CA Anti-Virus does what McAfee did last week


Recommended Posts

On Saturday 7/4 reports started that McAfee Anti-virus was breaking pc?s because of an Anti-Virus update that was quarantining Windows System files as viruses.

Well it seems that someone else wasn?t paying attention. As of this morning I have received numerous reports from clients reporting that their CA Antivirus is showing Virus alerts for the W32/alalum virus and the files that were being reported appeared to be Windows systems files. CA was quarantining those files as well. When this 1st started I assumed it was an isolated issue but with the client messages concerning this coming in more and more this morning, this definitely seems to be a wide spread issue.

The issue appears to have been caused by an update the was released within the past 12 hours as CA Anti-Virus is set up to check for updates every few hours if your have the auto update feature turned on.

The biggest concern is that when these files are quarantined, if you reboot, there is a good chance that your machine will not restart. I had 2 clients so far ?brick? their pc?s because of the restart. This point is made very clear as the WFP (Windows File protection) comes up saying that ?Files that are required to run windows properly have been replaced??? So far all reports (at least) from the clients I deal with show that CA Anti-virus 2007 ? 2009 are affected.

From the CA Forums ( http://homeofficeforum.ca.com/homeofficefo...read.php?t=4837 ) you will see others also reporting the same issue. I know CA only has 3% of the A/V market so this may not be as big as McAfee but I am passing this on as a public service. Here is what I've instructed my clients to do in the mean time that seems to clear this up

1) Open CA Anti-virus by double clicking the shield looking icon in the systray (That is in the lower right corner by the clock)

2) The Security Overview window will open. Under CA Anti-Virus you will see ?Open advanced settings?. Click that link.

3) Once you are there you will see the main overview window. From here click on the left side where it says Quarantine.

4) You will then see the list of files that are quarantined. Look for any file marked infected with W32/amalum (there is an additional part to the name after amalum but will be different on most pc?s). Highlight all items that are showing infected with amalum and then click on restore. (NOTE***That if you have another file in quarantine that shows something other than amalum as the Infection then that is probably an actual virus infection). Once the files are restored you can close the CA windows

A) You will be prompted to say do you want to restore. Click on ok for each message

5) At this point with no files in quarantine you should be able to hit cancel on the WFP.

6) You will be prompted for keeping changed files click yes to this message.

7) At this point restart P

So far no clients report files getting re-quarantined after the steps and reboot

(**Your situation my be different, so review your specific issue before following this information)

post-266234-1247161395_thumb.jpg

And this is why I still use Norton...never had any false positives with it.

http://community.norton.com/norton/board/m...e.id=2797#M2797

http://forum.worldwindcentral.com/archive/...hp?t-10261.html

http://community.norton.com/norton/board/m...ding&page=1

Not to be negative....but here are 3 different issues with Norton/Symantec products concerning False positives.

So no one is perfect. Your looking at products that are coded by humans, humans screw up. So until we get to the sky lab part of the story, there will always be a chance that something could be screwed up. We just hope that the software company (whomever they are) has a QA that isnt also sleeping.

If i was Symantec, i would buy some fancy security team with real good Pro?s, and erase Norton name from future press releases.

And maybe..maybee change Symantec name itself, and maybe..maybe then, we would trust their products again.

This is pure lack of Marketing department from Symantec, maybe very old peple running it.

TechGuyPA: The first link is not "false positive"

grik: Your statement would be more plausible if you'd capitalize your "I". At least give a more logical reason to your trolling. Your opinion sounds kiddish. I have used Norton/Symantec A/V for so long and I have not yet encounter one false positive on my system. But like TechGuyPA already mention, any product that is created by man will always have flaws.

Its a Marketing statment not if the real product is bad or even good. You obviously did not ynderstand the big picture.

Norton and Symantec branding are a bad image by just having that name.

You used to use Norton back in the days where it was malware and did not catch virus? And i would never say that Norton gives false positives, the image i have on that software, only by the name, is that no false or positive alerts if you know what i mean. Again i point to the fact im talking about the credibility/image behind the Name, dont confuse with anything thing that you tried to point out.

Regards

Its a Marketing statment not if the real product is bad or even good. You obviously did not ynderstand the big picture.

Norton and Symantec branding are a bad image by just having that name.

You used to use Norton back in the days where it was malware and did not catch virus? And i would never say that Norton gives false positives, the image i have on that software, only by the name, is that no false or positive alerts if you know what i mean. Again i point to the fact im talking about the credibility/image behind the Name, dont confuse with anything thing that you tried to point out.

Regards

I apologize. As explained I understand where you were going with the comment now.

All I tried to say was that in these days of get it out NOW it seems that the QA departments at most major software companies seem to be asleep at the well. The products themselves are made by people, people who can make mistakes, its up to the QA staff to double check and clean up any mistakes and thats were the issue is and that isnt happening....and it isnt just MS or Symantec or CA or MCafee, it seems to be almost all of them at one point or another.

This topic is now closed to further replies.
  • Recently Browsing   0 members

    • No registered users viewing this page.
  • Posts

    • Nvidia 610.62 driver lands with big bug fixes and Empulse support by Pulasthi Ariyasinghe There is a new driver available for Nvidia GeForce hardware owners, and it's carrying a whole lot of bug fixes. The WHQL-certified 610.62 Game Ready driver is also adding support for Empulse. Empulse lands from 1047 Games. That may be familiar to first-person shooter fans, as this is the studio that has been behind Splitgate and the Splitgate: Arena Reloaded sequel. This latest FPS entry will land into early access on June 24, and it will have support for DLSS 4.5 with dynamic multi-frame generation and Nvidia Reflex on day one. FIXED World of Warcraft: Gaming stability improvements [5563205] FIXED Apex Legends: Occasional visual corruption after extended gameplay [6239327] FIXED Users may observe DLSS settings being grayed out in certain games after updating to display driver 610.47 [6262805] FIXED Improved gaming stability in multi-monitor configurations when using V-SYNC with DLSS Frame Generation [6158481] FIXED Resolved an issue that could cause jittering or ghosting in some DirectX 11 games when Smooth Motion is enabled [5937897] FIXED Resolved an issue that could cause some games to crash when launched with Smooth Motion enabled [5466398] FIXED [Ada] Resolves a frame pacing issue on certain monitors when G-SYNC is enabled [6226972] FIXED Resolved an issue that prevented the EDID from being read on certain monitors causing them to be identified as "NVIDIA NV-Failsafe” [6005508] FIXED Resolved an issue where certain monitors would not wake from sleep mode [5806798/5635230] FIXED General stability improvements when the system fails to create a new allocation [5449920] Nvidia has only listed a single open issue for this release: “Prefer Maximum Performance” Power Management Mode may not be applied correctly [6007998] The NVIDIA 610.62 driver is now available for download from the NVIDIA app. For those who want to download it directly, standalone links are here. Here are the official release notes (PDF).
    • You could do that in the last 2 updates as well.
    • Bose Ultra Open Earbuds are once again selling at their lowest price by Fiza Ali Amazon is once again offering the Bose Ultra Open Earbuds at their lowest price ever with a limited-time 33 percent discount on their original MSRP, ahead of Father's Day. So, you may want to check it out if you are looking for a gift or if you have been wanting to upgrade your device. The earbuds feature an open-ear design and Bose's OpenAudio technology that should deliver high-quality sound while helping keep audio private. The earbuds also support Bose Immersive Audio, which creates a spatialised listening experience designed to place sound around the listener for a more engaging experience. In terms of wireless connectivity, the earbuds features Bluetooth, Bluetooth Low Energy (BLE), A2DP audio streaming, HFP, AAC, and SBC support. Furthermore, they are compatible with Bose SimpleSync technology, allowing pairing with compatible Bose smart soundbars and speakers. They are also compatible with the Bose App for setup, customisation, and software updates. Moreover, they offer an IPX4 water-resistance rating that should provide protection against sweat and light splashes. When it comes to the battery performance, the Bose Ultra Open Earbuds should provide up to seven hours of battery life on a single charge while a full recharge should take approximately one hour. Specifications Detail Fit type Open-ear Noise cancelling No Microphone Built-in Wireless Bluetooth (A2DP, HFP, AAC, SBC, BLE) Multipoint Yes; 2 devices simultaneously Charging interface USB-C Earbud size 0.73"x0.67" x 1.07" (0.014lb) Case size 1.65"x2.56" x 1.04" (0.097 lb) Materials PC-ABS plastic, metal, silicone, gold plating App support Bose app; adjustable EQ, SimpleSync Audio tech OpenAudio, immersive/spatialized sound Bose Ultra Open Earbuds: $199 (Amazon US) - 33% off Good to know This Amazon deal is U.S. specific, and not available in other regions unless specified. We only use first-party seller links (at the time of article publishing); ensure that you purchase from a first-party seller link only. Check out Today's Deals on Amazon | or our recent tech deals. Become a Prime member (for Students or SNAP) via Neowin Get Prime Access - Prime for half price (for qualifying Medicaid, EBT, SNAP) Subscribe to Prime Video, Audible Plus, Music Unlimited or Kindle Unlimited via Neowin As an Amazon Associate, we earn from qualifying purchases.
    • After enabling it in about:config, customize, density, compact; the toolbar/address bar gets smaller vertically. I enabled Nova, I notice the tab bar/title bar is a bit larger vertically now? Everything always becomes a waste of space.
    • Microsoft's Copilot Cowork now generally available with usage-based billing by Pradeep Viswanathan Back in March, Microsoft first revealed Copilot Cowork, a new agentic AI experience in Microsoft 365 Copilot through which users can assign tasks to AI to complete in the background. After testing the service with a limited set of customers in Research Preview for a few weeks, Microsoft announced the general availability of Copilot Cowork to customers in the Frontier program on March 30. Today, Microsoft announced the general availability of Copilot Cowork worldwide for Microsoft 365 Copilot customers. The company also highlighted that Cowork became the fastest-growing feature in the history of its Frontier program. Unlike regular Copilot Chat, Copilot Cowork can run complex, long-running, multi-tool tasks from start to finish in the cloud by using organizational context through Work IQ. When compared to Claude Cowork, Microsoft claims that Copilot Cowork will be 30% to 40% cheaper on average with its Microsoft 365 connector. For now, Copilot Cowork runs on Anthropic models, including Opus 4.8 and Sonnet 4.6. However, Frontier customers can now use GPT-5.5. Microsoft also announced Cowork 1, a secure fine-tuned model coming in the next few weeks, which is designed to handle everyday Copilot tasks at a lower cost. To access Copilot Cowork, a Microsoft 365 Copilot user subscription is required. Usage is billed separately through Copilot Credits, based on model use, context retrieval, tool calls, and runtime. Pay-as-you-go pricing is set at $0.01 per Copilot Credit. To offer IT teams full control over usage costs, Microsoft provides spending limits, usage alerts, user-level controls, reporting, and prepaid usage plans for organizations. Usage-based billing begins today. However, Frontier customers who used Cowork between March 30 and June 16 will not be billed until July 1, 2026. The Microsoft 365 Copilot app now includes a toggle to enter the full Cowork experience. Microsoft is also adding partner plugins, with Enosix, Harvey, LSEG, Miro, monday.com, Moody’s, Morningstar, S&P Global Energy, and TeamsMaestro available now. Adobe, Atlassian, Box, Canva, Databricks, and others are coming soon.
  • Recent Achievements

    • One Year In
      Console General earned a badge
      One Year In
    • One Year In
      Twozo Technologies earned a badge
      One Year In
    • One Month Later
      Twozo Technologies earned a badge
      One Month Later
    • Week One Done
      Twozo Technologies earned a badge
      Week One Done
    • Veteran
      branfont went up a rank
      Veteran
  • Popular Contributors

    1. 1
      +primortal
      511
    2. 2
      +Edouard
      190
    3. 3
      PsYcHoKiLLa
      109
    4. 4
      Steven P.
      89
    5. 5
      Nick H.
      71
  • Tell a friend

    Love Neowin? Tell a friend!