找回密码
 FreeOZ用户注册
查看: 1407|回复: 1
打印 上一主题 下一主题

[业界新闻] McAfee病毒更新出状况 电脑不断重开机

[复制链接]
跳转到指定楼层
1#
发表于 23-4-2010 04:23:09 | 只看该作者 回帖奖励 |倒序浏览 |阅读模式

马上注册,结交更多好友,享用更多功能,让你轻松玩转社区。

您需要 登录 才可以下载或查看,没有帐号?FreeOZ用户注册

x
网路安全公司McAfee今天提供的1次例行病码毒更新,把电脑视窗(Windows)作业系统1 个正常的档案误为病毒,使全球为数不详的电脑当机。

据报导,这个问题影响的是使用微软公司WindowsXP Service Pack 3作业系统的企业,但目前不清楚有多少部电脑受害。

出现的状况包括电脑在进行更新后,Windows作业系统1个正常的系统档案被当成病毒,因此电脑不断重新开机。

网路风暴中心(The Internet Storm Center)说,他们收到多达100件投诉。这个中心是由SANS科技研究所(SANS Technology Institute)设立,专门监控网际网路出现的问题。

风暴中心说:“有些机构说,他们有数千部电脑当机,还有些机构整个停止运作,要等问题解决再说。”

风暴中心在部落格贴文说:“受到影响的系统会不断重新开机,而且完全无法连接到网路。”

McAfee已开始提供1个可以防止“侦测错误”的更新档,该公司呼吁使用者下载。

法新社向McAfee发言人询问,但未见回覆,该公司的网上支援论坛无法连上,只贴出声明说:“McAfee社群目前流量超出平常,可能导致下载速度变慢。造成不便,敬请见谅。”(译者:中央社陈正杰)
回复  

使用道具 举报

2#
 楼主| 发表于 23-4-2010 10:37:38 | 只看该作者
McAfee AV Customers Have A Very Bad Day

22Apr2010 – The whole purpose of antivirus products is to protect your environment from malicious or annoying intrusions that can keep you from being productive. Unfortunately, McAfee antivirus customers had a very unproductive day yesterday, April 21, 2010, when McAfee released a virus signature that inadvertently identified a legitimate Windows operating system file (SVCHOST.EXE) as malicious. SVCHOST allows software components to communicate directly over a network and is part of the core Windows XP operating system.  With McAfee’s “fix” the file was detected, quarantined and deleted from the system, causing the machine to go into an endless cycle of reboots. The situation has become a huge issue for corporations, since many have not switched to newer versions of Microsoft’s operating system.

McAfee has now retracted the signature in question and re-posted an updated signature that does not contain the false positive.  However, these new signatures alone will not restore a previously deleted SVCHOST.EXE file.  The file must either be restored from the product’s Quarantine (if the machine has not been rendered inoperable), or must be restored manually by a technician via a clean boot from a Windows installation CD or via Windows Safe Boot Mode.

Symantec has spent a great deal of time over the years investing in an end-to-end process to prevent false positives.  Our automated processes test each new signature database against millions of known clean files before releasing them to the field.  This set of files is regularly updated to make sure we have the very latest clean programs from legitimate software vendors (e.g., Microsoft, etc.).  We also leverage our reputation technology to help us identify clean files not contained in our database, to ensure that we don’t incorrectly cause false positives on these files as well.

For McAfee endpoint security customers, there are a couple of Symantec solutions that can help them get back up and running.

    *
      Altiris Deployment Solution:  Helps customers remotely remediate this problem eliminating the need for a desk-side visits.  Even if you are not a current Altiris customer, this solution can be installed to address the problem.
    *
      Backup Exec System Recovery (BESR):  Can help restore systems to last known healthy image. Re-building a system manually can take a huge amount of time.  With BESR, this process is fully automated and can recover a server within minutes.


[ 本帖最后由 chubbycat 于 23-4-2010 09:39 编辑 ]
回复  

使用道具 举报

您需要登录后才可以回帖 登录 | FreeOZ用户注册

本版积分规则

小黑屋|手机版|Archiver|FreeOZ论坛

GMT+11, 6-3-2025 05:20 , Processed in 0.027721 second(s), 18 queries , Gzip On, Redis On.

Powered by Discuz! X3.2

© 2001-2013 Comsenz Inc.

快速回复 返回顶部 返回列表