SEVERE security hole in Microsoft Security Essentials; how to load a fresh signature database?

  • Thread starter Thread starter Phil Goetz
  • Start date Start date
P

Phil Goetz

I've been using MSE on a Win 7 64-bit system since about 2010.

Whenever it flags malware, I move the flagged file into a directory full of malware, to use to train an intrusion-detection program I developed.

This means I must always select "allow" in MSE, or else I won't have access to the file anymore.


I only now discovered, by testing, that it appears that "allow" doesn't just allow that FILE; it also removes that malware's signature from the database. MSE will no longer flag any file containing that malware.


Also, a bug in MSE: the allowed item is NOT listed under History -> Allowed items, though it is listed under History -> All detected items.


BUT... even if you check "All detected items", and then choose "Remove all"... MSE still won't detect that malware. It removes the file, but doesn't restore its signature to the database.


So... for 10 years I've been using a useless MSE, from whose database all the most-common malware's signatures have been removed.


I went here to download MSE, and it says,


"Microsoft Security Essentials reached end of service on January 14, 2020 and is no longer available as a download."


Bastards.


How can I install a fresh new MSE database with ALL the signatures?


(Also, note that because allowed items don't show up under "Allowed items", there is no way to remove a single allowed item; you can only use "Remove all" under "All detected items".)

Continue reading...
 
Back
Top