Global McAfee Glitch: No News is No News

khess 0 Tallied Votes 711 Views Share

There's no news yet on McAfee's about what happened today when their famed antivirus program went bonkers and froze computers by misidentifying a common Windows file as a virus. If it's an actual virus hack, it's a pretty darn clever one--to make the antivirus program think a system file is a virus so that the computer halts. This might be the first time I'd ever actually applaud a virus creator. I usually prescribe some sort of cruel and unusual punishment for such mongrels who write viruses and then unleash them upon the world's innocent but this time is different.

I hope it's just a glitch in McAfee's program. A virus signature update that went bad but I fear that it isn't. McAfee isn't likely to make such a mistake.

Don't worry, I'm neither lauding the virus writer nor McAfee over this but, as a virus, it's pure genius.

I haven't liked McAfee's antivirus program in at least a decade. It used to be such a simple program, a little TSR (Terminate and Stay Resident) application with its cute little "V" icon in your system tray.
But then, about ten years or so ago, they (McAfee) started getting weird like some other virus companies by adding a whole bunch of other stuff to their awesome antivirus programs. The result was a system that ran as slow as stagnant pond scum on a calm day. And, that is pretty darn slow.

I sought out other antivirus programs for my virus-prone Windows systems. For a few years, I used AVG antivirus and was quite pleased with it. That was until I discovered Avast. I've stuck with Avast for the past three or four years without disappointment.

I will be curious to find out the real cause of today's glitch with McAfee's antivirus freeze ray that affected so many of the world's computers. I'll wait with the rest of you to find out the answer.

What do you think it was that caused the massive outage--was it a virus or just a signature update gone bad? Was your computer affected?

Dani AI

Generated

Brief summary and practical context for the thread.

On April 21–22, 2010 a McAfee DAT update (identified as DAT 5958) produced a false positive that flagged the Windows system binary svchost.exe as W32/Wecorl.a; affected Windows XP SP3 machines could blue‑screen or enter an automatic reboot loop. The bad DAT spread quickly in many enterprise environments because centrally managed update systems amplified deployment. (isc.sans.edu)

What McAfee did and what to look for: the vendor pulled the bad DAT, published an EXTRA.DAT suppression file and a SuperDAT remediation tool (SDAT5958_EM.exe), and followed with an updated DAT (5959) that resolved the signature. Operators were explicitly warned to follow vendor remediation guidance before rebooting or running broad scans. (abc7chicago.com)

Recovery options (short checklist for sysadmins): verify the client DAT version and the detection string (W32/Wecorl.a → svchost.exe); if the system’s svchost.exe is missing or zero bytes, restore a known-good copy from the %SYSTEMROOT%\ServicePackFiles\i386 or the DLL cache, or restore from McAfee quarantine after suppression is in place. At scale, deploy the vendor EXTRA.DAT or SuperDAT via your management platform (ePO/SCCM) or use WinPE/boot media to copy the file back before rejoining the network. Automating the copy/update through startup scripts or PXE/WinPE task sequences saved many administrators hours. (abc7chicago.com)

Notes and cautions: avoid downloading unofficial “fix” tools offered by sites that surface in panic-driven searches — scammers frequently weaponize incidents like this. After recovery, review update rollout controls (pilot groups, staged ePO policies, rollback plans) so a single signature cannot cascade across the estate. As pointed out, this looked like a signature error more than a deliberate hack; and for members such as who asked for remedies, the vendor SuperDAT/EXTRA.DAT + restoring svchost copies were the supported paths. (helpnetsecurity.com)

kp21 0 Newbie Poster

Boy I don't know! But I sure wish I could get my computer to work normally again. Any suggestions?

khess 95 Practically a Master Poster

I would boot up in safe mode, remove McAfee and then install avast antivirus.

Be a part of the DaniWeb community

We're a friendly, industry-focused community of developers, IT pros, digital marketers, and technology enthusiasts meeting, networking, learning, and sharing knowledge.