Version: 2008

Comments on: Kaspersky inadvertently quarantines Windows Explorer

A false positive in company's antivirus products leads to quarantine or deletion of some Windows users' copies of explorer.exe.

Add a Comment (Log in or register) (20 Comments)
  • prev
  • 1
  • next
Not necessarily a false positive
by pinowudi December 21, 2007 7:19 AM PST
Considering there are newly released malicious codes that inject
directly into the Windows Explorer memory space, Kaspersky's
deetction is neither invalid or a false positive. At that point
Windows Explorer is a malicious process that needs to be
mitigated. Note that it is not replacing explorer.exe as many
previous virii have attempted. It is mangling the legitimate copy
as it is running to achieve it's ends.

One example:
http://www.symantec.com/enterprise/security_response/weblog
/2007/08/the_new_peacomm_infection_tech.html
Reply to this comment
Explorer.exe *IS* malicious code. They were right
by Anon-Y-mous December 21, 2007 7:30 AM PST
Explorer.exe and IExplorer.exe are the two things that let everything bad into a windows system. Therefore by definition it IS malicious. Delete it and replace with a real OS and you'll be much safer.
Reply to this comment
ugh
by chonnom December 24, 2007 5:40 AM PST
When Linux and/or Apple come out with a viable OS that allows me to play my games (without a dual boot), I'll gladly jump ship.
by LetsReason September 1, 2008 8:49 AM PDT
Windows IS the OS of choice. Everything else is a wannabe.

The ONLY reason ANY other OS could even be considered safer is because very few "baddies" are interested in attacking their minuscule population. Merely half-way educate yourself and practice good internet safety and Windows is perfectly fine for the majority of the population.

Put Linux on 90% of the computers in the world and it would be pounded as well.

Put Mac OS on 90% of the computers in the world and it would be pounded as well.

Put ????? on 90% of the computers in the world and it would be pounded as well.

Microsoft is doing a great job for it's system.
Kapsersky Maybe Right
by i_made_this December 21, 2007 8:30 AM PST
In general, this false positive ironically agrees with a positive on windows explorer executable in continuous use as an "undefined process" (and thus never wholly safe) by Microsoft Corp. MSFT enterprise security as well as retail security products, while not outright banning or quaranteening explorer both keep in a suspended state of being a "dangerous process."
Reply to this comment
Thumbs Up Kaspersky
by jeffgtr60 December 21, 2007 9:11 AM PST
Now if Kaspersky could just find a way to quarantine IE from the net the world would be a better place. Untold amounts of money and time would be saved coding standards compliant websites. The general health and well being of webdesigners all over the planet would improve resulting in a slight decrease in health care costs. Web users could breath a sigh of relief that the web would at least be a slightly safer place. Ahhh one can at least dream can't they?
Reply to this comment
Shouldn't that be "iexplore.exe"?
by Penguinisto December 21, 2007 9:54 AM PST
"explorer.exe" is the main 'doze file browser, and the taskbar (among a ton of other services) rely on it.

"iexplore.exe" is the bug-ridden, standards-hating, lock-in-generating web broswer thingy. ;)

/P
Reply to this comment
Ah - ne'ermind.
by Penguinisto December 21, 2007 9:56 AM PST
I'd read elsewhere that the quarantine walled-off the web browser... my goof.

/P
I would love to have explorer quarantined!
by sktuarim December 21, 2007 10:20 AM PST
With as many problems over the years with explorer windows freezing up or just plain not working, maybe it should be quarantined. It is not as if Microsoft will correct the problems within Windows.
Reply to this comment
I've also heard of
by hawkeyeaz1 December 22, 2007 11:46 AM PST
McAfee on a Vista machine flagging (and trying to remove) msconfig/System Configuration Utility. Unfortunately, I wasn't able to do much more analyzing with it.
Reply to this comment
what a blunder....
by ncftech December 22, 2007 1:09 PM PST
it was supposed to quarantine Windows Vista....(ALL FILES). :-). Sorry MSFT, Vista suuuuuuxxxxxxx......
Reply to this comment
Take the Norton Challenge
by mytetteh December 24, 2007 1:53 AM PST
For those of you who have not considered Norton lately: Maybe it's time to take the Norton Challenge and see how we have improved! Check  this out --  http://www.takethenortonchallenge.com/ See how we have enhanced our performance. And just give it a try, there's a money back guarantee!
Reply to this comment
Sorry,
by suyts2 December 29, 2007 1:42 PM PST
you had your chance. You guys lost out to free ware, no less. Maybe someone else will play your games but not me.
Kaspersky quarantines-Windows-Explorer?
by as901 December 24, 2007 3:56 AM PST
Perhaps they see Windows as a virus? I do.
Reply to this comment
You need to place this in the computer humor section
by wbenton December 24, 2007 8:32 PM PST
>>>Windows Explorer, one of the most crucial components of Microsoft's operating system<<<

That lead line just about sums up a whole bunch of Microsoft's security problems!

If IE is one of the most crucial components of Microsoft's OS, then they're doomed to fail one of these days.

IE is the most insecure browser in the world... and Microsoft freely opens it's OS innards up to IE in a way that no other manufacturer's application could do because they use so many secret built-in holes to get IE to do the insecure things the way it does!

If Microsoft ever opened up all their secrets about IE, you'd find 90% or more of Microsoft security woes wrapped up in this one nutshell!

Walt
Reply to this comment
Your confusing
by suyts2 December 29, 2007 1:36 PM PST
Windows explorer with Internet explorer. Two very different GUIs.
Windows Explorer is not Internet Explorer
by dapickle126 January 9, 2008 11:23 AM PST
You fail to realize that Internet Explorer is not Windows Explorer. Windows Explorer is the actual GUI of the operating system. Internet Explorer, although very tied in with the OS and yes is a common way to compromise a computer, is only the browser and was not affected by the Kaspersky bug.

So you can see why it would've been kinda hard to fix that problem if Kaspersky deleted a part of your OS?
by LetsReason September 1, 2008 8:43 AM PDT
This is just another example of the fact that the most vocal people (like these responding with "down with Microsoft"-types of remarks) are the ignorant people.

You should pay attention to what you read. And besides, Internet Explorer is a great web browser. When you are the web browser of likely more than 75%+ of the world's web users, you are going to be the focus of criminals and scoundrels to defeat. Considering probably 90%+ of the attention of web criminals and scoundrels focus on IE, they do a d@mn good job.

I've used FireFox 3, Flock and other Mozilla-based browsers intermittently for months and CONSTANTLY hit sites that require IE to operate properly. Sounds like, despite the vocal minority, most people look to IE to do their web-browsing...successfully.

With the VAST majority of the baddies in the world attacking Microsoft, salute to Microsoft for the success they have had in defending.

Robert
by aguizar October 30, 2008 1:44 AM PDT
Robert,

Shame on sites that require IE, or any other specific browser, to operate properly. That said, IE's lack of adherence to standards imposes considerable complexity to portable web development.

Sounds like most people are forced to turn to IE to do their web browsing for the above reasons. Inded I have been forced to keep a Windows installation in one of my computers just to access my bank's web site. If it wasn't for other financial reasons I'd have long closed my account with that bank. It's just ridiculous.
Reply to this comment
by R370ad January 13, 2009 12:54 PM PST
I'm a gamer and work as a security protocol technician for a large firm. I'm familiar with several different os's but I primarily use Vista 64 (hey, it works for my games ;~} ). As was stated earlier the reason Windows gets slammed on a continual basis, and you don't even have to install virus software on a Mac, is b/c of it's popularity. Not to mention the fact that the every day end-user walking down the street is using Windows and their lack of knowledge coupled with an abundance of complacency makes them the "easiest" targets. Don't blame Micro$oft and don't deify OSX or Linux. They all have strong points and weak points, trust me. Some are just more readily touted than others. Personally ,I don't like IE (Internet Explorer). Not because it's a bad browser, but because it's a bad browser for Windows(haha). I use FireFox with SSL Blacklist (www.codefromtheseventies.org), along with a couple more add-on's and never have a problem. Well, this is too wordy. GG.
Reply to this comment
(20 Comments)
  • prev
  • 1
  • next
advertisement

Latest tech news headlines

RSS Feeds

Add headlines from CNET News to your homepage or feedreader.

More feeds available in our RSS feed index.

advertisement