1MethodofProcedureRevisionCUsingtheMcAfeeRemovalToolContentsConfidentialityNoticeIntroductionProcedureTroubleshootingMassdeployments2ConfidentialityNoticeThisdocumentanditscontentsareconfidentialandproprietarytoMcAfee,Inc.
andareintendedonlyfortheindividualorentityspecifiedhereinorotherwiseidentifiedbyMcAfee.
Unauthorizeduse,reproduction,ordistributionofthisdocumentoranyofitscontentsmayresultinlegalandfinancialpenalties.
3IntroductionTheMcAfeeRemoval(MFERemoval100.
exe)toolallowsyoutoremoveePOproductsfromcomputersinyournetwork.
WarningsandliabilityTheMFERemoval100.
exetoolisprovidedasabesteffortbyMcAfeesupport.
Thissoftware:HasnotbeentestedorapprovedbyMcAfee.
Shouldbetestedinyourlocalenvironmentbeforeyouattempttodeployittoyourusers.
Expiresandceasestofunctionafterthedateindicated.
Tofindtheexpirationdate:1.
Extractthestandaloneexecutable.
2.
Right-clicktheexecutablefileandclickProperties|General|Description.
SystemrequirementsThefollowingbasicrequirementsarerequiredoneachmachine:Windows5.
x-10.
xX86orx64AdministrativepermissionsNOTE:Ifrunningsyscore15.
7orhigher,youcanonlyremoveallproducts.
Itwillonlyrunwiththeproductswitch/all.
IfyourunningtheapplicationmanuallywithUACenabled,elevationisalsorequired.
Formoreinformation:http://msdn.
microsoft.
com/en-us/library/windows/desktop/aa511445.
aspxOtherdependencies:VerisignClass3PublicPrimaryCertificationAuthority–G5https://kc.
mcafee.
com/corporate/indexpage=content&id=KB870964ProcedureYoucanruntheMFERemoval100.
exetoolonyourlocalmachinebyrunningitfromthecommandline.
TaskRunMFERemoval100.
exeatthecommandlinewiththeappropriateswitches.
Switchesarenotcasesensitive.
/norebootWillnotcallreboot,overwrites/tand/forcereboot/forcerebootWillcallrebootuponcompletion/txxTimeinminutestodelayifrebootisneededor/forcerebootisused.
Defaultis10minutes.
Forexample,/t10/passHIPsclientUIpassword.
DoesnotworkwithHIPs7.
Forexample,/passabcde12345/qor/quietPreventsstatusmessageboxes.
IfdeployedfromePO,thisisautomaticallyset.
Whenspecified,theprocessexitswhenitcompletessuccessfully.
/customprops[1-4]Onlyonecustompropcanbeused.
Ifmorethanoneisprovided,thelastinthelistwillbetheoneused.
Onlynumbers1-4areallowed.
NospacesareallowedintheprovidedcustompropIf/custompropsissetandMcAfeeAgentisnotbeingremoved,thetoolwillattempttosetcustompropsthatcanbeusedlaterinePO.
Examples:1.
/customprops1AllDone2.
/customprops2mycustomprop3.
/customprops3VSEremoved4.
/customprops4MFERemovalRanOnProductswitches:/MA–McAfeeAgent/DLP–HostDataLossPrevention/HIP–HostIntrusionPrevention/VSE–VirusScanEnterprise/ENS–EndpointSecurity/DXL–McAfeeDataExchangeLayer/EIA–EndpointIntelligenceAgent/TIEM–McAfeeThreatIntelligenceExchangeModuleforVSE/MAR–McAfeeActiveResponse(RebootRequired)Oneormorearerequired.
5/MCP-McAfeeClientProxy/PA-McAfeePolicyAuditorAgent/DATRep–DATReputation/All–AllproductsForexample:Scenario1:Removeallproductsandrebootafter5minutesMFERemoval100.
exe/all/forceboot/t5Scenario2:RemoveVSEandHIP.
IncludetheHIPpassword.
MFERemoval100.
exe/vse/hip/passabcde12345orMFERemoval100.
exe/vse/hip/pass"abc123"Rebootyourcomputer.
Arebootisstronglyrecommendedifyouhaveremovedproductswiththeintentionofreinstallingthem.
RemovingHDLPandMARrequiresareboot.
Removingindividualproductsdoesnotrequireareboot.
Removingallproductsrequiresarebootifyouwanttoreinstallthemlater.
RequiredrebootOccurswhenremovingHDLPusingforceoptionorfiles/registrykeycouldnotberemoved.
MFERemovalperformscleanup.
Normalmode–Rebootoptionappearsinstatusbox.
Quietmode–MFERemoval100callsshutdown.
exewithatimespecified/t(defaultof10minutes).
Validtimefor/tare0-99.
/norebootcanbeusedtopreventanautomaticreboot.
RecommendedrebootOccurswhenservice/driverispendingareboot.
Normalmode–Rebootoptionappearsinstatusbox.
Quietmode–Noaction.
Note:/forcerebootand/norebootcommandlineswitcheswillbeoverwrittenbystatusboxpromptswhenrunlocally.
6TroubleshootingUsethestatusboxandlogfilestotroubleshooterrors.
SuccessanderrordeterminationWhentheapplicationcompletessuccessfully,adialogboxdisplayswiththefollowinginformation:TheresultsThepathtothelogfileRebootrecommendation(ifany)Also,theapplicationwritesagenericregistrykeythatcanbequeried.
Thekeyisdeletedatthestartofeachrun,andthenrewrittenwhentheprocessissuccessful.
Iftheregistrykeyismissing,youknowtherewasanerror.
LogsanddataTheMFERemoval100.
exetoolwritesdatatothefollowinglogs:Runtimelog–generatesto%SYSTEMROOT%\TEMP\McAfeelogs\Applet-YYYY.
MM.
DD–HH.
MM.
SS-[MFERemoval100.
exe].
txtEventlog–afterruntime,createsaWindowsApplicationEventLogentryfromsourceMFERemoval100.
exe.
EventIDs:o666–failureo777–successRegistrykeyTheregistrykeycanbefoundintheselocations,dependingonyourversionofWindows:X64HKEY_LOCAL_MACHINE\Software\Wow6432Node\MFERemovalX86HKEY_LOCAL_MACHINE\Software\MFERemovalRegistrykeyvalues:ValuenameFinishValuenameforeachproductremovedMAVSEHIPDLPENSDATRepTIEMDXLEIAMCPMARPAData17ActivityiconWhentheapplicationruns,theActivityicondisplaysintheWindowsNotificationArea.
ThisiconisawhiteIntellogoonabluebackground.
Thepurposeoftheiconistoindicatethattheapplicationisrunning.
FormoreinformationabouttheWindowsNotificationArea:http://msdn.
microsoft.
com/en-us/library/windows/desktop/aa511448.
aspxToviewtheWindowsNotificationArea:http://windows.
microsoft.
com/en-us/windows7/change-how-icons-appear-in-the-notification-areaReviewthelogfileWhentheprocesscompletessuccessfully,thelogreads:Exit:SuccessIfthismessageismissingfromthelog,youwillneedtocorrecttheerrororcontactyourIntelSecuritySupportrepresentative.
CommonerrorsYoucandiagnoseproblemsusingerrormessagesinthestatusboxorinthelogfile.
InvalidPassword.
Pleaseprovidepasswordasaswitch.
Example:MFERemoval.
exe/passabcde12345/passswitchwasprovidedanditwasincorrectIfthereisaspaceintheHIPpassword,usequotes:/pass"abcde12345"HIPSEnabled.
PleasedisableHIPsIPSandre-run.
OpenHIPclientUI,unlocktheGUI,anddisableIPS.
InePO,disableHostIPSviapolicyandpushdowntoclient.
Providepasswordviacommandlineswitch:/passabcde12345or/pass"abcde12345"VSEAPEnabled.
PleasedisableVSEAPandre-run.
OpenVSEConsoleanddisableAccessProtection.
InePO,disableVSEAPviapolicyandpushdowntoclient.
Failedtoinstallcertificate:4EB6D578499B1CCF5F581EAD56BE3D9B6744A5E5MFERemovaldependsonVerisignClass3PublicPrimaryCertificationAuthority–G5towork.
MFERemovalattemptedtoinstallacertificateandfailed.
Formoreinformation:https://kc.
mcafee.
com/corporate/indexpage=content&id=KB87096UnabletodisableprotectionMFERemovalwasunabletoestablishTrustwithMcAfeesoftware.
Otherreasons,includingfailedcertificateinstall.
ContactIntelSecuritysupport.
WorkaroundsTheseoptionsshouldonlybeusedasalastresort.
Youcanusethe/forceand/safemodeswitchestoremoveproductswhenyouencountererrors.
Alwaysusethe/allswitchwiththeseoptions.
Testtheseoptionsbeforeusingtheminamassdeployment/forceUse/forcetobypassallcheckandremoveallproducts.
McAfeerecommendsthisoption.
/force/all8Requiresareboot.
/safemodeUse/safemodetobootacomputerintosafemode,run,andthenrebootbackintonormalmode.
/safemode/allSafemodetroubleshootingDoesnotworkwithprebootauthentication.
RebootwouldleaveatPrebootscreentwice(oncetogointosafemodeandoncetobackintonormalmode)GPOcouldinterfereautologin–rebootwouldleaveatsafemodelog-inscreenhttps://technet.
microsoft.
com/en-us/magazine/ee872306.
aspxhttps://technet.
microsoft.
com/en-us/library/cc978776.
aspxGPOcouldaddbacklegalnoticecaption–wouldleaveatsafemodewaitingonaclickhttps://technet.
microsoft.
com/en-us/library/cc939712.
aspxDoesnotworkproperlyonDomainControllers.
Safemodeprocess1Createatempuserandaddittothelocaladmingroup.
2SettheOStobootintosafemode.
3Rebootafteroneminuteunless/tissettoanothertime.
4Bootintosafemode.
5RunMFERemoval100.
exe,deletetempuser,resetallsettings.
6Reboot.
7InNormalmode,deletetempuserprofile.
9ReinstallationofMcAfeeAgentIfMcAfeeAgentisoneoftheproductsthatisbeingremoved,thefollowingswitchescanbeusedtoreinstallMAaftertheremovaltooliscomplete.
Ifrebootiseitherrequiredorrecommended,theinstallofMAwillhappenontherestartofthesystem.
Note:ThetoolwillsetMAinstalltostart,itdoesnotguaranteethatitwillbesuccessful.
Alllogswillbeavailableinwindows\temp\mcafeelogs.
Useoneofthefollowingformatsandthetoolwillusethedefaultcommandlineof/install=agent/silenttoinstallframepkg.
exe.
Ifframepkg.
execannotbelocated,nothingwillhappen.
Refertothelogformoredetails.
/framepkgIfframepkg.
exeisinthesamedirectoryasthemferemovalbinary.
/framepkg="c:\pathtoframepkg.
exe"Iffilepathspecifiedisvalid.
Single(')ordouble(")quotescanbeusedaroundthepath.
YoucanspecifyacustompropforanewMAinstallation.
Onlyonecustompropcanbeused.
Ifmorethanoneisprovided,thelastinthelistwillbetheoneused.
Onlynumbers1-4areallowed.
Nospacesareallowedintheprovidedcustomprop.
Examples:1.
/customprops1AllDone2.
/customprops2mycustomprop3.
/customprops3MAcleaninstall4.
/customprops4MFERemovalRanOnIfotherframepkg.
execommandlineswitchesbeside/install=agent/silentandcustompropsareneeded,inadditiontothe/framepkgswitch,youcanyouadd:/framepkgcmd='thefullcommandlineparametersyouwouldliketopasstoframepkg'Note1:Singlequotes(')arerequiredatthestartandfinishofthiscommand.
Note2:Doesnotworkwith/custompropsswitch.
SeetheMcAfeeAgentProductGuideformoreinformationonframepkg.
exeinstallationquestions.
10MassdeploymentsYoucanupdatemorethanonecomputeratatime.
Toimplementamassdeploymentprocess,createacustomePOEndpointDeploymentKit(EEDK)packageanddeployitusingePO.
BeforeyoubeginEEDKpackagesarenotsupportedbyIntelSecuritysupport.
However,youcanvisittheMcAfeeCommunitysiteforinformationandsupport:https://community.
mcafee.
com/docs/DOC-3401ThecurrentversionofEEDKis9.
6.
1.
TaskCompletetheinitialsetup.
a.
Extractthezipfile.
b.
CreateanewfoldercalledBuild.
c.
RunEEDK.
exe.
d.
ClickTools|OptionandclickBrowse.
e.
SelectyourBuildfolderandclickSave.
CreatetheEEDKforMFERemoval100.
a.
SelectFile.
BrowsetoMFERemoval100.
exe.
b.
Specifythesoftwarepackageproperties.
11c.
ClickBuildPackage.
Astatusboxnotifiesyouwhenthenewzipiscreated.
ChecktheEEDKpackageintoePO.
a.
InePO,opentheMasterRepository.
b.
ClickCheckinPackage.
c.
Selectthepackagetype:ProductorUpdate(.
ZIP)d.
NexttoFilePath,clickBrowseandlocatetheEEDKpackage.
e.
ClickNext,choosethebranch,clickSave.
CreatetheclienttaskinePO.
a.
InePO,opentheClientTaskCatalog.
b.
SelectMcAfeeAgent.
c.
ClickNewTask.
d.
Selectthetasktype:ProductDeployment.
ClickOK.
e.
IntheTaskNamefield,enteraname.
f.
CompletetheoptionsforProductsandComponents.
Forexample,youcanaddaproductswitch:/vse.
ProductNameTypeaname.
Limitto8alphanumericcharacters.
ProductIDTypea4digitnumber.
ProductVersionTypetheversionnumber.
Use4digitsseparatedbyperiods.
ProductDescriptionEnterthedescriptionyouwanttoappearwhencreatingtheePOtask.
CommandtoRunEnterthenameoftheexecutablefile:MFERemoval100.
exe.
Note:IntelSecurityrecommendsusingcommandlineswitchesintheePOdeploymenttask.
AnyswitchthatyouuseisautomaticallyhardcodedandalwaysusedwhendeployedthroughePO.
Thismethodmakesiteasytoidentifytheproductsthatarebeingremovedbythetask.
ProductDetectionKeySpecifytheregistrylocationthatcontainstheProductDetectionKeyValue.
IntheEEDK,abbreviatethetop-levelkeylocations.
Forexample,HKEY_LOCAL_MACHINEisabbreviatedHKLM.
ProductDetectionKeyValueSpecifytheregistrykeyvalue.
Ifthiskeyvalueexistsonamachinethedeploymenttaskwillnotrun.
Thefieldcannotbeblank.
Scenario1:UsetheproductdetectionkeyMFERemovalandthenon-existentkeyvalueNew.
Because,thekeyvaluedoesnotexist,allcomputersareupdated.
Scenario2:UsetheproductdetectionkeyMFERemovalandthenon-existentkeyvalueFinish.
Because,thekeyvalueisalreadypresentoncomputersthathaveupdatedsuccessfully,onlycomputersthataremissingthekeyareupdated.
OSSupportSelectalloftheWindowsoperatingsystemsthatyousupport.
12Assignclienttasks.
CautionIncorrectlyassignedtaskscancausetheremovaltooltomakechangestoyourentirenetwork.
IfMcAfeeAgentisremoved,itmeansthatyourcomputersarenotprotectedbyePO.
IntelSecurityrecommendsassigningthetasktojustthenodesthatneedtoruntheremovalprocessorusingtag-basedclienttaskassignments.
CreateEEDKwithFramePkgYoucanalsocreatetheEEDKusingFramePkg.
exe.
Mostofthestepsarethesame.
UsingFramePkgallowsyoutoreinstallMcAfeeAgentaftersuccessfullyrunningamassdeployment.
BeforeyoubeginEachcustomerrequiresauniquecopyofframepkg.
exeYoumustuseoneofthefollowingMFERemoval100.
exeswitches:/MA,/ALL,or/SAFEMODETaskCompletetheinitialsetup.
a.
Createanewfolder.
b.
CopyMFERemoval100.
exeandFramepkg.
exetothenewfolder.
SetupEEDK.
a.
InEEDK,selectFolder.
b.
ClickBrowseandlocateyournewfolder.
c.
Specifythesoftwarepackageproperties.
ProductNameTypeaname.
Limitto8alphanumericcharacters.
ProductIDTypea4digitnumber.
ProductVersionTypetheversionnumber.
Use4digitsseparatedbyperiods.
ProductDescriptionEnterthedescriptionyouwanttoappearwhencreatingtheePOtask.
Forexample,MFERemovalwithMAinstall5.
03CommandtoRunEnterthenameoftheexecutablefile:MFERemoval100.
exe.
UsetheFramePkgswitches:/framepkg/framepkgcmd='cmdlineswitches'/customprops1MFERemovalRanOnForexample:MFERemoval.
exe/framepkg/customprops113MFERemovalRanOnProductDetectionKeySpecifytheregistrylocationthatcontainstheProductDetectionKeyValue.
IntheEEDK,abbreviatethetop-levelkeylocations.
Forexample,HKEY_LOCAL_MACHINEisabbreviatedHKLM.
ProductDetectionKeyValueSpecifytheregistrykeyvalue.
Ifthiskeyvalueexistsonamachinethedeploymenttaskwillnotrun.
Thefieldcannotbeblank.
Scenario1:UsetheproductdetectionkeyMFERemovalandthenon-existentkeyvalueNew.
Because,thekeyvaluedoesnotexist,allcomputersareupdated.
Scenario2:UsetheproductdetectionkeyMFERemovalandthenon-existentkeyvalueFinish.
Because,thekeyvalueisalreadypresentoncomputersthathaveupdatedsuccessfully,onlycomputersthataremissingthekeyareupdated.
OSSupportSelectalloftheWindowsoperatingsystemsthatyousupport.
d.
ClickBuildPackage.
Astatusboxnotifiesyouwhenthenewzipiscreated.
CheckinEEDKpackage.
CreatetheclienttaskinePO.
Assignclienttasks.
Afterthetaskrunssuccessfully,thecomputerrebootsandFramePkgattemptstoreinstallMA.
Ifthereisnoreboot,FramePkgwillrunautomatically.
NoteMFERemoval100cannotguaranteethereinstallationofMA.
Forallissues,contacttheappropriateMcAfeesupportteam.
Copyright2017McAfee,Inc.
www.
mcafee.
comMcAfeeandtheMcAfeelogoaretrademarks/registeredtrademarksofMcAfee,Inc.
Othernamesandbrandsmaybeclaimedasthepropertyofothers.
00-B
标题【萤光云双十二 全场6折 15元/月 续费同价】今天站长给大家推荐一家国内云厂商的双十二活动。萤光云总部位于福建福州,其成立于2002 年。主打高防云服务器产品,主要提供福州、北京、上海 BGP 和香港 CN2 节点。萤光云的高防云服务器自带 50G 防御,适合高防建站、游戏高防等业务。这家厂商本次双十二算是性价比很高了。全线产品6折,上海 BGP 云服务器折扣更大 5.5 折(测试了一下是金...
vollcloud LLC创立于2020年,是一家以互联网基础业务服务为主的 技术型企业,运营全球数据中心业务。致力于全球服务器租用、托管及云计算、DDOS安 全防护、数据实时存储、 高防服务器加速、域名、智能高防服务器、网络安全服务解决方案等领域的智 能化、规范化的体验服务。所有购买年付产品免费更换香港原生IP(支持解锁奈飞),商家承诺,支持3天内无条件退款(原路退回)!点击进入:vollclo...
近日CloudCone商家对旗下的大硬盘VPS云服务器进行了少量库存补货,也是悄悄推送了一批便宜VPS云服务器产品,此前较受欢迎的特价20美元/年、1核心1G内存1Gbps带宽的VPS云服务器也有少量库存,有需要美国便宜大硬盘VPS云服务器的朋友可以关注一下。CloudCone怎么样?CloudCone服务器好不好?CloudCone值不值得购买?CloudCone是一家成立于2017年的美国服务...
legalnoticecaption为你推荐
360邮箱免费注册360账号-电子邮箱怎么填写?163yeah163,126,yeah哪个更好啊,各有什么特点啊解析cuteftp滴滴估值500亿滴滴拉屎 App 为何能估值 100 亿美金?是怎么计算出来的科创板首批名单首批公布的24个历史文化明城是那些即时通民生银行即时通是什么?温州都市报招聘在温州哪里好找工作?400电话查询如何辨别400电话的真伪?如何发帖子怎么发表贴子?艾泰科技艾泰的品牌介绍
查询ip site5 10t等于多少g 42u机柜尺寸 shopex空间 info域名 长沙服务器 发包服务器 好看qq空间 100m免费空间 秒杀预告 免费全能主机 福建铁通 无限流量 美国独立日 联通网站 yundun 中国联通宽带测试 腾讯数据库 域名和主机 更多