Desktop Release Notes Desktop Release Notes 5.2.1
COPYRIGHT Copyright 2011 McAfee, Inc. All Rights Reserved. No part of this publication may be reproduced, transmitted, transcribed, stored in a retrieval system, or translated into any language in any form or by any means without the written permission of McAfee, Inc., or its suppliers or affiliate companies. TRADEMARK ATTRIBUTIONS AVERT, EPO, EPOLICY ORCHESTRATOR, FOUNDSTONE, GROUPSHIELD, INTRUSHIELD, LINUXSHIELD, MAX (MCAFEE SECURITYALLIANCE EXCHANGE), MCAFEE, NETSHIELD, PORTALSHIELD, PREVENTSYS, SECURITYALLIANCE, SITEADVISOR, TOTAL PROTECTION, VIRUSSCAN, WEBSHIELD are registered trademarks or trademarks of McAfee, Inc. and/or its affiliates in the US and/or other countries. McAfee Red in connection with security is distinctive of McAfee brand products. All other registered and unregistered trademarks herein are the sole property of their respective owners. LICENSE INFORMATION License Agreement NOTICE TO ALL USERS: CAREFULLY READ THE APPROPRIATE LEGAL AGREEMENT CORRESPONDING TO THE LICENSE YOU PURCHASED, WHICH SETS FORTH THE GENERAL TERMS AND CONDITIONS FOR THE USE OF THE LICENSED SOFTWARE. IF YOU DO NOT KNOW WHICH TYPE OF LICENSE YOU HAVE ACQUIRED, PLEASE CONSULT THE SALES AND OTHER RELATED LICENSE GRANT OR PURCHASE ORDER DOCUMENTS THAT ACCOMPANY YOUR SOFTWARE PACKAGING OR THAT YOU HAVE RECEIVED SEPARATELY AS PART OF THE PURCHASE (AS A BOOKLET, A FILE ON THE PRODUCT CD, OR A FILE AVAILABLE ON THE WEBSITE FROM WHICH YOU DOWNLOADED THE SOFTWARE PACKAGE). IF YOU DO NOT AGREE TO ALL OF THE TERMS SET FORTH IN THE AGREEMENT, DO NOT INSTALL THE SOFTWARE. IF APPLICABLE, YOU MAY RETURN THE PRODUCT TO MCAFEE OR THE PLACE OF PURCHASE FOR A FULL REFUND. 2 5.2.1 Desktop Release Notes
Contents About this document 5 New features 7 Known issues 9 Finding product documentation 13 Index 15 5.2.1 Desktop Release Notes 3
About this document Thank you for choosing this McAfee product. This document contains important information about the current release. We strongly recommend that you read the entire document. We do not support the automatic upgrade of a pre-release software version. To upgrade to a production release of the software, you must first uninstall the existing version, then install the released version using the download URL sent to you by your service provider or from www.mcafeeasap.com. 5.2.1 Desktop Release Notes 5
New features Here is a list of new and updated features included with this release of the product. Active Directory support Administrators who use Active Directory to define group hierarchies in their networks can import the organizational unit (OU) structure into the McAfee SecurityCenter, then install McAfee SaaS Endpoint Protection, assign policies, and view reports based on the imported groups of computers. Use the Active Directory Synchronization utility to import the OU structure. (Available on the Active Directory Configuration tab of the My Account page.) Configure the Active Directory Synchronization utility to run automatically at regular intervals to import modifications made to your Active Directory. This ensures that the information in the SecurityCenter remains up-to-date. (Available on the Active Directory Configuration tab of the My Account page.) You can also run the utility manually at any time. Check details for the most recent synchronization performed. (Available on the Active Directory Configuration tab of the My Account page.) In SecurityCenter reports and listings, select either a flat list view or a tree view of groups created in the SecurityCenter and Active Directory groups. A tree view icon appears to the right of the Groups filter, and icons for flat list and tree views appear at the top of listings. (Available after importing Active Directory information for an account.) Enhanced installation features During installation, a greater number of conflicting programs are detected and uninstalled automatically. (Users are prompted for permission before programs are uninstalled.) If they cannot be uninstalled automatically, users are prompted to uninstall them manually. All methods for installing the client software include: Option for assigning a policy during installation. Option to perform a full scan on the client computer when installation is complete. URL installation now supports these web browsers: Microsoft Internet Explorer (versions 6, 7, and 8) Mozilla Firefox (versions 2.0, 3.0, and 3.5) Google Chrome (version 4.1) Apple Safari for Windows (version 4.0) The browser must be configured to enable Javascript. The Push Install utility, which can be downloaded and used to deploy the client software, now supports Active Directory (requires Active Directory credentials). 5.2.1 Desktop Release Notes 7
New features Additional new features Support for new versions of Microsoft software This release of the product supports: Microsoft Outlook 2010. R2 versions of Microsoft Windows 2008 Server operating systems (32-bit and 64-bit). New web browsers SecurityCenter support for Mozilla Firefox, Google Chrome, and Apple Safari for Windows. New virus and spyware protection features Script scanning support for Firefox browser pages. Addition of identification information to alerts and reports. The IP address or name of the source machine is provided when an infection originates from a remote source. Addition of status information for the last client scan and client update tasks on the Computer Details page of the SecurityCenter. Change to default settings for on-demand scanning option. By default, the optional feature to scan for processes running in memory during on-access scans is disabled on all server operating systems. It remains enabled by default for on-access scans on non-server operating systems and for all on-demand scans. New firewall protection features Installation on servers defaults to trusted mode. No reboot is necessary after installing the firewall protection service (unless installing over an existing installation). Notification alert when the network connection changes. 8 5.2.1 Desktop Release Notes
Known issues Here is a list of known issues that we were aware of at production time. To view a new list of additional issues associated with this release, see KB69952 in the McAfee Support online KnowledgeBase: https://mysupport.mcafee.com. Platforms Client computers running the product on Microsoft Windows Home Media Server will not be migrated to this release of the product. Installation The firewall protection service cannot be installed on 64-bit versions of Windows XP. When using the URL method to install the firewall protection service to a computer running a Windows desktop operating system via a remote desktop connection, the remote connection closes at the end of the installation. This happens because the firewall protection service sets the connection type for the desktop computer to Untrusted by default. Therefore, the administrator won't be able to verify that the installation is successful via the remote connection for client operating systems such as Windows 7, Windows Vista, and Windows XP. The connection is re-established automatically on server operating systems, which are set to Trusted by default. The browser protection service supports Windows Internet Explorer 8 (32-bit and 64-bit versions). However, after installing the browser protection service, you must restart the client computer before the safe search icons appear in Google search results. Silent (VSSETUP) installation The VSSETUP parameter c= (to install the web filtering module) is not available. Web filtering is installed automatically as part of the browser protection service for customers who purchased it. To use web filtering features, enable the associated policy options. To configure a computer where the product software is already installed as a relay server, run vssetup.exe /SetRelayServerEnable=1. (Enter vssetup.exe /? to display a list of supported parameters.) Push installation Before pushing the client software to computers running with any type of firewall enabled, you must disable the firewall for those computers and then restart them. Domain administrator credentials are required to perform a push installation. 5.2.1 Desktop Release Notes 9
Known issues Version 2.0 of the Microsoft.NET Framework redistributable package must be installed on the administrative computer running the Push Install utility. If only Version 4.0 is installed, this error message displays when you try to run the Push Install utility: Unable to find the version of runtime required to run this application. Restarting a client computer while a push installation is in progress can make the computer unstable. To avoid this problem, schedule push installations for a time when users are not using their computers. [272935] Compatibility with other software: Popup blockers If a user is running Ad-Aware Plus SE software and the administrator has enabled the Automatic Blocking feature, the McAfee product icon does not appear in the system tray after restart, and McAfee SaaS Endpoint Protection does not function correctly. To fix this issue, the administrator must turn off Automatic Blocking in Ad-Aware. To do so: 1 Open Ad-Aware. 2 Under Tools and Preferences, click the red circle next to the word Automatic. 3 Exit and save changes. 4 Reinstall McAfee SaaS Endpoint Protection. To use McAfee SaaS Endpoint Protection and keep Ad-Aware Automatic Blocking enabled, set up a custom rule in Ad-Aware to make an exception for McAfee SaaS Endpoint Protection registry values that are being blocked. See the Ad-Aware documentation for more information. [213323] Compatibility with other software: Uninstalling other software During installation, McAfee SaaS Endpoint Protection detects most existing versions of virus protection software and firewall software, then either uninstalls them automatically or prompts users to uninstall them manually. View this list on the SecurityCenter at http:// www.mcafeeasap.com/downloads/uninstallinfo/detected_software_list.html. Upgrading Before upgrading the McAfee SaaS Endpoint Protection client software from version 4.x to version 5.2.1, you need to upgrade to version 5.0 Patch 6. You cannot upgrade directly from a 4.x version to version 5.2.1. SDAT Updates This release includes a SuperDAT (SDAT) file, which is a standalone package that contains the latest DAT file and compatible engine. The contents of the SDAT file can be used to update a client computer that is not properly receiving DAT updates. SDAT updates do not occur for computers on expired accounts; the message Product rejected the update request is displayed. Scanning On-demand scans do not scan encrypted files. They report that the files could not be scanned. When encrypted files are opened, an on-access scan is performed. [271669] 10 5.2.1 Desktop Release Notes
Known issues Buffer overflow protection The buffer overflow protection feature does not work for computers running Windows 2003 Server (SP1) with Data Execution Prevention enabled. [364702] Buffer overflow protection is not supported on 64-bit platforms. The following third-party products are not compatible with the buffer overflow feature of the virus and spyware protection service. If it is necessary to use these products, McAfee recommends that you disable the buffer overflow feature. (See the product guide for instructions.) Tiny Personal Firewall CyberArmour Firewall BlackIce Firewall Install McAfee SaaS Endpoint Protection before you install BlackIce Firewall to ensure they are compatible. Firewall protection service The firewall protection service cannot be installed on 64-bit versions of Windows XP. Server operating systems install the firewall protection service with Trusted connection type as the default setting. Before using Microsoft Windows VPN, configure a custom connection by entering the specific IP address and port number. Access custom connection settings from the General Settings tab on the Firewall Protection policy page. For more information, see KB article https://kc.mcafee.com/corporate/ index?page=content&id=kb70592. When using the URL method to install the firewall protection service to a computer running a Windows desktop operating system via a remote desktop connection, the remote connection closes at the end of the installation. This happens because the firewall protection service sets the connection type for the desktop computer to Untrusted by default. Therefore, the administrator won't be able to verify that the installation is successful via the remote connection for client operating systems such as Windows 7, Windows Vista, and Windows XP. The connection is re-established automatically on server operating systems, which are set to Trusted by default. If intermittent loss of the Internet connection occurs after upgrading to this version from the previous version of the firewall protection service, reboot the computer. (This has occurred inconsistently on computers where the previous version of the firewall protection service was uninstalled and the new version installed.) When using an FTP program that does not support passive mode in FTP protocol (such as the ftp.exe command utility shipped with Windows), many activities may appear to hang. This is a result of the FTP program listening and binding to random ports. Select an FTP program that supports passive mode to work with the firewall protection service. [355322] Quarantine Viewer Windows Vista and Windows 2003 Server: If you restore an item listed in the Quarantine Viewer, McAfee SaaS Endpoint Protection detects that item and places it back in the Quarantine Viewer the next time that item is accessed. [371053] Detected files with a path greater than 256 characters in length are cleaned and/or deleted, but cannot be restored from the Quarantine Viewer. [290395] 5.2.1 Desktop Release Notes 11
Known issues Browser protection service The browser protection service supports Windows Internet Explorer 8 (32-bit and 64-bit versions). However, after installing the browser protection service, you must restart the client computer before the safe search icons appear in Google search results. McAfee SiteAdvisor, on which the browser protection service is based, does not support 64-bit versions of the Windows Vista or Windows 2008 server operating system. The web filtering module is sometimes installed in error and reported in the SecurityCenter for customers who have not purchased it. It is uninstalled within 24 hours, during the next manual update or policy download. [565826] Uninstalling Some registry keys might remain on a client computer after using the VSSETUP /uninstall parameter to remove the client software. These keys are harmless and do not cause any problems. [470297] When McAfee SaaS Endpoint Protection is uninstalled, some files might not be correctly removed if Microsoft Outlook or Microsoft Internet Explorer is open during the uninstallation process. To remove these files manually, restart the system and delete the folder <InstallDrive>:\Program Files \McAfee\Managed VirusScan. [213768] General Pre-installed and CD-based trial users: The Buy option can appear in the menu for up to a week after an installation is merged with an existing account in the SecurityCenter. [364893] When starting or logging on to a computer where McAfee SaaS Endpoint Protection is installed, Windows might display a message that your anti-virus protection is turned off. This message should disappear as soon as the product icon in the system tray displays its normal state (without a red slash). Your computer is protected as soon as you turn it on, but the reporting feature sometimes takes a minute or two to notify Windows. [373758] 12 5.2.1 Desktop Release Notes
Finding product documentation McAfee provides the information you need during each phase of product implementation, from installation to daily use and troubleshooting. After a product is released, information about the product is entered into the McAfee online KnowledgeBase. Task 1 Go to the McAfee Technical Support ServicePortal at http://mysupport.mcafee.com. 2 Under Self Service, access the type of information you need: To access... User documentation Do this... 1 Click Product Documentation. 2 Select a Product, then select a Version. 3 Select a product document. KnowledgeBase Click Search the KnowledgeBase for answers to your product questions. Click Browse the KnowledgeBase for articles listed by product and version. 5.2.1 Desktop Release Notes 13
Index D documentation product-specific, finding 13 T Technical Support, finding product information 13 M McAfee ServicePortal, accessing 13 S ServicePortal, finding product documentation 13 5.2.1 Desktop Release Notes 15