The Notebook Review forums were hosted by TechTarget, who shut down them down on January 31, 2022. This static read-only archive was pulled by NBR forum users between January 20 and January 31, 2022, in an effort to make sure that the valuable technical information that had been posted on the forums is preserved. For current discussions, many NBR forum users moved over to NotebookTalk.net after the shutdown.
Problems? See this thread at archive.org.

    Mcaffee UPDATE **FALSE POSITIVE on critical system file!

    Discussion in 'Security and Anti-Virus Software' started by Evil Claw, Apr 21, 2010.

  1. Evil Claw

    Evil Claw Notebook Evangelist

    Reputations:
    7
    Messages:
    386
    Likes Received:
    0
    Trophy Points:
    30
    FYI***

    At work(gov't) today computers started logging off and rebooting. :confused: At first, I looked up and saw "logging off" and I hadn't even touched the keyboard. It rebooted and said svchost.exe is deemed virus and instead of deleting, shuts down within a minute, and reboots in endless cycle. If you have Mcafee and your computer starts rebooting, its because Mcafee has identified a critical system file as a virus. :rolleyes: Our IT Director has contacted Mcafee and they have responded with a "yeah, we have a problem with our daily update and we are working on it, but it could be the end of the day before something is sent out." :eek: Good thing I switched my AV last year.

    **update**12:50pm
    From my IT Director:
    "The apparent Virus attack this morning is actually not a virus attack at all. McAfee sent out a virus update this morning that has ACCIDENTALLY tagged the SVCHOST file on computers as being a virus. They are aware that they have created this issue and will be sending out the updated virus data file shortly. (This will be one of those news stories tonight) In the meantime, we are shutting down our Virus update server until the issue is resolved. Thanks for your patience."
     
  2. Tinderbox (UK)

    Tinderbox (UK) BAKED BEAN KING

    Reputations:
    4,745
    Messages:
    8,513
    Likes Received:
    3,823
    Trophy Points:
    431
  3. Evil Claw

    Evil Claw Notebook Evangelist

    Reputations:
    7
    Messages:
    386
    Likes Received:
    0
    Trophy Points:
    30
    There is no virus. Mcafee is their own worst enemy.
     
  4. Tinderbox (UK)

    Tinderbox (UK) BAKED BEAN KING

    Reputations:
    4,745
    Messages:
    8,513
    Likes Received:
    3,823
    Trophy Points:
    431
  5. coolguy

    coolguy Notebook Prophet

    Reputations:
    805
    Messages:
    4,679
    Likes Received:
    12
    Trophy Points:
    106
  6. booboo12

    booboo12 Notebook Prophet

    Reputations:
    4,062
    Messages:
    4,272
    Likes Received:
    96
    Trophy Points:
    116
    I think symantec's gonna get a bunch of corporate converts.

    The consumer product isn't affected, thank goodness. Imagine if that was affected....:S
     
  7. Angelic

    Angelic Kickin' back :3

    Reputations:
    4,496
    Messages:
    2,075
    Likes Received:
    0
    Trophy Points:
    55
    They failed so hard.
     
  8. ryan24

    ryan24 Notebook Enthusiast

    Reputations:
    0
    Messages:
    24
    Likes Received:
    0
    Trophy Points:
    5
    That's quite unacceptable. Never really been a McAffee fan.
     
  9. StormEffect

    StormEffect Lazer. *pew pew*

    Reputations:
    613
    Messages:
    2,278
    Likes Received:
    0
    Trophy Points:
    55
    I spent ALL DAY AT WORK today fixing this problem. I had it figured out around noon EST so I think I was ahead of the curve. McAfee released an iso with a script that fixes the problem, but before that I was fixing it by adding an exception DAT to the McAfee definitions folder and then reintroducing svchost.exe either from an internal backup directory or by using a copy from another XP SP3 Pro machine.

    Let me tell you, work was WILD today because of this. We're calling it the Great McAfee Disaster of 2010!
     
  10. yuyi64

    yuyi64 Notebook Consultant

    Reputations:
    38
    Messages:
    260
    Likes Received:
    0
    Trophy Points:
    30
    Now you guys see why McAfee is the first thing I uninstall on any new computer I buy for myself or I'm asked by someone else to set up. To think that some people INTENTIONALLY install McAfee on their computers and even pay for it just blows my mind!
     
  11. Greg

    Greg Notebook Nobel Laureate

    Reputations:
    7,857
    Messages:
    16,212
    Likes Received:
    58
    Trophy Points:
    466
    This was a pretty big deal today, one that McAfee will pay for I hope. I stopped using their software six years ago, and I'm glad I did.

    What is really funny about this though is that it shows that McAfee probably did not even test their update before releasing it.
     
  12. jedisolo

    jedisolo Notebook Deity

    Reputations:
    155
    Messages:
    933
    Likes Received:
    8
    Trophy Points:
    31
    I work in the IS department at the local children hospital and last year we moved from using Norton to Sophos and Sophos is a pretty good AV suite.
     
  13. Evil Claw

    Evil Claw Notebook Evangelist

    Reputations:
    7
    Messages:
    386
    Likes Received:
    0
    Trophy Points:
    30
  14. dyusem

    dyusem Notebook Guru

    Reputations:
    0
    Messages:
    55
    Likes Received:
    0
    Trophy Points:
    15
    My laptop (Sony BX-760) is experiencing many of the symptoms (no task bar, no internet connection and many other funkiness) of this update.

    I was able to download the patch on my iMac and bluetooth it to the BX-760 BUT I can't boot the Sony in safe mode to install the patch.

    I'm thinking of using Revo to uninstall McAfee. Does anyone know if this will rectify the situation???

    Any other suggestions?

    Thanks!!!
     
  15. StormEffect

    StormEffect Lazer. *pew pew*

    Reputations:
    613
    Messages:
    2,278
    Likes Received:
    0
    Trophy Points:
    55
    The fix should be burned onto a disk. I don't think it will do anything on your laptop if you transferred it there, it's an image file. Can you link me the patch you are using?


    Otherwise, you need to somehow turn McAfee off and replace the svchost.exe file in your C:/windows/system32 directory with a clean copy from another Win XP SP3 computer. Copy and paste will be broken, so you might need to use a ubuntu live cd or something to transfer the file into the correct folder.
     
  16. dyusem

    dyusem Notebook Guru

    Reputations:
    0
    Messages:
    55
    Likes Received:
    0
    Trophy Points:
    15
    The patch that I was going to use is at:

    http://download.nai.com/products/mcafee-avert/tools/SDAT5958_EM.exe

    However I've done the following since posting:

    1/ fully uninstalled McAfee using Revo. Once the application was gone I was able to boot the computer in safe mode and the svchost.exe file in the system32 directory was also gone.
    2/ spent gobs of time waiting for and speaking with McAfee level 1 tech support. They were unable to fix the problem so it has been escalated and I'm waiting for a tech support call which is scheduled for 5-8am PDT today...I'm not hopeful that the call is forthcoming; cynicism is this case is warranted.

    I'm unsure where to get a clean copy of svchost.exe but I believe that I could transfer one via a flash drive from my iMac to the XP laptop. If anyone can point me to that file I'll owe you a 6-pack :)

    Cheers again,
    David
     
  17. dyusem

    dyusem Notebook Guru

    Reputations:
    0
    Messages:
    55
    Likes Received:
    0
    Trophy Points:
    15
    It is amazing what a shot of French Roast will do...

    I just realized that the file that I downloaded (SDAT5958_EM.exe) included a new svchost.exe file for the system32 folder so I installed it in safe mode and I believe that I'm back in business.

    The only obvious visual issue that I've noticed is the quick launch part of the task bar has vanished...perhaps a bit more leaded java will help me discover how to revive it...

    Now I'll need to noodle whether I want to download McAfee again...
     
  18. qhn

    qhn Notebook User

    Reputations:
    1,654
    Messages:
    5,955
    Likes Received:
    1
    Trophy Points:
    205
    It is a conspiracy since, so far, only XP systems were being affected, and not a single Vista or W7 system has been reported :D

    cheers ...
     
  19. Heiji1412

    Heiji1412 Notebook Geek

    Reputations:
    24
    Messages:
    82
    Likes Received:
    0
    Trophy Points:
    15
    That's because, according to a leaked internal memo, they didn't test XP during their QA, considering XP is still the de facto corporate OS, it's quite a careless decision by them.
     
  20. dyusem

    dyusem Notebook Guru

    Reputations:
    0
    Messages:
    55
    Likes Received:
    0
    Trophy Points:
    15
    FWIW, I received the following generous offer from McAfee yesterday; very unsure if I'm going to take them up on it or not:

    Important Message from McAfee

    Dear David,

    According to our records, you recently contacted McAfee Customer Support regarding the faulty update to your PC security software. We are very sorry for the inconvenience this may have caused. We value our loyal customers, so we are offering an extension of your current McAfee product subscription for an additional 2 years, free of charge. In addition, if you incurred expenses with a 3rd party to fix your PC as a result of the faulty update, we are offering to reimburse reasonable expenses in satisfaction of this matter.

    To apply for a subscription extension and/or expense reimbursement, simply complete the form by clicking here. Please note that all information collected will be completely confidential. After you complete the form, please print or save the confirmation page for reference.

    Our commitment to safeguarding your PCs from hackers and cybercriminals remains steadfast. We value you as a customer and are determined to provide you with the highest levels of security.

    Thank you,

    The McAfee Team