Pennock's Fiero Forum
  Totally O/T - Archive
  McAfee DAT 5958 Update Issues

T H I S   I S   A N   A R C H I V E D   T O P I C
  

Email This Page to Someone! | Printable Version


McAfee DAT 5958 Update Issues by Jake_Dragon
Started on: 04-23-2010 05:17 AM
Replies: 11
Last post by: rogergarrison on 04-24-2010 07:34 PM
Jake_Dragon
Member
Posts: 32853
From: USA
Registered: Jan 2001


Feedback score: (5)
Leave feedback





Total ratings: 403
Rate this member

Report this Post04-23-2010 05:17 AM Click Here to See the Profile for Jake_DragonSend a Private Message to Jake_DragonDirect Link to This Post
http://isc.sans.org/diary.html?storyid=8656

The problem is a false positive which identifies a regular Windows binary, "svchost.exe", as "W32/Wecorl.a", a virus. If you are affected, you will see a message like:

The file C:WINDOWS\system32\svchost.exe contains the W32/Wecorl.a Virus.
Undetermined clean error, OAS denied access and continued.
Detected using Scan engine version 5400.1158 DAT version 5958.0000.

We replaced McAfee last year so we were not effected. But I know there have been issues at one of our partners business.

------------------
Our legacy will be the dirt that is swept out of abandoned factories as the industrious youths of the future go back to work.
Bravery is being the only one who knows you're afraid.
click me

IP: Logged
PFF
System Bot
Jake_Dragon
Member
Posts: 32853
From: USA
Registered: Jan 2001


Feedback score: (5)
Leave feedback





Total ratings: 403
Rate this member

Report this Post04-23-2010 05:31 PM Click Here to See the Profile for Jake_DragonSend a Private Message to Jake_DragonDirect Link to This Post
Bump

No one uses McAfeee anymore?
IP: Logged
avengador1
Member
Posts: 35467
From: Orlando, Florida
Registered: Oct 2001


Feedback score:    (7)
Leave feedback





Total ratings: 571
Rate this member

Report this Post04-23-2010 06:04 PM Click Here to See the Profile for avengador1Send a Private Message to avengador1Direct Link to This Post
I haven't used it for years. They screwed up their last update.
http://www.pcmag.com/articl...,2817,2362993,00.asp
McAfee Apologizes for Update Fiasco.
McAfee on Thursday issued an apology for the faulty update that shut down users' computers and prompted a continuous reboot cycle.
Here is a link that might help.
https://kc.mcafee.com/corporate/index?page=content&id=KB68787

[This message has been edited by avengador1 (edited 04-23-2010).]

IP: Logged
User00013170
Member
Posts: 33617
From:
Registered: May 2006


Feedback score: N/A
Leave feedback





Total ratings: 224
User on Probation

Report this Post04-23-2010 07:38 PM Click Here to See the Profile for User00013170Send a Private Message to User00013170Direct Link to This Post
 
quote
Originally posted by Jake_Dragon:

Bump

No one uses McAfeee anymore?


We do, but we hadn't pushed out the update yet via EPO.
IP: Logged
Jake_Dragon
Member
Posts: 32853
From: USA
Registered: Jan 2001


Feedback score: (5)
Leave feedback





Total ratings: 403
Rate this member

Report this Post04-23-2010 08:00 PM Click Here to See the Profile for Jake_DragonSend a Private Message to Jake_DragonDirect Link to This Post
 
quote
Originally posted by User00013170:


We do, but we hadn't pushed out the update yet via EPO.


It took 9 workstations off line at one of our partners. They had to reload the OS.

EPO is great, I wish our current solution was a good. But McAfee AV stinks. When we did have it I would always down load new dats to a test repository and then update a few test workstations and non mission critical servers and let them run for a week. If they didn't have any issues then it would go to the prod repository.
IP: Logged
User00013170
Member
Posts: 33617
From:
Registered: May 2006


Feedback score: N/A
Leave feedback





Total ratings: 224
User on Probation

Report this Post04-23-2010 08:09 PM Click Here to See the Profile for User00013170Send a Private Message to User00013170Direct Link to This Post
 
quote
Originally posted by Jake_Dragon:


It took 9 workstations off line at one of our partners. They had to reload the OS.

EPO is great, I wish our current solution was a good. But McAfee AV stinks. When we did have it I would always down load new dats to a test repository and then update a few test workstations and non mission critical servers and let them run for a week. If they didn't have any issues then it would go to the prod repository.


Shouldn't have taken a reload.. disabling it and reinstalling the file should have been enough.
IP: Logged
Jake_Dragon
Member
Posts: 32853
From: USA
Registered: Jan 2001


Feedback score: (5)
Leave feedback





Total ratings: 403
Rate this member

Report this Post04-23-2010 08:21 PM Click Here to See the Profile for Jake_DragonSend a Private Message to Jake_DragonDirect Link to This Post
 
quote
Originally posted by User00013170:


Shouldn't have taken a reload.. disabling it and reinstalling the file should have been enough.


I don't have the entire story but apparently it took out more than just the svhost file and it was taking longer to trouble shoot than reload the workstation. Thats why we have so many thin clients, they are not prone to these kinds of issues.
IP: Logged
User00013170
Member
Posts: 33617
From:
Registered: May 2006


Feedback score: N/A
Leave feedback





Total ratings: 224
User on Probation

Report this Post04-24-2010 08:31 AM Click Here to See the Profile for User00013170Send a Private Message to User00013170Direct Link to This Post
 
quote
Originally posted by Jake_Dragon:


I don't have the entire story but apparently it took out more than just the svhost file and it was taking longer to trouble shoot than reload the workstation. Thats why we have so many thin clients, they are not prone to these kinds of issues.


What are your thinclients hooked to, TS, Citrix, VDI?

We tried a pilot a few years ago for using them as TS clients, but middle management didn't like them, so they wanted to 'prove' the wouldn't work to upper by setting things up to fail.. but now we are revisiting with middle management buy-in to hook to VDI. Typical cycles
IP: Logged
Jake_Dragon
Member
Posts: 32853
From: USA
Registered: Jan 2001


Feedback score: (5)
Leave feedback





Total ratings: 403
Rate this member

Report this Post04-24-2010 09:23 AM Click Here to See the Profile for Jake_DragonSend a Private Message to Jake_DragonDirect Link to This Post
 
quote
Originally posted by User00013170:


What are your thinclients hooked to, TS, Citrix, VDI?

We tried a pilot a few years ago for using them as TS clients, but middle management didn't like them, so they wanted to 'prove' the wouldn't work to upper by setting things up to fail.. but now we are revisiting with middle management buy-in to hook to VDI. Typical cycles


Citrix
We just expanded our farm to 110 servers. We avarage 7 - 12 user per server. We use published desktops and run 3 core programs and office.
IP: Logged
User00013170
Member
Posts: 33617
From:
Registered: May 2006


Feedback score: N/A
Leave feedback





Total ratings: 224
User on Probation

Report this Post04-24-2010 06:13 PM Click Here to See the Profile for User00013170Send a Private Message to User00013170Direct Link to This Post
 
quote
Originally posted by Jake_Dragon:


Citrix
We just expanded our farm to 110 servers. We avarage 7 - 12 user per server. We use published desktops and run 3 core programs and office.


We virtualized our farm, and run it MUCH hotter then that.. id say 50 or more clients. ( im on the vmware team, but not the citrix one ) but we don't do full desktops, just applications.

on the ESX side, we run upwards of 50 VMs per host.
IP: Logged
Jake_Dragon
Member
Posts: 32853
From: USA
Registered: Jan 2001


Feedback score: (5)
Leave feedback





Total ratings: 403
Rate this member

Report this Post04-24-2010 06:54 PM Click Here to See the Profile for Jake_DragonSend a Private Message to Jake_DragonDirect Link to This Post
 
quote
Originally posted by User00013170:


We virtualized our farm, and run it MUCH hotter then that.. id say 50 or more clients. ( im on the vmware team, but not the citrix one ) but we don't do full desktops, just applications.

on the ESX side, we run upwards of 50 VMs per host.


We are running Xen server on blades, each blade runs 4 virtual Citrix servers. One of the applications we are using needs the extra horse power. Before that we could comfortably run 30 users per server.
IP: Logged
PFF
System Bot
rogergarrison
Member
Posts: 49601
From: A Western Caribbean Island/ Columbus, Ohio
Registered: Apr 99


Feedback score: N/A
Leave feedback





Total ratings: 551
Rate this member

Report this Post04-24-2010 07:34 PM Click Here to See the Profile for rogergarrisonSend a Private Message to rogergarrisonDirect Link to This Post
I have Mac on my new computer and it gets its updates automaticly. I havent seen any problems. From what I heard it only affects Professional versions of windows.
IP: Logged



All times are ET (US)

T H I S   I S   A N   A R C H I V E D   T O P I C
  

Contact Us | Back To Main Page

Advertizing on PFF | Fiero Parts Vendors
PFF Merchandise | Fiero Gallery | Ogre's Cave
Real-Time Chat | Fiero Related Auctions on eBay



Copyright (c) 1999, C. Pennock