In the past 24 hours, McAfee identified a new threat that impacts Windows PCs. Our researchers worked to address this threat that attacks critical Windows system executables and buries itself deep into a computer’s memory.
The research team created detection and removal to address this threat. The remediation passed our quality testing and was released with the 5958 virus definition file at 2.00 PM GMT+1 (6am Pacific Time) on Wednesday, April 21.
McAfee is aware that a number of customers have incurred a false positive error due to this release. We believe that this incident has impacted a small percentage of our enterprise accounts globally and a fraction of our consumer base–home users of products such as McAfee VirusScan Plus, McAfee Internet Security Suite and McAfee Total Protection. That said, if you’re one of those impacted, this is a significant event for you, we understand that and we’re very sorry.
Our initial investigation indicates that the error can result in moderate to significant issues on systems running Windows XP Service Pack 3.The immediate impact on corporate users was lessened for corporations who kept a feature called “Scan Processes on Enable” in McAfee VirusScan Enterprise disabled, as it is by default, though those customers could also be impacted when running a scan.
The faulty update was removed from all McAfee download servers within hours, preventing any further impact on customers.
McAfee teams are working with the highest priority to support impacted customers. We have also worked swiftly and released an updated virus definition file (5959) within a few hours and are providing customers detailed guidance on how to repair any impacted systems.
Corporate Customers
- This entry in our virus information library provides workarounds
- Our knowledge base has two articles, one specific for VirusScan Enterprise users and one for Total Protection Service users
- Customers are discussing the issue in our online support community
- More details on this topic are available in an FAQ.
Consumers
- This support page provides information for impacted consumers
- Consumers are also discussing the topic in the online community
To contact McAfee by phone in your region, go to the “Contact Us” page on our Web site and select your country for the correct number.
Early morning on Thursday night (at around 1 AM PT) we published a SuperDAT Remediation Tool to help customers fix affected systems. The tool suppresses the driver causing the false positive by applying an Extra.dat file in folder. It then restores the “svchost.exe” Windows file. The tool has been successful at remediating the problem caused by the faulty DAT update for multiple customers. The tool itself and more details on how it works are available in our knowledge base.
We are investigating how the incorrect detection made it into our DAT files and will take measures to prevent this from reoccurring.
We sincerely apologize for the inconvenience this has caused our customers and will update this blog posting as more details become available.
Barry
PS: I just published another blog in response to some of your comments below.
(Updated at 3.35 PM PT to include statement on number of customers impacted.)
(Updated at 3.50 PM PT with a link to details for consumers who were impacted.)
(Updated at 5.13 PM PT with link to knowledge base.)
(Updated at 5.44 PM PT to correct the number of impacted consumers.)
(Updated at 8.20 PM PT removing detail on 5959 DAT capabilities.)
(Updated at 9.27 PM PT to provide additional detail on customer impact added link to new blog post.)
(Updated at 10.01 PM PT to add a link to the support community.)
(Updated at 11.58 AM PT on Thursday to add additional KB article links.)
(Updated at 1.10 PM PT on Thursday to add mention of remediation tool.)
(Updated at 2.45 PM PT on Thursday to restate number of customers impacted.)
(Updated at 12.53 PM PT on Friday to add a link to the FAQ.)
how do you restall mcafee because it say so and a bought a one and i try to fix it with the butten that say fix.
I have taken my computers to the same shop for over 10 years now, i have even worked there in the past, only 1 person there works on mine an we have taught each other some things – i stay more informed than she does on some things.
So its not like taking it to a stranger or doing it remotely, its a built up relationship thats been formed over years.
Ok I have two computers running McAffe. It has taken me a week to get sorted as I didn’t have ready access to an internet machine. Four hours of fiddling and one machine is now sorted.
I had the additional problem that I could not copy or paste, or move the repair files from a pen drive to the machine. Solved it in the end by zipping the files then choosing unzip to location and saving onto desktop.
Sadly this isn’t working on the second machine and after another four/ five hours its not working. How much is IT support an hour? Where do I send the bill for my time?
I must agree Andrew[UK].
Yeah, McAfee most certainly made a huge negative impact on businesses…
Yeah, a lot of computers dived…
Yeah, a lot of labour and thumbs twiddled…
Yeah, IT depts have spent many hours…
But this is technology mass produced like cell phones… anyone had a cell phone breakdown?
LG’s cell phone division had a recall early 2009 for a particular model which was more powerful than it was created for; but they found a solution and delivered, it took some time but a solution was still provided.
Point is that mistakes happen… by everyone. EVERYONE has made it known that McAfee goofed up and McAfee has also admitted recognizes their mistake, you may not beleive that they understand the extent of the impact only because we’re too angry at them to read inbetween the lines.
Let McAfee handle the programming codes stuff.
To McAfee, you do have a great challenge, a lot of angry consumers. I know you know that. Good luck !
Cheers!
I’m a freelance PC repairman and I’ve worked with dozens of people on this issue. Consumers are pissed. Large Enterprises are pissed. Drop “McCrappy” like a hot potato. Not only does their product perform poorly against malware but, they DO NOT care about their customers. In this case, they are lying about the “0.5%” of people affected.
Obvious lies are obvious.
I urge McCrappy users to switch to another AV product. Companies like Kaspersky, F-Secure, ESET, Sunbelt, Symantec, etc, actually care.
I use Vista. My computer has been crippled since Friday morning. Firstly, McAfee don’t call me back within the time limit they give me. Now I’m waiting for Engineering to ring me because Technical support are unable to fix my computer. What a SHAMBLES ! I will NEVER EVER use McAfee products again and I would advise anyone else not to go near them.
Wow, I am glad that I dumped the big mac 2 months ago. They (macafees) as a service to me withdrew money from my account for the current suscription fee. The main problem is that I never gave them authorization or anyone authorization to tap my account. After a phone call to their service dept. they refunded the money that they took from me. I had to go to my bank and request a stop payment which was to late of course. Things must be rough for the big mac that they have to resort to this kind of action. I had been a customer for about 7 years. Gee they didn’t even kiss me.
Im still not running, everybody is not compter geeks, last thing to do is re format the stupid computer, thanks to McAfee….
Never ever going to use McAfee again
Hi, I’m also one of the many victims that came across this headache of a problem. Eventually i fixed it (in a matter of speaking) by googleing for the solution. Found the solution and my machine started working again. However my systems mcaffee was reseted back to the factory defaults that come with my CD. After the 4th automatic update the problem occured again!! Why is the fault still being downloaded after update?? VERY SUSPICIOUS!! Uninstalled mcaffee and allowed one update for virus definition then prompted it to notify me of any new updates. I prefer a little control during these hard times … wouldn’t you?
Dear All,
I share your pain – and after having tried to use the McAfee ‘fix’ it copied via a hack computer from their website I had stopped the rot, but hadn’t got my functionality or internet back.
What finally seemed to have fixed it was copying the svchost.exe copied using cmd line! – see D Slinger’s item.
(Thought the McAfee extra.dat and superdat was supposed to have done that)
A happy man, I\’m off to walk the dog !
Well, I run a McAfee ePo solution which has the McAfee AV software deployed to ~1500 Windows Computers, ~1000 of these Windows XP.
About ~1300 computers in the estate had the rouge DAT file installed, yet I was able to update to the subsequent DAT’s without issue.
Hopefully, for some that puts into perspective McAfee’s claims that a small percentage of computers were affected. As an example, if you take my ~1500 computers and add it to 20 companies which each have 5 computers (100) where 4 out of 5 are affected before the ‘global’ figures for systems affected are 5% (i.e. 80 computers = 5% of 1500+100).
So in summary, although the figures may be worse than McAfee are admitting, people who put comments like ‘I have an office with 20 computers and 100% were affected so McAfee’s figures are wrong’ need to take a step back. I think a number of people posting here need to get a sense of perspective – the person that wrote ‘I wouldn’t want McAfee to crash a computer running life support systems in a hospital’ needs to step back and think. Why would you have a presumably ‘networked’ Windows XP computer (that can maybe even access the Internet) to provide life support. I’m pretty sure that life support(ing) systems run bespoke software and hardware that can’t multitask running a ventilator, drip and Solitaire for example.
I also think the person that wrote that the McAfee issues feels like the equivalent to hiring a security guard and then he turns round and shoots you in the face. Wouldn’t it be better to equate it to the said security guard detecting you as Osama Bin Laden, shooting you in the face, but then upon realising his mistake gives you some anti-bullet medicine that makes you well again. I haven’t read all the comments as I have to take breaks to get my laughing fits out the way.
I do feel for those that have spent money having a computer repaired, or for companies who lost resources (peoiple-time, money, services) whereby the issue was caused by McAfee, and if the said users could prove it, I think that McAfee should reimberse for the cost and inconvenience.
I also think there is a lot of scaremongering going on with many comments saying things like ‘I’m going to uninstall McAfee right away’ or ‘I’m going to boycott McAfee’ etc etc. I can’t count the number of times that my Microsoft-OS’d computer has crashed to the point of rebuild because of inherently poor underlying code in the operating system, which lets not forget is the reason we need AV software in the first place – because the OS is inherently unsafe – and I’m sure many of you reading this have experienced the same – yet how many of you are saying you’re going to ditch Microsoft Windows etc etc?? – yet I bet a good percentage of users reading this are currently doing so in an out of date or non-fully-patched version of Internet Explorer and underpatched version of XP – with a underconfigured firewall and no web filtering software. I would even wager that quite a few of you probably visit websites that have malicious code in them that gets stopped at the door by your McAfee AV software.
I’m not pro-McAfee, but the majority of posters need to get real, and get a sense of perspective. If you’re still alive and your business hasn’t folded and you haven’t lost millions of pounds/dollars, maybe you should just count your lucky stars and find something else to moan about.
It is very kind of you to offer to resolve these issues over the phone especially as you are only going to charge £1 per minute per the privilege!
Talk to your technical support and tell them to support this issue for FREE!
Why don’t you use plain English. This sounds like a law suit protected script to me. I think you (Barry) need to learn a more positive approach to you clients. We screwed up, your computer system will fail due to our update and this is how you fix it. This should be plastered on the front page of the website. Can we bill our lost time and costs to McAfee?
Thanks to McAfee Total Protection I’ve spent a total of 17hrs since Wednesday to try and repair my pc.
Out of sheer desperation I wiped everything and installed a new OS.
And to think I nearly recommended McAfee to friends..
I am running Windows Vista. My Real-Time scanning of McAfee has gone OFF and doesn’t turn ON. My internet has stopped working. Consequently, no McAfee updates can be downloaded. The system has crippled. I am afraid that I will have to format my hard drive and restore my system to factory defaults of SONY VAIO.
Will you be hasty enough to provide remedies or Simply want your customers to move onto some better options.
Suggestion to everyone is to switch to Avast and Comodo
When this problem came up, I immediately called Mcafee technical support. I paid $90 to your tech support group and was told that it was not a virus problem. The tech said that I should contact Dell because he didn’t know what was happening with my system and stated that my credit card would be refunded (at this time no refund has been given). I called Dell and they asked whether or not I had recently updated my Mcafee virus file. Unfortunately, I had.
This process took six hours and cost $250. Since you stated this problem only affected a small portion of your customer base, I would expect that you would have no problem providing restitution for the cost of repair and the promised refund to the credit card.
Cant even open up to a single game without the thing being quarantined
It just comes to show that you can never be too prepared, I have been googling backup software and came across Genie Timeline it looks perfect for my backup needs, but im not sure if the software does what it says it does, has anyone heard of this company?
Submit your own comments / message for this post