FYI: Mcafee Enterprise Update Dat 5958

Pegun

Golden Member
Jan 18, 2004
1,334
0
71
Just so everyone knows, McAfee Virus Scan Dat version 5958.0000 is causing shutdowns at enterprises nationwide.

That is all.
 

Pegun

Golden Member
Jan 18, 2004
1,334
0
71
I'm glad we can help. I was going to post in Off topic as well but decided against it due to the audience there.

If you do have any that have already updated, consider rolling back updates with a startup script.
 

ramj70

Senior member
Aug 24, 2004
764
1
81
We got hit at work with this also, I was one of the lucky ones and didn't get hit with it. I guess the updates went in batches
 
Last edited:

leeland

Diamond Member
Dec 12, 2000
3,659
0
76
Boy we got Fucked hard on this one...like 4,000 computers are hosed...

got an im that simply stated...

'If you have xp, get off the network...NOW"
 

Josh123

Diamond Member
Aug 4, 2002
3,034
2
76
We got hit as well, what are you guys doing to fix this? McAfee's site is jacked at the moment.
 

BW86

Lifer
Jul 20, 2004
13,115
29
91
Damn, I wonder if we were hit as I wasnt in work today - we have ~2500 workstations.
 

leeland

Diamond Member
Dec 12, 2000
3,659
0
76
We got hit as well, what are you guys doing to fix this? McAfee's site is jacked at the moment.

I am asking one of the folks who was hit and recovered their steps...it involved rolling back the update I know for sure...

If I can get the steps we used here at work I will post them
 

handyrandyrc

Member
Nov 3, 2009
42
0
0
http://arstechnica.com/business/new...-dat-update-cripples-windows-workstations.ars

Here is a few steps pulled from the official McAfee forum before it went tits-up. I don't have a copy of extra.dat -- I assume this is a 'patch' for the bugged DAT file?

Anyhow, good luck all! I got notice that one of my offsite users got hit in the middle of a presentation... "Why is my PC shutting down now!?" lol They must have gotten an auto web update this morning...
 

terry107

Senior member
Dec 8, 2005
891
0
0
My company got nailed too - thousands of computers affected across the nation. These are the procedures we had to go through to fix:

Boot in safe mode with networking;
In windows explorer, go to Program Files/Common Files/McAfee/Engine
Delete avvscan.dat
Reboot normally
Manually update McAfee

Note that this is what we were instructed to do for our company. There were stacks of computers what couldn't be fixed (memory errors, all connections deleted, menu bar disappearing, etc).
 

Josh123

Diamond Member
Aug 4, 2002
3,034
2
76
McAfee put out a 5959.dat but we have been running a script to put their temp .dat file in and moving the svchost.exe file to the right location then doing a system restore. The problem I'm having now is how the hell am I supposed to fix a lone computer when it can't access the damn internet?
 

shiner

Lifer
Jul 18, 2000
17,116
1
0
McAfee put out a 5959.dat but we have been running a script to put their temp .dat file in and moving the svchost.exe file to the right location then doing a system restore. The problem I'm having now is how the hell am I supposed to fix a lone computer when it can't access the damn internet?

Sneakernet
 

Pegun

Golden Member
Jan 18, 2004
1,334
0
71
Glad to hear people didn't get completely screwed in this one. We ended up creating a Vbs to kill the dat, install 5957 and replace svchost.exe. We caught it before the main domain did which thankfully ensured the entire university didn't crash.
 

snikt

Member
May 12, 2000
198
0
0
I don't think we were affected by this. 1500+ workstations, 75+ servers in our datacenter, and no one's reported any problems.
 

Chiefcrowe

Diamond Member
Sep 15, 2008
5,048
181
116
Lucky! you may have gotten the updated dat files before the bad ones got sent out to you.


I don't think we were affected by this. 1500+ workstations, 75+ servers in our datacenter, and no one's reported any problems.
 

Bob151

Senior member
Apr 13, 2000
857
0
0
Half ours are down.

No comments about QC?

McAfee, wow, that is some nice quality control. Windows XP SP3 is one of the most common operating systems out there among your corporate clients. Was 5958 tested?

I could accept this from a free product, like the Avira product I use at home. The support we paid for on McAfee was unavailable and eventually the support forums went down. Good thing for us there were other community forums discussing remediation by 11:00 EDT or so.
 

handyrandyrc

Member
Nov 3, 2009
42
0
0
I saw the OFFICIAL McAfee response to the issue, find-able from their main website. Reading the comments was my favorite... The one where a company migrated from Symantec to McAfee literally a week or so ago -- their management said, "PUT US BACK!" The guys driving all over their respective states, manually fixing disconnected PCs. OUCH.

The McAfee response was 100% PANSY.
 
Last edited:

Chiefcrowe

Diamond Member
Sep 15, 2008
5,048
181
116
agreed, their response was horrible. no idea how something like this was not detected before it was sent out to everyone. i'm glad we don't use them because it would not have been fun completely switching over!