So who got hit with McAfee issues this morning

Page 2 - Seeking answers? Join the AnandTech community: where nearly half-a-million members share solutions and discuss the latest tech.

MotF Bane

No Lifer
Dec 22, 2006
60,801
10
0
Write a vbs to kill the old dat, install 5957 and replace svchost. Our users don't have shutdown command rights so we couldn't fix this any way but techy office visits. Caught it only hours before the entire university went down. Hopefully mcafee thinks long and hard about how this happened because lawsuits may start

Oh, that would have sucked. Big campus to run around making office visits too. :p
 

amdhunter

Lifer
May 19, 2003
23,332
249
106
We're using Symantic End point protection as well. It's not too bad...

lol Endpoint is crap. I've had a bunch of computers get infected with Spyware at work and Endpoint won't do crap to prevent them...although most of the time it's the users fault in the first place.

I'll admit, it's usually the bunch that have admin rights that get bombed, but a few times we've had a machine get hosed that has been pretty limited.
 

lizardth

Golden Member
Oct 5, 2005
1,242
0
76
The Railroad Commission of Texas got hit, and I am to understand that A LOT of other state agencies got it too.
 

BCYL

Diamond Member
Jun 7, 2000
7,803
0
71
I can see how this is a fine line for Mcafee/enterprises using Mcafee... On one hand you want to get the virus definitions/signatures out there ASAP so users are protected... on the other hand if the signature causes problems it hits everyone...
 

natto fire

Diamond Member
Jan 4, 2000
7,117
10
76
No problems here. I don't use any AV or anything like that, but am careful of websites, no virii since Windows 95 days.
 

foghorn67

Lifer
Jan 3, 2006
11,883
63
91
The DAT update didn't fix everything. Some machines needed it's svchosts file replaced by a known good one.
 

Mike Gayner

Diamond Member
Jan 5, 2007
6,175
3
0
LOL @ everyone in this thread who is affected by this. You got what you deserved by running McAfee TBH.
 

TXHokie

Platinum Member
Nov 16, 1999
2,558
176
106
How did something like this even got out to production? I'd be so pi$$ed if I was still in IT support.
 

grrl

Diamond Member
Jun 21, 2001
6,204
1
0
From Australia...

Botched antivirus knocks out 10% of Coles registers
ASHER MOSES
April 22, 2010 - 2:55PM

Havoc descended on Coles stores across the country this morning after 10 per cent of the company's cash registers were knocked out by a botched McAfee anti-virus update.

Virgin Mobile was also affected, a spokeswoman for the company confirmed, but she did not know off hand how many computers were knocked out.

The routine anti-virus update confused a valid Windows file with a virus, disrupting millions of computers around the world.

Universities, hospitals and businesses were among those reporting problems after the update misidentified a valid Windows system file as malicious code and caused computers to continually reboot.

Coles spokesman Jim Cooper confirmed today that 1100, or 10 per cent, of Coles's cash registers were knocked out by the issue.

"It's a moveable feast with us but we have been affected by it - so it's been a pretty tough morning out there," Cooper said.

"The registers that were affected couldn't be operated and there were a number of stores that actually had to be closed because there were too many registers down in those stores for the store to be able to trade.

"So at this stage it's been 14-18 stores [that] were closed at any point in time. Some of them are still closed. Most of them are coming back online as we speak."

Cooper said the issue predominantly affected stores in Western Australia, the Northern Territory and South Australia.

It is not clear how many other Australian businesses were affected but it is believed the issue is widespread among McAfee's business customers. Several affected workers in Australia have vented on Twitter.

The problem hit corporate users of Microsoft's Windows XP Service Pack 3 operating system, according to McAfee, which released another update later in the day to fix the problem and urged customers to download it.

The Internet Storm Centre, an initiative of the SANS Technology Institute which monitors problems on the web, said "the affected systems will enter a reboot loop and lose all network access".

The centre said it received reports of "networks with thousands of down machines and organisations who had to shut down for business until this is fixed".

The McAfee software slip "pretty much took Intel down today", said analyst Rob Enderle of Enderle Group in Silicon Valley.

Enderle told of being at the computer chip titan's headquarters in Northern California for an afternoon of meetings when laptop computers began crashing around him.

"Much of Intel was actually taken out," Enderle told AFP. "I imagine most companies running Intel and McAfee were literally taken out."

But McAfee's head of global support, Barry McPherson, said the company believed less than one half of 1 per cent of its enterprise accounts globally were affected.

- with AFP
 

thepd7

Diamond Member
Jan 2, 2005
9,423
0
0
Everyone here at work got killed by it.... except those of us who showed up late to work and didn't get to install the update. >_>

lol - ya us too. you can tell which people woke up early and logged into their laptops


lol yeah they don't automatically push to us (force run after 24 hours if we don't download it before then) so I just never installed it since I was in training all morning.


Well, be happy if you're not in the corporate IT dept. It's free day off, what are you complaining about!?

Some people have jobs to do. I'm salaried, if I don't get the work done today then I'll be working until 9 the next few days.


We have McAfee, but nothing happened to us. Our IT dept was pretty surprised and our local IT person has no idea why we were not effected.

It only affected XP.
 

SpiderWiz

Senior member
Nov 24, 2004
897
3
81
We got hit also. Most of the PCs have been fixed but not after entire day of downtime. Lucky few (myself included) has Linux boxes.
 

rasczak

Lifer
Jan 29, 2005
10,437
23
81
We're using Symantic End point protection as well. It's not too bad...

except when you are trying to rollout a new OS (vista) and the sep client will not deploy. ugh. I HATE VISTA!!!

/rant

sorry to thread crap, i'm just having a hard time getting these two to work together with all the crappy security policies getting in my way.
 

BarkingGhostar

Diamond Member
Nov 20, 2009
8,410
1,617
136
There was a patch today, but only on computers that haven't already been affected. Those that were affected can go kiss McAfee's arse. :D

Law suit!
 

evident

Lifer
Apr 5, 2005
12,132
754
126
i
fucking
hate
mcafee

scan32 can suck my balls!!!!!!

running a database on my machine and scan32 goes up to 50% non stop!!!
 

Wyndru

Diamond Member
Apr 9, 2009
7,318
4
76
Wow, that sucks.

We had a malware outbreak about a month ago that used an svchost file, and Malwarebytes found it and correctly fixed it. It was actually a different svchost file that was running in addition to the legit one. I had to forward the info to CA so etrust and pestpatrol would add it to their definitions, and I was thinking, what would happen if they marked the legit version of svchost as a virus and removed it, would the PC's just crash? Now I know...