Comments on: CA antivirus deletes Windows 2003 file
Company's eTrust software detects Windows file as a virus and deletes it, causing servers to crash and fail to reboot.
Company's eTrust software detects Windows file as a virus and deletes it, causing servers to crash and fail to reboot.
December 7, 2009 7:34 AM PST
December 7, 2009 7:08 AM PST
December 7, 2009 6:30 AM PST
Add headlines from CNET News to your homepage or feedreader.
More feeds available in our RSS feed index.
Related quotes
:-)
But also note that a certain [http://lsass.exe|http://lsass.exe] is a process which is registered as a trojan. This Trojan allows attackers to access your computer from remote locations, stealing passwords, Internet banking and personal data. This process is a security risk and should be removed from your system.
And also note that one [http://lsass.exe|http://lsass.exe] is also registered as a downloader. This process usually comes bundled with a virus or spyware and its main role is to do nothing other than download other viruses/spyware to your computer. This process is a security risk and should be removed from your system.
If Microsoft only allowed authenticated processes/programs to be run, we would have never had any of the past lsass.exe exploits and thus this false positive as well would never have happened.
Walt
The reason they chose to use [http://lsass.exe|http://lsass.exe] for thier trojans and downloaders is because it would blend in with the running processes. I don't believe this was preventable, and I'm not sure your solution is the right answer as it would only result in a re-design of the current problem.
An O/S is a living program that runs other programs, I don't forsee that changing in my lifetime. As long as someone has the ability to run architected code on any O/S, they will find a way to do so.
Nice try though bud! ;-)
~Mr. Network
Vista will really lock down on this kind of stuff in an even more extreme way than Mac OS X and yet at the end there are still prompts, and security experts complain that people will get desensitized to the prompts and approve them without thinking about it.
There's no way to truly stop a trojan given a sufficiently boneheaded user that has access to admin credentials (and most home users do). I don't see why this hasn't happened on Mac OS X yet, other than the fact that the median Mac user is much more savvy than the median PC user.
This is "a fact"??? You're an idiot.
- OOPS!
- by heystoopid September 5, 2006 8:35 PM PDT
- Oops, a big boo boo ! that one, but as a majority of the real savvy users will never make these simple mistakes and errors!
- Like this Reply to this comment
-
(13 Comments)But, it is not the first and won't be the last, false positive from A-T software!
But then again, there is no such a thing as a perfect Operating System either, all have both positives and negatives, and windows vista due to a lot of additional bloatware, will never run on the current run of the mill machines as used by the ordinary user or office worker(best is cheap crap), unless they spend up big on upgrades to next gen cpu's and motherboards etc!
Choices, as always, is the end user's perogative!