{"id":344,"date":"2010-04-26T08:26:05","date_gmt":"2010-04-26T13:26:05","guid":{"rendered":"http:\/\/blogs.uww.edu\/uptimes\/?p=344"},"modified":"2010-04-26T08:26:05","modified_gmt":"2010-04-26T13:26:05","slug":"icit-team-restores-service-after-mcafee-gaff","status":"publish","type":"post","link":"https:\/\/blogs.uww.edu\/uptimes\/icit-team-restores-service-after-mcafee-gaff\/","title":{"rendered":"iCIT team restores service after McAfee gaff"},"content":{"rendered":"<p>When a faulty McAfee update released\u00a0last Wednesday morning caused a network-wide Windows XP crash, many iCIT employees were called on to manage restoration of computer\u00a0functionality\u00a0across campus.\u00a0 \u00a0<\/p>\n<p>\u00a0&#8220;I&#8217;d like to thank each and every one of you who stepped up, putting in extra effort, time and hard work, to help manage this situation in a smooth and timely fashion, even when there were many &#8216;unknowns&#8221; to deal with,&#8221; said Elena Pokot, CIO.<\/p>\n<p>To recap:\u00a0 The security firm McAfee\u00a0provides daily updates to its subscribers.\u00a0\u00a0\u00a0Wednesday&#8217;s update (DAT 5958), \u00a0misidentified &#8220;svchost.exe&#8221; file in Windows XP Service Pack 3 (SP3) as malware.\u00a0 The false positive detection caused \u201csvcholst.exe\u201d to be quarantined or deleted, locking computers with Windows XP SP3 in\u00a0 re-boot mode, and disconnecting them from the network.<\/p>\n<p>At UW-W, the iCIT response was quick.\u00a0 Distribution of the update was disabled within 40 minutes.\u00a0 The fix provided by McAfee, which required machines to restart in order to restore connectivity, was in hand by 11 a.m.\u00a0\u00a0 The iCIT team restored computer labs by 11:15 a.m., and most personal workstations were up and running by 3 p.m.\u00a0 In some cases, the affected file was deleted, and in those situations, the fix requires a technician to visit and restore the PC.\u00a0 \u00a0Those computers are being restored on a case-by-case basis as the\u00a0Technology Service Center\u00a0is being notified.<\/p>\n<p>The faulty release impacted businesses and institutions across the globe, including Intel, Dish Network, several major hospitals and other institutions.\u00a0\u00a0 For more information, attached are links to ZDNet and Computer World:<\/p>\n<p><a href=\"http:\/\/blogs.zdnet.com\/Bott\/?p=2003\">http:\/\/blogs.zdnet.com\/Bott\/?p=2003<\/a><\/p>\n<p><a href=\"http:\/\/www.computerworld.com\/s\/article\/9175928\/The_McAfee_update_mess_explained?source=CTWNLE_nlt_pm_2010-04-22\">http:\/\/www.computerworld.com\/s\/article\/9175928\/The_McAfee_update_mess_explained?source=CTWNLE_nlt_pm_2010-04-22<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>When a faulty McAfee update released\u00a0last Wednesday morning caused a network-wide Windows XP crash, many iCIT employees were called on to manage restoration of computer\u00a0functionality\u00a0across campus.\u00a0 \u00a0 \u00a0&#8220;I&#8217;d like to thank each and every one of you who stepped up, putting in extra effort, time and hard work, to help manage this situation in a &hellip; <\/p>\n<p class=\"link-more\"><a href=\"https:\/\/blogs.uww.edu\/uptimes\/icit-team-restores-service-after-mcafee-gaff\/\" class=\"more-link\">Continue reading<span class=\"screen-reader-text\"> &#8220;iCIT team restores service after McAfee gaff&#8221;<\/span><\/a><\/p>\n","protected":false},"author":1305,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[72],"tags":[],"class_list":["post-344","post","type-post","status-publish","format-standard","hentry","category-general-news"],"_links":{"self":[{"href":"https:\/\/blogs.uww.edu\/uptimes\/wp-json\/wp\/v2\/posts\/344","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/blogs.uww.edu\/uptimes\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/blogs.uww.edu\/uptimes\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/blogs.uww.edu\/uptimes\/wp-json\/wp\/v2\/users\/1305"}],"replies":[{"embeddable":true,"href":"https:\/\/blogs.uww.edu\/uptimes\/wp-json\/wp\/v2\/comments?post=344"}],"version-history":[{"count":7,"href":"https:\/\/blogs.uww.edu\/uptimes\/wp-json\/wp\/v2\/posts\/344\/revisions"}],"predecessor-version":[{"id":351,"href":"https:\/\/blogs.uww.edu\/uptimes\/wp-json\/wp\/v2\/posts\/344\/revisions\/351"}],"wp:attachment":[{"href":"https:\/\/blogs.uww.edu\/uptimes\/wp-json\/wp\/v2\/media?parent=344"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/blogs.uww.edu\/uptimes\/wp-json\/wp\/v2\/categories?post=344"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/blogs.uww.edu\/uptimes\/wp-json\/wp\/v2\/tags?post=344"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}