It is currently Thu May 02, 2024 6:15 PM


All times are UTC - 7 hours [ DST ]




Post new topic Reply to topic  [ 9 posts ] 
Author Message
PostPosted: Sat Jul 04, 2009 6:30 PM 
Bored Guru
Bored Guru
User avatar

Joined: Tue Sep 13, 2005 3:29 PM
Posts: 934
EQ1: Worthy
WoW: Worthy
Quote:
McAfee false-positive glitch fells PCs worldwide

When AV attacks

By Dan Goodin in San Francisco

Posted in Security, 3rd July 2009 22:48 GMT

IT admins across the globe are letting out a collective groan after servers and PCs running McAfee VirusScan were brought down when the anti-virus program attacked their core system files. In some cases, this caused the machines to display the dreaded blue screen of death.

Details are still coming in, but forums here (http://forums.mcafeehelp.com/showthread.php?p=569669) and here (http://forums.mcafeehelp.com/showthread.php?t=231904) show that it's affecting McAfee customers in Germany, Italy, and elsewhere. A UK-based Reg reader, who asked to remain anonymous because he was not authorized by his employer to speak to the press, said the glitch simultaneously leveled half of a customer's 140 machines after they updated to the latest virus signature file.

"Literally half of the machines were down with this McAfee anti-virus message IDing valid programs as having this trojan," the IT consultant said. "Literally half the office switched off their PCs and were just twiddling their thumbs."

When the consultant returned to his office he was relieved that his own laptop, which also uses VirusScan, was working normally. Then, suddenly, when it installed the latest McAfee DAT file, his computer was also smitten. The anti-virus program identified winvnc.exe and several other legitimate files as malware and attempted to quarantine them. With several core system files out of commission, the machine was rendered an expensive paperweight.

A McAfee representative in the US didn't immediately respond to phone calls seeking comment. Friday is a holiday for many US employees in observance of Saturday's Independence Day.

Based on anecdotes, the glitch appears to be caused when older VirusScan engines install DAT 5664, which McAfee seems to have pushed out in the past 24 hours. Affected systems then begin identifying a wide variety of legitimate - and frequently crucial - system files as malware. Files belonging to Microsoft Internet Explorer, drivers for Compaq computers, and even the McAfee-associated McScript.exe were being identified as a trojan called PWS!hv.aq, according to the posts and interviews.

We're still trying to determine how widespread this false-positive glitch is being felt and whether people have found any reliable fixes. If you have insight, please leave a comment below. ®


Top
Offline Profile  
 
PostPosted: Sat Jul 04, 2009 7:16 PM 
Sports Guru
Sports Guru
User avatar

Joined: Mon Aug 08, 2005 6:15 AM
Posts: 5747
Location: Houston
WoW: Peno
Who's Dan Goodin?


Top
Offline Profile  
 
PostPosted: Sun Jul 05, 2009 3:25 AM 
Destroyer of Douchenozzles
User avatar

Joined: Sat Sep 16, 2006 12:13 AM
Posts: 2102
EQ1: Givin
WoW: Tacklebery
By Givin Wetwillies on the Internet:

McAffee is, and always was, a giant piece of bloated shit. This is not the first time shit like this has happened. 10 years or so ago, one of their "critical updates" thought explorer.exe was a worm.


Top
Offline Profile  
 
PostPosted: Sun Jul 05, 2009 10:52 AM 
What does this button do?
What does this button do?

Joined: Mon Nov 28, 2005 2:18 PM
Posts: 402
Givin Wetwillies wrote:
By Givin Wetwillies on the Internet:

McAffee is, and always was, a giant piece of bloated shit. This is not the first time shit like this has happened. 10 years or so ago, one of their "critical updates" thought explorer.exe was a worm.



QFT, It misses lots of stuff too.


Top
Offline Profile  
 
PostPosted: Sun Jul 05, 2009 11:54 AM 
The Lurker at the Threshold

Joined: Mon Oct 31, 2005 2:54 PM
Posts: 4156
Location: Atlanta, GA
EQ1: Vanamar
WoW: Kallaystra
Rift: Tarathia
Avira or AVG > McAfee.

_________________

World of Warcraft: Kallaystra, Gweila, Steakumn, Tarathia [ Feathermoon/Horde ]


Top
Offline Profile  
 
PostPosted: Mon Jul 06, 2009 2:33 PM 
For the old school!
For the old school!
User avatar

Joined: Thu Sep 14, 2006 9:57 PM
Posts: 1147
Norton 2009 is about equal to NOD32 at this point. Something to review if you've been put off by the bloat before.


Top
Offline Profile  
 
PostPosted: Tue Jul 07, 2009 1:02 PM 
Destroyer of Douchenozzles
User avatar

Joined: Sat Sep 16, 2006 12:13 AM
Posts: 2102
EQ1: Givin
WoW: Tacklebery
They force us to use Cooperate on campus. My only complaint is with the auto updater, and has been with Symantec products for the longest time. "Except for Ghost, god I loved Ghost" For some reason it has a hard time telling the difference between a definition update and a physical software update, especially when both are published and rolled out on the same update or if you have to reinstall. It has a habit of going batshit if you try to apply a definition update on older versions.


Top
Offline Profile  
 
PostPosted: Tue Jul 07, 2009 1:54 PM 
The Sleeper
The Sleeper
User avatar

Joined: Tue Jul 05, 2005 12:30 PM
Posts: 1674
Location: Miami, FL
EQ1: Leolan
Rift: Leolan
Anyone testing the new MS AV?


Top
Offline Profile  
 
PostPosted: Tue Jul 07, 2009 3:08 PM 
For the old school!
For the old school!
User avatar

Joined: Thu Sep 14, 2006 9:57 PM
Posts: 1147
Yup. Very solid, but the UI is a bet feh. Integrates well with Win7 and Defender. I'm actually VERY impressed with it. Even compared to paid products it's nice. The only ones I'd rate higher are Kaspersky (to a degree), NOD32 (older release) and NIS2009.


Top
Offline Profile  
 
Display posts from previous:  Sort by  
Post new topic Reply to topic  [ 9 posts ] 

All times are UTC - 7 hours [ DST ]


Who is online

Users browsing this forum: No registered users and 2 guests


You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum

Search for:
Jump to:  
cron
Powered by phpBB® Forum Software © phpBB Group
Theme created StylerBB.net
Karma functions powered by Karma MOD © 2007, 2009 m157y