Ads by TechWords

See your link here
Receive the latest technology news and information.
Security
Computerworld Daily News (First Look and Wrap-Up)
Computerworld Blogs Newsletter
The Weekly Top 10
Cloud Computing
View all newsletters




Privacy Policy
 

Flawed Trend Micro antivirus update cripples PCs

It quarantines critical Windows files, prevents booting of some XP, Vista machines

September 8, 2008 12:00 PM ET

Active Comments
Anonymous says: I think saying, "This isn't the first time that Trend Micro has pushed a malicious signature update to its customers"...
Rick Savoia says: I agree that using the term "malicious" was unwarranted. The word "malicious" means "with malice", i.e. to be intentionally harmful,...


Computerworld - Antivirus updates issued by Trend Micro Inc. on Friday crippled Windows XP and Vista PCs when they mistook several critical system files for malware, and blocked access to those files.

Some users have yet to regain control of their PCs, according to e-mail sent to Computerworld.

Two signature updates that Trend Micro released Friday for its most popular consumer security software incorrectly identified up to eight different Windows files as Trojans, then quarantined those files, thinking they were dangerous. The updates were issued to users running Trend Micro's AntiVirus plus AntiSpyware 2008, Internet Security 2008 and Internet Security Pro 2008.

In some cases, quarantining the files prevented the PC from booting.

Trend Micro acknowledged the snafu, but said the buggy updates were out for only a short time. "For a brief period of time late last week, primarily some continental European consumers were affected by a Trend Micro pattern-file update with a false positive that could have led to quarantining a few Windows components," said company spokeswoman Andrea Mueller in an e-mail.

When it realized that the updates were flagging innocent files, Trend Micro issued a replacement signature update.

That was too late for some users, however.

"I have spent a lot of hours to fix this issue, also with a long phone call with [Trend Micro] support this afternoon," said Bruno Misonne from Belgium in an e-mail to Computerworld.

Misonne said two PCs, one running Vista and the other XP, were affected by the faulty update. He was able to restore the Vista system, but had been unable to recover the XP machine. "Technical support told me that they are overfilled with cases," he said in a follow-up e-mail. "This bad signature simply removes essential files."

Trend Micro has published a detailed support document for users whose antivirus software downloaded and installed the flawed updates. The document includes step-by-step instructions for users who are unable to boot their PCs that requires them to use Windows' Safe Mode to regain control, then asks them to download and run a restore utility that moves the system files out of quarantine and to their proper locations.

This isn't the first time that Trend Micro has pushed a malicious signature update to its customers. In April 2005, the company issued a buggy definition file that locked up Windows XP machines, most of them owned by Japanese users, as the software consumed 100% of the processor's cycles.

Last year, an antivirus signature released by rival Symantec Corp. knocked out thousands of Chinese PCs by falsely labeling two Windows .dll files as malware, preventing users from booting their computers.

Read more about security in Computerworld's Security Knowledge Center.



Jump to comments

Trend Micro

Additional Resources

EFD vs. HDD - What You Need to Know
WHITE PAPER
Enterprise flash drives provide a new Tier 0 storage layer capable of delivering high I/O performance at a very low latency. Proper use of EFDs in an Oracle environment can deliver increased performance compared to fibre channel drives. Read the recommendations for identification of the best DB components for EFDs.
Gartner Research Report: Magic Quadrant for Application Delivery Controllers, 2009
WHITE PAPER
The market for products to improve the delivery of application software over networks remains dynamic and innovative. Vendors focused on solving enterprises' most-pressing application problems have become the top players.
Eight Criteria for Server Load Balancing
WHITE PAPER
Server load balancers are a simple yet highly effective means to scale an application environment while ensuring its availability. Today's solutions should also address application performance and security. Read about the top eight criteria you should consider when choosing a server load balancer and how Citrix NetScaler meets those requirements.

What People Are Saying

White Papers & Webcasts

Death to PST Files
Download Now  

Web 2.0, Social Media and the Dark Web - A Web Criminals Paradise?
In this discussion, learn about the challenges of protecting your users from the potentially unsafe content hidden in the "Dark Web".

eGuide: Enterprise Security
Smart Security Strategies for 2010. Read now!  

Disaster Recovery 2008: Reduced Costs and Improved Performance
How long can your Enterprise afford to be without your data? With an accelerated disaster recovery program, you never have to answer this...


IT Jobs