Feeds

Avast alert finds WHOLE WEB malign

Evil is everywhere!

Next gen security for virtualised datacentres

Major freebie anti-virus scanner Avast has apologised for a cock-up defining the vast majority of the web as malign.

Rather than a Howard Beale-style insight into the state of the modern interwebs, the finding of any sites with scripts or frames - including Avast's own support forums - as malign was the result of a rogue virus definition update.

The Czech Republic-based firm quickly realised its mistake, and released a revised definition file within a hour of discovering the problem on Tuesday morning.

In an advisory, Avast said sorry for the snafu.

Virus definition update 110411-1 contained an error that resulted in a good number of innocent sites being flagged as infected. Generally, all sites with a script in a specific format were affected.

The problem is simple enough to resolve by simply manually updating definition files. Faulty definition updates are a well known shortcoming of security software suites.

Such screw-ups often result in the quarantine of benign files, bricking systems if the falsely flagged files happen to be system files. No local files were quarantined in the Avast case.

Anti-virus definition updates are routinely tested prior to release. In the Avast case this seems to have been done on a machine without internet access, hence the failure to detect a glaringly obvious problem.

An estimated 130 million users worldwide use Avast's software. The firm, like AVG and Avira, offers basic anti-virus scanner software free to consumers while making money selling security suites with added features and scanners to companies, mostly targeting small businesses. ®

Bootnote

A big thank you to the Reg reader who had to go through the rigmarole of adding an exception to Avast's misfiring software before he was able to pass on this tip.

The essential guide to IT transformation

More from The Register

next story
Goog says patch⁵⁰ your Chrome
64-bit browser loads cat vids FIFTEEN PERCENT faster!
Chinese hackers spied on investigators of Flight MH370 - report
Classified data on flight's disappearance pinched
NIST to sysadmins: clean up your SSH mess
Too many keys, too badly managed
Scratched PC-dispatch patch patched, hatched in batch rematch
Windows security update fixed after triggering blue screens (and screams) of death
Researchers camouflage haxxor traps with fake application traffic
Honeypots sweetened to resemble actual workloads, complete with 'secure' logins
prev story

Whitepapers

Top 10 endpoint backup mistakes
Avoid the ten endpoint backup mistakes to ensure that your critical corporate data is protected and end user productivity is improved.
Implementing global e-invoicing with guaranteed legal certainty
Explaining the role local tax compliance plays in successful supply chain management and e-business and how leading global brands are addressing this.
Backing up distributed data
Eliminating the redundant use of bandwidth and storage capacity and application consolidation in the modern data center.
The essential guide to IT transformation
ServiceNow discusses three IT transformations that can help CIOs automate IT services to transform IT and the enterprise
Next gen security for virtualised datacentres
Legacy security solutions are inefficient due to the architectural differences between physical and virtual environments.