Oh dear, McAfee fouls up

Started by Rik, Apr 23, 2010, 10:27:41

Previous topic - Next topic

0 Members and 1 Guest are viewing this topic.

Rik

The BBC reports that:

QuoteThousands of PCs around the world have been paralysed by a security update that wrongly labelled part of Windows as a virus.

The update was sent out by security firm McAfee and made affected PCs endlessly restart.

Corporate customers of McAfee seemed to be hardest hit but some individuals reported problems too.

McAfee apologised for the mistake and released a fix to ensure PCs started working again.

The problems were caused by an update to the long list McAfee's anti-virus uses to identify which programs are malicious.

McAfee's 5958 update wrongly identified the Windows svchost.exe file as the wecorl.a virus. This worm tries to replace an existing svchost file with its own version to help it take over a machine.

The update wrongly labelled svchost as the virus and then quarantined it. This caused many PCs to crash as Windows uses many copies of the file to keep the operating system going.

Makes you feel really confident in their products, doesn't it.
Rik
--------------------

This post reflects my own views, opinions and experience, not those of IDNet.

Gary

Considering it effected Intel badly that says alot it was mostly the corporate client I believe :eyebrow:
Damned, if you do damned if you don't

Rik

Rik
--------------------

This post reflects my own views, opinions and experience, not those of IDNet.

Gary

Damned, if you do damned if you don't

Glenn

I came to work yesterday, to find with 4 PC's with the problem. It only takes 30 minutes each to get them back up and running.
Glenn
--------------------

This post reflects my own views, opinions and experience, not those of IDNet.

Rik

What's the fix, Glenn, presumably it has to be done outside of Windows?
Rik
--------------------

This post reflects my own views, opinions and experience, not those of IDNet.

Glenn

Glenn
--------------------

This post reflects my own views, opinions and experience, not those of IDNet.

Rik

Rik
--------------------

This post reflects my own views, opinions and experience, not those of IDNet.

Simon

Doesn't a simple System Restore work?
Simon.
--
This post reflects my own views, opinions and experience, not those of IDNet.

Glenn

Basically boot from a cd, replace the svchost file (must be from the same OS version), run the 5959xdat.exe file, then reboot, it should all then be working.
Glenn
--------------------

This post reflects my own views, opinions and experience, not those of IDNet.

Glenn

Quote from: Simon on Apr 23, 2010, 11:09:49
Doesn't a simple System Restore work?

No idea, Simon, the PC's here have system restore disabled by group policy.
Glenn
--------------------

This post reflects my own views, opinions and experience, not those of IDNet.

Gary

Quote from: Simon on Apr 23, 2010, 11:09:49
Doesn't a simple System Restore work?
System restore is not always the most elegant way to do things at home, so in a corporate environment I imagine its hardly ever used.
Damned, if you do damned if you don't

zappaDPJ

I think McAfee should be congratulated. It's the first time I've heard of it stopping anything, including a virus  ::)

Seriously, the number of times I've had to deal with a compromised PCs that have had McAfee installed and fully up-to-date is lamentable.
zap
--------------------

This post reflects my own views, opinions and experience, not those of IDNet.

Rik

I know what you mean, Zap. I lost faith in them years ago. Curiously, back in the days of Compuserve, the sysops/wizops (mods/admins) were given free issue of both Norton and McAfee so that we could check files before they were uploaded to our libraries. Then, I preferred Norton, but I soon got over that. ;D
Rik
--------------------

This post reflects my own views, opinions and experience, not those of IDNet.

zappaDPJ

zap
--------------------

This post reflects my own views, opinions and experience, not those of IDNet.