PDA

View Full Version : McAfee OOps!



SyntaXmasteR
03-14-2006, 05:01 PM
McAfee forgot to put 8 bits of information into the latest DAT file which causes it to think over *00 applications contain viruses! OoPs?

Here is the article from Information Week:
---------------------------------------------------

For over five hours Friday, McAfee's anti-virus software erroneously flagged hundreds of legitimate executables as a malicious virus, leading some ********s to quarantine or delete the offending files and render applications such as Microsoft Excel inoperative.

An error in McAfee's daily virus definition file (dubbed "DAT") identified the files as W*5/CTX, a virus first discovered in 2004. All editions of McAfee's on-demand-scanning products, including both the enterprise and consumer versions of VirusScan, were affected.

Among the legitimate files painted as malware were Microsoft's Excel spreadsheet, Adobe's Flash, the Google Toolbar installer, several Adaptec drivers, and parts of Sun Microsystems' Java Runtime Environment. The list that McAfee posted of the affected files numbers more than **0, but even so, the SANS Institute's Internet Storm Center called it incomplete.

"It doesn't include any of the Oracle binaries that have been reported to be affected by some of our readers," one of the Storm Center's analysts wrote on the site Sunday.

Depending on how users had configured VirusScan, the harmless files were either quarantined to a special folder or deleted. In either case, applications were broken as files were moved or erased from hard drives.

The flawed DAT went out at *0:*5 a.m. PST Friday, said Joe Telafici, director of operations at McAfee's AVERT Labs. "About two hours later, we started getting reports of large numbers of files identified as W*5/CTX," he said.

McAfee pushed out a corrected DAT a couple hours after that, at *:28 p.m. PST.

By then, however, it was too late for some McAfee users.