Mcafee VIRUS SCAN ENTERPRISE RELEASE NOTES

Release Notes for McAfee® VirusScan® Enterprise 8.7i Patch 2
Thank you for using McAfee VirusScan Enterprise software version 8.7i Patch 2. This document contains important information about this release. We strongly recommend that you read the entire document.
Contents
{ Previous Improvements z Known issues z Resolved issues
{ Patch 2 resolved issues
{ Patch 1 resolved issues z Installation instructions
{ Verifying installation
{ Removing the patch z License attributions
About this release
z Patch Release: 08-31-2009
This release was developed for use with:
z VirusScan Enterprise: 8.7i z Detection Definitions (DAT): 5700.0000 z Scan Engine: 5.3.01
Make sure you have installed the correct version of the product(s) in this list before using this release.
*This document makes references to the following products as VirusScan Modules:
z
McAfee® VirusScan® Enterprise for Offline Virtual Images 1.0
z
McAfee® VirusScan® Enterprise for Offline Virtual Images 2.0
z
McAfee® VirusScan® Enterprise for use with SAP NetWeaver® platform 1.0
z
McAfee® VirusScan® Enterprise for Storage 1.0
Purpose
This document supplements the product Release Notes in the release package and details fixes included in VirusScan Enterprise 8.7i Patch 2.
This Patch contains a variety of improvements. McAfee has spent a significant amount of time finding, fixing, and testing the fixes in this release. Please review the Known and Resolved Issues lists for additional information on the individual issues. Refer to online KnowledgeBase article KB66795 at http://knowledge.mcafee.com for the most current information regarding this release.
Rating
McAfee recommends this release for all environments. Patch 2 is considered a High Priority Release. See McAfee Support KnowledgeBase article KB51560 for information on ratings.
Improvements
This release of the software includes the following improvements.
1. Improvements were made to the way that the CommonShell scanner interacts with file I/O. This improves performance with on-access scanners within the product.
2. VirusScan Enterprise 8.7i Patch 2 now has the ability to report compliance to the newer versions of Security Center.
3. The VirusScan Enterprise 8.7i extension has improved support for ePolicy Orchestrator 4.5 with Firefox 3.0 and Internet Explorer 8.0.
4. Several modification were made to the way that VirusScan Enterprise's system tray icon interacts with the new functionality of McAfee Agent 4.5.
5. The file extension .txt was added to the SmoothWritesExtension registry value to increase performance in handling text files.
6. Russian language support was added to the VirusScan Enterprise user interface, NAP file, and extension.
NOTE: See items #3 and #4 under Known Issues for further information about this topic.
Windows
Previous Improvements
Previous releases of the software include the following improvements.
1. The VirusScan Reports extension now has updated queries to show the status of Artemis settings for the on­access, on-demand, and email scanners.
NOTE: The Artemis status requires VirusScan Enterprise 8.5i Patch 8 or VirusScan Enterprise 8.7i be installed on the client systems, in order to correctly populate the reports. Refer to McAfee Support KnowledgeBase article KB53732 for further information on Artemis functionality.
Patch 1 to
2. On-Access Scanner’s Artemis level setting is now modifiable via the properties UI, and the equivalent VirusScan 8.7i NAP and Extension included in the patch package.
NOTE: Because this setting is new with this release of the VirusScan 8.7i NAP and extension, there is no preserved setting upon check-in of the management package. The ePolicy Orchestrator administrator will need to update that setting in the policies to match the current Artemis policy.
3. Several modifications have been made to the way VirusScan Enterprise interacts with the operating system on startup, suspend, and shutdown. These modifications resolve and improve performance issues.
4. Current DAT files are compressed to conserve network bandwidth. Now, changes have been made to decompress the DATs during the AutoUpdate process and leave them in that state, so that scanners do not have to decompress them during initialization of the scan.
5. The on-demand scanner now uses Windows Priority Control setting for the scan process. This lets the operating system set the amount of CPU time that the on-demand scanner receives at any point in the scan process. The System Utilization setting in the On-Demand Scan Properties maps to Windows Priority Control as:
Utilization Priority
10% Low 20%-50% Below Normal 60%-100% Normal
6. The on-access, on-demand, email, and script scanners now use a runtime copy of the DATs. This change has reduced the memory consumption of affected scanners by having the DATs in a readily available state for the scan engine to load.
NOTE: In some scenarios, the runtime DATs are not available. See item #1 under Known Issues. Refer to
McAfee Support KnowledgeBase article KB65459 for further information on runtime DATs.
7. VirusScan Enterprise functions that request the current version of DATs no longer need to initialize the scan engine to do so. This prevents excessive CPU spikes during ePolicy Orchestrator properties collection, as well as other areas that poll the DATs.
8. The on-access scanner memory scan function (Processes on enable) has been modified significantly to make it more comprehensive.
NOTE: The improved functionality can cause a performance impact to the system. See item #2 under Known Issues.
9. When a web browser opens a site that is script-intensive, scanning the scripts adds to the delay of loading the page. This Patch contains new functionality for ScriptScan whitelisting. If the web site is a trusted Intranet and/or frequently visited, the new script scanning.
NOTE: Refer to McAfee Support KnowledgeBase article KB65382 for further information.
10. The installation packages for patches and reposts have been upgraded so that the installation log name, created in the McAfeeLogs folder, has a dynamically generated name based on the current date and time of the installation. This helps save logs that might have been overwritten with the previous “backup previous log only” method.
implementation now allows for the exclusion of that the site from
Known issues
Known issues in this release of the software are described below:
1. Issue: In some situations, the product switches over to using the normal copy of the DAT files, instead of the runtime DATs:
{ If the McAfee AntiSpyware Enterprise module is installed after
the system, some of the new registry settings, which are new for the runtime functionality, were changed back. This resolves itself with a restart of the McTaskManager service or with a reboot.
{ If one of the scanners is busy on a large file when the AutoUpdate process posts the revised copy of
the DATs, the process of refreshing the runtime copy of the DATs times out. All scanners use the normal DATs until the next successful update.
{ The VirusScan Modules* will not use the runtime DAT functionality until they received their next
Patch.
2. Issue: With the improved functionality of the on-access scanner memory scan, lower and middle ranged systems may see a performance impact at startup and after a successful AutoUpdate of the engine or DATs. Currently the Process on enable option is enabled by default on the shipping version of VirusScan Enterprise
8.7i. McAfee recommends that in a managed environment, disable this option prior to deployment of the Patch, until the impact of memory scanning can be determined for your environment. It is not possible to maintain both the more comprehensive scanning that comes with Patch 1 and later, and the former level of scanning. Therefore, only the more comprehensive scan is used.
NOTE FOR CURRENT AND NEW USERS:
{ The Patch installation does not modify current settings to disable the Process on enable option. { The VirusScan 8.7i NAP and extension that are
policy, but do not modify the My Default policy, or any custom policy settings that were made the checkin of the new NAP/extension.
{ The VirusScan Enterprise 8.7i Repost with Patch now installs with the Process on enable option
disabled, unless the Maximum Security option is selected during the installation.
included with the Patch do change the McAfee Defau l t
VirusScan Enterprise 8.7i Patch 1 is on
prior to
3. Issue: With the introduction of support for Russian, you might need to remove the previous version of the extension from ePolicy Orchestrator before adding the new extension. If you do not, some of the interface might be displayed in the original language.
4. Issue: McAfee Agent 4.0 Patch 2 and later include support for displaying status and logs in Russian. Older versions display this information in English by default.
5. Issue: Since VirusScan Enterprise 8.7i Patch 2 and later include the new interface for reporting status to Windows Security Center, uninstalling the Patch removes this function -- without reintroducing the older
expired function. This means that Windows Security Center does not report VirusScan Enterprise 8.7i being installed until Patch 2 or later is implemented.
6. Issue: When you remove the McAfee AntiSpyware Module, the status in Windows Security Center is not updated.
7. Issue: In deployments of VirusScan Enterprise 8.7i Patch 2 with McAfee Agent 4.5, the VirusScan tray plug­in does not appear until after a restart of the McAfee system tray icon. If VirusScan is uninstalled, the VirusScan tray plug-in is still visible until a similar restart.
8. Issue: This Patch adds needed support for McAfee VirusScan Enterprise for Offline Virtual Images 2.0, and should not be removed unless the VirusScan Module is removed first.
9. Issue: The Patch installer included an MSI deferred action to resolve an issue found when attempting to uninstall the Patch on some newer operating systems. The deferred.mfe file updated the cached MSI of the currently installed VirusScan 8.7i product. If the Patch is included in a McAfee Installation Designer customized package, the deferred.mfe file was not included, and therefore the uninstalled in some newer operating systems.
10. Issue: If you installed this release interactively and cancelled the installation on a system where a previous Patch was installed, after the rollback was complete, the previous Patch might no longer reported to ePolicy Orchestrator or appeared in the About VirusScan Enterprise window.
11. Issue: Installing the Patch and specifying a log file path using the Microsoft Installer (MSI) switch “/L” did not log to the specified path. A log file capturing full data was logged to the folder “McAfeeLogs” under the Temp folder.
Patch might not be able to be
12. Issue: If Host Intrusion Prevention 6.x or later was installed and disabled prior to installing VirusScan Enterprise, it was necessary to re-enable Host Intrusion Prevention and disable it again, in order for VirusScan Buffer Overflow Protection to be properly enabled.
13. Issue: Uninstalling VirusScan Enterprise Patches is possible for computers running Windows Installer v3.x or later. This technology is not fully integrated for Windows 2000 operating systems, so there is no option to remove the Patch in Add/Remove programs. See instructions under Removing the Patch for removal via command-line options.
14. Issue: Patches for VirusScan Enterprise 8.7i can only be uninstalled via Add/Remove programs, not via ePolicy Orchestrator.
Resolved issues
The resolved issues are divided into subsections per patch, showing when each fix was added to the compilation.
Patch 2 resolved issues:
1. Issue: Processes that ended were still listed in Task Manager. (Reference: 482720) Resolution: The link driver no longer retains the handles to processes that have closed.
2. Issue: On a system using large quantities of handles, particularly busy servers, VirusScan would cache excessive amounts of data in non-paged pool memory. (Reference: 492541) Resolution: The link driver has been updated to reduce the amount of overhead in the data used for operations.
3. Issue: In high I/O environments where Access Protection is enabled, a performance degradation symptom could be encountered, appearing as a hang. Internal processing by VirusScan drivers occurred serially, contributing to a bottleneck when large volumes of I/O were filtered. (Reference: 497580) Resolution: The link and mini-firewall drivers no longer cause a sequential release of objects containing gathered information on the I/O request. This should increase performance on multi-processor environments.
4. Issue: The setting in Email Scan for Heuristic network check for suspicious files was not being updated based on the user interface or policy changes. (Reference: 493594)
Loading...
+ 9 hidden pages