Serious false positive hits users of old McAfee engines

Batch of system files wrongly flagged as malware, current versions not affected.

An update released by McAfee last week resulted in problems around the world, as some vital system files were flagged as malware by updated scanner products, bringing affected systems to a crashing halt. The issue is believed only to have affected users of McAfee's VirusScan 8.01, with those who have upgraded to versions 8.5i and onward not affected by the problems. The misbehaving DAT file was corrected fairly quickly.

VB100

Numerous user comments have been posted on forums and elsewhere detailing the serious issues caused by the update, which resulted in a selection of files, some of them core components of Windows, to be flagged as a generic password stealer. With many admins already away from their posts thanks to the US 4th July holidays, damage could be considerable despite the limited range of products affected. As usual, we advise readers to run the latest versions of all components of their security software where possible.

Details on the glitch are at ITPro here, with a flood of comments at The Register here. Further input from users reached McAfee forums here and here.

07 July 2009

Tags: false positive, mcafee, update.    del.icio.us  digg this! digg this

0 comments

Leave a comment

Quick Links



Poll

When do you install software updates?
As soon as they are released
As soon as I have some time
I take my time, but I always install them eventually
Only when I feel it is absolutely necessary
Never
Leave a comment
View 12 comments

Jobs Career Sidebar

Twitter Feed

virusbtn: RT @emailsecmatters: The typical spam message has sources as diverse as the spam lunch meat: http://ht.ly/2yucd
2 hours ago


virusbtn: Can anyone write a rap about our RAP tests (http://bit.ly/255ySQ) and submit it to the Symantec competition http://bit.ly/bOJg8r
6 hours ago


VB100 certification

VB100 With another epic haul of 54 products to test this month, the VB test team could have done without the bad behaviour of a number of products: terrible product design, lack of accountability for activities, blatant false alarms in major software, numerous problems detecting the WildList set, and some horrendous instability under pressure. Happily, there were also some good performances to balance things out. John Hawes has the details.
See full results.

Virus Bulletin currently has 208,224 registered users.