Microsoft's Antivirus Briefly Flags Google.com As Malicious
tsu doh nimh writes "Computers running Microsoft's antivirus and security software may be flagging google.com — the world's most-visited Web site — as malicious, apparently due to a faulty Valentine's Day security update shipped by Microsoft. For several hours on Tuesday, PC users browsing with Internet Explorer on a machine equipped with Microsoft Security Essentials or Forefront saw warnings that Google.com was serving up a 'severe' threat – Exploit:JS/Blacole.BW — basically that google.com was supposedly infected with a Blackhole exploit kit. The warning prompted users to 'delete' the threat, although accepting the default action appeared to cause no ill result. The episode is more embarrassing than harmful, given that Microsoft is expected to ship antivirus technology with the next version of Windows."
Isn't the real virus actually windows?
...something the world does not know !
Dear Google,
Happy Valentine's Day!
Your valentine,
Microsoft
by Cyphase ( 907627 )
Fan boys really don't know how to spot a joke...
Google already flagged MS France as malicious 2 years ago: http://gilouweb.com/bordel/google_truth.png (Ce site risque d'endommager votre ordinateur meaning: this website might harm your computer) So I guess it's only revenge ;)
Since anti-malware programs largely work by looking for known patterns and fingerprints, and the databases of these patterns and fingerprints keep growing steadily, when will we have reached the point where basically every software ever written will fit one of the patterns? :)
Does this mean that all antivirus makers must start doing sanity checks before releasing definition updates to the public? For example, there was once a definition update for an antivirus program that deleted some critical system file in Windows. Running a scan against a set of known clean Windows files and other popular programs should always be done before a release. Same idea for popular websites.
in Microsoft's eyes, they are the most malicious threat in existence right now.
Same as Windows don't know how to spot a threat!
Aren't all search engines technically spyware? Especially in the case of Google where it tailors your results based on previous browsing history (if you've got that option on).
Note: Yeah, MS made a mistake. Go figure. At least they dealt with it within *hours* instead of a greater span of time and it didn't really have much, if any, negative effects other than mild annoyance on the part of the users. Still preferable to them not having any antivirus.
Incidentally I was doing a google search from a Win8 VM and did not see this behavior. I _did_ get a notification to update my spyware/malware definitions for Windows Defender as well, so maybe my definitions did not yet include this snafu.
Of course I have updated post Vday, so cannot confirm this behavior now, even with an older snapshot.
Seven Days with Ubuntu Unity
It might have been kinda funny some 5+ years ago when someone first told it. Maybe if I came across it less than once per week, I'd eventually find it kind of amusing again.
This is Slashdot, remember? Obviously, it's Apple's fault.
I like MS bashing just as much as the next slashdot-poster, but I think here the blame is minimal. AV software based on signatures has a very high probability of doing things like that and testing all common possibilities is very hard or impossible, while at the same time new signatures need to be pushed fast in order for them to be effective.
That also shows that AV software is, at best, a temporary measure. IMO the future is better OS security (and here MS is to blame), better application security (which is a budgetary and an education/knowledge problem).
Most ACs are not even worth the keystrokes to insult them. Be generically insulted by this and ignored otherwise.
I just had an image of Steve Ballmer and Bill Gates going down on Larry Page and Sergey Brin (which by the way, google had to guess at being the right answer for being the founder of google) in a nerd love fest...
My eyes! What has been seen cannot be unseen.
...
...
...
Oh who am I kidding. Fap fap fap fap fap
MMO Quests are like orgasms:
You may solo them, I prefer them in a group.
It didn't flag apple.com
Let's just wait until they block microsoft.com due to some related screwup.
Exploit:JS/Idiots.ASS detected
I run the full Microsoft stack, visited Google today and never had an issue...
Microsoft simply confused Valentines Day with April Fools Day
Donte Alistair Anderson Roberts - hi son!
Karma: Chameleon
Would have been absolute gold if the message that came up was something along the lines of:
"We're sorry but Google.com has been identified as a threat to Microsoft *cough* *cough*, I mean your computer. We suggest you fix this by going to Bing.com. Would you like us to make Bing your homepage and redirect all future request for Google to Bing instead?"
[Yes] [OK]
Ryans Tutorials - A collection of technology tutorials.
Since everyone knows Microsoft's Bing uses Google search results - and denies it this means users of their own "search engine" are hit too. Spock: "Fascinating".
I find it amusing. Probably because all I use is linux :)
So, did anyone manage to delete the threat? Google.com is still running.
Meh, I guess nobody really reads the warning dialogues anymore.
the old slashdot would not include the word "briefly" in the title.
I come here for a reality distortion field.
5+ years ago? Somebody first told it the day the first windows AV software shipped.
To be honest, I don't think this is really *that* big of a deal. This can happen. Worse has happened, not only at Microsoft but by other AV products as well. I recall Avast crying out loud over Steam less than a month ago, moving its service into containment. And if I recall correctly, Avast even flagged notepad.exe as a virus once. I specifically mention Avast, because a.) I use it, and b.) it actually scored rather well last time I bothered to look it up in comparative studies.
As long as there are probabilities involved, false positives and false negatives are bound to happen. When it comes to AV, I don't mind if it errs on the side of caution as long as it doesn't happen too often.
Mod me down or call me fanboy as much as you want, but I really don't consider this too problematic, regardless of Microsoft being the "aggressor" here.
ZING!
... went the strings of my heart!
But when you got it you forgot to mention the irony of their already having shipped useless firewall bloatware which takes up space and no one uses. Microsoft; all your harddrive are belong to us.
*Repent!Quit Your Job!Slack Off!The World Ends Tomorrow and You May Die!
And stranger than that, you are not bonch and your post isn't a criticism of Google claiming that they deserve it and Microsoft is right to label them as malicious. What are the odds!
Perhaps Microsoft was right about the Google homepage on the 14th:
- MS Security Essentials is written by programmers/nerds.
- On the 14th, Google had an animated "Valentine's Day" logo.
- The animated logo was an animated female. Innocent and harmless, but female none the less.
- As usual, nerds (or in this case MS Security Essentials, the product of nerds) had no idea how to react to a female.
- When MS Security Essentials determined that the animated female was holding a valentine it panicked.
- MS Security Essentials protected Windows from Google's trojan horse valentine (metaphorically, of course).
Most of the /. "Open" community has danced with MS Malicious at one time or another over the past 20 years. US, EU, RU ... Faux-capitalism, if you can't compete any "WhoopsFU" that may help the profit line is legally fine.
Capitalism=Meritocracy+Value: If the best cannot compete, enter the market, and/or is fettered by sector/product protectionist law, plus increases in profits, benefits, pay-packs ... are not attributable to value added, then the national economy is Faux/Pseudo-Capitalism based and must exploit the general public value for private Faux/Pseudo-Capitalist profit.
So, MS Malicious and other Faux/Pseudo-capitalist will always be pleasured by "WhoopsFU."
Note: There are still many real capitalist in the world, but most folks controlling law-writing, economic policy, a/o expounding capitalist values are in fact just Faux-capitalist with a "WhoopsFU" attitude.
Unaccountable leaders are masters, and unrepresented people are slaves. How do US and EU fare?
I think poking fun at Microsoft Google Apple and the whole lot is for the most part almost always funny. Ever considered removing the giant stick from your ass?
The soylentnews experiment has been a dismal failure.
Nice to know nobody was effected.
I was checking the Site to Zone Assignment feature of group policy. I found this posting ( http://www.grouppolicy.biz/2010/03/how-to-use-group-policy-to-configure-internet-explorer-security-zone-sites/ ) where the example was to put google.com (and everything in it) to be the "restricted sites zone."
I think poking fun at Microsoft Google Apple and the whole lot is for the most part almost always funny.
Sounds like you still have some growing up to do.
Ever considered removing the giant stick from your ass?
Such irony coming from a guy with his head up his own ass. Get bent, Trollgrove.
This happened to me last night when I was playing a game. I used google to look up something, and that warning came up. So I had them "remove" it. I was concerned because it didn't really give me a lot of information, but when you're left with the choice of removing a virus/trojan and just leaving it there, you're generally going to go for removing it. Reading about it today, I now realize what happened last night. This reminds me of years ago when I was installing some update to Microsoft Internet Explorer, and I received a message along the lines of: "Microsoft Explorer has detected an illegal program. Would you like to remove Netscape Navigator?" Something like that is really hard to forget, even though I found myself laughing at the time it happened.
Sarbonn's blog: http://www.sarbonn.com/blog
Does that mean that you were paid by Google, since I, in turn, disagree with you?
You're acting really childish with these constant comments to the tune of "You can't be disagreeing with me! It must be an illegitimate opinion!". Just accept that not everyone conforms to your worldview.
Except that people don't rationally poke fun. They are just corporate cheerleaders for companies they don't work for, compete against, or know anybody who falls into those camps.
Learn how to use the tag, stupid.
...just 'cause it was faulty, doesn't necessarily make it untrue...
It's no different than when they "accidentally" (note the word) flagged chrome as a virus before.
Expect these accidents to become more frequent as microsoft panics about google competition.
Apparently this has to happen more than 50 times before people accept that it's not just some magic "mistake".
see http://chrome.blogspot.com/2011/09/problems-with-microsoft-security.html
when skynet becomes self-aware
God damn speed filter
I'm not a cowboy! Sod off you damn Whore Mongers, the damn speed filter doesn't apply to me as I'm a Fast Turtle for damn good reason,.
Mod me up/Mod me down: I wont frown as I've no crown
Except that people don't rationally poke fun.
Sure they do. It's a fundamental part of the human condition to make fun of things and joke around. Only on the internet when the jest is directed at $SOMEBODIES_FAVORITE_CORPORATION does this reality ever seem to come into contention.
They are just corporate cheerleaders for companies they don't work for, compete against, or know anybody who falls into those camps.
Maybe loosen the tin foil, man.
The soylentnews experiment has been a dismal failure.
I'm still working on the part where a group of convicted Liars, and Thieves are still allowed to do business. But then again, I'm amazed that Criminal Law is second to Torts.
I would say it is more an issue of the current cultural climate that has most people believing that if you couch your very serious statements in the form of a joke it isn't OK for anyone to point out how wrong you are.
So we need a joke police now to protect the poor underrepresented mega-corps? This website gets stupider and stupider. I see why Taco left.
What bloatware would that be? The firewall in Vista/7 that has pretty damned comprehensive rules based filtering while being easy to use, THAT bloatware? or are you still bitching about a certain 12 year old OS that is going for a record on years of support even though they've passed any legal obligation they had to keep updating the thing, could it be that? Give me a damned break! What's next, you gonna complain that XP which is already 3 generations behind (XP X64, Vista, 7) runs as admin too? Move on dude. Man the world is gonna be full of butthurt nerds when 2014 gets here and XP doesn't get another extension so they will actually have to try to find things in the modern version to bitch about. But don't worry Ballmer is gonna shoot Windows in the face because he wants to be Apple so fucking bad he sleeps with an iPad under his pillow.
As for TFA frankly if that is the WORST thing an AV does color me happy. We've seen dllhost marked as a bug thus disabling the system, we've seen core boot files flagged as bugs thus bricking the system unless you had a second machine to Google how to fix the first, frankly MSE has been so far pretty harmless. That said even though I use it on my netbook and gamer machines I do NOT use it on the machine I actually do any real surfing on because frankly in my tests it doesn't really DO anything. What I mean by that is while it has a pretty decent scanner for downloaded files that is pretty much it, you load up a webpage with malicious code MSE isn't gonna say a word or try to block that site whereas both Comodo Internet Security and Avast Free stop the page from loading. I will give them credit for being just about the lowest resource using on any AV but the flipside is it simply isn't doing much. So while I recommend it for geeks that actually practice safe computing or for machines like my gamer PC and netbook where the only surfing they are doing is checking webmail or going to well vetted sites like this for regular users I simply can't give it out.
Maybe its because it was never really intended to be an AV, it was originally Giant Antispy before being purchased by MSFT, maybe the guys at MSFT got tired of AVs slowing down the system so focused on speed above all, who knows, but for a clean computer in my own tests which involved taking an offlease and hitting every topsite and crapsite I could find then using a disc filled with offline scanners to check the system I found MSE on XP scored horribly, MSE on Vista/7 did better simply because OS protections like low rights mode did most of the work, but in no version of Windows did it stop as much as Comodo IS or Avast Free. Oh and since you seem to hate the firewall so much Comodo IS is not only free for home AND business use but also has its own quite excellent firewall built in, which for those that just want one or the other its as simple as unchecking a box during install. For business users or those that want more finer grained controls I'd go with Comodo IS, for those that want a drop and go solution Avast Free is what you want. MSE? Meh only use it if resources are the highest concern, like say on an underclocked netbook (for those that haven't tried Brazos Tweaker it does rock and added an extra hour on my E350's battery) or a gamer system where you simply aren't doing any risky behavior.
ACs don't waste your time replying, your posts are never seen by me.
Microsoft Security Essentials recognized that Google was sucking up all of Bing's patrons like a Blackhole, and sought to remove the threat once and for all by having users 'delete' Google en masse!
I am surprised that Microsoft didn't rejigger IE to just block Google altogether about the time Bing was being first promoted. By the time the lawyers got done beating each other to a bloody pulp - even if Google managed a legal victory - there would be millions of users who would have used Bing as the only alternative because they didn't know about the existence of any other browsers than the IE on their Windows desktop.
If Slashdot were chemistry it would look like this:Cadaverine
Indeed, all you use is linux. You definitely don't use your penis with anyone other than yourself too. That much is clear.
If criminals and thieves weren't allowed to do business, what would happen to all the multinational corporations?
Valentine's day is just a little to convenient. I wander if there are a couple of developers from both companies chuckling at each other. I know I have pulled pranks on friends and co-workers before. {I would not however want to answer to the boss when my prank hit the news}
they took out AOL's TCP/IP stack years ago too and low and behold it happened right around the time Microsoft was getting MSN going. The default action for users clicking their AOL links and finding the dialer stopped working was to use the MSN dialer and bring MSN in. It took a court case to get them fix it and that fix was claimed to take months. It was a bug. Right, because they didn't bother to test against the most used TCP/IP stack out there. Google's a target now so stuff like this is just fun for Microsoft.
LoB
"Anyone who stands out in the middle of a road looks like roadkill to me." --Linus
Since every PC you buy has crapware that WILL include that and the firewall, nobody uses the windows one.
Because they settled the case. When the Appeals Court and the Department of Justice decide it is okay for Microsoft to do business, it is ok for Microsoft to do business. I guess Microsoft is basing it's practices on the law, and not your opinion. But you can read all about it in the link you posted.
"But this one goes to 11!"
Heh, it's just how Ballmer expresses his repressed admiration. Akin to throwing chairs as a sigh of respect.
who dares wins
Gee, no antivirus has EVER given out a false positive before huh?? You little MS-hating fruit lovers just enjoy the chance to bash MS.. Does it make you feel better?
Microsoft wasn't convicted. The case was settled with a consent decree.
So legally, no wrongdoing was found. Microsoft essentially agreed to let the government watchdog them for a few years in exchange for the charges going away.
Embarrassing I guess, but really? This sort of mistake happens with every single anti-virus on the market. Some will even flag and delete core system files causing the installation of the OS to get crippled. I'd say that's embarrassing. It happens. It always will happen. It's not like this is some new slip up that only Microsoft could cause.
In all fairness Microsoft Server does flag all Microsoft websites as "UNTRUSTED" already by default.
Also, it wasn't just Microsoft Security Essentials or Forefront that were affected by this, but Microsoft Defender and Microsoft Windows Malicious Software Removal Tool as well, so it wasn't just affecting web browsing sessions contrary to what the article stated. Our Mail Servers running on Windows 2008 were brought to their knees post-Update last night due to MRT.EXE flagging every piece of Inbound or Outbound mail connecting to GMail, causing a 99% Load on all CPUs. We had to throttle the MRT.EXE process thread in order to get things back up and running. So, it was a little worse than Microsoft making a "Opps! Our bad! That's a little embarrassing." Mission Critical Systems were adversely affected making this more than just a "faux pas".
I'm not looking forward to an Out-of-Band Update to resolve this issue if it is going to require more down-time. My biggest complaint as a SysAdmin running any MS Server products is Microsoft's incessant need to net stop Mission Critical Services while installing an Update and then still requiring a reboot afterwards (pick one or the other Microsoft, not both!).
(But since I started this "In all fairness..." I should end this on the same note. "In all fairness...as a SysAdmin I have different but equally as valid complaints about *Nix systems as well. It's not just Microsoft that has need for improvement.)
Convicted liars and thieves that also pay 55,000 persons worth of payroll tax?
Dear AC, no one pays a fine and allows themselves to be "watched" when they've done nothing wrong, Period.
There are many laws. Torts, in this case, are not a pastry. And the way that law enforcement is handling their litigation is not cute. When business comes before people, someone has been bribed.
Dear AC, so what is the minimum threshold for a business to not be criminally prosecuted for Fraud? Ignoring criminal activities is in itself, criminal; especially by Wards of the Court.
Greece is paying through the nose and allowing themselves to be watched, so I would disagree with that.
For a site about things like basic rights, Slashdot users sure do like to censor "dissent".
You should loosen your tin foil hat. I think it's constricting blood flow to your brain.
For a site about things like basic rights, Slashdot users sure do like to censor "dissent".
Wow, you're quite an advocate.
Unfortunately, my experience with MS and their range of products supersedes your sincere hyperbole.
Even without the list of aches and pains, having a firewall at the workstation,rather than the gateway is like putting mud and snow tires on roller skates.
But don't feel bad, I think ads are a bunch of crap too.
Nicely written.
*Repent!Quit Your Job!Slack Off!The World Ends Tomorrow and You May Die!
Dear LifesABeach - the law is the law and is not defined by your opinions of the way you think things should be. Period. Just because you have a bone to pick with Microsoft for whatever irrational reason does not mean they were "convicted" or "found guilty" of anything. Sorry, but that is all in your mind. In reality MS reached a settlement, was not found guilty of any wrong doing, and was allowed to keep doing business legally. Unethical and amoral do not have the same meaning as illegal.
thanks for providing a useful and informative reply. I can clearly see your opinion is very useful, and should be modded somewhere between 0 and -1.
I mean it's not like they're a convicted monopolist more than twice over or anything, right?