Windows Automatic Update Prompts a Virus

  • Thread starter Thread starter John
  • Start date Start date
J

John

Hi,

Typically, I ignore the automatice update balloon on my
windows xp system and go to microsoft's web site and have
it check for updates. However, on two occassions, I
utilized the balloon and both times received a virus from
critical updates. Fortunately, Norton AV caught it and
quarantined the Bloodhound Exploit virus. Why does this
occur?
 
John,

It is most likely a false - positive. Updates from WU are scanned
for viruses :

http://servicenews.symantec.com/cgi...ort.generic.virus_corporate.general&tpre=ent&
or
http://snipurl.com/8bu3

" I too have been plagued by the Exploit.12 issue and and have found
no solution to the problem, in spite of losing almost a whole day
trying to weed it out. I finally had one of those "eureka" moments
and decided that it is possible that the Bloodhount.Exploit.12
detection on the MBR was false.

+++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
+++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++

This seems to be the case. I decided to insert my original XP CD and
give it a scan. Sure enough, there it was, reporting the same
Exploit.12 on the MBR of the CD.
FIW it would appear that Symantec have a serious bug in their
heuristic detection algorithms. Unless Microsoft have a virus on all
of their production CD's, it would appear that we have nothing to be
overly concerned about.

++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++

I would be interested to know if others can replicate my results
using their original Microsoft CD's. "


MowGreen [MVP]
===============
*-343-* FDNY
Never Forgotten
===============
 
Back
Top