Kaspersky Lab corrects false positive detection of a particular Windows explorer.exe file.
An incorrect threat signature was added to the company's antivirus databases on December 19, 2007, around 7PM GMT. It falsely detected a relatively uncommon version of explorer.exe as Worm.Win32.huhk.c and quarantined the file. The incorrect signature was removed from the database after two hours.
The version of explorer.exe which was falsely detected was released via Microsoft Windows Update service as an Update for Windows XP on 24.07.2007
Unfortunately, the incorrect signature caused a limited number of Kaspersky Lab product users to experience problems with system functionality.
Kaspersky Lab apologizes for any inconvenience caused to users by the error. The company's free 24-hour technical support service is available to assist any affected users in rectifying the problem.
A solution for the issue has also been added to the Kaspersky Lab Technical Support Site. It can be found at http://www.kaspersky.com/support/viruses/computers?qid=208279581 .
Related Posts:
Kaspersky inadvertently quarantines Windows Explorer
Users of Kaspersky Lab's antivirus products noticed the issue, which Kaspersky claimed lasted two hours, on Wednesday night.
The security company's systems had decided that a virus called Huhk-C was present in the explorer.exe file, leading to its confinement or, in some cases, deletion. As Windows Explorer is the graphical user interface (GUI) for Windows' file system, this made it difficult to perform many common tasks within the operating system, such as finding files.
David Emm, a senior technology consultant at Kaspersky Lab, told ZDNet UK on Friday that the company was still examining its checklist to find out why the false positive "slipped through the net."
"This is classic false-alarm territory," Emm said. "We will check through our systems and see if we can tighten them up so we don't run into this problem in the future. No antivirus company, including ourselves, can say they have never had a false alarm, (but) on all fronts, we do what we can to minimize any potential risk for our customers."
Emm pointed out that Kaspersky adds about 3,000 records per week to its database, demonstrating the "scale of the issue, in terms of testing procedures."
The "offending signature" went out at around 7 p.m. on Wednesday, according to Emm, who claimed that it was pulled two hours later in a "makeshift" attempt to limit the damage while Kaspersky examined the signature.
"We proactively went out to our enterprise customers to make them aware there was this potential issue," Emm said. "Only one corporate customer (in the U.K.) encountered this problem, as well as a handful of home users." He added that users who have not changed their default settings would have found explorer.exe to be only quarantined, rather than deleted.
In March of this year, Kaspersky criticized Microsoft's consumer antivirus product, OneCare, for incorrectly quarantining and, in some cases, deleting Microsoft Outlook files.
source:
David Meyer of ZDNet UK reported from London.
Kaspersky Lab, a leading developer of secure content management solutions, has released a new analytical report on the evolution of self-defense technologies in malicious programs. The report is authored by Alisa Shevchenko, one of the company's senior malware analysts.
The article provides an overview of how malicious programs have evolved to combat security solutions and which self-defense techniques are currently used. It also discusses techniques used by virus writers in the past which are no longer effective due to the continued evolution of security solutions. The article also includes predictions as to which technologies are likely to be used in the near future.
The complete report is available on Viruslist.com at the following link:
The following file types were used.
SH, ELF, COM, EXE, PL, BAT, PRC, DOC, XLS, BIN, MDB, IMG, PPT, VBS, MSG, VBA, OLE, HTM, INI, SMM, TD0, REG, CLASS, HTA, JS, VI_, URL, PHP, WMF, HLP, XML, SCR, PIF, SHS, WBT, CSC, MAC, DAT, CLS, STI, INF, HQX, XMI, SIT.
The virus samples were divided into these categories, according to the type of the virus :
Kaspersky Lab, a leading developer of secure content management solutions, has discovered the first virus designed to infect iPod portable media players. The virus, which has been named Podloso, is a proof of concept program which does not pose a real threat.
The virus is a file which can be launched and run on an iPod. It should be stressed that in order for the virus to function, Linux has to be installed on the iPod. If the virus is installed on the iPod by the user, the virus then installs itself to the folder which contains program demo versions. Podloso cannot be launched automatically without user involvement.
Once launched, the virus scans the device’s hard disk and infects all executable .elf format files. Any attempt to launch these files will cause the virus to display a message on the screen which says "You are infected with Oslo the first iPodLinux Virus".
Podloso is a typical proof of concept virus, which is created in order to demonstrate that it is possible to infect a specific platform. It does not have a malicious payload and is unable to spread on its own: a user has to save the virus to the iPod for the device to become infected.
Vulnerabilities fixed:
This vulnerability allows remote attackers to download and remove any file on vulnerable versions of Kaspersky Anti-Virus. User interaction is required to exploit this vulnerability: the user must visit a webpage which takes advantage of this vulnerability. The specific flaw exists within the ActiveX controls in AxKLProd60.dll and AxKLSysInfo.dll
During installation of Maintenance Pack 2, the DLLs will be removed from the system.
The remote exploitation of the information disclosure vulnerability in Kaspersky Anti-Virus 6.0 could allow malicious websites to steal files from end user machine running Kaspersky Anti-Virus.
The SysInfo ActiveX control includes a method called StartUploading which allows malicious web scripts to perform an anonymous FTP transfer of any file the scripts identify on the victim's machine. No dialogs, warnings or user action is required to perform the transfer.
During installation of Maintenance Pack 2, this DLL will be removed from system.
This vulnerability affected systems which are running the Kaspersky Anti-Virus Engine. User interaction is not required to exploit this vulnerability.
The OnDemand Scanner incorrectly parses specially crafted ARJ archives inside the arj.ppl module. This results in a memory overrun. Most often the product simply crashes. The corruption potentially can be exploited to execute arbitrary code without user interaction. Any products using arj.ppl are vulnerable.All these vulnerabilities have been fixed in the build 6.0.2. 614.
1 Kaspersky would like to thank an anonymous researcher working with TippingPoint (www.tippingpoint.com) and the Zero Day Initiative (www.zerodayinitiative.com) for reporting this issue.
2Kaspersky would like to thank iDefence (http://labs.idefense.com) for reporting this issue.
Labels: antivirus, kaspersky, vulnerability