1MethodofProcedureRevisionCUsingtheMcAfeeRemovalToolContentsConfidentialityNoticeIntroductionProcedureTroubleshootingMassdeployments2ConfidentialityNoticeThisdocumentanditscontentsareconfidentialandproprietarytoMcAfee,Inc.
andareintendedonlyfortheindividualorentityspecifiedhereinorotherwiseidentifiedbyMcAfee.
Unauthorizeduse,reproduction,ordistributionofthisdocumentoranyofitscontentsmayresultinlegalandfinancialpenalties.
3IntroductionTheMcAfeeRemoval(MFERemoval100.
exe)toolallowsyoutoremoveePOproductsfromcomputersinyournetwork.
WarningsandliabilityTheMFERemoval100.
exetoolisprovidedasabesteffortbyMcAfeesupport.
Thissoftware:HasnotbeentestedorapprovedbyMcAfee.
Shouldbetestedinyourlocalenvironmentbeforeyouattempttodeployittoyourusers.
Expiresandceasestofunctionafterthedateindicated.
Tofindtheexpirationdate:1.
Extractthestandaloneexecutable.
2.
Right-clicktheexecutablefileandclickProperties|General|Description.
SystemrequirementsThefollowingbasicrequirementsarerequiredoneachmachine:Windows5.
x-10.
xX86orx64AdministrativepermissionsNOTE:Ifrunningsyscore15.
7orhigher,youcanonlyremoveallproducts.
Itwillonlyrunwiththeproductswitch/all.
IfyourunningtheapplicationmanuallywithUACenabled,elevationisalsorequired.
Formoreinformation:http://msdn.
microsoft.
com/en-us/library/windows/desktop/aa511445.
aspxOtherdependencies:VerisignClass3PublicPrimaryCertificationAuthority–G5https://kc.
mcafee.
com/corporate/indexpage=content&id=KB870964ProcedureYoucanruntheMFERemoval100.
exetoolonyourlocalmachinebyrunningitfromthecommandline.
TaskRunMFERemoval100.
exeatthecommandlinewiththeappropriateswitches.
Switchesarenotcasesensitive.
/norebootWillnotcallreboot,overwrites/tand/forcereboot/forcerebootWillcallrebootuponcompletion/txxTimeinminutestodelayifrebootisneededor/forcerebootisused.
Defaultis10minutes.
Forexample,/t10/passHIPsclientUIpassword.
DoesnotworkwithHIPs7.
Forexample,/passabcde12345/qor/quietPreventsstatusmessageboxes.
IfdeployedfromePO,thisisautomaticallyset.
Whenspecified,theprocessexitswhenitcompletessuccessfully.
/customprops[1-4]Onlyonecustompropcanbeused.
Ifmorethanoneisprovided,thelastinthelistwillbetheoneused.
Onlynumbers1-4areallowed.
NospacesareallowedintheprovidedcustompropIf/custompropsissetandMcAfeeAgentisnotbeingremoved,thetoolwillattempttosetcustompropsthatcanbeusedlaterinePO.
Examples:1.
/customprops1AllDone2.
/customprops2mycustomprop3.
/customprops3VSEremoved4.
/customprops4MFERemovalRanOnProductswitches:/MA–McAfeeAgent/DLP–HostDataLossPrevention/HIP–HostIntrusionPrevention/VSE–VirusScanEnterprise/ENS–EndpointSecurity/DXL–McAfeeDataExchangeLayer/EIA–EndpointIntelligenceAgent/TIEM–McAfeeThreatIntelligenceExchangeModuleforVSE/MAR–McAfeeActiveResponse(RebootRequired)Oneormorearerequired.
5/MCP-McAfeeClientProxy/PA-McAfeePolicyAuditorAgent/DATRep–DATReputation/All–AllproductsForexample:Scenario1:Removeallproductsandrebootafter5minutesMFERemoval100.
exe/all/forceboot/t5Scenario2:RemoveVSEandHIP.
IncludetheHIPpassword.
MFERemoval100.
exe/vse/hip/passabcde12345orMFERemoval100.
exe/vse/hip/pass"abc123"Rebootyourcomputer.
Arebootisstronglyrecommendedifyouhaveremovedproductswiththeintentionofreinstallingthem.
RemovingHDLPandMARrequiresareboot.
Removingindividualproductsdoesnotrequireareboot.
Removingallproductsrequiresarebootifyouwanttoreinstallthemlater.
RequiredrebootOccurswhenremovingHDLPusingforceoptionorfiles/registrykeycouldnotberemoved.
MFERemovalperformscleanup.
Normalmode–Rebootoptionappearsinstatusbox.
Quietmode–MFERemoval100callsshutdown.
exewithatimespecified/t(defaultof10minutes).
Validtimefor/tare0-99.
/norebootcanbeusedtopreventanautomaticreboot.
RecommendedrebootOccurswhenservice/driverispendingareboot.
Normalmode–Rebootoptionappearsinstatusbox.
Quietmode–Noaction.
Note:/forcerebootand/norebootcommandlineswitcheswillbeoverwrittenbystatusboxpromptswhenrunlocally.
6TroubleshootingUsethestatusboxandlogfilestotroubleshooterrors.
SuccessanderrordeterminationWhentheapplicationcompletessuccessfully,adialogboxdisplayswiththefollowinginformation:TheresultsThepathtothelogfileRebootrecommendation(ifany)Also,theapplicationwritesagenericregistrykeythatcanbequeried.
Thekeyisdeletedatthestartofeachrun,andthenrewrittenwhentheprocessissuccessful.
Iftheregistrykeyismissing,youknowtherewasanerror.
LogsanddataTheMFERemoval100.
exetoolwritesdatatothefollowinglogs:Runtimelog–generatesto%SYSTEMROOT%\TEMP\McAfeelogs\Applet-YYYY.
MM.
DD–HH.
MM.
SS-[MFERemoval100.
exe].
txtEventlog–afterruntime,createsaWindowsApplicationEventLogentryfromsourceMFERemoval100.
exe.
EventIDs:o666–failureo777–successRegistrykeyTheregistrykeycanbefoundintheselocations,dependingonyourversionofWindows:X64HKEY_LOCAL_MACHINE\Software\Wow6432Node\MFERemovalX86HKEY_LOCAL_MACHINE\Software\MFERemovalRegistrykeyvalues:ValuenameFinishValuenameforeachproductremovedMAVSEHIPDLPENSDATRepTIEMDXLEIAMCPMARPAData17ActivityiconWhentheapplicationruns,theActivityicondisplaysintheWindowsNotificationArea.
ThisiconisawhiteIntellogoonabluebackground.
Thepurposeoftheiconistoindicatethattheapplicationisrunning.
FormoreinformationabouttheWindowsNotificationArea:http://msdn.
microsoft.
com/en-us/library/windows/desktop/aa511448.
aspxToviewtheWindowsNotificationArea:http://windows.
microsoft.
com/en-us/windows7/change-how-icons-appear-in-the-notification-areaReviewthelogfileWhentheprocesscompletessuccessfully,thelogreads:Exit:SuccessIfthismessageismissingfromthelog,youwillneedtocorrecttheerrororcontactyourIntelSecuritySupportrepresentative.
CommonerrorsYoucandiagnoseproblemsusingerrormessagesinthestatusboxorinthelogfile.
InvalidPassword.
Pleaseprovidepasswordasaswitch.
Example:MFERemoval.
exe/passabcde12345/passswitchwasprovidedanditwasincorrectIfthereisaspaceintheHIPpassword,usequotes:/pass"abcde12345"HIPSEnabled.
PleasedisableHIPsIPSandre-run.
OpenHIPclientUI,unlocktheGUI,anddisableIPS.
InePO,disableHostIPSviapolicyandpushdowntoclient.
Providepasswordviacommandlineswitch:/passabcde12345or/pass"abcde12345"VSEAPEnabled.
PleasedisableVSEAPandre-run.
OpenVSEConsoleanddisableAccessProtection.
InePO,disableVSEAPviapolicyandpushdowntoclient.
Failedtoinstallcertificate:4EB6D578499B1CCF5F581EAD56BE3D9B6744A5E5MFERemovaldependsonVerisignClass3PublicPrimaryCertificationAuthority–G5towork.
MFERemovalattemptedtoinstallacertificateandfailed.
Formoreinformation:https://kc.
mcafee.
com/corporate/indexpage=content&id=KB87096UnabletodisableprotectionMFERemovalwasunabletoestablishTrustwithMcAfeesoftware.
Otherreasons,includingfailedcertificateinstall.
ContactIntelSecuritysupport.
WorkaroundsTheseoptionsshouldonlybeusedasalastresort.
Youcanusethe/forceand/safemodeswitchestoremoveproductswhenyouencountererrors.
Alwaysusethe/allswitchwiththeseoptions.
Testtheseoptionsbeforeusingtheminamassdeployment/forceUse/forcetobypassallcheckandremoveallproducts.
McAfeerecommendsthisoption.
/force/all8Requiresareboot.
/safemodeUse/safemodetobootacomputerintosafemode,run,andthenrebootbackintonormalmode.
/safemode/allSafemodetroubleshootingDoesnotworkwithprebootauthentication.
RebootwouldleaveatPrebootscreentwice(oncetogointosafemodeandoncetobackintonormalmode)GPOcouldinterfereautologin–rebootwouldleaveatsafemodelog-inscreenhttps://technet.
microsoft.
com/en-us/magazine/ee872306.
aspxhttps://technet.
microsoft.
com/en-us/library/cc978776.
aspxGPOcouldaddbacklegalnoticecaption–wouldleaveatsafemodewaitingonaclickhttps://technet.
microsoft.
com/en-us/library/cc939712.
aspxDoesnotworkproperlyonDomainControllers.
Safemodeprocess1Createatempuserandaddittothelocaladmingroup.
2SettheOStobootintosafemode.
3Rebootafteroneminuteunless/tissettoanothertime.
4Bootintosafemode.
5RunMFERemoval100.
exe,deletetempuser,resetallsettings.
6Reboot.
7InNormalmode,deletetempuserprofile.
9ReinstallationofMcAfeeAgentIfMcAfeeAgentisoneoftheproductsthatisbeingremoved,thefollowingswitchescanbeusedtoreinstallMAaftertheremovaltooliscomplete.
Ifrebootiseitherrequiredorrecommended,theinstallofMAwillhappenontherestartofthesystem.
Note:ThetoolwillsetMAinstalltostart,itdoesnotguaranteethatitwillbesuccessful.
Alllogswillbeavailableinwindows\temp\mcafeelogs.
Useoneofthefollowingformatsandthetoolwillusethedefaultcommandlineof/install=agent/silenttoinstallframepkg.
exe.
Ifframepkg.
execannotbelocated,nothingwillhappen.
Refertothelogformoredetails.
/framepkgIfframepkg.
exeisinthesamedirectoryasthemferemovalbinary.
/framepkg="c:\pathtoframepkg.
exe"Iffilepathspecifiedisvalid.
Single(')ordouble(")quotescanbeusedaroundthepath.
YoucanspecifyacustompropforanewMAinstallation.
Onlyonecustompropcanbeused.
Ifmorethanoneisprovided,thelastinthelistwillbetheoneused.
Onlynumbers1-4areallowed.
Nospacesareallowedintheprovidedcustomprop.
Examples:1.
/customprops1AllDone2.
/customprops2mycustomprop3.
/customprops3MAcleaninstall4.
/customprops4MFERemovalRanOnIfotherframepkg.
execommandlineswitchesbeside/install=agent/silentandcustompropsareneeded,inadditiontothe/framepkgswitch,youcanyouadd:/framepkgcmd='thefullcommandlineparametersyouwouldliketopasstoframepkg'Note1:Singlequotes(')arerequiredatthestartandfinishofthiscommand.
Note2:Doesnotworkwith/custompropsswitch.
SeetheMcAfeeAgentProductGuideformoreinformationonframepkg.
exeinstallationquestions.
10MassdeploymentsYoucanupdatemorethanonecomputeratatime.
Toimplementamassdeploymentprocess,createacustomePOEndpointDeploymentKit(EEDK)packageanddeployitusingePO.
BeforeyoubeginEEDKpackagesarenotsupportedbyIntelSecuritysupport.
However,youcanvisittheMcAfeeCommunitysiteforinformationandsupport:https://community.
mcafee.
com/docs/DOC-3401ThecurrentversionofEEDKis9.
6.
1.
TaskCompletetheinitialsetup.
a.
Extractthezipfile.
b.
CreateanewfoldercalledBuild.
c.
RunEEDK.
exe.
d.
ClickTools|OptionandclickBrowse.
e.
SelectyourBuildfolderandclickSave.
CreatetheEEDKforMFERemoval100.
a.
SelectFile.
BrowsetoMFERemoval100.
exe.
b.
Specifythesoftwarepackageproperties.
11c.
ClickBuildPackage.
Astatusboxnotifiesyouwhenthenewzipiscreated.
ChecktheEEDKpackageintoePO.
a.
InePO,opentheMasterRepository.
b.
ClickCheckinPackage.
c.
Selectthepackagetype:ProductorUpdate(.
ZIP)d.
NexttoFilePath,clickBrowseandlocatetheEEDKpackage.
e.
ClickNext,choosethebranch,clickSave.
CreatetheclienttaskinePO.
a.
InePO,opentheClientTaskCatalog.
b.
SelectMcAfeeAgent.
c.
ClickNewTask.
d.
Selectthetasktype:ProductDeployment.
ClickOK.
e.
IntheTaskNamefield,enteraname.
f.
CompletetheoptionsforProductsandComponents.
Forexample,youcanaddaproductswitch:/vse.
ProductNameTypeaname.
Limitto8alphanumericcharacters.
ProductIDTypea4digitnumber.
ProductVersionTypetheversionnumber.
Use4digitsseparatedbyperiods.
ProductDescriptionEnterthedescriptionyouwanttoappearwhencreatingtheePOtask.
CommandtoRunEnterthenameoftheexecutablefile:MFERemoval100.
exe.
Note:IntelSecurityrecommendsusingcommandlineswitchesintheePOdeploymenttask.
AnyswitchthatyouuseisautomaticallyhardcodedandalwaysusedwhendeployedthroughePO.
Thismethodmakesiteasytoidentifytheproductsthatarebeingremovedbythetask.
ProductDetectionKeySpecifytheregistrylocationthatcontainstheProductDetectionKeyValue.
IntheEEDK,abbreviatethetop-levelkeylocations.
Forexample,HKEY_LOCAL_MACHINEisabbreviatedHKLM.
ProductDetectionKeyValueSpecifytheregistrykeyvalue.
Ifthiskeyvalueexistsonamachinethedeploymenttaskwillnotrun.
Thefieldcannotbeblank.
Scenario1:UsetheproductdetectionkeyMFERemovalandthenon-existentkeyvalueNew.
Because,thekeyvaluedoesnotexist,allcomputersareupdated.
Scenario2:UsetheproductdetectionkeyMFERemovalandthenon-existentkeyvalueFinish.
Because,thekeyvalueisalreadypresentoncomputersthathaveupdatedsuccessfully,onlycomputersthataremissingthekeyareupdated.
OSSupportSelectalloftheWindowsoperatingsystemsthatyousupport.
12Assignclienttasks.
CautionIncorrectlyassignedtaskscancausetheremovaltooltomakechangestoyourentirenetwork.
IfMcAfeeAgentisremoved,itmeansthatyourcomputersarenotprotectedbyePO.
IntelSecurityrecommendsassigningthetasktojustthenodesthatneedtoruntheremovalprocessorusingtag-basedclienttaskassignments.
CreateEEDKwithFramePkgYoucanalsocreatetheEEDKusingFramePkg.
exe.
Mostofthestepsarethesame.
UsingFramePkgallowsyoutoreinstallMcAfeeAgentaftersuccessfullyrunningamassdeployment.
BeforeyoubeginEachcustomerrequiresauniquecopyofframepkg.
exeYoumustuseoneofthefollowingMFERemoval100.
exeswitches:/MA,/ALL,or/SAFEMODETaskCompletetheinitialsetup.
a.
Createanewfolder.
b.
CopyMFERemoval100.
exeandFramepkg.
exetothenewfolder.
SetupEEDK.
a.
InEEDK,selectFolder.
b.
ClickBrowseandlocateyournewfolder.
c.
Specifythesoftwarepackageproperties.
ProductNameTypeaname.
Limitto8alphanumericcharacters.
ProductIDTypea4digitnumber.
ProductVersionTypetheversionnumber.
Use4digitsseparatedbyperiods.
ProductDescriptionEnterthedescriptionyouwanttoappearwhencreatingtheePOtask.
Forexample,MFERemovalwithMAinstall5.
03CommandtoRunEnterthenameoftheexecutablefile:MFERemoval100.
exe.
UsetheFramePkgswitches:/framepkg/framepkgcmd='cmdlineswitches'/customprops1MFERemovalRanOnForexample:MFERemoval.
exe/framepkg/customprops113MFERemovalRanOnProductDetectionKeySpecifytheregistrylocationthatcontainstheProductDetectionKeyValue.
IntheEEDK,abbreviatethetop-levelkeylocations.
Forexample,HKEY_LOCAL_MACHINEisabbreviatedHKLM.
ProductDetectionKeyValueSpecifytheregistrykeyvalue.
Ifthiskeyvalueexistsonamachinethedeploymenttaskwillnotrun.
Thefieldcannotbeblank.
Scenario1:UsetheproductdetectionkeyMFERemovalandthenon-existentkeyvalueNew.
Because,thekeyvaluedoesnotexist,allcomputersareupdated.
Scenario2:UsetheproductdetectionkeyMFERemovalandthenon-existentkeyvalueFinish.
Because,thekeyvalueisalreadypresentoncomputersthathaveupdatedsuccessfully,onlycomputersthataremissingthekeyareupdated.
OSSupportSelectalloftheWindowsoperatingsystemsthatyousupport.
d.
ClickBuildPackage.
Astatusboxnotifiesyouwhenthenewzipiscreated.
CheckinEEDKpackage.
CreatetheclienttaskinePO.
Assignclienttasks.
Afterthetaskrunssuccessfully,thecomputerrebootsandFramePkgattemptstoreinstallMA.
Ifthereisnoreboot,FramePkgwillrunautomatically.
NoteMFERemoval100cannotguaranteethereinstallationofMA.
Forallissues,contacttheappropriateMcAfeesupportteam.
Copyright2017McAfee,Inc.
www.
mcafee.
comMcAfeeandtheMcAfeelogoaretrademarks/registeredtrademarksofMcAfee,Inc.
Othernamesandbrandsmaybeclaimedasthepropertyofothers.
00-B
老薛主机,虽然是第一次分享这个商家的信息,但是这个商家实际上也有存在有一些年头。看到商家有在进行夏季促销,比如我们很多网友可能有需要的香港VPS主机季度及以上可以半价优惠,如果有在选择不同主机商的香港机房的可以看看老薛主机商家的香港VPS。如果没有记错的话,早年这个商家是主营个人网站虚拟主机业务的,还算不错在异常激烈的市场中生存到现在,应该算是在众多商家中早期积累到一定的用户群的,主打小众个人网站...
近期RAKsmart上线云服务器Cloud Server产品,KVM架构1核1G内存40G硬盘1M带宽基础配置7.59美元/月!RAKsmart云服务器Cloud Server位于美国硅谷机房,下单可选DIY各项配置,VPC网络/经典网络,大陆优化/精品网线路,1-1000Mbps带宽,支持Linux或者Windows操作系统,提供Snap和Backup。RAKsmart机房是一家成立于2012年...
IT狗为用户提供 在线ping、在线tcping、在线路由追踪、域名被墙检测、域名被污染检测 等实用工具。【工具地址】https://www.itdog.cn/【工具特色】1、目前同类网站中,在线ping 仅支持1次或少量次数的测试,无法客观的展现目标服务器一段时间的网络状况,IT狗Ping工具可持续的进行一段时间的ping测试,并生成更为直观的网络质量柱状图,让用户更容易掌握服务器在各地区、各线...
legalnoticecaption为你推荐
企业信息查询系统查企业信息哪个的软件好?支付宝是什么什么是支付宝? 请详细介绍.重庆网站制作重庆网站制作哪家好,重庆做网站制作的公司有谁比较了解的,应该去哪里做好些?360arp防火墙在哪arp防火墙在哪开额- -360里是哪个?邮件eset2828商机网2828商机网的信息准确吗,可信度高吗厦门三五互联科技股份有限公司厦门三五互联科技股份有限公司广州分公司 待遇怎么样啊,电话营销的35邮箱邮箱地址怎么写骑士人才系统骑士人才系统程序怎么那么难用,刚开始用盗版的不好用,买了正版的还是不好用,不是程序不兼容,就是功能powerbydedecms织梦dedecms怎么去掉power by dedecms方法
国外免费vps 免费注册网站域名 google电话 阿里云邮箱登陆首页 独享100m 美国主机推荐 双12活动 lighttpd 新站长网 轻量 hostloc 卡巴斯基试用版 cn3 搜索引擎提交入口 上海联通宽带测速 学生服务器 实惠 中美互联网论坛 卡巴斯基官方下载 linux命令vi 更多