查看: 3534|回复: 26
收起左侧

[砖头] 汗,5958误杀系统……

  [复制链接]
wellofsouls
发表于 2010-4-22 08:19:10 | 显示全部楼层 |阅读模式
据说昨晚10点多更新的DAT 5958会误杀XP系统……
幸好我已经不用XP了……


难道McAfee想帮助微软强制淘汰XP
tetris
头像被屏蔽
发表于 2010-4-22 08:29:06 | 显示全部楼层
解决办法:

McAfee's "DAT" file version 5958 is causing widespread problems with Windows XP SP3. The affected systems will enter a reboot loop and loose all network access. We have individual reports of other versions of Windows being affected as well. However, only particular configurations of these versions appear affected. The bad DAT file may infect individual workstations as well as workstations connected to a domain. The use of "ePolicyOrchestrator", which is used to update virus definitions across a network, appears to have lead to a faster spread of the bad DAT file. The ePolicyOrchestrator is used to update "DAT" files throughout enterprises. It can not be used to undo this bad signature because affected system will lose network connectivity.

The problem is a false positive which identifies a regular Windows binary, "svchost.exe", as "W32/Wecorl.a", a virus. If you are affected, you will see a message like:

The file C:WINDOWS\system32\svchost.exe contains the W32/Wecorl.a Virus.
Undetermined clean error, OAS denied access and continued.
Detected using Scan engine version 5400.1158 DAT version 5958.0000.

McAfee released an updated DAT file, and an "EXTRA.DAT" file to fix the problem. An EXTRA.DAT file is a patch to just fix the bad signature. McAfee's support web sites currently respond slowly and are down at times, likely due to the increased load caused by this issue.

Several readers reported that this procedure worked to recover:

1 - Boot the system in "Safe Mode"
2 - copy extra.dat in c:/program files/common files/mcafee/engine
3 - reboot.

If you lost "svchost.exe", then you need to copy it back to c:/Windows/system32/svchost.exe while in safe mode. This fix has to be applied locally at the workstation. However, it may be possible to do this remotely if your workstations support Intel's "vPro" technology. We should have a link to instructions shortly.

Our reader Jim wrote in about how he managed to get some systems back remotely, as long as svchost.exe was not deleted or moved. In this case, the computer will be in a reboot loop. Here is what Jim wrote:

I created a batch file to run the following command:

echo f | xcopy.exe {server}netlogonextra.dat
   "c:program files\common files\mcafeeengine\extra.dat" /R /Y

I put this batch file and the extra.dat in the netlogon folder.

I then set the computer configuration>windows settings>scripts>startup to run this command in a GPO that gets applied to all computers.  Then link the GPO to the domain root, or wherever is appropriate.

Upon reboot the computers process this command and so far we seem to be good to go, "mostly".  There have been a few cases where the files end up missing.



ISC reader Linnie wrote in and indicated this method works as well:

- Copy the EXTRA.dat file to c:program files\common files\mcafeeengine
- copy the svchost.exe to c:windows\system32
- Reboot, everything is back to normal.



Additional information from McAfee: http://community.mcafee.com/thread/24056?tstart=0
McAfee Knowledgebase Article: https://kc.mcafee.com/corporate/index?page=content&id=KB68780
EXTRA.DAT file: http://home.mcafee.com/VirusInfo/VirusProfile.aspx?key=265240.
山卧河横
发表于 2010-4-22 08:49:59 | 显示全部楼层
我用的是XP,没有遇到这种情况。
shenxiaogang
发表于 2010-4-22 08:56:57 | 显示全部楼层
还好我还没升级到5958
zhousf
发表于 2010-4-22 09:06:20 | 显示全部楼层
直接5959。
苍茫
发表于 2010-4-22 09:22:29 | 显示全部楼层
咖啡出现失误
stevenlee87
发表于 2010-4-22 10:10:49 | 显示全部楼层
这个也太杯具了啊。。。
72380656
发表于 2010-4-22 10:21:40 | 显示全部楼层
没有遇见
Enterole
发表于 2010-4-22 12:29:23 | 显示全部楼层
我也直接5959了
且不是XP系统
且 就算装我也喜欢SP2
xiepengx
发表于 2010-4-22 12:30:55 | 显示全部楼层
还好没有更新0.0,过两天在更新
您需要登录后才可以回帖 登录 | 快速注册

本版积分规则

手机版|杀毒软件|软件论坛| 卡饭论坛

Copyright © KaFan  KaFan.cn All Rights Reserved.

Powered by Discuz! X3.4( 沪ICP备2020031077号-2 ) GMT+8, 2024-11-30 04:52 , Processed in 0.128911 second(s), 16 queries .

卡饭网所发布的一切软件、样本、工具、文章等仅限用于学习和研究,不得将上述内容用于商业或者其他非法用途,否则产生的一切后果自负,本站信息来自网络,版权争议问题与本站无关,您必须在下载后的24小时之内从您的电脑中彻底删除上述信息,如有问题请通过邮件与我们联系。

快速回复 客服 返回顶部 返回列表