September 5, 2006 7:21 AM PDT

CA antivirus deletes Windows 2003 file

Related Stories

CA looks to tech squads to sell security wares

August 30, 2006

John Swainson: CA's Mr. Fix-It

December 5, 2005
Some Windows 2003 users have been experiencing problems with the operating system after CA antivirus software wrongly detected part of the operating system as malicious software last week.

At the heart of the problem is part of Windows' built-in security, a file called Lsass.exe. This was wrongly detected as a virus by CA's eTrust software and was deleted, causing some servers to crash and fail to reboot.

CA, formerly known as Computer Associates, said that it quickly spotted and remedied the problem on Friday and also advised affected users to find out how to fix it.

The cause of the confusion seems to be Lsass.exe being mistaken for the Trojan Win32/Lassrv.B.

Lassrv.B was discovered in the wild on Aug. 24 and was rated as a very low threat. The problem for Windows 2003 and eTrust users occurred in a subsequent signature update from CA on Friday.

Will Sturgeon of Silicon.com reported from London.

See more CNET content tagged:
Microsoft Windows 2003, Computer Associates International Inc., CA eTrust, antivirus, virus

Add a Comment (Log in or register) 13 comments
Whoops!
by Mr. Network September 5, 2006 7:42 AM PDT
Guess someone screwed up, or there is an insider that doesn't like M$
Reply to this comment View reply
Were they really wrong? (* GRIN *)
by wbenton September 5, 2006 8:43 AM PDT
[http://lsass.exe|http://lsass.exe] is a system process of the Microsoft Windows security mechanisms. It specifically deals with local security and login policies. This program is important for the stable and secure running of your computer and should not be terminated.

But also note that a certain [http://lsass.exe|http://lsass.exe] is a process which is registered as a trojan. This Trojan allows attackers to access your computer from remote locations, stealing passwords, Internet banking and personal data. This process is a security risk and should be removed from your system.

And also note that one [http://lsass.exe|http://lsass.exe] is also registered as a downloader. This process usually comes bundled with a virus or spyware and its main role is to do nothing other than download other viruses/spyware to your computer. This process is a security risk and should be removed from your system.

If Microsoft only allowed authenticated processes/programs to be run, we would have never had any of the past lsass.exe exploits and thus this false positive as well would never have happened.

Walt
Reply to this comment View reply
Let the fun begin!
by Shifty200 September 5, 2006 3:02 PM PDT
I just finished working on a computer running Windows XP Pro and CA anti-virus. It would not due to problem with lsass.exe file. Ran a repair from the Windows XP Pro CD and cured the error.
Reply to this comment View reply
Are authentication prompts enough?
by starmonkey1 September 5, 2006 3:07 PM PDT
Actually it's been a long time since Windows would let you run or install a program from the web without getting at least one prompt telling you that the operation you're about to do is potentially dangerous and could harm your computer. Many people just click Yes without looking anyway.

Vista will really lock down on this kind of stuff in an even more extreme way than Mac OS X and yet at the end there are still prompts, and security experts complain that people will get desensitized to the prompts and approve them without thinking about it.

There's no way to truly stop a trojan given a sufficiently boneheaded user that has access to admin credentials (and most home users do). I don't see why this hasn't happened on Mac OS X yet, other than the fact that the median Mac user is much more savvy than the median PC user.
Reply to this comment View reply
OOPS!
by heystoopid September 5, 2006 8:35 PM PDT
Oops, a big boo boo ! that one, but as a majority of the real savvy users will never make these simple mistakes and errors!

But, it is not the first and won't be the last, false positive from A-T software!

But then again, there is no such a thing as a perfect Operating System either, all have both positives and negatives, and windows vista due to a lot of additional bloatware, will never run on the current run of the mill machines as used by the ordinary user or office worker(best is cheap crap), unless they spend up big on upgrades to next gen cpu's and motherboards etc!

Choices, as always, is the end user's perogative!
Reply to this comment
Powered by Jive Software
advertisement

Latest tech news headlines

RSS Feeds

Add headlines from CNET News to your homepage or feedreader.

More feeds available in our RSS feed index.

advertisement

Inside CNET News

Scroll Left Scroll Right
  • News - Business Tech

    Chrome's JavaScript challenge to Silverlight

    The advent of Google's Chrome browser, software pros say, should spur a big speedup for JavaScript, which would raise its standing against Microsoft's Silverlight technology.

  • Gallery

    Photos: Top 10 reviews of the week

    Here are CNET Reviews' 10 favorite items from the past week, including the TiVo HD XL, Sony Cyber-shot DSC-H50, and the Dish Network's newest digital TV converter box.

  • News - Apple

    Apple watchers spot 'iPod Nano' pix, iTunes hints

    The rumor mill has long been predicting a longer, leaner new version of the iPod Nano, and now it's conjuring up some pictures.

  • Coop's Corner

    Chris Shipley 1, Internet lynch mob 0

    Demo's impresario goes public with a tart and smartly written riposte to the shoot-from-the-lip crowd.

  • Video

    Katie Couric reflects on first Webcast

    The political conventions are over and so are CBS Evening News anchor Katie Couric's first series of Webcasts. CNET's Kara Tsuboi sat down with Couric on the final night of the Republican National Convention to discuss what she liked about Webcasting, some of her most memorable guests, and whether TV news will still be around by the next round of conventions.

  • News - Digital Media

    Google-focused satellite enters orbit

    The search titan has exclusive rights among online mapping sites to images from the new GeoEye-1 satellite, which launched Saturday.

  • Video

    YouTube plays party politics

    During the presidential campaigning four years ago, YouTube didn't even exist. Now it's a tool candidates must master to get their message across. CNET's Kara Tsuboi stops by the YouTube upload booths at the Democratic and Republican conventions to find out why Google's video site has such a big presence in Denver and St. Paul, Minn.

  • News - Gaming and Culture

    Are Demo and TechCrunch50 fragmenting their audiences?

    With both events scheduled to start Monday, many press, as well as venture capitalists and others are having to choose which one to attend.

  • News - Cutting Edge

    Execs predict next Google-like tech

    On eve of company's 10-year anniversary, researchers and business pundits speculate about what technologies might someday have as much impact as Google.

  • Gallery

    Images: The art of 'Spore' prototypes

    Will Wright and his Maxis team worked on dozens of prototypes to test the elements of their soon-to-be-released evolution game. Here's a sampling.

  • Crossfade

    The Standard, 'A Different Skin': Free MP3 of the Day

    Eschewing the danceable beats favored by many of its post-punk brethren, while opting instead for more ominous and insistent rhythms, is what makes the Standard visceral and engaging. Download a free MP3 of "A Different Skin" courtesy of CNET Download Mus

  • Green Tech

    Duke Energy to invest in mini solar power plants

    Can hundreds of rooftop solar panels collectively operate like a central power plant? Duke Energy launches $100 million distributed solar program to find out.