McAfee update: File SK_det.mcs is corrupt

C

Cautious Nerd

While updating McAfee definitions, I got this message:

File SK_det.mcs is corrupt.
Downloading complete file again.

I don't normally expect files to be corrupt in Win2K/SP4/NTFS,
especially with proper shutdown (or mostly, hibernation).
Of course, I let it download again and am rescanning. I wonder
if it is overly paranoid to suspect that it resulted from malware?
I realize that anything is possible, but I'm wondering about
likelihood. Any thoughts?

Cautious Nerd
 
R

Robert Moir

Cautious said:
While updating McAfee definitions, I got this message:

File SK_det.mcs is corrupt.
Downloading complete file again.

I don't normally expect files to be corrupt in Win2K/SP4/NTFS,
especially with proper shutdown (or mostly, hibernation).
Of course, I let it download again and am rescanning. I wonder
if it is overly paranoid to suspect that it resulted from malware?
I realize that anything is possible, but I'm wondering about
likelihood. Any thoughts?

This is more properly a question for McAfee tech support, but if it reports
corrupt files in the context of a download, I would suggest it could be
saying that the downloaded file is what is corrupt.
 
D

David H. Lipman

From: "Cautious Nerd" <[email protected]>

| While updating McAfee definitions, I got this message:
|
| File SK_det.mcs is corrupt.
| Downloading complete file again.
|
| I don't normally expect files to be corrupt in Win2K/SP4/NTFS,
| especially with proper shutdown (or mostly, hibernation).
| Of course, I let it download again and am rescanning. I wonder
| if it is overly paranoid to suspect that it resulted from malware?
| I realize that anything is possible, but I'm wondering about
| likelihood. Any thoughts?
|
| Cautious Nerd

I suggest posting this query on the McAfee support board.

http://forums.mcafeehelp.com/index.php
 
P

Peacekeeper

I will ask to save you the trouble of posting it
To date in many years using mcafee havent seen this error.

can you confirm what dat filr you were downloading and what version of
mcafee virusscan?
peace
 
N

Norman L. DeForest

While updating McAfee definitions, I got this message:

File SK_det.mcs is corrupt.
Downloading complete file again.

I don't normally expect files to be corrupt in Win2K/SP4/NTFS,
especially with proper shutdown (or mostly, hibernation).
Of course, I let it download again and am rescanning. I wonder
if it is overly paranoid to suspect that it resulted from malware?
I realize that anything is possible, but I'm wondering about
likelihood. Any thoughts?

Right-click on the file, select "Properties" and note the *exact*
file size in bytes. Then bring up the Windows calculator, select
Scientific, enter the number as a decimal number and convert it to
hexadecimal. See if the last three digits are all zero.

If they are, you may have run afoul of a Windows bug that truncates
downloads to the next lowest multiple of the download buffer size.

Fetching the EditPad Pro Demo from the distributor's website,
http://download.jgsoft.com/editpad/SetupEditPadProDemo.exe
I tried Internet Explorer, PC-Lynx, two versions of links, and three
versions of Firefox. I also tried Lynx on a Unix machine and wget and
GetBot on the Windows machine.

IE, PC-LYNX, and all versions of Firefox truncated the file at a multiple
of 2000 hexadecimal. An earlier version of links corrupted the file by
changing all linefeeds to carriage-return/linefeed pairs even though
binary download was selected. A later version of links, wget, GetBot and
the version of Lynx on the Unix machine all downloaded the file with no
corruption or truncation.

A detailed record of my results (files numbered after download so
I could keep them separate and keep track of them; if you try
downloading the same file your file sizes may differ if a newer
build is now available):

SETUPEDI EXE 1,942,590 08-16-04 1:57p SETUPEDI.EXE
Fetched with lynx on CCN[1] and downloaded via ZModem

SETUPE~2 EXE 1,941,504 08-16-04 11:47a SetupEditPadProDemo2.exe
Downloaded with Firefox 0.8

SETUPE~3 EXE 1,942,590 08-09-04 5:52a SetupEditPadProDemo3.exe
Downloaded with wget

SETUPE~4 EXE 1,941,504 08-16-04 12:27p SetupEditPadProDemo4.exe
Downloaded with Firefox 0.8 again

SETUPE~5 EXE 1,941,504 08-16-04 1:16p SetupEditPadProDemo5.exe
Downloaded with Firefox 0.9.3

SETUPE~6 EXE 1,941,504 08-18-04 2:44a SetupEditPadProDemo6.exe
Downloaded with Firefox 0.8 once again

SETUPE~7 EXE 1,941,504 08-18-04 3:03a SetupEditPadProDemo7.exe
Downloaded with Firefox 0.9.3 again

SETUPE~8 EXE 1,942,590 08-09-04 5:52a SetupEditPadProDemo8.exe
Downloaded with wget again

SETUPE~9 EXE 1,941,504 08-18-04 6:00a SetupEditPadProDemo9.exe
Downloaded with Internet Explorer

SETUPE~1 EXE 1,941,504 08-18-04 6:27a SetupEditPadProDemo10.exe
Downloaded with PC-LYNX

SETUP~10 EXE 1,942,590 08-18-04 7:02a SetupEditPadProDemo11.exe
Downloaded with GetBot

SETUP~11 EXE 1,949,953 08-18-04 7:36a SetupEditPadProDemo12.exe
Downloaded with links [sic] 0.83 (has different icon)

SETUP~12 EXE 1,942,590 08-18-04 7:59a SetupEditPadProDemo13.exe
Downloaded with links [sic] 0.98

SETUPE14 EXE 1,942,590 08-18-04 11:55p SETUPE14.EXE
Fetched with lynx on CCN[1] and downloaded via ZModem, again

SETUP~13 EXE 1,949,953 08-18-04 10:21p SetupEditPadProDemo15.exe
Downloaded with links [sic] 0.83 (has different icon), again

SETUP~14 EXE 1,942,590 08-09-04 5:52a SetupEditPadProDemo16.exe
Downloaded with wget with user-agent string set to same one
as used by links 0.83 -- at same time as download below.

SETUP~15 EXE 1,949,953 08-19-04 4:24a SetupEditPadProDemo17.exe
Downloaded with links [sic] 0.83 (has different icon), again,
this time with wget simultaneously fetching the same file
with the same user-agent string from the same IP address
(see above)

1,942,590 decimal is hexadecimal 1DA43E (the correct file size)
1,941,504 decimal is hexadecimal 1DA000 (file truncated)
1,949,953 decimal is hexadecimal 1DC101 (file corrupted by invalid
end-of-line conversion)

Footnote(s):
[1] CCN: The Chebucto Community Net, which offers PPP accounts and
dial-up text-only accounts with lynx 2.7ac as the "shell". A
download through the text account first downloads the file to the
local server then lynx offers the user the options of (a) saving
it to the user's account filespace, (b) downloading with Kermit,
or (c) downloading with ZModem. I chose the latter. Filename
truncated to DOS 8.3 name since I use a DOS-based terminal program.

I'm not sure what the solution is unless you can fetch the upgrades with
wget.
 
C

Cautious Nerd

Peacekeeper said:
I will ask to save you the trouble of posting it
To date in many years using mcafee havent seen this error.

can you confirm what dat filr you were downloading and what version of
mcafee virusscan?
peace

Thanks, Peacekeeper. I had it on my to-do until I could get some air.
The problem has actually not repeated itself.
In any case, the McAfee info is VirusScan Enterprise 7.0.0,
Virus Definitions: 4456; Scan Engine: 4.4.00.
Platform: Win2K/SP4..
I can't seem to find a log file for updates. Is there something
else I can do to answer the question of what dat file was downloading
when the error occurred?

C. Nerd
 
C

Cautious Nerd

Norman L. DeForest said:
Right-click on the file, select "Properties" and note the *exact*
file size in bytes. Then bring up the Windows calculator, select
Scientific, enter the number as a decimal number and convert it to
hexadecimal. See if the last three digits are all zero.

If they are, you may have run afoul of a Windows bug that truncates
downloads to the next lowest multiple of the download buffer size.

Hi, Norman,

The last 2 hex digits are not zero. I suspect that this is not the problem,
because it hasn't repeated itself. But thanks for pointing it out as a
possible cause.

C. Nerd


Fetching the EditPad Pro Demo from the distributor's website,
http://download.jgsoft.com/editpad/SetupEditPadProDemo.exe
I tried Internet Explorer, PC-Lynx, two versions of links, and three
versions of Firefox. I also tried Lynx on a Unix machine and wget and
GetBot on the Windows machine.

IE, PC-LYNX, and all versions of Firefox truncated the file at a multiple
of 2000 hexadecimal. An earlier version of links corrupted the file by
changing all linefeeds to carriage-return/linefeed pairs even though
binary download was selected. A later version of links, wget, GetBot and
the version of Lynx on the Unix machine all downloaded the file with no
corruption or truncation.

A detailed record of my results (files numbered after download so
I could keep them separate and keep track of them; if you try
downloading the same file your file sizes may differ if a newer
build is now available):

SETUPEDI EXE 1,942,590 08-16-04 1:57p SETUPEDI.EXE
Fetched with lynx on CCN[1] and downloaded via ZModem

SETUPE~2 EXE 1,941,504 08-16-04 11:47a SetupEditPadProDemo2.exe
Downloaded with Firefox 0.8

SETUPE~3 EXE 1,942,590 08-09-04 5:52a SetupEditPadProDemo3.exe
Downloaded with wget

SETUPE~4 EXE 1,941,504 08-16-04 12:27p SetupEditPadProDemo4.exe
Downloaded with Firefox 0.8 again

SETUPE~5 EXE 1,941,504 08-16-04 1:16p SetupEditPadProDemo5.exe
Downloaded with Firefox 0.9.3

SETUPE~6 EXE 1,941,504 08-18-04 2:44a SetupEditPadProDemo6.exe
Downloaded with Firefox 0.8 once again

SETUPE~7 EXE 1,941,504 08-18-04 3:03a SetupEditPadProDemo7.exe
Downloaded with Firefox 0.9.3 again

SETUPE~8 EXE 1,942,590 08-09-04 5:52a SetupEditPadProDemo8.exe
Downloaded with wget again

SETUPE~9 EXE 1,941,504 08-18-04 6:00a SetupEditPadProDemo9.exe
Downloaded with Internet Explorer

SETUPE~1 EXE 1,941,504 08-18-04 6:27a SetupEditPadProDemo10.exe
Downloaded with PC-LYNX

SETUP~10 EXE 1,942,590 08-18-04 7:02a SetupEditPadProDemo11.exe
Downloaded with GetBot

SETUP~11 EXE 1,949,953 08-18-04 7:36a SetupEditPadProDemo12.exe
Downloaded with links [sic] 0.83 (has different icon)

SETUP~12 EXE 1,942,590 08-18-04 7:59a SetupEditPadProDemo13.exe
Downloaded with links [sic] 0.98

SETUPE14 EXE 1,942,590 08-18-04 11:55p SETUPE14.EXE
Fetched with lynx on CCN[1] and downloaded via ZModem, again

SETUP~13 EXE 1,949,953 08-18-04 10:21p SetupEditPadProDemo15.exe
Downloaded with links [sic] 0.83 (has different icon), again

SETUP~14 EXE 1,942,590 08-09-04 5:52a SetupEditPadProDemo16.exe
Downloaded with wget with user-agent string set to same one
as used by links 0.83 -- at same time as download below.

SETUP~15 EXE 1,949,953 08-19-04 4:24a SetupEditPadProDemo17.exe
Downloaded with links [sic] 0.83 (has different icon), again,
this time with wget simultaneously fetching the same file
with the same user-agent string from the same IP address
(see above)

1,942,590 decimal is hexadecimal 1DA43E (the correct file size)
1,941,504 decimal is hexadecimal 1DA000 (file truncated)
1,949,953 decimal is hexadecimal 1DC101 (file corrupted by invalid
end-of-line conversion)

Footnote(s):
[1] CCN: The Chebucto Community Net, which offers PPP accounts and
dial-up text-only accounts with lynx 2.7ac as the "shell". A
download through the text account first downloads the file to the
local server then lynx offers the user the options of (a) saving
it to the user's account filespace, (b) downloading with Kermit,
or (c) downloading with ZModem. I chose the latter. Filename
truncated to DOS 8.3 name since I use a DOS-based terminal program.

I'm not sure what the solution is unless you can fetch the upgrades with
wget.

--
">> consider moving away from Front Page...."
">To what? Any suggestions?"
"Naked bungee-jumping. It's less humiliating <g>"
-- Matt Probert in alt.www.webmaster, March 20, 2005
 
P

Peacekeeper

Dave that will do probably a once once glitch, will ask. Will post back only
if i have anything interesting to comment on..
 
C

Cautious Nerd

David H. Lipman said:
I suggest posting this query on the McAfee support board.
http://forums.mcafeehelp.com/index.php
I will ask to save you the trouble of posting it
To date in many years using mcafee havent seen this error.
can you confirm what dat filr you were downloading and what version of
mcafee virusscan?

Cautious said:
McAfee info is VirusScan Enterprise 7.0.0,
Virus Definitions: 4456; Scan Engine: 4.4.00.
Platform: Win2K/SP4..

The problem happened again. I found the log file for updating
virus definitions. Here is the content:

3/30/2005 10:06:18pm HOST\user Starting VirusScan task: AutoUpdate
3/30/2005 10:06:20pm HOST\user Checking update packages from repository NAIHttp.
3/30/2005 10:06:29pm HOST\user Initializing update ...
3/30/2005 10:06:29pm HOST\user Downloading catalog.z.
3/30/2005 10:06:30pm HOST\user Verifying catalog.z.
3/30/2005 10:06:30pm HOST\user Extracting catalog.z.
3/30/2005 10:06:31pm HOST\user Loading update configuration from: Catalog.xml
3/30/2005 10:06:32pm HOST\user Searching available updates for Engine.
3/30/2005 10:06:34pm HOST\user Product(s) running latest Engine.
3/30/2005 10:06:39pm HOST\user File SK_det.mcs is corrupt. Downloading complete file again.
^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^
3/30/2005 10:06:44pm HOST\user Searching available updates for DATs.
3/30/2005 10:06:45pm HOST\user Downloading PkgCatalog.z.
3/30/2005 10:06:46pm HOST\user Verifying PkgCatalog.z.
3/30/2005 10:06:46pm HOST\user Extracting PkgCatalog.z.
3/30/2005 10:06:46pm HOST\user Loading update configuration from: PkgCatalog.xml
3/30/2005 10:06:56pm HOST\user Starting DAT update.
3/30/2005 10:06:56pm HOST\user Pre-notifying for DAT update.
3/30/2005 10:06:59pm HOST\user Downloading DAT.
3/30/2005 10:06:59pm HOST\user Downloading delta.ini.
3/30/2005 10:07:00pm HOST\user Downloading 44564457.upd.
3/30/2005 10:07:35pm HOST\user Downloading 44574458.upd.
3/30/2005 10:08:30pm HOST\user Backing up file(s) SCAN.DAT, NAMES.DAT, CLEAN.DAT
3/30/2005 10:08:31pm HOST\user Copying SCAN.DAT, NAMES.DAT, CLEAN.DAT.
3/30/2005 10:08:33pm HOST\user Post-notifying for DAT update.
3/30/2005 10:08:41pm HOST\user Update succeeded to version 4.0.4458.
3/30/2005 10:08:45pm HOST\user Update Finished
3/30/2005 10:09:16pm HOST\user Closing update session.

I couldn't find a posting from you at the McAfee forums about this.
I started a new thread.

C. Nerd.
 
C

Cautious Nerd

David H. Lipman said:
I suggest posting this query on the McAfee support board.
http://forums.mcafeehelp.com/index.php
I will ask to save you the trouble of posting it
To date in many years using mcafee havent seen this error.
can you confirm what dat filr you were downloading and what version of
mcafee virusscan?

Cautious said:
McAfee info is VirusScan Enterprise 7.0.0,
Virus Definitions: 4456; Scan Engine: 4.4.00.
Platform: Win2K/SP4..

The problem happened again. I found the log file for updating
virus definitions. Here is the content:

3/30/2005 10:06:18pm HOST\user Starting VirusScan task: AutoUpdate
3/30/2005 10:06:20pm HOST\user Checking update packages from repository NAIHttp.
3/30/2005 10:06:29pm HOST\user Initializing update ...
3/30/2005 10:06:29pm HOST\user Downloading catalog.z.
3/30/2005 10:06:30pm HOST\user Verifying catalog.z.
3/30/2005 10:06:30pm HOST\user Extracting catalog.z.
3/30/2005 10:06:31pm HOST\user Loading update configuration from: Catalog.xml
3/30/2005 10:06:32pm HOST\user Searching available updates for Engine.
3/30/2005 10:06:34pm HOST\user Product(s) running latest Engine.
3/30/2005 10:06:39pm HOST\user File SK_det.mcs is corrupt. Downloading complete file again.
^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^
3/30/2005 10:06:44pm HOST\user Searching available updates for DATs.
3/30/2005 10:06:45pm HOST\user Downloading PkgCatalog.z.
3/30/2005 10:06:46pm HOST\user Verifying PkgCatalog.z.
3/30/2005 10:06:46pm HOST\user Extracting PkgCatalog.z.
3/30/2005 10:06:46pm HOST\user Loading update configuration from: PkgCatalog.xml
3/30/2005 10:06:56pm HOST\user Starting DAT update.
3/30/2005 10:06:56pm HOST\user Pre-notifying for DAT update.
3/30/2005 10:06:59pm HOST\user Downloading DAT.
3/30/2005 10:06:59pm HOST\user Downloading delta.ini.
3/30/2005 10:07:00pm HOST\user Downloading 44564457.upd.
3/30/2005 10:07:35pm HOST\user Downloading 44574458.upd.
3/30/2005 10:08:30pm HOST\user Backing up file(s) SCAN.DAT, NAMES.DAT, CLEAN.DAT
3/30/2005 10:08:31pm HOST\user Copying SCAN.DAT, NAMES.DAT, CLEAN.DAT.
3/30/2005 10:08:33pm HOST\user Post-notifying for DAT update.
3/30/2005 10:08:41pm HOST\user Update succeeded to version 4.0.4458.
3/30/2005 10:08:45pm HOST\user Update Finished
3/30/2005 10:09:16pm HOST\user Closing update session.

I couldn't find a posting from you at the McAfee forums about this.
I started a new thread.

C. Nerd
 
D

David H. Lipman

From: "Cautious Nerd" <[email protected]>

|
| I couldn't find a posting from you at the McAfee forums about this.
| I started a new thread.
|
| C. Nerd

No, YOU needed to make the post, not me.

Please keep this thread updated however.
 
C

Cautious Nerd

David H. Lipman said:
From: "Cautious Nerd" <[email protected]>


|
| I couldn't find a posting from you at the McAfee forums about this.
| I started a new thread.

No, YOU needed to make the post, not me.
Please keep this thread updated however.

David,

I included in my post the reply by Peacekeeper saying that he would
post to the McAfee forum. That's what I was referring to. His
headers show that he restricted his reply to alt.comp.anti-virus. However,
this thread seems to be no longer present in that NG, at least in one
alternate newserver that I checked.

C. Nerd
 
D

David H. Lipman

From: "Cautious Nerd" <[email protected]>


|
| David,
|
| I included in my post the reply by Peacekeeper saying that he would
| post to the McAfee forum. That's what I was referring to. His
| headers show that he restricted his reply to alt.comp.anti-virus. However,
| this thread seems to be no longer present in that NG, at least in one
| alternate newserver that I checked.
|
| C. Nerd

It is in alt.comp.anti-virus It's a News Server problem !

I see the thread in; m.p.s.v, a.c.v and a.c.a-v and all are on my Verizon News server.
 
D

David H. Lipman

From: "David H. Lipman" <[email protected]>


|
| It is in alt.comp.anti-virus It's a News Server problem !
|
| I see the thread in; m.p.s.v, a.c.v and a.c.a-v and all are on my Verizon News server.
|
|

Let me modify the above statement. I access m.p.s.v via the MS News Server, not Verizon
even though Verizon carries it..
 
C

Cautious Nerd

David H. Lipman said:
From: "David H. Lipman" <[email protected]>
|| It is in alt.comp.anti-virus It's a News Server problem !
| I see the thread in; m.p.s.v, a.c.v and a.c.a-v and all are on my Verizon News server.
Let me modify the above statement. I access m.p.s.v via the MS News Server, not Verizon
even though Verizon carries it..

I was hoping that it was just a newserver problem, but wasn't sure.
Strange that the newserver problem only afflicts one NG. But hey, I
don't pretend to understand the policies with which the newserver is
administered.

C. Nerd
 
P

Peacekeeper

| David,
|
| I included in my post the reply by Peacekeeper saying that he would
| post to the McAfee forum. That's what I was referring to. His
| headers show that he restricted his reply to alt.comp.anti-virus.
However,
| this thread seems to be no longer present in that NG, at least in one
| alternate newserver that I checked.
|

Cautious ....by my post i meant I will ask or Tech our our private forum if
he has seen this occur. the forum is not accessable to mear mortals:)

Our Tech is off training other mcafee staff so will not read the post I made
till Friday US time...

Sorry for the confusion...
Peace
 
C

Cautious Nerd

Peacekeeper said:
Cautious ....by my post i meant I will ask or Tech our our private forum if
he has seen this occur. the forum is not accessable to mear mortals:)

Our Tech is off training other mcafee staff so will not read the post I made
till Friday US time...

Thanks for clarifying, Peacekeeper. And appreciate the inside inquiry.

C. Nerd
 
P

Peacekeeper

Cautious Nerd said:
Thanks for clarifying, Peacekeeper. And appreciate the inside inquiry.

C. Nerd
Gees I need to watch what I type too many errors.

Re our tech sorry monday is the earliest he will return.
 

Ask a Question

Want to reply to this thread or ask your own question?

You'll need to choose a username for the site, which only take a couple of moments. After that, you can post your question and our members will help you out.

Ask a Question

Top