Linked by David Adams on Fri 23rd Apr 2010 15:58 UTC
Bugs & Viruses A version of the McAfee antivirus software used in the corporate and public sectors misidentified the svchost.exe file in Windows XP systems as malware, sending the affected machines into a loop of restarts. Only users of McAfee VirusScan Enterprise on Windows XP service pack 3 were affected, but the fallout was pretty severe, with hospital and police systems among those taken down.
Thread beginning with comment 420511
To view parent comment, click here.
To read all comments associated with this story, please click here.
RE: Why?
by mtzmtulivu on Fri 23rd Apr 2010 17:07 UTC in reply to "Why?"
mtzmtulivu
Member since:
2006-11-14

Why exactly are important services, like hospitals and police, running Windows and relying on Antivirus? Yet more proof that we've got idiots in charge I guess.

whats the alternative? solaris? :-)

the question to me is why were these computers configured to auto update? any update should first go through a process to make sure nothing breaks before being allowed to spread to all the computers in an organization.

Reply Parent Score: 6

RE[2]: Why?
by Elv13 on Fri 23rd Apr 2010 17:19 in reply to "RE: Why?"
Elv13 Member since:
2006-06-12

And it is why you pay for support and testing from them. They reality is, most of these corporate user don't have proper IT department.

The best way for them would be a network anti malware solution. Blocking them in a gateway before they are installed. Signature check can be done on packet too, not just files... (and yes, it does slow your internet connection and your intranet, but just as much as anti virus slow your computers).

Reply Parent Score: 2

RE[2]: Why?
by darknexus on Fri 23rd Apr 2010 18:36 in reply to "RE: Why?"
darknexus Member since:
2008-07-15

Well, my original comment didn't quite come across the way I'd intended, and the edit timeout bit me. I meant to stress the and, as in why are they running Windows *and* relying on Antivirus *instead* of locking the systems down? That's what the policies and mmc are for after all and, while they can be a big pain in the ass and obscure at times, they're far more effective than any Antivirus could ever be. Lock them down, then use a gateway/firewall/network-based AV solution to check traffic from the outside in. split the subnets, so that if they do have a public access point it doesn't get anywhere near the corporate environment. Lock down the browser, forbid the user to install *anything*, and do not let any existing software automatically update. These steps would eliminate the need for per-system antivirus if they really must use Windows. If they're going to secure their Windows machines, they need to do it right.

Reply Parent Score: 4

RE[3]: Why? - more "why"
by jabbotts on Fri 23rd Apr 2010 19:34 in reply to "RE[2]: Why?"
jabbotts Member since:
2007-09-06

Which leads us to the next question, why does one need to lock down the system in the first place. Why is it not delivered with services off by default and configuration hardened. Why am I turning the majority of stuff off instead of turning just what I need on?

In terms of auto-updates, was this a program patch or something delivered through Mcafee's signature updater? It seems to be a signature issue that decided svchost.exe was malicious. Antivirus is probably the one category of software that should be updating it's signature files and scanning engine automatically. This puts the responsibility on McAfee for pushing a bad signature file update.

If it was something like a bad Windows update, I'd be all over the municipality asking why they don't have compitent IT. For an AV data file update it's more understandable.

Reply Parent Score: 2

RE[3]: Why?
by Bill Shooter of Bul on Fri 23rd Apr 2010 19:47 in reply to "RE[2]: Why?"
Bill Shooter of Bul Member since:
2006-07-14

Even if everything you just said made sense, its still wrong. Why? HIPAA requires antivirus for all the reasons you don't understand.

Reply Parent Score: 2

RE[2]: Why?
by cb88 on Fri 23rd Apr 2010 20:56 in reply to "RE: Why?"
cb88 Member since:
2009-04-23

You really think they had a competent admin... they probably can't afford one with the politicians sucking up all the money.

Reply Parent Score: 1