McAfee Security Awareness
28,605 Views 90 Replies Last post: Jul 10, 2009 7:40 AM by The_Librarian RSS 1 2 3 ... 7 Previous Next
onda Newcomer 10 posts since
Jul 3, 2009
Currently Being Moderated

Jul 3, 2009 2:28 AM

False positive after dat 5664

Hi, this night some server have updates the dat to 5664, after this updates this happen:

03/07/2009 07:17:45 Spostato (Pulizia non riuscita. Non è possibile eliminare il virus.) NT AUTHORITY\SYSTEM C:\Programmi\Network Associates\Common Framework\McScript.exe Generic PWS!hv.aq
03/07/2009 07:18:26 Spostato (Pulizia non riuscita. Non è possibile eliminare il virus.) NT AUTHORITY\SYSTEM C:\WINNT\system32\drivers\cpqasm2.sys Generic PWS!hv.aq
03/07/2009 07:18:26 Spostato (Pulizia non riuscita. Non è possibile eliminare il virus.) NT AUTHORITY\SYSTEM C:\WINNT\system32\drivers\cpqteam.sys Generic PWS!hv.aq
03/07/2009 07:18:26 Spostato (Pulizia non riuscita. Non è possibile eliminare il virus.) NT AUTHORITY\SYSTEM C:\WINNT\system32\drivers\q57w2k.sys Generic PWS!hv.aq
03/07/2009 07:18:27 Spostato (Pulizia non riuscita. Non è possibile eliminare il virus.) NT AUTHORITY\SYSTEM C:\WINNT\system32\drivers\bxvbdx.sys Generic PWS!hv.aq
03/07/2009 07:18:27 Spostato (Pulizia non riuscita. Non è possibile eliminare il virus.) NT AUTHORITY\SYSTEM C:\WINNT\system32\drivers\hpqilo2.sys Generic PWS!hv.aq
03/07/2009 07:18:27 Spostato (Pulizia non riuscita. Non è possibile eliminare il virus.) NT AUTHORITY\SYSTEM C:\Programmi\HP\hponcfg\hponcfg.exe Generic PWS!hv.aq

and other our programs is recognized as "Generic PWS!hv.aq" as virus but analizing the files with other antivirus it's appear clean.
We are in caos because our broductivity is stopped!

Any suggestion/idea?
D-Fens Newcomer 60 posts since
Feb 14, 2006
0
votes
Currently Being Moderated
1. Jul 3, 2009 3:20 AM in response to: onda
RE: False positive after dat 5664
first of all: send the files to AVERT: https://www.webimmune.net/default.asp and mention the false positives.
(unfortunately they are slow on adjusting this :(

then rollback the DATs ( https://kc.mcafee.com/corporate/index?page=answers&question_box=dat+rollback&type=forward&searchid=1246609015639 )

or exclude the folder temporarily.

you could check whether it's a false postives at virustotal.com too
FredK Newcomer 1 posts since
Jul 3, 2009
0
votes
Currently Being Moderated
2. Jul 3, 2009 3:20 AM in response to: onda
RE: False positive after dat 5664
Same Problem here in Germany.

Any Advice from Mcafee ?????
D-Fens Newcomer 60 posts since
Feb 14, 2006
0
votes
Currently Being Moderated
3. Jul 3, 2009 3:24 AM in response to: FredK
RE: False positive after dat 5664
the advice from mcafee would be the same like the 8.7i-patch1-massacre: mention nothing and fix it with an "emergency" dat wink
Guest12 Newcomer 26 posts since
Mar 15, 2005
0
votes
Currently Being Moderated
6. Jul 3, 2009 4:33 AM in response to: onda
RE: False positive after dat 5664
What is version of VirusScan you running?
I noticied about this ptoblem just in XP workstations with VSE 8.0
tonyb99 Volunteer Moderator 2,344 posts since
Apr 10, 2006
0
votes
Currently Being Moderated
7. Jul 3, 2009 4:51 AM in response to: Guest12
RE: False positive after dat 5664
I had one workstation come on the network with vse 8.0 and after it updated ( but beofre it upgraded itself to 8.5) it showed this behaviour, didnt get the same thing with 8.5 or 8.7 though.

McAfee Maniac (Volunteer Moderator)
x2 4.00 ePolicy Orchestrator (Patch 5/Build 1298)
x1 4.5 ePolicy Orchestrator ( Test server)
x1 3.6.1.255 ePolicy Orchestrator 3.6.1 Patch 4
Mcafee Agent 3.6.0.608 & 4.0.0.1494
Groupshield 6.02
VSE 8.5.0.781 Patch 4/8 5400 10000 units
VSE 8.7.0.570 Patch 2 5400
x1 Sophos EC 3 SAV 10 x 70
DV27 Newcomer 130 posts since
Jun 18, 2008
0
votes
Currently Being Moderated
9. Jul 3, 2009 5:44 AM in response to: onda
RE: False positive after dat 5664
It looks like after searching for the files affected, that this issue is involving Compaq/HP device drivers - I'd be interested to hear if those affected would be able to confirm if they are running HP/Compaq Workstations and Servers.
RSACCHI Newcomer 3 posts since
Jul 3, 2009
0
votes
Currently Being Moderated
10. Jul 3, 2009 5:59 AM in response to: onda
Same problem here
The VS moved some files of office and now we have more problems....

Generic PWS!hv.aq


Where we can find the emergency dat ? (if it already exist)
:confused:


It´s a big problem....


Thanks,
Rafael
Guest12 Newcomer 26 posts since
Mar 15, 2005
0
votes
Currently Being Moderated
11. Jul 3, 2009 6:21 AM in response to: RSACCHI
RE: Same problem here
Update from McAfee

Issue possible just on machnes with engine 5100 and dat 5664.
So gentelmens - upgrade engine urgent !!!!
RSACCHI Newcomer 3 posts since
Jul 3, 2009
0
votes
Currently Being Moderated
13. Jul 3, 2009 6:41 AM in response to: onda
Engine 5300 too
Engine 5300 DAT 5664... now rolling back to 5662....
D-Fens Newcomer 60 posts since
Feb 14, 2006
0
votes
Currently Being Moderated
14. Jul 3, 2009 6:56 AM in response to: RSACCHI
RE: Engine 5300 too
so it's not only engine 5100?
have you tried an upgrade to 5301?
Go to original post 1 2 3 ... 7 Previous Next

More Like This

  • Retrieving data ...

Bookmarked By (0)