Welcome guest. Before posting on our computer help forum, you must register. Click here it's easy and free.

Author Topic: Buggy McAfee update slams Windows XP PCs  (Read 4218 times)

0 Members and 2 Guests are viewing this topic.

Broni

    Topic Starter

    Mastermind
  • Kraków my love :)
  • Thanked: 614
    • Computer Help Forum
  • Computer: Specs
  • Experience: Experienced
  • OS: Windows 8
Buggy McAfee update slams Windows XP PCs
« on: April 21, 2010, 01:42:27 PM »
http://isc.sans.org/diary.html?storyid=8656

McAfee's "DAT" file version 5958 is causing widespread problems with Windows XP SP3. The affected systems will enter a reboot loop and loose all network access. We have individual reports of other versions of Windows being affected as well. However, only particular configurations of these versions appear affected. The bad DAT file may infect individual workstations as well as workstations connected to a domain. The use of "ePolicyOrchestrator", which is used to update virus definitions across a network, appears to have lead to a faster spread of the bad DAT file. The ePolicyOrchestrator is used to update "DAT" files throughout enterprises. It can not be used to undo this bad signature because affected system will lose network connectivity.

The problem is a false positive which identifies a regular Windows binary, "svchost.exe", as "W32/Wecorl.a", a virus. If you are affected, you will see a message like:

The file C:WINDOWSsystem32svchost.exe contains the W32/Wecorl.a Virus.
Undetermined clean error, OAS denied access and continued.
Detected using Scan engine version 5400.1158 DAT version 5958.0000.

McAfee released an updated DAT file, and an "EXTRA.DAT" file to fix the problem. An EXTRA.DAT file is a patch to just fix the bad signature. McAfee's support web sites currently respond slowly and are down at times, likely due to the increased load caused by this issue.

Several readers reported that this procedure worked to recover:

1 - Boot the system in "Safe Mode"
2 - copy extra.dat in c:/program files/common files/mcafee/engine
3 - reboot.

If you lost "svchost.exe", then you need to copy it back to c:/Windows/system32/svchost.exe while in safe mode. This fix has to be applied locally at the workstation. However, it may be possible to do this remotely if your workstations support Intel's "vPro" technology. We should have a link to instructions shortly.

Additional information from McAfee: http://community.mcafee.com/thread/24056?tstart=0
McAfee Knowledgebase Article: https://kc.mcafee.com/corporate/index?page=content&id=KB68780
EXTRA.DAT file: http://home.mcafee.com/VirusInfo/VirusProfile.aspx?key=265240.

rthompson80819



    Specialist

    Thanked: 94
  • Experience: Experienced
  • OS: Windows 7
Re: Buggy McAfee update slams Windows XP PCs
« Reply #1 on: April 21, 2010, 03:04:11 PM »
Basically same story, different source, and a few different details.

http://www.comcast.net/articles/news-technology/20100421/US.TEC.McAfee.Antivirus.Flaw/

Broni

    Topic Starter

    Mastermind
  • Kraków my love :)
  • Thanked: 614
    • Computer Help Forum
  • Computer: Specs
  • Experience: Experienced
  • OS: Windows 8
Re: Buggy McAfee update slams Windows XP PCs
« Reply #2 on: April 21, 2010, 03:08:25 PM »

BC_Programmer


    Mastermind
  • Typing is no substitute for thinking.
  • Thanked: 1140
    • Yes
    • Yes
    • BC-Programming.com
  • Certifications: List
  • Computer: Specs
  • Experience: Beginner
  • OS: Windows 11
Re: Buggy McAfee update slams Windows XP PCs
« Reply #3 on: April 21, 2010, 06:14:12 PM »
An interesting demonstration of "the cure is sometimes worse then the disease" if I ever saw one.
I was trying to dereference Null Pointers before it was cool.

Broni

    Topic Starter

    Mastermind
  • Kraków my love :)
  • Thanked: 614
    • Computer Help Forum
  • Computer: Specs
  • Experience: Experienced
  • OS: Windows 8
Re: Buggy McAfee update slams Windows XP PCs
« Reply #4 on: April 21, 2010, 06:18:03 PM »
I assume, you're referring to McAfee as a disease  ???  ;D

rthompson80819



    Specialist

    Thanked: 94
  • Experience: Experienced
  • OS: Windows 7
Re: Buggy McAfee update slams Windows XP PCs
« Reply #5 on: April 21, 2010, 06:23:03 PM »
That's one of the reasons I have automatic updates turned off in Windows and av programs.  I always do the updates, but wait a few days to make sure there are no bugs.

Broni

    Topic Starter

    Mastermind
  • Kraków my love :)
  • Thanked: 614
    • Computer Help Forum
  • Computer: Specs
  • Experience: Experienced
  • OS: Windows 8
Re: Buggy McAfee update slams Windows XP PCs
« Reply #6 on: April 21, 2010, 06:30:44 PM »
Well, with AV program it may work to your disadvantage.
I think, it's better to keep your AV up to date and keep a fresh image of your drive.

James1431997



    Beginner

    Thanked: 2
    • Yes
  • Experience: Experienced
  • OS: Windows 8
Re: Buggy McAfee update slams Windows XP PCs
« Reply #7 on: April 22, 2010, 09:51:53 AM »
Haha. We use McAffe at school. Only some computers worked (the ones turned off before the update) and we rely on our IT for everything (registers being a prime example.) Taking ages to fix, though, bearing in mind we have 1500 PCs running McAfee.