Skip Links

Network World

  • Social Web 
  • Email 
  • Close

Flawed Trend Micro antivirus update cripples PCs

By Gregg Keizer , Computerworld , 09/09/2008
  • Share/Email
  • Comment
  • Print

Antivirus updates issued by Trend Micro Inc. on Friday crippled Windows XP and Vista PCs when they mistook several critical system files for malware, and blocked access to those files.

Some users have yet to regain control of their PCs, according to e-mail sent to Computerworld.

Two signature updates that Trend Micro released Friday for its most popular consumer security software incorrectly identified up to eight different Windows files as Trojans, then quarantined those files, thinking they were dangerous. The updates were issued to users running Trend Micro's AntiVirus plus AntiSpyware 2008, Internet Security 2008 and Internet Security Pro 2008.

In some cases, quarantining the files prevented the PC from booting.

Trend acknowledged the snafu, but said the buggy updates were out for only a short time. "For a brief period of time late last week primarily some continental European consumers were affected by a Trend Micro pattern-file update with a false positive that could have led to quarantining a few Windows components," said company spokeswoman Andrea Mueller in an e-mail.

When it realized that the updates were flagging innocent files, Trend Micro issued a replacement signature update.

That was too late for some users, however.

"I have spent a lot of hours to fix this issue, also with a long phone call with [Trend Micro] support this afternoon," said Bruno Misonne from Belgium in an e-mail to Computerworld .

Misonne said two PCs, one running Vista and the other XP, were affected by the faulty update. He was able to restore the Vista system, but had been unable to recover the XP machine. "Technical support told me that they are overfilled with cases," he said in a follow-up e-mail. "This bad signature simply removes essential files."

Trend Micro has published a detailed support document for users whose anti-virus software downloaded and installed the flawed updates. The document includes step-by-step instructions for users who are unable to boot their PCs that requires them to use Windows' Safe Mode to regain control, then asks them to download and run a restore utility that moves the system files out of quarantine and to their proper locations.

This isn't the first time that Trend Micro has pushed a malicious signature update to its customers. In April 2005, the company issued a buggy definition file that locked up Windows XP machines, most of them owned by Japanese users, as the software consumed 100% of the processor's cycles.

  • Share/Email
  • Comment
  • Print
Partner Content

Brilliantly simple security and control solutions for email, web and endpoint

www.sophos.com

Stopping data leakage

Learn how to exploit your current security investment to control the information that flows into, through and out of your network.

Download the white paper.

Why detection rates aren't enough

Evaluating endpoint security products is a time-consuming and daunting task. Learn the six critical questions you need to ask prospective vendors to get the right endpoint solution.

Download the white paper.

Applications: taking back control

Employees installing unauthorized applications is a growing threat to business security and productivity. Cost-effectively reduce this threat by integrating control into your malware protection.

Learn more today.

Comments (2)
Login
Forgot your account info?

Really?!By Anonymous on September 11, 2008, 3:34 pmI had to click to page two just to read the last sentence in the article? CPM FTW!!!

Reply | Read entire comment

Gregg, Take a vocabulary lessonBy Anonymous on September 11, 2008, 1:45 am"This isn't the first time that Trend Micro has pushed a malicious signature update to its customers." Look up the word malice, then provide your supporting information...

Reply | Read entire comment

View all comments

Add comment
Anonymous comments subject to approval. Register here for member benefits.
Have a NetworkWorld account? Log in here. Register now for a free account.

Videos

rssRss Feed