September 2nd, 2006

CA Antivirus Software IDs Windows Component as Malware

By Michael Santo
Executive Editor, RealTechNews

It’s not uncommon to see false positives in AV and anti-spyware software … for example, McAfee IDing Excel as a virus, Microsoft Anti-Spyware IDing Norton Antivirus. ‘Course, that doesn’t give companies an excuse. And IDing part of Windows as malware … now that’s even more inexcusable than IDing Excel.

The problem was that eTrust Antivirus was mistakenly flagging the Windows Lsass.exe process, said Bob Gordon, a CA spokesman. “CA quickly discovered and fixed an issue which temporarily caused some customers to detect a problem in their Lsass.exe files,” he said in an e-mail. Source: InfoWorld

We Say: I’m sure the “quick discovery” happened as soon as Tech Support calls starting flooding their call center. Systems crashed and were unable to boot if people didn’t recognize that eTrust was trying to quarantine part of the OS (I would have recognized the filename, but my wife sure wouldn’t have!). I wonder what their Tech Support department is doing for those people who are in that situation? New AV signatures aren’t going to fix those issues.

Really, why wasn’t this caught in QA? Makes me glad I follow my own advice about using a lesser known, but well-rated AV product. (In a sidenote, I liked it a lot better when CA was Computer Associates … less likely to mix up their gaffes with California’s gaffes) :-)

Share and Enjoy:These icons link to social bookmarking sites where readers can share and discover new web pages.
  • del.icio.us
  • digg
  • Fark
  • NewsVine
  • Reddit
  • YahooMyWeb
You can leave a comment, or trackback from your own site. RSS 2.0

3 comments to "CA Antivirus Software IDs Windows Component as Malware"

  1. Tom says:

    CA’s mistake shut my business down for 15 hours.
    The techs that fixed my server said they talked to CA and CA was no help at all!

    September 2nd, 2006 at 10:14 am

  2. GreekWizard says:

    Been “lesser known” NOD32 for over a year.

    No going back to anything else.

    September 2nd, 2006 at 2:45 pm

  3. IT Blogwatch says:

    Browzar is ++ungood (and peek into future)

    Yowzar! It’s IT Blogwatch, in which Browzar launches and bloggers point and laugh. Not to mention a worrying peek into the future of programming…

    September 4th, 2006 at 3:54 am

Leave a comment