The error caused several versions of McAfee's antivirus software to quarantine or delete system files
McAfee's recent update mistakenly flagged system files as malware
R E L A T E D   C O N T E N T

Free email newsletters




ADVERTISEMENT

McAfee virus update wreaks havoc

Update quarantines or deletes legitimate system files

Tom Sanders in California, vnunet.com 14 Mar 2006
ADVERTISEMENT

McAfee was forced to publish an update to its virus pattern database on Friday after the previous version mistakenly flagged system files as malware.

The error caused several versions of McAfee's antivirus software to quarantine or delete system files, depending on the software's configuration.

Affected applications included Microsoft Excel, Google Toolbar Installer, Macromedia Flash Player and Windows XP.

McAfee has published a full list of files (PDF download) that were incorrectly flagged. The error spanned all operating systems from Linux to OS X and Windows. 

"Users who have moved detected files to quarantine should restore them to their original location. Windows users who have had files deleted should restore files from backup or use System Restore," McAfee said in an advisory

The company had not, at the time of going to press, returned several phone calls from vnunet.com seeking further information.

The Sans Internet Storm Center said that the bad signature files were available for several hours. A user had to run a virus scan for the problem to arise.

While users who have quarantined the infected files should have relatively little trouble restoring them, the error could still cause considerable damage, according to Daniel Wesemann, a volunteer with the Sans Internet Storm Center.

"Things like this can get messy pretty quickly if the antivirus scanner starts to quarantine vital components of your environment," he warned.

In a similar case last month, antivirus firm Sophos wrongly claimed that files on Mac computers running OS X were infected with the Inqtana-B worm. The software in some cases reported over 1,000 infections.

One user reported to vnunet.com that the Sophos mix-up caused the software to delete over 1,200 files from his PC, and that he was forced to completely reinstall the system.

See also:

Apple's latest update repairs five vulnerabilities in OS X and bundled applicationsSecond update in two weeks  14 Mar 2006
Netsky is still the most common virus on the internetFebruary a quieter month overall as more users update definitions  02 Mar 2006
Proof-of-concept worm leaps across platforms  28 Feb 2006
Mobile viruses are fast catching up with PC virusesSecurity firm reports steeper growth curve for mobile viruses than for PC viruses  16 Feb 2006

All Enterprise Security Technology

Like this story? Spread the news by clicking below:

Post this to Delicious del.icio.us    Post this to Digg Digg this    Post this to reddit reddit!

Permalink for this story
R E A D E R   C O M M E N T S

M A R K E T P L A C E
Sponsored links
F E A T U R E D   J O B S
| Computer People
SQL Server 2008 Developer – Staffordshire – Market Rate – 3 - 6 month initial role Computer People have an exciting opportunity for a SQL Server 2008 Developer within an Large organisation based in Staffordshire. ... more >
| Aston Carter
JAVA J2SE DEVELOPER – CREDIT DERIVATIVES amp; Credit Derivatives (CDS, CDO, CDX, IRD, IRS), Exotics and Structured Hybrid products. Technical skills include: Server side Java, SQL, Sybase, SOAP, WEB SERVICE and OOA/D. Nice to have ... more >
| Aston Carter
JAVA J2SE DEVELOPER – CREDIT DERIVATIVES amp; Credit Derivatives (CDS, CDO, CDX, IRD, IRS), Exotics and Structured Hybrid products. Technical skills include: Server side Java, SQL, Sybase, SOAP, WEB SERVICE and OOA/D. Nice to have ... more >
| Aston Carter
Java, C++, SQL Analyst Developer – Interest Rate Risk Java, C++, SQL, Analyst Developer, interest rate, risk, credit risk, market risk, perl, scripting • At least 2-5 years experience developing in C++ and Java • ... more >
More job opportunities