Mcafee Says 3.95 Beta 1 is a Virus

Forum to report beta release bugs and discuss the latest beta releases with other users.
• If reporting a beta release bug, be sure read the bug reporting guidelines first.
Forum rules
IMPORTANT : Be sure to read the NewsLeecher forums policy before posting.
Tracker Tim
Posts: 17
Joined: Sun Jun 24, 2007 4:59 pm

Post by Tracker Tim »

Has newsleecher staff checked back with Mcafee on this? An update on this would be nice.

Thanks

User avatar
Smudge
Site Admin
Posts: 10034
Joined: Tue Aug 17, 2004 1:42 am

Post by Smudge »

We are working with McAfee but it will probably require changes to our installer/software for the next beta since they are unwilling to make an exception in their def file.

You will either need to revert to a previous NewsLeecher version or switch to a different antivirus program.
Please be aware of and use the following pages...
Services Status Page : SuperSearch and Usenet Access server status, retention, server load, indexing time, etc.
Support Request Form : Use this if you have a problem with billing or account status. The forum is only for NewsLeecher application issues.

cory1492
Posts: 30
Joined: Thu Jul 15, 2004 10:01 pm
Location: AB, Canada

Post by cory1492 »

It seems to be because the installer is renaming *.tmp files during installation - the actual file they quarantine when copied out of the quarantine and scanned by itself by on-access scanner from the app that quarantined it produces no virus hits.

edit:/ nope, my bad. Disabled on access scanning for the duration of the install and the newsleecher.exe is picked up still in an on demand scan. Thankfully, I am able to add exceptions in McAfee Enterprise.

kublai
Posts: 137
Joined: Thu Jun 17, 2004 3:06 pm

Post by kublai »

Smudge wrote:We are working with McAfee but it will probably require changes to our installer/software for the next beta since they are unwilling to make an exception in their def file.

You will either need to revert to a previous NewsLeecher version or switch to a different antivirus program.
Any chance of a new beta to prevent Mcafee from deleting newsleecher?

xacci
Posts: 1
Joined: Sat Feb 10, 2007 5:01 pm

Re: Mcafee Says 3.95 Beta 1 is a Virus

Post by xacci »

I experienced the same problem at first so the fix is to open mcafee Security Center and disable Viruscan and any other related function and then run the Newsleecher setup and complete its installation and startup: Then return to Mcafee security center and switch your antivirus functions back on or just tell it to fix when it says your system is not protected.
You should be fine from here on...
:arrow:

mbezik
Posts: 13
Joined: Tue Sep 23, 2008 2:45 pm

Post by mbezik »

this fix doesnt work - this was the first thing i tried, but as has been mentioned since, mcaffee sees the installed newsleecher exe as a virus aswell and removes it......only fix at mo is stick with earlier version or change virus software as has been mentioned

clive386
Posts: 10
Joined: Tue Jan 30, 2007 9:09 pm

Post by clive386 »

There is another more serious matter here that I have noticed with the new beta and McAfee VirusScan Enterprise. When I have 3.95B1 running with the exception in place on %Program Files%\Newsleecher, the on-access shield keeps terminating due to an error. This affects 8.5 and 8.7 at least on my own testing but the problem went away when I downgraded by to 3.91B2. Whatever it is about the new beta that causes McAfee to think there's a problem also seems to be enough to crash its protection engine. That's a security problem and may be something they'd be obligated to fix?

deviousapple
Posts: 3
Joined: Sun Sep 16, 2007 11:57 pm

Boo Mcafee

Post by deviousapple »

This sucks, I liked the new beta alot. It fixed several annoying issues but I don't like it enough to leave my computer vulnerable. :cry:

User avatar
BeatBuster
Posts: 9
Joined: Sat Jun 11, 2005 11:12 am

Re: Boo Mcafee

Post by BeatBuster »

deviousapple wrote:This sucks, I liked the new beta alot. It fixed several annoying issues but I don't like it enough to leave my computer vulnerable. :cry:
I agree with this user. I like the new features but regret to install this beta til it is fixed. I've just cleaned my pc from sTuff. There are the he last months lots of trojans and spyware the antiviruscompagnies also not found. The scanner says there's a vulnerable component. I will wait, it is a beta... it is simple. 8) And its not my problem. :twisted:

User avatar
Smudge
Site Admin
Posts: 10034
Joined: Tue Aug 17, 2004 1:42 am

Post by Smudge »

Good news! We just received the following back from McAfee and they will be removing this false positive in the next DAT release on Tuesday (Oct 14).
A.V.E.R.T. Sample Analysis


Identified: No Virus/Trojan

AVERT(tm) Labs, Aylesbury, UK

Thank you for submitting your suspicious file.

Synopsis -

The file submitted has been analysed and no viral code was found inside. The detection of 'New Poly win32' will be suppressed in 5405 DATS which will be released on Tuesday

Solution -

This correction will be included in DAT 5405
Please be aware of and use the following pages...
Services Status Page : SuperSearch and Usenet Access server status, retention, server load, indexing time, etc.
Support Request Form : Use this if you have a problem with billing or account status. The forum is only for NewsLeecher application issues.

kublai
Posts: 137
Joined: Thu Jun 17, 2004 3:06 pm

Post by kublai »

Smudge wrote:Good news! We just received the following back from McAfee and they will be removing this false positive in the next DAT release on Tuesday (Oct 14).
A.V.E.R.T. Sample Analysis


Identified: No Virus/Trojan

AVERT(tm) Labs, Aylesbury, UK

Thank you for submitting your suspicious file.

Synopsis -

The file submitted has been analysed and no viral code was found inside. The detection of 'New Poly win32' will be suppressed in 5405 DATS which will be released on Tuesday

Solution -

This correction will be included in DAT 5405
This is awesome news. I have been waiting for this since the day it was released. I ran this version for awhile with MAcfee turned off and got teh vundo virus but I was able to remove it.

User avatar
BeatBuster
Posts: 9
Joined: Sat Jun 11, 2005 11:12 am

Post by BeatBuster »

Smudge wrote:Good news! We just received the following back from McAfee and they will be removing this false positive in the next DAT release on Tuesday (Oct 14).
A.V.E.R.T. Sample Analysis


Identified: No Virus/Trojan

AVERT(tm) Labs, Aylesbury, UK

Thank you for submitting your suspicious file.

Synopsis -

The file submitted has been analysed and no viral code was found inside. The detection of 'New Poly win32' will be suppressed in 5405 DATS which will be released on Tuesday

Solution -

This correction will be included in DAT 5405
Smudge for President :P 8) :D

kublai
Posts: 137
Joined: Thu Jun 17, 2004 3:06 pm

Post by kublai »

Smudge wrote:Good news! We just received the following back from McAfee and they will be removing this false positive in the next DAT release on Tuesday (Oct 14).
A.V.E.R.T. Sample Analysis


Identified: No Virus/Trojan

AVERT(tm) Labs, Aylesbury, UK

Thank you for submitting your suspicious file.

Synopsis -

The file submitted has been analysed and no viral code was found inside. The detection of 'New Poly win32' will be suppressed in 5405 DATS which will be released on Tuesday

Solution -

This correction will be included in DAT 5405
I just did an update with Mcafee and now it stopped seeing this version of Newsleecher as a virus. HOOORAY!!!!!!!

marcbrol
Posts: 1
Joined: Sun Oct 19, 2008 3:39 pm

NOD32 - test version is virus

Post by marcbrol »

"A Variant of Win32/Packed.Themida application"
NOD32 Version 3.0.672.0
AV Signature DB 3535 (18/10/2008)

User avatar
BeatBuster
Posts: 9
Joined: Sat Jun 11, 2005 11:12 am

Post by BeatBuster »

I would install the 3.95 b2 because the b1 takes 50% from the cpu power but must stop because mcafee delete an important file:

Type gebeurtenis: Fout
Bron van gebeurtenis: McLogEvent
Categorie van gebeurtenis: Geen
Gebeurtenis-ID: 259
Datum: 19-10-2008
Tijd: 22:04:56
Gebruiker: NT AUTHORITY\SYSTEM
Computer: ********
Beschrijving:
In het bestand C:\Program Files\NewsLeecher\is-SFR1D.tmp is New Poly Win32 Virus aangetroffen. De opschoonfunctie is niet beschikbaar. Het bestand is verwijderd. Gedetecteerd met behulp van scanprogramma versie 5300.2777 met DAT-versie 5408.0000.

Sorry the log was in dutch.
Ill hope i can help with this message to improve the next beta (s). I thougt that this problem was resolved with the the introduction from mcafee dat 5405?? Strange the problem has returned... :cry:

Post Reply