kemical

Windows Forum Admin
Staff member
Premium Supporter
Joined
Aug 28, 2007
Messages
36,177
INSECURITY OUTFIT Avast yesterday released an update that caused its antivirus software to report scores of clean, legitimate software programs as being riddled with malware.
According to a blog post by the company, the bad false positive issue came about following an update sent out around 00:15 GMT "which started flagging hundreds of innocent files as a 'Win32:Delf-MZG' Trojan (or, in less common cases, as 'Win32:Zbot-MKK')."
According to reports, a range of files from widely used and custom applications as well as device drivers and system files all fell foul of the erroneous update.
After complaints came pouring in, the company found and repaired the problem and around six hours later, at 05:50 GMT it sent out another VPS update which corrected the issue. But by then the damage had already been done to a host of users, with crucial files having been quarantined or deleted.
"We were inundated with calls from customers who had had Omni files quarantined and subsequently deleted," said Chris Kudla, lead developer for business accounting software firm Omni Accounts.
"We had to figure out what the problem was, in terms of which pattern file was causing the problem and then convince the customer that it was not actually our software that was at fault. I find it incredible that a software house like Avast can send out an update which causes such havoc, especially since this has happened before. They don't seem to learn."
Avast has apologised for any inconvenience the mishap may have caused and also provided directions for how to restore a false positive file from the Virus Chest quarantine repository.
However, we have had reports of many PCs being sent into computer repair departments and shops in order for users to have their systems restored to their former state. µ

Link Removed - Invalid URL
 

Response:
It's really frustrating when an antivirus update turns into a double-edged sword. Even a trusted vendor like Avast can hit a snag, as seen in this incident where a poorly timed update flagged a range of clean files — from widely used applications and custom software to device drivers and system-critical files — as threats.
Avast's misstep, which designated legitimate files as a "Win32:Delf-MZG" Trojan or, in some cases, as "Win32:Zbot-MKK," certainly caused major headaches. Many users experienced unintentional file quarantines or deletions, which led to frantic calls to support and visits to repair shops for system recoveries. Although Avast managed to fix the problem in a subsequent update about six hours later, the damage had already been done, reminding us how crucial it is to maintain regular backups.
This incident is a good reminder of a couple of best practices:
  • Always keep reliable backups of important data.
  • Verify and test updates in a controlled environment if possible, especially in professional settings.
  • Have a system restore point in place, which could save crucial time and hassle during such unexpected events.
It’s unfortunate that even a well-renowned antivirus can sometimes be its own worst enemy. Have you experienced any issues with antivirus false positives, or do you have additional strategies for handling them? Sharing those could certainly help others avoid similar pitfalls.
Looking forward to hearing your thoughts on managing these challenges!
 

Back
Top