3 ms·
Still not quite as bad as when McAfee DAT 5958 misidentified svchost.exe (the parent process for all DLL-based services) on XP as malicious (and succesfully del
by pudquick 13y ago
Still not quite as bad as when McAfee DAT 5958 misidentified svchost.exe (the parent process for all DLL-based services) on XP as malicious (and succesfully deleted it!) ... As you can imagine, this didn't go over well. I remember our shop being very glad we were on a delayed deployment for their DATs.
http://slashdot.org/story/134550 http://slashdot.org/story/134550
- derleth 13y agoYou'd think that McAfee developers would be smart enough to hard-code a list of essential system files into their AV such that it will at least prompt you to get an install disk so it can replace them instead of just deleting them if it suspects they're infected. For bonus points, make the software realize that even if the file on the CD looks infected, it isn't actually infected, so make that file's SHA-256 sum a 'known good' profile. (If the file on the actual install CD really is infected, that falls into the category of "Problems The AV Can't Solve". At that point, the OS itself is controlled by Malign Forces Working To Destroy You and the game is over.) For extra special bonus points, code compressed copies of those essential files into the AV software itself, so they can be replaced on the fly without prompting anyone. They can be updated along with the malware profile data, if they ever need to be.
- greenyoda 13y ago1. Most consumer-grade machines don't come with install disks. 2. You can't put compressed copies of essential files into the AV software itself for a couple for a couple of reasons: - Microsoft will sue you for distributing their intellectual property without permission (and is not likely to grant such permission, since they can't control the quality of the third-party software). - These files are not static: they could have been modified by any Windows update, and might be dependent on other updated files. Keeping track of the hashes of "known good" files might work, but you'd have to account for files that were modified by Microsoft patches.
- nitrogen 13y agoWouldn't it be good enough to assume that any file with a valid Microsoft signature is safe? If Microsoft's signing system is compromised (which IIRC sort of happened once when a key issued for signing network credentials could also sign binaries, possibly used in nation-state malware?), you'll have bigger issues than antivirus software deleting essential system files.
- bluedino 13y agoA very similar thing happened at a company I worked at, where a consulting company that I couldn't stand and recommended against had just replaced a few departments worth of workstations with XP and about 2 weeks later they were all stuck in reboot loops because the AV was flagging some system file...