Monday, September 26, 2016
Search
  
Submit your own News for
inclusion in our Site.
Click here...
Breaking News
Snapchat Introduces 'Spectacles' Camera-equipped Glasses, Changes Company name To Snap
Nvidia GPUs Could Return To Apple Macs
Lenovo Brings Fingerprint Authenticated Payments To Laptops
Report Cites Google, Salesforce Interest For Twitter
Dalian Wanda and Sony Enters Team Up in China Movie Business
Apple Develops Amazon Echo-Style Device
ALD Technology Chosen By Samsung, LG For Flexible OLEDs
TSMC To Use Different Processes And 3D Packages Across Future Design Platforms
Active Discussions
Which of these DVD media are the best, most durable?
How to back up a PS2 DL game
Copy a protected DVD?
roxio issues with xp pro
Help make DVDInfoPro better with dvdinfomantis!!!
menu making
Optiarc AD-7260S review
cdrw trouble
 Home > News > PC Parts > GFI Sec...
Last 7 Days News : SU MO TU WE TH FR SA All News

Thursday, March 31, 2011
GFI Security Apologizes For False Virus Alarm On Samsung Laptops


Samsung Laptops eventually do not have a keylogger, and the false alarm surfaced yesterday was based on a false positive from VIPRE, a malware-detection product sold by GFI Security.

The problem wasn't that Samsung was secretly installing keyloggers on its systems, but that GFI's software was mistakenly reporting that the laptops contained the malware.

Alex Eckelberry, General Manager at GFI Security, today apologized to Samsung, as well as any users who may have been affected by this false positive.

As he explained, the false detection was based off of a rarely-used and aggressive VIPRE detection method, using folder paths as a heuristic.

The directory in question was C:\WINDOWS\SL, and is the Slovenian language directory for Windows Live. This same directory path is used by the StarLogger keylogger.

In VIPRE software, among some of the detection types are heuristic (meaning, using a method of pattern analysis on the file); behaviorial (looking at the behaviour of a file in VIPRE's emulator to see if it does anything malicious) or signature-based (simply creating a file signature for the file). Part of the heuristic toolkit used might be any number of types of analyses, and these can include looking at the contents of the file for specific patterns that indicate malware. A researcher can also use a folder path as part of a more comprehensive detection set.

"Imagine you're a researcher, Eckelberry said. "You see the folder name "C:\windows\sl". This is, indeed, something one would never find on a Windows system at the time the detection was written, so the researcher added this folder path to his heuristics for this keylogger. It was peer-reviewed and tested against a broad range of Windows platforms, including every foreign language set. Everything is fine and dandy... except that at some point several years after the original detection was written, Windows Live started using that directory to install Slovenian language files for Windows Live. Samsung started pre-installing Windows Live, including all the languages, and there you have the problem we're having today."

In a statement earlier today, Samsung had denied that its computers contain keylogging software.

"The statements that Samsung installs keylogger on R525 and R540 laptop computers are false," Samsung's statement reads.

"Our findings indicate that the person mentioned in the article used a security program called VIPRE that mistook a folder created by Microsoft?s Live Application for a key logging software, during a virus scan.

The confusion arose because VIPRE mistook Microsoft's Live Application multi-language support folder, "SL" folder, as StarLogger."


Previous
Next
Sony Ericsson Xperia PLAY Launches With Many Games        All News        Intel's Upcoming Ivy Bridge Microprocessors to Support PCI Express 3.0
Hynix Introduces New DDR4 DRAM     PC Parts News      Intel's Upcoming Ivy Bridge Microprocessors to Support PCI Express 3.0

Get RSS feed Easy Print E-Mail this Message

Related News
Samsung Says Battery Not Related To Note 7 Fire Reports in China
Samsung Narrows Gap With Intel In Semiconductor Industry Ranking
How to Identify the New Galaxy Note7
Samsung Sells Stakes in ASML, Seagate, Rambus and Sharp
Samsung's Recall For The Galaxy Note 7 Smartphones In Official In The U.S.
Samsung's Software "Fix" For Galaxy Note 7 Limits Battery Recharges
HP To Buy Samsung's Printer Business For $1.05 billion
Samsung Urges Galaxy Note7 Users To Immediately Bring Their Phones For Replacement
US, Japan Aviation Authorities Warn Against Using Samsung Galaxy Note 7 On Planes
Samsung to Sell Stake in Chip Equipment Maker ASML
Five Samsung C-Lab Projects are Rethinking the Future
Samsung To Replace Current Note7 Devices Due To Overheating Issues

Most Popular News
 
Home | News | All News | Reviews | Articles | Guides | Download | Expert Area | Forum | Site Info
Site best viewed at 1024x768+ - CDRINFO.COM 1998-2016 - All rights reserved -
Privacy policy - Contact Us .