Category: Mcafee/Trellix

Mcafee DLP, Microsoft September 2015 update disables Mcafee-DLP

5 Microsoft Patches take out Mcafee DLP copy handler function. Device control (USB) black is not affected. Environment McAfee Data Loss Prevention Endpoint (DLP Endpoint) software earlier than 9.3.425 (DLP Endpoint 9.3 Patch 4 HF25) Microsoft Windows 7 64-bit (32-bit is not affected.) Problem Several applications fail to start after you install Microsoft Patch MS15-038 or […]

Mcafee EPO prevent exe RUNNING FROM %appdata%

Mcafee EPO prevent exe RUNNING FROM %appdata% folders with an Access protection Policy How to protect from most 0day Flash Exploits and malware like Ransom Cryptowall in summer 2015. You simply can’t keep up with patching even with deployment or Management solutions in place. Now you should have an IPS Filter like Fortigate with Fortiguard. […]

Mcafee GETSUSP (Stinger V2) free Virus Scan / HIPS

http://www.mcafee.com/us/downloads/free-tools/getsusp.aspx http://www.mcafee.com/us/downloads/free-tools/index.aspx http://www.mcafee.com/uk/downloads/free-tools/how-to-use-getsusp.aspx Bei Virenbefall würde ich auf einzelnen Clients ab sofort das Tool mcafee GETSUSP laufen lassen. Dies zusätzlich zum VSE. GETSUSP Macht Scan auf GTI-basis (Cloud DB von Mcafee Online) (Manuell kann man auch Binaries uploaden um diese zu analysieren) Aktiviert (Nicht installiert) eine HIPS (IPS) Firewall welche den Netzwerk traffic überwacht wenn […]

Mcafee DLP 9.3 missing option Removable Storage Protection in Agent Configuration

Mcafee DLP 9.3 missing option Removable Storage Protection in Agent Configuration.   Problem: You are unable to choose “Removable Storage Protection” as 4th option in Agent Configuration on the new DLP9.3 Migration from: Existing EPO 4.6 and 9.1 Under Agent Configuration i can choose “Removable Storage Protection” as 4th option NEW EPO 5.11 and 9.3.400.23 […]

Exchange: Anti Virus Software on Exchange 2010/2013 Servers – Mcafee

File and Process Exclusion for Anti Virus Software for Exchange 2010 / 2013 http://technet.microsoft.com/en-us/library/bb332342(v=exchg.150).aspx Cdb.exe Microsoft.Exchange.Pop3service.exe MSExchangeRepl.exe Cidaemon.exe,Microsoft.Exchange.ProtectedServiceHost.exe MSExchangeSubmission.exe Clussvc.exe, Microsoft.Exchange.RPCClientAccess.Service.exe MSExchangeTransport.exe Dsamain.exe Microsoft.Exchange.Search.Service.exe MSExchangeTransportLogSearch.exe EdgeCredentialSvc.exe Microsoft.Exchange.Servicehost.exe MSExchangeThrottling.exe EdgeTransport.exe Microsoft.Exchange.Store.Service.exe Msftefd.exe ExFBA.exe Microsoft.Exchange.Store.Worker.exe Msftesql.exe hostcontrollerservice.exe Microsoft.Exchange.TransportSyncManagerSvc.exe OleConverter.exe Inetinfo.exe Microsoft.Exchange.UM.CallRouter.exe Powershell.exe Microsoft.Exchange.AntispamUpdateSvc.exe MSExchangeDagMgmt.exe ScanEngineTest.exe Microsoft.Exchange.ContentFilter.Wrapper.exe MSExchangeDelivery.exe ScanningProcess.exe Microsoft.Exchange.Diagnostics.Service.exe MSExchangeFrontendTransport.exe TranscodingService.exe Microsoft.Exchange.Directory.TopologyService.exe MSExchangeHMHost.exe UmService.exe Microsoft.Exchange.EdgeSyncSvc.exe MSExchangeHMWorker.exe UmWorkerProcess.exe […]

Behebung Fehler Mcafee VSE 8.8 SP2 TRUST beim Scannen und Event 516 crypt32.dll

Dieses Dokument beschreibt wie man Mcafee Event516 oder Untrusted Fehlermeldung beheben kann. Fehlermeldung: scan32.exe – Ungültiges Bildscan64.exe – Ungueltiges Bild Versionen:   * Client Windows 7 64BIT SP1, German Language * Mcafee VSE 8.8 P2 with HF Post SP2 (8.8.0.975 BUILD 14.08.2012) * DAT 7180.0000 * Framework 4.8.0.887 * EPO 4.6   Der Fehler tritt […]

Massive Spam Reply wave in Switzerland 08.08.2013 – Federal E-Mail domain admin.ch involved

Subject Range: RE: [#SMV-xxxxxxxxxxxxxxxxxxxx]: Transfer – Ueberweisung   Since today 08.08.2013 starting around 17:10 O’clock CET we see a large amount of “Reply – Delete me also” spam running through all kind devices and also large enterprise Spam filters. We even have a reply from Swiss federal E-Mail domain @admin.ch which hosts all or most […]

W32/Autorun.worm.aaeb-h

Subject: *URGENT* McAfee SNS ALERT: *UPDATE* Reports of W32/autorun.worm.aaeb-h infections   **Update to original message: Stinger tool now available. See Mitigation section below** McAfee has received multiple reports of customers who are severely affected by variants of W32/autorun.worm.aaeb-h. ImpactW32/Autorun.worm.aaeb-h has the ability to infect removable media devices and mounted network shares. It can also copy itself […]

MCAFEE: Hotfix VSE88HF793640 per EPO verteilen

www.butsch.ch Diese Anleitung beschreibt wie man einen HOTFIX auf einem MCAFEE EPO Server 4.5/4.6 integriert und alle Systeme oder eine bestimmte Gruppe verteilt. Als Beispiel den Patch/Hotfix vom 21.08.2012 für Mcafee VSE 8.8. https://kc.mcafee.com/corporate/index?page=content&id=KB76004 DAT 6807/6808 Causing Issues with VSE 8.8.x   Inhalt Hotfix Paket einchecken    1 Distribute/Update an alle Endpoints im Netz    2 Distribute/Update PRO Untergruppe […]

Windows XP Sp3, Event 516, mfehdik, SLL-API, memory Leak, crypt32.dll

Windows XP Sp3, Event 516, mfehdik, SLL-API, memory Leak, crypt32.dll Memory leak in MFEVTPS.EXE Recent Microsoft security updates for Windows XP SP3 and Server 2003R2 introduce a memory leak for the VirusScan Enterprise process MFEVTPS.EXE. The leak is actually from a Windows binary, Crypt32.dll, that MFEVTPS.EXE utilizes. A fix for this issue is available from Microsoft. […]