SlideShare a Scribd company logo
Knowledge Base Article
Page 1 of 6
Created On: 28-Oct-2013
Author: Eric Roberson
Title
Computers running McAfee Antivirus (beta) become unresponsive during
startup
Description of Issue
 Computers running McAfee Antivirus hang or freeze when starting up
or while logging onto the network.
 Information in this solution applies only to pilot/test computers for
McAfee Antivirus (beta).
Description of Resolution
This solution contains several parts. Follow each section carefully. The
variable {computername} refers to the remote or target computer.
PREREQUISITE: Recover an unresponsive computer
This section must be performed locally on the remote computer. Consider
connecting to the remote computer using Remote Desktop Protocol (RDP.)
1. If the computer hangs during startup, press CTRL + ALT + END to
start task manager.
2. Click the Processes Tab, then click Image Name to sort the list of
running processes.
3. Click the MfeFFCore.exe process, then click End Process.
4. The computer will log on successfully after stopping the MfeFFCore.exe
process.
PART 1: Copy necessary files to remote computer
Parts one, two, and three may be performed remotely without user
intervention. Before completing these sections, go to Part 4: Confirm
Functionality to determine whether these steps are necessary.
1. On the target computer, check for
{computername}c$windowssystem32psexec.exe. If necessary,
copy EDCAPP25MMQT$PSEXEC.EXE to
{computername}c$windowssystem32.
2. Open a command using an account with elevated privileges (eg.
A_UserID). Type net use ohcfs01groups * /u:lyb{user_ID},
Knowledge Base Article
Page 2 of 6
then press Enter. When prompted, enter the password for a regular
user ID.
3. Type Copy ohcfs01groupseveryonesleep.exe
{computername}C$Batch.
4. Type Copy ohcfs01groupseveryoneframepkg.exe
{computername}C$Batch.
5. Type Net use ohcfs01groups /d. Press the letter ‘Y’ to
disconnect when prompted. Continue to Part 2: Apply the Soulution.
PART 2: Apply the solution
1. Open a command using an account with elevated privileges (eg.
A_UserID). Type psexec –s –h {computername} cmd.exe.
2. Type hostname to verify connectivity to the remote computer.
3. Type c:batchframepkg.exe /forceuninstall, then press Enter.
Wait for the command to complete, which may take five minutes or
longer.
4. Type SET TEMP=C:BATCH, then press Enter.
Knowledge Base Article
Page 3 of 6
NOTE: The command line SET TEMP=C:BATCH is case sensitive.
Please use All CAPS.
5. Type C:BatchFramePkg.exe /install=agent /forceinstall
/DataDir=C:Batch, then press Enter. Wait for the command to
complete, which may take ten minutes or longer.
NOTE: This command line is case sensitive. Be sure to use correct
upper and lower case letters.
Knowledge Base Article
Page 4 of 6
6. Restart the computer. Type shutdown /r /f /t 600 /c “Save your
work! Restarting computer in 10 minutes to complete antivirus
agent installation.”
7. Type ping -4 {computername} –t –w 15000. Continue to Part 3
once a ping response is received.
PART 3: Retrieve updated policy
Retrieve the updated policy so new encryption keys are copied and files are
decrypted on the remote computer.
1. Open a command using an account with elevated privileges (eg.
A_UserID). Type psexec –s –h {computername} cmd.exe.
2. Type hostname to verify connectivity to the remote computer.
3. Type CDProgram FilesMcAfeeCommon Framework, then press
Enter.
4. Type each of the following commands, waiting 60 seconds between
typing each command:
 CmdAgent.exe /C
 CmdAgent.exe /E
 CmdAgent.exe /P
5. Restart the computer. Type shutdown /r /f /t 600 /c “Save your
work! Restarting computer in 10 minutes to complete antivirus
agent installation.”
PART 4: Confirm functionality
Confirm necessary decryption keys are present and files are being decrypted.
1. Connect to the remote computer using RDP.
2. Browse to the folder C:Program FilesMcAfeeEndpoint
Encryption for Files and Folders. Double click MfeFFConsole.exe.
3. Click the Status Report button at the top left, then expand Available
Keys in the column on the right.
Knowledge Base Article
Page 5 of 6
4. If both encryption keys appear, then the solution has been applied
successfully and the new policy is in effect.
5. To check for files waiting to be decrypted, open Windows Explorer.
Right click the C: drive, then click McAfee Endpoint Encryption >
Search Encrypted.
6. Click the Search button at the top right. If no encrypted files are
found, then the solution has been applied successfully and the new
policy is in effect. Also consider checking the following directories for
encrypted files:
 C:localdocs (both Win XP and Win 7)
 C:ProgramData (Win 7 only)
 C:Documents and SettingsAll UsersApplication Data (Win XP
Only)
Knowledge Base Article
Page 6 of 6
NOTE: Please allow enough time for the decryption process after
applying Steps two and three above.
Additional Information
For additional support, contact the End User Computing or Information
Technology Foundation teams.
Revision History
Revision Number Date Editor Summary of revision
0.1 28-Oct-2013 Eric Roberson First Draft
1.0 28-Oct-2013 Eric Roberson Technical Edit
Tags
McAfee Endpoint Encryption, Decrypt, Decryption, Encrypt, Encryption,
Antivirus

More Related Content

PPTX
174.123.230.82 virus removal guide
PPTX
Get rid of 90.84.59.147 connection virus
PPTX
Delete trojan.tobfy.a virus
PPTX
How to get rid of win32 viking g virus
PPTX
Guide to get rid of unlockthenet hijacker virus
PPTX
How to get rid of system progressive protection virus
PPTX
Findgala.com redirect removal guide
PPTX
Fine@fbi.gov virus removal guide to unlock pc
174.123.230.82 virus removal guide
Get rid of 90.84.59.147 connection virus
Delete trojan.tobfy.a virus
How to get rid of win32 viking g virus
Guide to get rid of unlockthenet hijacker virus
How to get rid of system progressive protection virus
Findgala.com redirect removal guide
Fine@fbi.gov virus removal guide to unlock pc

What's hot (20)

PPTX
Get rid of windows secure workshop virus
PPTX
Delete infomash.com browser redirect virus
PPTX
Crackle.com redirect virus removal help
PPTX
File recovery virus removal guide
PPTX
Cridex trojan removal guide
PPTX
Bifrost trojan or bifrose virus removal help
PPTX
How to get rid of polizia postale e delle virus
PPTX
Guide to remove infomoneyservice.com redirect virus
PPTX
Delete runclips.com browser hijacker
PPTX
How to get rid of windows web commander virus
PPTX
Isearch.claro search.com virus removal help
PPTX
How to get rid of windows premium defender virus
PPTX
How to get rid of microsoft security essentials alert virus
PDF
TEMS Intallation 8.0.3 Guide
PPTX
How to get rid of windows control series
PPTX
How to get rid of live security platinum 3.6.1
PPTX
How to get rid of windows profound security virus
PPTX
How to get rid of xp antispyware 2013 virus
PPTX
How to get rid of stop online piracy automatic protection system virus
PPTX
How to get rid of xp internet security 2013 virus
Get rid of windows secure workshop virus
Delete infomash.com browser redirect virus
Crackle.com redirect virus removal help
File recovery virus removal guide
Cridex trojan removal guide
Bifrost trojan or bifrose virus removal help
How to get rid of polizia postale e delle virus
Guide to remove infomoneyservice.com redirect virus
Delete runclips.com browser hijacker
How to get rid of windows web commander virus
Isearch.claro search.com virus removal help
How to get rid of windows premium defender virus
How to get rid of microsoft security essentials alert virus
TEMS Intallation 8.0.3 Guide
How to get rid of windows control series
How to get rid of live security platinum 3.6.1
How to get rid of windows profound security virus
How to get rid of xp antispyware 2013 virus
How to get rid of stop online piracy automatic protection system virus
How to get rid of xp internet security 2013 virus
Ad

Viewers also liked (20)

PPTX
The Etiological Spectrum of Acute Sensory Myelitis
PDF
Natali
PDF
Greenough Group Company Overview 04.19.2015
ODP
CreativEva
PDF
mens graphics
PDF
THE ADDRESS : The Business of Extraordinary Living : Presented by Sotheby's :...
PDF
ENG3305_Adv_Essay_Writing_gay_men_and_barebacking
PDF
Lập bản đồ tư duy - Nguyenngoquyen.com
DOCX
Karlov_GIS_Mapping_Final (2)
PDF
Certified QA QC Manager
DOCX
Shailendra Singh_Business_Analyst
PDF
How to Use Social Media
PDF
Shot list
ODP
PPTX
College magazine analysis
PDF
14185310 김다인
PPTX
Audience Research
DOCX
Video worksheet
PDF
PG Diploma in Piping Design Course
The Etiological Spectrum of Acute Sensory Myelitis
Natali
Greenough Group Company Overview 04.19.2015
CreativEva
mens graphics
THE ADDRESS : The Business of Extraordinary Living : Presented by Sotheby's :...
ENG3305_Adv_Essay_Writing_gay_men_and_barebacking
Lập bản đồ tư duy - Nguyenngoquyen.com
Karlov_GIS_Mapping_Final (2)
Certified QA QC Manager
Shailendra Singh_Business_Analyst
How to Use Social Media
Shot list
College magazine analysis
14185310 김다인
Audience Research
Video worksheet
PG Diploma in Piping Design Course
Ad

Similar to McAfee_Causes_Computer_To_Hang (20)

PDF
Hacking Highly Secured Enterprise Environments by Zoltan Balazs
PPT
Prueba de Presentacion
PPTX
Hacker Halted 2014 - Post-Exploitation After Having Remote Access
PPTX
pr-complete-data-protection-suites-new-customers.pptx
PDF
ESET_ENDPOINT_PROTECTION_STANDARD_DATASHEET
PDF
ESET_ENDPOINT_PROTECTION_ADVANCED_DATASHEET
PDF
RemoteExec DataSheet
PDF
How to-remove- virus
PDF
Data Center Server security
PDF
DEFCON 22: Bypass firewalls, application white lists, secure remote desktops ...
PDF
Complete Endpoint protection
PPT
Redefining Endpoint Security
PPTX
DFIR Austin Training (Feb 2020): Remote Access & Deploying Agents
PDF
Defcon 22-zoltan-balazs-bypass-firewalls-application-whiteli
PPTX
How to Turn off Norton Antivirus firewall?
PPTX
Presentatie McAfee: Optimale Endpoint Protection 26062015
PPTX
Ransomware 0 admins 1
PDF
ESET_SECURE_ENTERPRISE_DATASHEET
PPTX
cscu module 02 Securing Operating Systems.pptx
PPTX
PPT ON CYBER SECURITY FRAMEWORK & CYBER AUDITING IN CRPF .pptx
Hacking Highly Secured Enterprise Environments by Zoltan Balazs
Prueba de Presentacion
Hacker Halted 2014 - Post-Exploitation After Having Remote Access
pr-complete-data-protection-suites-new-customers.pptx
ESET_ENDPOINT_PROTECTION_STANDARD_DATASHEET
ESET_ENDPOINT_PROTECTION_ADVANCED_DATASHEET
RemoteExec DataSheet
How to-remove- virus
Data Center Server security
DEFCON 22: Bypass firewalls, application white lists, secure remote desktops ...
Complete Endpoint protection
Redefining Endpoint Security
DFIR Austin Training (Feb 2020): Remote Access & Deploying Agents
Defcon 22-zoltan-balazs-bypass-firewalls-application-whiteli
How to Turn off Norton Antivirus firewall?
Presentatie McAfee: Optimale Endpoint Protection 26062015
Ransomware 0 admins 1
ESET_SECURE_ENTERPRISE_DATASHEET
cscu module 02 Securing Operating Systems.pptx
PPT ON CYBER SECURITY FRAMEWORK & CYBER AUDITING IN CRPF .pptx

More from Eric Roberson (20)

PDF
ENG3331_Adv_Desktop_Publishing_adp_aat_catalog_assignment4
PDF
ENG3373_Advertising_finalsubmissionletter
PDF
ENG3373_Advertising_poster_slogan2
PDF
ENG3373_Advertising_poster_slogan1
PDF
ENG3373_Advertising_featurestory_fordateline
PDF
ENG3329_Environmental_Writing_greening_of_datacenters
PDF
ENG3308_Legal_Writing_legal_memo_cov
PDF
ENG3317_Public_Relations_positionpaper_lgbt_workplace_equality
PDF
ENG3317_Public_Relations_newsrelease_print
PDF
ENG3317_Public_Relations_newsrelease_broadcast
PDF
ENG3317_Public_Relations_media_kit_contents
PDF
ENG3317_Public_Relations_featurestory_lgbt_workplace_equality
PDF
ENG3317_Public_Relations_backgrounder_lgbt_workplace_equality
PDF
ENG3317_RhetoricalTheory_ideological_analysis_of_aids_memorial_quilt
PDF
ENG3317_RehtoricalTheory_neo_aristotelian_analysis_of_karlyn_kohrs_campbell
PDF
gradschool_personalstatement
PDF
County_AccessDataEnterprise3_3TopologyChart_RevisedJune2011_byERoberseon
PDF
Visio-AccessDataEnterprise3_3TopologyChart_Revised13Jul2011_byERoberson
PDF
LargeCorp_AccessData_Examiner3TopologyChart_Revised22June2011_byERoberseon
DOCX
Robersone5_ENG6318_FinalEssayOnLanguageUse
ENG3331_Adv_Desktop_Publishing_adp_aat_catalog_assignment4
ENG3373_Advertising_finalsubmissionletter
ENG3373_Advertising_poster_slogan2
ENG3373_Advertising_poster_slogan1
ENG3373_Advertising_featurestory_fordateline
ENG3329_Environmental_Writing_greening_of_datacenters
ENG3308_Legal_Writing_legal_memo_cov
ENG3317_Public_Relations_positionpaper_lgbt_workplace_equality
ENG3317_Public_Relations_newsrelease_print
ENG3317_Public_Relations_newsrelease_broadcast
ENG3317_Public_Relations_media_kit_contents
ENG3317_Public_Relations_featurestory_lgbt_workplace_equality
ENG3317_Public_Relations_backgrounder_lgbt_workplace_equality
ENG3317_RhetoricalTheory_ideological_analysis_of_aids_memorial_quilt
ENG3317_RehtoricalTheory_neo_aristotelian_analysis_of_karlyn_kohrs_campbell
gradschool_personalstatement
County_AccessDataEnterprise3_3TopologyChart_RevisedJune2011_byERoberseon
Visio-AccessDataEnterprise3_3TopologyChart_Revised13Jul2011_byERoberson
LargeCorp_AccessData_Examiner3TopologyChart_Revised22June2011_byERoberseon
Robersone5_ENG6318_FinalEssayOnLanguageUse

McAfee_Causes_Computer_To_Hang

  • 1. Knowledge Base Article Page 1 of 6 Created On: 28-Oct-2013 Author: Eric Roberson Title Computers running McAfee Antivirus (beta) become unresponsive during startup Description of Issue  Computers running McAfee Antivirus hang or freeze when starting up or while logging onto the network.  Information in this solution applies only to pilot/test computers for McAfee Antivirus (beta). Description of Resolution This solution contains several parts. Follow each section carefully. The variable {computername} refers to the remote or target computer. PREREQUISITE: Recover an unresponsive computer This section must be performed locally on the remote computer. Consider connecting to the remote computer using Remote Desktop Protocol (RDP.) 1. If the computer hangs during startup, press CTRL + ALT + END to start task manager. 2. Click the Processes Tab, then click Image Name to sort the list of running processes. 3. Click the MfeFFCore.exe process, then click End Process. 4. The computer will log on successfully after stopping the MfeFFCore.exe process. PART 1: Copy necessary files to remote computer Parts one, two, and three may be performed remotely without user intervention. Before completing these sections, go to Part 4: Confirm Functionality to determine whether these steps are necessary. 1. On the target computer, check for {computername}c$windowssystem32psexec.exe. If necessary, copy EDCAPP25MMQT$PSEXEC.EXE to {computername}c$windowssystem32. 2. Open a command using an account with elevated privileges (eg. A_UserID). Type net use ohcfs01groups * /u:lyb{user_ID},
  • 2. Knowledge Base Article Page 2 of 6 then press Enter. When prompted, enter the password for a regular user ID. 3. Type Copy ohcfs01groupseveryonesleep.exe {computername}C$Batch. 4. Type Copy ohcfs01groupseveryoneframepkg.exe {computername}C$Batch. 5. Type Net use ohcfs01groups /d. Press the letter ‘Y’ to disconnect when prompted. Continue to Part 2: Apply the Soulution. PART 2: Apply the solution 1. Open a command using an account with elevated privileges (eg. A_UserID). Type psexec –s –h {computername} cmd.exe. 2. Type hostname to verify connectivity to the remote computer. 3. Type c:batchframepkg.exe /forceuninstall, then press Enter. Wait for the command to complete, which may take five minutes or longer. 4. Type SET TEMP=C:BATCH, then press Enter.
  • 3. Knowledge Base Article Page 3 of 6 NOTE: The command line SET TEMP=C:BATCH is case sensitive. Please use All CAPS. 5. Type C:BatchFramePkg.exe /install=agent /forceinstall /DataDir=C:Batch, then press Enter. Wait for the command to complete, which may take ten minutes or longer. NOTE: This command line is case sensitive. Be sure to use correct upper and lower case letters.
  • 4. Knowledge Base Article Page 4 of 6 6. Restart the computer. Type shutdown /r /f /t 600 /c “Save your work! Restarting computer in 10 minutes to complete antivirus agent installation.” 7. Type ping -4 {computername} –t –w 15000. Continue to Part 3 once a ping response is received. PART 3: Retrieve updated policy Retrieve the updated policy so new encryption keys are copied and files are decrypted on the remote computer. 1. Open a command using an account with elevated privileges (eg. A_UserID). Type psexec –s –h {computername} cmd.exe. 2. Type hostname to verify connectivity to the remote computer. 3. Type CDProgram FilesMcAfeeCommon Framework, then press Enter. 4. Type each of the following commands, waiting 60 seconds between typing each command:  CmdAgent.exe /C  CmdAgent.exe /E  CmdAgent.exe /P 5. Restart the computer. Type shutdown /r /f /t 600 /c “Save your work! Restarting computer in 10 minutes to complete antivirus agent installation.” PART 4: Confirm functionality Confirm necessary decryption keys are present and files are being decrypted. 1. Connect to the remote computer using RDP. 2. Browse to the folder C:Program FilesMcAfeeEndpoint Encryption for Files and Folders. Double click MfeFFConsole.exe. 3. Click the Status Report button at the top left, then expand Available Keys in the column on the right.
  • 5. Knowledge Base Article Page 5 of 6 4. If both encryption keys appear, then the solution has been applied successfully and the new policy is in effect. 5. To check for files waiting to be decrypted, open Windows Explorer. Right click the C: drive, then click McAfee Endpoint Encryption > Search Encrypted. 6. Click the Search button at the top right. If no encrypted files are found, then the solution has been applied successfully and the new policy is in effect. Also consider checking the following directories for encrypted files:  C:localdocs (both Win XP and Win 7)  C:ProgramData (Win 7 only)  C:Documents and SettingsAll UsersApplication Data (Win XP Only)
  • 6. Knowledge Base Article Page 6 of 6 NOTE: Please allow enough time for the decryption process after applying Steps two and three above. Additional Information For additional support, contact the End User Computing or Information Technology Foundation teams. Revision History Revision Number Date Editor Summary of revision 0.1 28-Oct-2013 Eric Roberson First Draft 1.0 28-Oct-2013 Eric Roberson Technical Edit Tags McAfee Endpoint Encryption, Decrypt, Decryption, Encrypt, Encryption, Antivirus