McAfee quarantines svchost.exe on millions of WinXP machines worldwide
andreyf.tumblr.com
andreyf.tumblr.com
"Well, consider this community hospital fubared.
IT dudes running around pulling out their hair. If it wasn't affecting patient care it would be a humorous scene-but I can't check xray's, or labs or anything. Took out a horrendously bloody gallbladder this morning, and I can't tell (labwise) if she's still bleeding...not good."
However, what are the odds of someone being able to make special-purpose machines to do everything COTS boxes are used for, and making those machines as fast, cheap, and reliable as COTS systems are now? Some things seem obvious (x-ray machines, lab machines) but accounting and record-keeping? Going back to adding machines and purely manual filing is not an option in a large hospital, especially if it has to maintain modern standards of patient care over a large patient population.
I need to think about how to exploit this to promote the installation of *nix-based systems and get people to hire my company to do it.
I'm all for nix-based systems. Please, oh please, convince these people to go to nix and web app (that aren't slaved to IE: eg, AHLTA, or Fuji's Synapse imaging software). I will give you their numbers.
I guess I don't understand the use case -- I had assumed that the computers needed to tell if a patient was bleeding or not were connected to a machine that did some kind of image-taking or internal measurement, and that that machine was the stationary "is patient bleeding machine" computer. Do doctors generally perform analyses like that one on personal computers or normal workstations? I guess I just got a false impression from medical dramas or something.
Though on the AV front it doesn't make sense to have all of your organization's computers running critical software to update at the same time (no matter what software, it just happened to be the anti-virus this time).
The Parallels windows pc on my mac was hit by this very problem. I had to restore to a 3 day old snapshot just to get it running again. I feel bad for those who were running windows bare-metal who can't just press a button and go back.
Not saying it's better, and in fact it'll be worse. The net goes down way more than the AntiVirus gets a bogus config file. But you'll see cash-strapped facilities get sold on the idea of cheaper clients on-site and a large server with a juicy maintenance package behind it.
- McAfee has been crap for a long time now; they're not much better than Norton's products from the last few years.
- Corporate networks are running McAfee because McAfee (and TrendMicro, and other garbage a/v vendors) provide incentives to VARs, consultants, resellers, etc.
- However, this is a far cry from "all antivirus is bad". There are plenty of good products available, some of them are free, and they don't have serious negative impacts on system performance. The on-demand catch rating of some of these products exceeds 97% in independent lab testing, which is pretty damn good.
- If you use a company computer, and you have disabled antivirus on your system because you don't like it, you are putting not just your company's computer, but your company's network at risk. In most "serious" companies, this would be grounds for termination, and I don't blame them. I would also like to emphasize that the workstation you use belongs to your employer, not you.
- I don't care how smart you think you are, if you're running Windows, you're at risk. Even current versions of Firefox are vulnerable to remote exploits, and we've been seeing a hell of an uptick recently in website infections. That blog that you've been visiting for years might try to hit your computer with something nasty tomorrow, and you'll never even notice. For that matter, a lot of website administrators don't realize they have a problem for a long time.
- Rootkits are getting very quiet and very sneaky. I think we're starting to see a trend where computers are coming in with a couple of different infections: one is a recent rogue antivirus infection which drives the user to get help, and the other is an older rootkit that's been running quietly in the background for a while.
You guys should know better.
Then I'd say you probably have a virus ;-)
I don't open attachments from strangers, I don't have warez on my computer, and I call / confirm when I get a word doc. (It doesn't matter because I do the conversion on googledocs anyway).
I know not everyone is fortunate enough to do all of that, but it is entirely possible to avoid viruses if one really wants to.
That you know of.
I can say the same thing, but I always put in that little caveat at the end. Same for being hacked. I've looked for evidence, and never found any reason to believe otherwise.
I've done too many cleanups for people, for whom I have the upmost respect, who said similar things for me lose my humility on that score.
For non technical people reading this thread, the general sentiment of other commentators is correct. Most AV is garbage. It will protect you from about a 1/3 of what is out there at the cost of computer performance. Make an educated decision about whether to run it at home or not. On your corporate network, do whatever your security guy tells you to do.
1. I've been doing virus and malware cleanups for people since -- well, since 1995 or so, at least.
2. I've recently begun presenting seminars on basics for novice computer users.
3. I was among the first to clean up the rather nasty kbiwkm rootkit a while back. One of my clients was infected with it before there had been an a/v response, and before anything could be learned about it anywhere.
4. I've recently begun to get contacted internationally (well, from Canadian individuals, anyway) to clean up websites infected with various sorts of nasty bugs.
5. Most importantly, I follow the results and reports from av-comparatives.org religiously; they're not affiliated with any particular antivirus vendor, product, or group, their tests appear to be very thorough, their methods appear to be fairly rigorous, and they provide reasonable results for a number of different metrics related to antivirus products, all in a regularly-released report that's quite readable.
6. I started a company three years ago to address the various flaws that I saw in the I.T. industry, one of which was the number of people that got hit with viruses over and over again. I have a very, very low rate of repeat virus cleanups for my clients, many of whom are novices that are particularly susceptible to multiple computer virus vectors. You might feel like being snarky and saying that I never hear back from them because they don't care for the service, but then again, I'm currently experiencing my third straight year of 300% growth, and most of my "marketing" comes from word-of-mouth.
But, I don't have a blog, so of course I'm not an expert. Carry on.
edit: ohbtw, two of today's systems that were infected with rogue antivirus also had up-to-date and active McAfee installations, which isn't at all unusual. But, yeah, you're right, it's much better now than it used to be.
In regards to AV Comparatives, I responded to why their tests aren't relevant in in the real world here: http://news.ycombinator.com/item?id=1284321. The bottom line is that detection rates as high as 97% are generally regarded by industry experts as inflated (John Viega says in one of his books that some people estimate actual detection rates to be around 30%). AV companies themselves would never use that number as a part of their marketing campaigns. You'll note that on the product pages of the AV products tested, the numbers aren't listed. If a 99.6% detection rate was actually. valid, don't you think it would be displayed in large and bold letters on the product page?
I'm not saying people shouldn't run AV, but we need to be honest about the actual capabilities of these products. Even if actual detection is only 30%, 30% is better than 0%.
* the task manager
* Quicken
* ATI Drivers
* the GIMP
* other antivirus programs (including products from Kaspery, ESET, Avast, and Trend Micro)
* VLC
* Cygwin
* Acrobat reader
* text editors (including Notepad2 and Notepad++)
* TrueCrypt
AV run in the real world on these settings would be disastrous.
Issues with the samples used by AV Comparatives:
* The malware sample size is only around 1 million.
* The sample size of clean programs is far too small.
* The malware samples used aren't public. We don't even know if the malware used by AV Comparatives are found in the wild anymore.
More generally, evaluations like those done by AV Comparatives and similar organizations are misleading. What actually matters is the vulnerability window. This window is generally a week or two and occurs after a piece of malware is released into the wild. It is the amount of time it takes AV vendors to get a signature distributed. Most damage is done during the vulnerability window, during which infected machines will have their AV disabled by the virus. The fact that your AV can detect viruses released years ago actually doesn't have any bearing on your security; it's a meaningless evaluation of the product.
You have to ask yourself, why don't AV vendors report numbers like the percentages found in AV Comparatives? They don't because they know it's bogus. Sure, most AV vendors will list AV Comparatives and others as an "award" or a "certification", but they'll never list the actual number. I think that should tell you something. In the real world no one is experiencing detection rates like those in the report. If they were, you can be sure the numbers would be part of an AV marketing campaign.
Care to list some please? I don't use Windows, but I'm sick of my dad's PC being infected by the "Windows Security" scam application every 4 months. Not to mention the set of other viruses I find when trying to clean it up...
http://free.avg.com/ww-en/free-antivirus-download
ClamAV for windows is ok too:
Hell, just running housecall once in a while manually can do wonders:
http://www.cnet.com.au/microsoft-security-essentials-3392988...
Boot the affected client into Windows Safe Mode with Networking (Hit F8 During the system boot phase.)
Disable the McAfee McShield service by opening the Registry Editor (regedit.exe), and set the McAfee McShield service to the Disabled startup type: HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\McShield\Start=4.
Once you've rebooted in to normal mode you can rollback definitions from the McAfee gui.
My work computer actually has McAfee on it, which I've disabled through the registry. Don't like how slow it makes my computer.
Education, people! It's better than buying useless feel-good software.
The hit from MacAfee was approximately 15-20% by my reckoning, in terms of time taken to run a compile and link cycle.
Worse still, as you pointed out, responsiveness is affected, which can be incredibly frustrating.
I'm thinking no.
A cold virus's best strategy, for example, is to keep you awake coughing so your immune system is weak, make you sneeze and cough and have a runny nose so you spread germs, etc. But it shouldn't kill you, especially not before you pass it on. I've heard (did I read it in Guns, Germs and Steel?) that syphillis used to be more deadly, but that it got milder as an adaptive strategy.
Likewise, computer viruses probably have a pain threshold they shouldn't pass. If they can do their masters' bidding without hacking you off so bad that you format the computer, they'll be more successful.
Possibly unwarranted conclusion: computer viruses are now widespread precisely because they're Not That Bad.
So, are they worse than antivirus software? A lot of non-geeks may be asking themselves that question today. "Dang, we got a virus one time, but it didn't keep the computer from BOOTing!"
McAfee has just demonstrated a computer autoimmune disease.
Then people realized there was money in botnets and password stealing. The goal of those viruses is to get onto your computer and stay there as long as possible. If you notice it, you'll remove it, so it is in their best interest to avoid being noticed.
Unfortunately, a lot of them are so poorly written they are hard not to notice.
As far as whether viruses or antivirus software are worse to deal with -- well, I have three systems in the shop so far today for virus infections that were so bad that it rendered the computer unusable. One woman told me she broke down and cried because her brand new laptop got infected yesterday and quit working just before she was supposed to do online college course work.
Running without A/V software is exceptionally stupid at this point, even if you think you're smarter than everyone else.
And I never run anti-virus software. At home I have Windows, OS X and Linux boxen and not in 20 years have I had a computer virus.
It's really all about usage patterns more than anything else.
EDIT:Fixed some typos
Chances are you have contracted something, but just don't know about it.
The OS X and linux boxes are pretty safe, but if you use your windows machines online you're bound to have been bitten by drive by malware at least once.
Unless those machines have never been used to surf the web.
Even very reputable sites have had bad cases of advertising injected malware, in some of the most unlikely delivery vehicles.
Erm. Sex with one partner who is not promiscuous and doesn't have a disease is pretty safe without a condom. That's a usage pattern, right?
Does anyone recall the Michelangelo virus? One of the virus detection programs special release for that wiped the boot sector of every drive it was installed on. I think it is fair to say that in that case, the anti caused more monetary loss that the virus.
My goodness, what a fascinating idea. (And a search suggests the you are the first person in all of history to think of that.)
When will the biological parallels end? Will we someday get viral transmission of OS code snippets from one machine to another, leading to improved OSs? The mind boggles ....
(I can't copy and paste URL on thic stupid cell phone, so ask google for "virus wine linux" for the details.)
I could make antivirus software that does nothing and probably make people happier by virtue of the fact that I'm not taking their system's resources.
It's all a bit moot though as before this happened, McAfee was probably worse than anything a PC can get infected with. Now it's gone and proved it beyond any doubt.
Think of it in another way, at any point in time you have x number of virus that you are likely to come across through whatever means. If all those viruses are in the 0.2%, then the catch rate isn't going to be 99.8% it's going to be 0%.
So being able to catch 99.8% of 3 millions viruses when new ones are released all the time is a pointless comparison for efficiency.
Take something you don't know about. For me it's cars. If prevailing wisdom was that unless you bought some $40 item for your car, it could easily be stolen, you'd probably buy it right?
This is what people are told: Windows is insecure and anyone with a clue can just steal your credit card number. I know that if I just don't install crap from the internet, and have a reasonable firewall, I'm not going to get a virus. I haven't had antivirus in over a decade, though I've run some web-based ones on occasion to check, and have never had a problem. I know that, and you know that. My dad (who is much closer to the other 98% of the population) doesn't know that.
(As for corporate use, you answered your own question. IT staff installs it for no reason other than to be able to prove to their boss that it isn't their fault when stuff goes wrong. )
Oh, you mean "The Club", which slows down a car thief by about 10 seconds ;)
They also don't know how smart their users are. Some of them are great, and might read HN, but others will go download any game or smiley pack they can find.
If IT staff were paid based on how smoothly the computers run, they might have a different opinion. Their current goal is usually just to make sure it runs at all.
Indeed. I'm the lead of the "IT Staff" at a small non-profit (~70 users) running mostly on second-hand desktops. Two-thirds of our staff is unpaid, usually interns who are here a few days a week for 3 months, and then they're gone and someone new takes their place. Training proper computer behavior is hard.
So... we run A/V (not McAffee), because we have to. We also lock down the systems hard, not because I think that's a nice thing to do to your users, but because we have to. Imaging all these different desktop models is difficult, and we have very limited resources for doing re-imaging/re-installs/virus cleaning/whatever.
My goal is to enable you to sit down at your computer and be able to perform your job. A 20% performance hit on all computers is worth it if it means that 20% of the computers aren't down for maintenance. :)
Here's a few things I'd consider if I wanted to run an office with minimal computer support:
- run the LTS Ubuntu instead of Windows
- maybe run OS X, on Mac Minis if buying new hardware
- install one Windows terminal server for critical Windows-only software
- lock down firewall to permit only whitelisted web-sites
- run locally hosted (I believe this is possible) Google Docs as office software
Windows virus problems, people surfing Facebook, porn, you-tube, Twitter etc., will suck away time in an office if you don't get some kind of a handle on it. I hate offices where stuff is super locked-down, but put in charge, I'd want to screw things down pretty tight.Obviously developers, salespeople might be somewhat of an exception... it's a hard call to make.
But what do I know, my laptop is running Ubuntu, my primary desktop has always been Linux since 1997.
Or at least: http://www.engadget.com/2010/04/21/mcafee-update--shutting-d...
EDIT: This could actually be a profitable venture. Somewith with at least basic HN-type knowledge and a daytrading account could make serious money. Finance professionals most probably have no idea how important specific IT news are during the day. One should be able to trade ahead of consensus pretty easily.
Or if they lose big clients. My wife tells me all computers in PWC's NYC office are out.
Yes, they do. There are lots of hedge funds that do nothing but analyze news feeds and trade on them all day long.
Seriously though, although there are plenty of algorithms that crawl news all day and trade accordingly, I still think there is money to be made by watching the news with a financial eye. After reading Google's "A New Approach to China" post (which I saw on HN minutes after it was posted), I specifically remember thinking it would be a good time to go long BIDU. And of course, kicked myself after the stock gained ~15% over the next three days. The market responds fast, but consensus is not always reached immediately.
I think the opportunity exists because events like this are like tiny "black swan" events, the lasting effects of which are not immediately perceptible to most people, let alone a computer algorithm. It's easy to write a script to trade on something like "expected earnings were 3c/share, actual earnings 5c/share" but this is complex information. The ability to put the pieces together and realize what a significant outage this is, why it is significant, why there is not an easy fix, and what most companies will do about it (prolly sue 'em or switch to Symantec) is more than a computer can do.
And I'm sure hedge funds are doing the math right now, trying to estimate the possible damages from lawsuits and how it changes the company's value. But remember, you don't have to beat the fastest hedge funds, you just have to beat most of the market, and you'll still make money. Anyway, it will be interesting to see what happens at market open tomorrow :)
Also, whilst market participants watch news feeds, there is a clear difference between following news and trading the tape vs having an actual clue as to what a specific news item means in hard money for a company.
No one may have thought to protect those back doors...
A subscription model is detrimental to users' security. But try to explain that to your PHB who reads websites and magazines making money on advertisements from the industry.
- Skynet IS the virus!!!"