 05/25/07
even an idiot can make a good point jymbolia   | 05/25/07
EULA protection? DNSB   | 05/26/07
No matter how you slice it, Symantec just plain sucks... shawkins   | 05/27/07

What do you think?

advertisement
advertisement

The Green Enterprise

advertisement
Click Here