Webroot Identified Windows as Malware and Sowed Chaos
Webroot

Few things are as dangerous as a corrupt update in an antivirus. Once the detection engine starts deleting or quarantining legitimate system files, the average user must walk on broken glass and avoid data loss. This time it was Webroot that had a fiery Monday after receiving hundreds of reports indicating that the latest update of its antivirus spewed false positives on Windows files, and identified Facebook as a phishing portal.

Webroot's AI went 'full Skynet.' Its ultimate solution is that there can't be malware if there's no Windows, said a user on Twitter. And if we go by the reports, exactly that happened. The idea of an antivirus receiving a corrupt update and marking legitimate files is not new. It happened to AVG, it happened to Avast (which bought AVG), it happened to Sophos... and we all assume it will keep happening as long as antivirus exists as a security solution. In recent months, the usefulness of third-party antivirus has been strongly questioned, with engineers from Mozilla and Google leading the charge. And so we return to Webroot, with a latest update that, for lack of other words, blew up in its face.

Webroot Identified Windows as Malware and Sowed Chaos
Something tells us that Webroot's damage control is going to be long and painful...

Webroot began quarantining what appear to be hundreds of Windows files necessary for its proper functioning, infected with the designation W32.Trojan.Gen, classic among false positives. This also extended to builds in the Insider program, hundreds of applications, and several web pages marked as phishing portals, among which Facebook and Bloomberg stand out. The official thread on Webroot's forums already reached 22 pages in depth, even though the error in the database was active (according to the company) for just thirteen minutes.

Webroot is working on a universal tool to repair affected systems (no availability date yet), but there are people out there who can't afford to wait. Due to the breadth of the error, recommendations range from disabling Webroot entirely and bringing quarantined material back, to uninstalling the antivirus in safe mode and manually restoring the damaged files. To users who have suffered this, patience. The good news is that it can be reversed. The bad news is that it will take time.

Official forum: