Author Topic: McAfee AV Users NOTE!  (Read 2257 times)

0 Members and 1 Guest are viewing this topic.

Offline Chris_

  • Little Lebowski Urban Achiever
  • Hero Member
  • *****
  • Posts: 46845
  • Reputation: +2028/-266
McAfee AV Users NOTE!
« on: April 21, 2010, 01:19:03 PM »
http://isc.sans.org/diary.html?storyid=8656

Quote
We have received several reports indicating some issues with McAfee DAT 5958 causing Windows XP SP3 clients to be locked out. It is affecting svchost.exe. Here is an example of the message:

The file C:WINDOWSsystem32svchost.exe contains the W32/Wecorl.a Virus. Undetermined clean error, OAS denied access and continued. Detected using Scan engine version 5400.1158 DAT version 5958.0000.

McAfee has posted additional information here.

Anyone else affected by this? How are you affected? Please contact us via our contact page.

Update 1

Symptoms are: reboot loops and networking down. Trying to roll back to last version is difficult.

Early analysis leads us to believe the false positive only occurs on WinXP workstations with SP3 installed.

Dennis indicated that for him it appears to only affect systems connected to the internet and/or non-domain members. Workstations on the domain with the bad DAT appear do not appear to be affected.

Update 2

We have received several reports that it is affecting domain member workstation as well.

Update 3

McAfee has published an extra.dat file for W32/Wecorl.that can be downloaded here.


doc
If you want to worship an orange pile of garbage with a reckless disregard for everything, get on down to Arbys & try our loaded curly fries.