On CBS.com: Exclusive video from MEDIUM
BNET Business Network:
BNET
TechRepublic
ZDNet

November 11th, 2008

AVG and Rising signatures update detects Windows files as malware

Posted by Dancho Danchev @ 9:50 am

Categories: Anti Virus, Malware, Microsoft, Spyware and Adware, Viruses and Worms

Tags: Security, Antivirus, AVG, Rising Antivirus, False Positive, Microsoft Outlook, Windows XP, Dancho Danchev

AVG AntivirusYesterday, a signatures update pushed by AVG falsely labeled a critical Windows file as a banker malware, prompting the company to quickly fix the issue and issue a workaround, following end users complaints at its support forums.

AVG’s false positive causing downtime for Windows users is happening a week after Rising antivirus apologized to its customers for falsely detecting Outlook Express as malware leading to loss of emails, and yes, productivity too.

The impact of the false positive leads to a continuous reboot cycle :

“An update for the AVG virus scanner released yesterday contained an incorrect virus signature, which led it to think user32.dll contained the Trojan Horses PSW.Banker4.APSA or Generic9TBN. AVG then recommended deleting this file; this causes the affected systems to either stop booting or go into a continuous reboot cycle. So far, the problem only appears to affect Windows XP, but there is no guarantee that other versions of Windows don’t have the same issue.”

Rising AntivirusAVG’s brief response to the situation, with the workaround posted at AVG’s support section under the “False positive user32.dll” title :

“Unfortunately, the previous virus database might have detected the mentioned virus on legitimate files. We can confirm that it was a false alarm. We have immediately released a new virus update (270.9.0/1778) that removes the false positive detection on this file. Please update your AVG and check your files again.

We are sorry for the inconvenience and thank you for your help.

Best regards,
Zbynek Paulen
AVG Technical Support”

AVG and Rising aren’t an exception to previous cases where components of Microsoft’s Windows have been detected as false positives. In fact, in 2006 Microsoft’s Anti-Spyware was detecting a competing solution as a piece of malware :

Response time is crucial in such a situation, so the best thing the vendors can do is go public and provide assistance in fixing the problem.

Dancho DanchevDancho Danchev is an independent security consultant and cyber threats analyst, with extensive experience in open source intelligence gathering, malware and cybercrime incident response. He's been an active security blogger since 2007, and maintains a popular security blog. See his full profile and disclosure of his industry affiliations.

Email Dancho Danchev

Subscribe to Zero Day via Email alerts or RSS.

  • Talkback
  • Most Recent of 19 Talkback(s)
AVG screws this musician! I NEED MY COMPUTER!!
What i think is.. well NM at all except how the hell am i going to fix my computer??? i tried all of their suggestions from their website like booting from a disk and flashdrive what am i left with...... (Read the rest)
Posted by: BradFromHC Posted on: 12/19/08  (Edited: 12/19/08 @ 10:14) You are currently: a Guest | | Terms of Use
And why would they not?  Ole Man | 11/11/08
Undermedicated  dprozzo | 11/11/08
No, he's quite correct  masonwheeler | 11/12/08
And this has just what to do with the topic?  bob.kerns2 | 11/12/08
Isn't the first time.  CobraA1 | 11/11/08
Switch fast  Sandeep108 | 11/13/08
Any decent AV would quarantine Windows anyway.  fr0thy2 | 11/12/08
 masonwheeler | 11/12/08
RE: AVG and Rising signatures update detects Windows files as malware  glassangel | 11/12/08
correction  dinosaur_z | 11/12/08
RE: AVG and Rising signatures update detects Windows files as malware  paulymitch@... | 11/12/08
AVG update detects Windows files as malware - LOL  digitrog | 11/12/08
RE: AVG and Rising signatures update detects Windows files as malware  adamjames | 11/12/08
AVG finally turned into a virus on Vista  graham.lv | 11/13/08
RE: AVG and Rising signatures update detects Windows files as malware  unclefixer@... | 11/13/08
RE: AVG and Rising signatures update detects Windows files as malware  john9010 | 11/14/08
RE: AVG and Rising signatures update detects Windows files as malware  fernald@... | 11/14/08
RE: AVG and Rising signatures update detects Windows files as malware  rMatey | 11/14/08
AVG screws this musician! I NEED MY COMPUTER!!  BradFromHC | 12/19/08

What do you think?

SponsoredWhite Papers, Webcasts, and Downloads

advertisement

Recent Entries

advertisement

Archives

Favorite Links

ZDNet Blogs

White Papers, Webcasts, and Downloads