Microsoft Antispyware false positive pooches SAV

| | Comments (0) | TrackBacks (0)

Looks like I should blog this since Chris Mosby is linking over here. (thanks for the linkage chris). I posted about it on the myitforum.com antivirus discussion list rather than posting here so I could see what others were seeing.

An blog entry by tech reporter Brian Krebs notes that Microsoft Antispyware (MSAS) is (or has) tagged Symantec Antivirus as a keystroke logger. If you then follow the MSAS removal prompt, you'll remove enough of your SAV client that it wont work anymore.

The source of these reports are Microsoft Antispyware newsgroups, I haven't seen anything on the Symantec or Microsoft website on this. Apparently the problem was with the 2/10 definitions. Newer definitions are available.

One interesting thing from the comments in the MS Newsgroup, they have had problems in the beta with deploying Microsoft Antispyware updates. Caching servers are really causing a problem.

If this has happened to you, you best bet is probably an uninstall reinstall. I dont know if restoring from Quarantine will work in this case. Time to go check on the status of systems in my enterprise to see if any have had this problem.

[UPDATE]:
Techworld reports that this effects pretty much all SCS and SAV corporate edition. That makes sense since it is detecting something in the landesk registry key that SAV stores all its stuff in.

Categories

0 TrackBacks

Listed below are links to blogs that reference this entry: Microsoft Antispyware false positive pooches SAV.

TrackBack URL for this entry: http://www.infosecblog.org/mt-tb20071121.pl/102

Leave a comment

Powered by Ajax Comments

About this Entry

This page contains a single entry by Roger published on February 13, 2006 11:19 AM.

NTBugtraq was the previous entry in this blog.

Windows Defender Beta 2 is the next entry in this blog.

Find recent content on the main index or look in the archives to find all content.

Add to Google
Please contact me by leaving a comment where appropriate. Otherwise, you can click here to reveal an email address for me.
Got Backups? Get Safe Online Remember Rick Rescorla Powered by Movable Type 4.23-en