Update: Flawed AVG antivirus update cripples Windows XP PCs
Quote:
Deletes critical 'user32.dll' system file, blocks booting
A flawed signature update to AVG Technologies' antivirus software over the weekend crippled some Windows XP PCs by mistakenly deleting a critical system file, the company has confirmed.
According to AVG, an update released late Saturday fingered the "user32.dll" file as a Trojan horse. As per the program's settings, the AVG software, shut the .dll away in quarantine, then deleted it. "A number of users who installed the update mistakenly received a warning that the Windows system file user32.dll product Version 5.1.2600.3099 was infected with a Trojan virus and were prompted to delete a file essential to the operation of Windows XP," a company spokeswoman said Tuesday.
Users of the newest AVG Antivirus 8.0 and its predecessor, AVG Antivirus 7.5, were affected. The AVG spokeswoman claimed that only users running Dutch, French, Italian, Portuguese and Spanish language versions of Windows XP were affected.
"If you have chosen 'heal' or 'quarantine,' your PC will no longer restart," said a panicked user named "pa3bar" in a message Sunday. "It shows a blue screen at start-up and tells you it cannot find winsvr, error c0000135. System recovery has no effect."
On its support site, AVG posted instructions that involved running Windows XP's Recovery Console, disabling several AVG services and restoring the user32.dll file by copying it from the operating system's install CD. For users unable to locate their installation disc, AVG offered a utility that fixed the problem; those users also needed to create a bootable CD or USB drive.
The utility work-around was for AVG Antivirus 8.0 only; a similar utility for AVG Antivirus 7.5 will be available "soon," according to a message posted by a support forum moderator today.
AVG released a follow-up signature update to correct the problem, but that solution only worked if the user had not turned off his PC, or rebooted it, after installing the buggy update and then deleting user32.dll.
"Affected users unable to use their PCs should contact their AVG reseller or ask a friend to download the information and fix the tool for them," the spokeswoman suggested. "AVG sincerely regrets the inconvenience users have experienced. We are working to remedy the problem and ensure that any other potential vulnerabilities are identified and eliminated before they can impact users," she continued.
Although AVG posted work-arounds on its support site, it did not publicize the problem on the front page of its Web site.
This wasn't the first time that AVG has been in the limelight. Last summer, the LinkScanner Search-Shield component of its antivirus software triggered a flood of bogus traffic to Web sites, angering site operators.
Nor is AVG the only security vendor to issue a damaging update. Only last September, a Trend Micro signature mistook several critical Windows XP and Vista system files for malware, blocking the PCs from booting.
Compworld
LOL All i have to say is thank god for avast and Antivir....
__________________
Without Order Nothing Can Exist,Without Chaos Nothing Can Grow
Re: Update: Flawed AVG antivirus update cripples Windows XP PCs
Wait a minute, a blue screen that isn't actually Microsoft's fault...that sounds more like something to celebrate about....hehe
Definitely is going to hurt Grisoft's credibility a bit for anti-virus. Like any other company though they will probably just blame it on the user. Like its the users fault for updating or its the users fault they weren't running the English version of XP....hehe