Chinese Internet Security Response Team (GMT +0800)

Black Friday, Backdoor.Haxdoor

[Post on : May 18, 2007 23:51 | Category : Others | by : smallmo] Reship : Original

It's a terrible day for lots of Chinese users (especially Enterprise Users) who use Norton products today. Since this morning, we have received many reports from lots of users. They meet the same problem that Norton detects two system files "netapi32.dll" and "lsasrv.dll" as Backdoor.Haxdoor when they finish upgrading their database to May.17,2007 , and these two files will be deleted. After reboot, the operate system will be loaded into blue screen, and display the following windows file protection message box:

Open in new window

Open main program, we can see:

Open in new window

Only simplified Chinese Windows XP,SP2 users are affected by this false detection because they have patched Microsoft bulletins(MS06-070, KB924270). As now, Symantec has already fixed this false detection through LiveUpdate definitions (20070517, version 71).

This issue has made a huge effection to Chinese people. According to Rising reports, more than 7,000 users have asked help for solving this problem to Rising.

We hope this kind of issue will not happen again.

Related news:

1. Rising: http://it.rising.com.cn/Channels/Info/ITWorld/Corp_news/2007-05-18/1179471988d42211.shtml

2. Kingsoft Duba: http://news.duba.net/virnews/2007/05/18/109171.shtml

3. Tencent QQ: http://tech.qq.com/zt/2007/norton/index.htm



Last modified by smallmo onMay 19, 2007 18:42

adam Says :
August 1, 2007 16:50
[url=http://o2.pl]aout[/url]
Yuri Says :
May 25, 2007 02:05
dynia grin
Zyndram z Maszkowic Says :
May 23, 2007 17:36
pomidor!dog
Jimo Says :
May 23, 2007 06:13
Though this was a terrible mistake on their part, the crash did not require a reformat and reinstall of the OS - but sometimes that's the quickest way to get things back up and running.

Antivirus is not an exact science so, unfortunately, other protection products are bound to follow suit as others already have (Norton now included) in the past.
bobby Says :
May 22, 2007 11:23
Norton screwed up my entire Chinese office's computers.  3 in total.  We only use legitimate softwarel all paid for licenses.  what a bunch of crap. I will not use norton products after this. We had to reformat 3 PCs and install windows again.   they cost us all of our data between scheduled backups. and it is not a small loss, it is HUGE.  Do not use their products as they obvioulsly dont test them, checm them, or they possibly took willing action to knock out pirated software while not considering those who paid for their licenses.
Pages: 1/1 First page 1 Final page