About Me

Barry McPherson

Barry McPherson
Executive Vice President Worldwide Technical Support and Customer Service

Barry McPherson is ...

Read More

Enterprise Blogs

Feeds & Podcasts

Meet the Bloggers

Archive

Tags

#McAfeeFOCUS, #MFETrivia, #SecChat, #SecurityLegos, 12 Scams of Christmas, 2012, 2012 Security Predictions, Acquisition, Advanced Persistent Threat, Android, android antivirus, Android Malware, Android security, android security app, anti-phishing, anti-theft, anti-virus, antivirus, APIs, App Alert, Apple, application blacklisting, application developers, application security, app protection, apps, app safety, ATM scams, attacks, authentication, automotive, Bad Apps, balanced scorecard, best practices, Big Data, big security data, BlackBerry, Blackhat, Black Hat, black hat hackers, botnet, Brazil, breach, Business IT, car hacking, certification, Change Control, China, CISO Executive Summit, Citrix, class action lawsuit, cloud, Cloud city, Cloud computing, Cloud Expo, cloud security, Cofer Black, collaboration, Compliance, Conficker, consolidation, Consumer, consumerization, consumerization of IT, Content Protection, counter identity theft, credit card fraud and protection, credit card skimming, critical infrastructure, CSP, cyber attack, Cybercrime, cyberespionage, Cyber Insurance, Cyber Intelligence Sharing and Protection Act of 2011, cyber security, cybersecurity, cyber security awareness, Cyber Security Mom, cyber threat, cyberthreats, data, database activity monitoring, database security, data breach, Datacenter, data center, data center security, Data Classification, data loss, Data Loss Prevention, Data Protection, Data Protection Act, Dave DeWalt, Dave Marcus, dedicated security appliances, Deep Command, Deep Defender, DeepSAFE, DefCon, DefCon Kids, Department of Commerce, device, Device Control, devices, dewalt, DLP, Dmitri Alperovitch, easter, Ecuador, Eelectric Vehicle, Email & Web Security, Email & Web Security, email security, embedded, embedded devices, Embedded Security, Emerging Markets, Emerging Market Security, EMM, encryption, Endpoint Protection, Endpoint Security, enterprise, enterprise mobility, enterprise resource planning, enterprise scurity, enterprise security, epayment, epo, ePO Deep Command, ePolicy Orchestrator, ERP, ESM, espionage, EV, exploit, exploits, facebook, Facial recongnition, Family Safety, FDCC, file sharing, Financial Security, firewall, FISMA, Fixed Function Devices, Focus, Focus11, FOCUS 2011, forrester, Foundstone, Friday Security Highlights, Garter, Gartner, Gartner Security and Risk Management Summit, George Kurtz, Global Cybersecurity, Global SecurityAlliance Partner Summit, global threat intelligence, google, government, GTI, Hackers, hacking, Hacking Exposed, Hacktivism, HB1140, Healthcare, Heuristics, HIPAA, host intrusion prevention, Host IPS, HV, Hybrid Vehicle, ICS, IDC, identify potential cyber-threats, identity protection, identity theft, IDF 2011, Incident Response, Information leak, Information Protection, Information Security, Information Warfare, Insider Threats, Integrity, Integrity Control, intel, intellectual property, Internet Explorer, internet security, Interop, IntruShield, In vehicle Infotainment, IP, iphone, IPS, IT, IT Security, japan earthquake safe donation, japan earthquake scams, kurtz, labs, laptops, Larry Ponemon, law, legal, legal risk, linkedin, live-tweeting, lizamoon, Lockheed Martin, mac, Mac OS X, malware, Malware research, managed security services, Management, Mariposa, mass sql injection, mastercard, Maturity Model, McAfee, McAfee Application Control, McAfee Cloud Security Platform, McAfee Data Loss Prevention, Mcafee DLP, McAfee Email Gateway 7.0, McAfee Enterprise Mobility Management, McAfee ePO, McAfee ePolicy Orchestrator, McAfee Firewall Enterprise, McAfee FOCUS, McAfee FOCUS 2011, McAfee Identity Protection, McAfee Labs, McAfee Mobile Security, McAfee MOVE AV, McAfee Network Security Platform, McAfee NSP, McAfee Policy Auditor, McAfee Risk Advisor, McAfee Security Journal, McAfee Security Management, McAfee Security Webinars, McAfee SiteAdvisor, McAfee Vulnerability Manager, McAfee Vulnerability Manager for Databases, mcafee wavesecure, Microsoft, Microsoft Security Bulletin, Mid-Market, Mobile, mobile antivirus, mobile app, mobile data communications, mobile device, mobile devices, mobile devices and security threats, mobile malware, mobile phone spyware, mobile security, mobile security app, mobile smartphone security, mobiles security, mom, MS12-020, MySQL, NACACS, near field communication, Network Perimeter Security, Network Security, Network Security; Email & Web Security; Security-as-a-Service, network security server security, new year resolution, next-gen IPS, Next Generation IPS, NFC, Night Dragon, NIST, NitroSecurity, NitroView, OMB, online banking, Open Source, operational risk, Operation Aurora, Optimized, outages, OWASP, passwords, password security, patch, Patch Tuesday, Patmos, PCI, PCI Compliance, PCI DSS, Peer to Peer file sharing, perception, personal information over mobile phones, phishing, PII, Ponemon Institute, PostScript, Potentially unwanted program, power grid, power loss, Pre-detection, Pre-Installed Malware, Printers, privacy, protection, Public-Private partnerships, Public Sector, pup, QR codes, reference architecture, regulations, reporting, reputational risk, retail, risk, Risk Advisor, Risk and Compliance, Risk Management, ROI, Rookits, Rootkits, RSA, RSA 2012, SaaS, SaaS security solutions, safe searching, Saviynt Access Manager, SCADA, scam, SCAP, SEC Guidance, SecTor, secure cloud computing, secure container, security, Security-as-a-Service, Security and Defense Agenda, security attacks, security awareness, security breach, security conferences, Security Connected, Security Connected Reference Architecture, Security Influence, security information and event management, security management, security metrics, security optimization, security policy, security threats, Sentrigo acquisition, Shady RAT, SharePoint, shortened URLs, SIA Partners, SIEM, SiteAdvisor, Situational Awareness, Small Business, smartphones, smartphone security, SMB, social business, social media, social networking, social networks, Software-as-a-Service, spam, Spearphishing, sql attacks, SQL Injection, State of Security, stealth attack, stealth crimeware, stealth detection, Steve Jobs, storage, Stuxnet, Support, Symbian, T-Mobile, Tablet, tablets, tablet security, targeted attacks, TCO, technology development, Telecommunications, threat reduction, TJX, TPM, Trusted Computing Module, trustedsource, twitter, Twitter online security, U.S. Cyber Challenge Camps, urchin.js, Vericept DLP, ViaForensics, Virtualization, VIrtual Machines, visa, Vontu DLP, vPro, vulnerability, Vulnerability Manager, vulnerability manager for databases, Web 2.0, Webinar, web protection, web security, Websense DSS, Web services, white hat hackers, Whitelisting, wikileaks, Windows 7, Windows Mobile, Wind River, Xerox, youtube, Zero-Day, zeus

An Update on False Positive Remediation

Thursday, April 22, 2010 at 11:04pm by Barry McPherson
Barry McPherson

As you know, McAfee on Wednesday released a faulty signature update file (DAT file) that caused problems for a number of our customers.

First off, I want to apologize on behalf of McAfee and say that we’re extremely sorry for any impact the faulty signature update file may have caused you and your organizations.

I want to give you a brief update on what has happened since we first became aware of the false detection. McAfee team members have been working around the clock to fix the problem and work with impacted customers. We estimate that the majority of the affected systems are back up and running at this time and more systems are coming back online quickly.

Early Thursday morning (at around 1 AM PT) we published a SuperDAT Remediation Tool to help customers fix affected systems. The tool suppresses the driver causing the false positive by applying an Extra.dat file in folder. It then restores the “svchost.exe” Windows file, the file quarantined as a result of the false detection.

The tool has been successful at remediating the problem caused by the faulty DAT update for multiple customers. The tool itself and more details on how it works are available in our knowledge base. Additionally, we have support team members onsite and on the phone to assist impacted customers.

Of course many of you are asking how the faulty DAT made it past our quality assurance checks. The problem arose during the testing process for this DAT file. We recently made a change to our QA environment that resulted in a faulty DAT making its way out of our test environment and onto customer systems.

To prevent this from happening again, we are implementing additional QA protocols for any releases that directly impact critical system files. In addition, we plan to add capabilities to our cloud-based Artemis system that will provide an additional level of protection against false positives by leveraging an expansive whitelist of critical system files. (More details are available in an FAQ that was published Thursday night.)

Again, on behalf of McAfee, I’m very sorry for how you may have been impacted by the faulty DAT file update and thank you for your continued support and cooperation as we work to remediate the situation.

Barry

Bookmark and Share

Tags: ,

Submit your own comments / message for this post

Your email is never published nor shared. Required fields are marked *

You may use these HTML tags and attributes: <a href="" title=""> <abbr title=""> <acronym title=""> <b> <blockquote cite=""> <cite> <code> <del datetime=""> <em> <i> <q cite=""> <strike> <strong>

Comments (128)

  • P.J. van Assum April 27, 2010 7:05AM

    The only thing you can do for me:
    Give me three years subscription for the time I have given to my system to get it working again.

    Best regards
    P.J. van Assum

  • eric chary April 27, 2010 6:10AM

    Dear Mister DeWalt,

    First of i hope you will excuse me for my poor english, being french ,this not my native language.

    As try to correct my parents, one friends and my pc after the 21 april 2010 incident.
    I am not able to order one of your CD to correct at least my parents PC (my parents not been very keen with pc & informatique) it is not posssible to oder a CD as when you press “order” button an “error” page keep coming up on your website.
    i ran your free french telephone phoneline, it’s over 45 mins waiting time on tuesday 27 april 2010 12.37 PM !!
    I bought three different account with your company, telling to my parents and my friend you were a safe company.
    Now, my parents pc keep booting up all day long.

    I really wish you could help me or at least my parents.

    Your sincerely;
    Eric

  • unique April 27, 2010 1:09AM

    Crappy software. Switched right away after realising how much system resources it used up and the boot time is ridiculous!

    Norton Internet Security 2010 for the world!

  • Elizabeth April 26, 2010 8:29PM

    McAfee just lost my business after many years. Avast has a new customer! Me.

  • Linda Henris April 26, 2010 8:20PM

    McAfee has screwed up my HP Laptop so bad, the “SuperDat” didn’t even repair it.I am using,now an old laptop. BUT MY HP laptop lost so much I can’t even log on. If I have lost work, which was backed up, someone is gonna pay!!!!!Screen pops on and states I need to reinstate DCOM Server etc etc..Then something about “vbalsgrid6.ocx” Haven’t a clue what that is. My fonts are different, my colors changed, few installed programs gone. There isn’t anyone with ion 100 miles that can repair it!! Tick off..Oh you bet I am..McAfee better do something for me and my HP Laptop soon. I am moving 4-30-10 to Ca and I’ll be without a PC or laptop until McAfee repairs it. I’ll never ever use McAfee again, after THEY repair my laptop.! I have spent hours, trying to use their “fix-it” patch or whatever and it only got worse.. Ticked off..Oh you bet I am!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!

  • J. Jameson April 26, 2010 7:57PM

    I want a refund and reimbursement. Await a class action lawsuit Barry!

  • Johnny Stork April 26, 2010 5:14PM

    Simple solution to significantly reducing your risk of virus’s and other malware.

    1: Run Linux or Mac

    2: If thats not possible, stop running Internet Exploiter and ‘Look Out!” Express (Outlook Express)

    2: Download Microsofts “Security Essentials”

    3: Download and install AVGFree

    4: Stop using any P2P applications

    5: Practice “safe” computing (search Google)

  • P. Olsen April 26, 2010 2:28PM

    I am in medical school. We have no choice over our laptops or what is installed on them.

    We got an email from IT warning us about the problem, but the stupid program would not allow us to disable it.

    My husband, a programmer, DESPISES McAfee, and was livid that I had a program that could not even be turned OFF!

    The next morning, I was sunk while extracting research data from medical records. This has taken several hours of my time, the medical school IT people time, and my husband\’s time. And I am one of the lucky ones who actually has readily available technical help.

    I SHOULD have been studying for pharmacology and pathology finals, and NOT all the hours trying to get this worked out. I am still having computer issues–but no time to keep working on stuff.

    I would never use McAfee again if I had a choice.

  • Filip April 26, 2010 2:08PM

    I did find this blog looking at who is this McAfee company. I have to restart my computer like every second hour becourse of McAfee. I call it McAfee virus as I can not unistall it and it is permanent problem on my comp. It even does not have an uninstall in the menu. It is like a curse and I am getting like dayly request to pay more money on their account. If there is any law on this please let me know.

  • Gary Burzell April 26, 2010 1:51PM

    Why did McAfee not send out an email telling folks this happened? My wife’s computer suddenly stopped working correctly last Wednesday and I had no idea why. After spending hours trying to fix it I just decided it was time to replace her computer (it is 7 years old). However after seeing a tweet today I was able to fix her computer in 5 minutes. But the new computer from Dell is already on the way …

  • Stanicus April 26, 2010 1:36PM

    I worked 15 hours on wednesday to clean this crap up. It’s not the first time we have had issues due to McCrapee. What a lame apology on their part.

  • Miguel Lemen April 26, 2010 1:28PM

    McCafee,
    I thought you were a responsible organization and compromised with the customers. What about us as customers?. What about when your support reseller just say to you “please do not update this dat”, but it’s late. We got a mid-sized network where this kind of mistakes are not solved just requesting an “apologize”. Mistakes costs money and time. So, in the future keep in mind both terms. Quality Assurance is a phrase that comes to my mind when i’m solving problems originated by third people.

  • Jay Z April 26, 2010 1:07PM

    I have read on numerous posts and have two issues. If you are a home user than I feel sorry for you as this type of QA should be addressed with more due care. Home users should not have have to worry if a particular trusted update will be applied successfully and not impact availability. It would be like allowing a critical update from Microsoft to be downloaded and then start crashing your home PC. 9 times out of 10 the home user will just accept the update and be done with the patching process.

    If you are a IT professional than you need to be fired in the first place for automatically deploying DAT files on your network without internal testing. Yes, ultimately it is McAfee’s responsibility but DAT files should be tested on a development box in a test environment before deploying to production machines period. People have no right to bitch about McAfee’s QA process, when it’s evident QA doesn’t exist on there network for the companies or businesses they run or support!

  • MIguel Manzo April 26, 2010 9:57AM

    I have been working for almost 8 years and this is the second time that we got a major problem worldwide, I would expect more attention and better response from McAfee but it was the same situation as 7 seven years ago, unfurtunally I have no influcnece to change the solution inside my organization, otherwise I will do it inmediatly, may be your products are good for some markets, no for big organizations.

  • Torsten April 26, 2010 5:01AM

    I am luckily on Vista, but there is still a “False Positive” detection in the current dat file!

    The progam which you deleting is the latest version (5.3.9) of the Inno Setup Compiler (is a free installer for Windows programs)

    This problem persist since the 21.4.2010 (more as 5 days from now)?

    How can i make McAfee aware of this problem? How long will it take to solve this fault?

    I do not have a Remediation – i have a Frustation!

  • Hiroyoshi Oshida April 26, 2010 1:00AM

    I thought that my old pc died for some reasons, but in fact you killed it. I will never renew your subscription.

  • Valente Gonzalez April 25, 2010 10:49PM

    We dodged a bullet and we are glad that we did not get affected, but after this we had to develop our own QA for DAT release.

    Also McAfee is bloated and causes our systems to be slow, and renewal of the Enterprise Virus Scan product is more than we care to pay. We have a sizable installed client base. We are told that the Anti-Spy ware is extra, and that the Site Adviser piece is also extra. Money is important, but using that money to get only a features and then to have such a threat brought to us and from our Virus protection product.

    Redemption is only a matter of price now.

  • Pauline April 25, 2010 10:04PM

    I used to have strong confidence (and preference) using McAfee over other security software. But not now anymore (after it crashed both pc’s at home). I even have to replace 1 of the HDD because it simply didn’t respond to the setup formatting command.

    It is a great disappointment. I’ve switched to another security software ever since.

    ex-fan from Singapore

  • Raji April 25, 2010 9:16PM

    ANOTHER SORRY MICROSOFT USER

    I’m very sorry to be using Microsoft products after all these years. Any company dumb enough to delete svchost.exe as a security patch goes down in computing history. Fortunately, Ubuntu Server 10.04 is about to be released with real UNIX (Linux) security and a 5 year support lifecycle.

  • McAfee Lover April 25, 2010 5:00PM

    Yes It happens-but we recovered quickly.The reconstruction time and recovery time is impeccable.Learning and how quickly we implement is where we McAfee stands.Our 17000 worked for one goal-It happens to everyone today us-tomorrow who??? lets not look back take the learning and bolt our screws with stronger basements.Microsoft, Apple, and many others Experienced .Mistakes happen. No excuses.But now get all our customers onceagain under our shell with stronger learning.Good work McAfee So far