CA in Windows FP

eTrust identifies critical file as virus.

A mistake at CA caused some trouble over the weekend, as its eTrust products started identifying part of the Windows local authentication system in Windows 2003 Server as infected with a virus called 'lassrv.b'. Clean copies of lsass.exe, a popular target for viruses, were blocked by the software, and even deleted by some users, causing some nasty problems.

confidence-2012

The update causing the FP, Vet DAT signature 30.3.3054, was released in the early hours of Friday morning US time, and was fixed by an update issued before 9:30AM the same day. CA has released some instructions on recovering a system which has lost or blocked the file, here. Read the SANS announcement of the problem here.

4 September 2006

Tags: virus  

 del.icio.us  digg this! digg this

Quick Links

Poll
Does your company allow you to use a personal laptop/mobile device to access company resources?
Yes, it's allowed
Yes, it's actively encouraged
No
I don't know
Leave a comment
View 1 comment

Jobs Recruit Sidebar

Jobs
In Virus Bulletin's jobs pages among others:

Virus Bulletin currently has 225,202 registered users.