Release Notes for McAfee VirusScan Enterprise for Offline Virtual Images 2.1.0

About this document

Thank you for using McAfee VirusScan Enterprise for Offline Virtual Image 2.1.0. This document contains important information about this release. We strongly recommend that you read the entire document.

CAUTION: McAfee does not support automatic upgrading of a pre-release version of the software. To upgrade to a production release of the software, first uninstall the existing version of the software.

Product license

NOTE: The Evaluation license expires 90 days after installing the evaluation version of the product.

Features

Features in the current release of the software are described below:

  • This release supports McAfee® VirusScan® Enterprise 8.8.
  • McAfee VirusScan Enterprise for Offline Virtual Image 2.1.0 can now be managed using ePolicy Orchestrator 4.6.
  • This product is an upgrade for McAfee VirusScan Enterprise for Offline Virtual Image 2.0.1.
  • This release adds support for VMware ESX 4.1 and Citrix XenServer 5.6.
  • This release supports Microsoft Windows Server 2008 R2.
  • Support for Artemis (Heuristic network check for suspicious files) — Looks for suspicious programs and DLLs running on the client systems. When the real-time malware defense detects a suspicious program, it sends a DNS request.

    By default, Artemis settings from VirusScan Enterprise On-Access Scan will be used.

    If you intend to configure different Artemis settings for Storage:

    1. Go to the Registry Editor.
    2. Navigate to the following path: HKEY_LOCAL_MACHINE\SOFTWARE\McAfee\VSEV
    3. Configure the following DWORD values:
      DWORD Value name Value data
      ArtemisEnabled 0 or 1
      • 0 — Disable
      • 1 — Enable
      ArtemisLevel 0 to 4
      • 0 — Very low
      • 1 — Low
      • 2 — Medium
      • 3 — High
      • 4 — Very high

Installation Prerequisites

  • McAfee VirusScan Enterprise 8.8 Patch 1

Known issues

Known issues in this release of the software are described below.

Installation

  • Issue

    ePolicy Orchestrator does not show an extension for products that do not have a policy associated with the product. VirusScan Enterprise for Offline Virtual Images is a scheduled task, so it does not use a policy. Therefore, when you install the VirusScan Enterprise for Offline Virtual Image extension in the ePolicy Orchestrator repository, a placeholder policy is provided for this product so that the product appears in the list of installed extensions. The placeholder policy is blank. Access the VirusScan Enterprise for Offline Virtual Image task from the client tasks section of the ePolicy Orchestrator console.

  • Issue

    VirusScan Enterprise for Offline Virtual Image 2.1.0 only supports ESX, vCenter, and Xen servers that use the default port values.

Miscellaneous

  • Issue

    While a VirusScan Enterprise for Offline Virtual Image 2.1.0 scan is running, it attaches the drives it scans to the local computer. You may see this if you open Microsoft Windows Explorer. However these drives are not accessible to the end user. The drives are removed once the scan is completed.

  • Issue
    VMware Workstation or Server .lck (lock) files might cause VirusScan Enterprise for Offline Virtual Image 2.1.0 to try to scan and fail the associated virtual machine.
    NOTE: A failed to mount the disk message is added in the VirtualImageScanLog.txt file if the scan fails.

    These .lck files remain on the workstation or server if the virtual server is abnormally terminated (for example, using a system reset) or if the virtual machine is not properly shutdown. Removing the .lck file allows the VirusScan Enterprise for Offline Virtual Image 2.1.0 file based scan to proceed.

  • Issue

    If the computer conducting a virtual machine scan is turned off during the scan, it leaves the disks for that virtual machine in a locked state. Re-running the scan should unlock the disks. However, the VMware feature that allows VirusScan Enterprise for Offline Virtual Image to unlock the virtual machine's disks has known issues which should be resolved with VMware's KL U1 release. Until VMware addresses this issue you might need to wait several hours for the ESX server to unlock the disks, or power cycle the ESX server to unlock the virtual machine's disks.

  • Issue

    You can scan dynamic disks with all virtual image types except for Xen. Dynamic disk scanning is not supported with Xen on any operating system. If a Xen virtual image is scanned and it contains a dynamic disk, that disk is not scanned and the following error might appear in the log:

    Failed to scan virtual drive G:. hdc () on host may be a removable drive that is empty.

  • Issue

    Do not run multiple VirusScan Enterprise Offline Virtual Image 2.1.0 scan tasks for Citrix XenServer based virtual machines. The VirusScan Enterprise Offline Virtual Image 2.1.0 is unable to properly handle this situation and we are working on a solution for the release. If you would like to run concurrent VirusScan Enterprise Offline Virtual Image 2.1.0 scan tasks install VirusScan Enterprise Offline Virtual Image 2.1.0 on two separate virtual machines to accomplish this.

    When using the VirusScan Enterprise Offline Virtual Image 2.1.0 to scan virtual machines for Citrix XenServer there must be at least a 3 minute gap between a scan completing and the start of the next scan.

  • Issue
    When scanning Citrix virtual machine images, VirusScan Enterprise Offline Virtual Image 2.1.0 disables Windows AutoPlay at the start of the scan. Once the scan is completed, VirusScan Enterprise Offline Virtual Image 2.1.0 restores AutoPlay to its previous condition.
    NOTE: This does not occur when scanning VMware virtual machine images.
  • Issue

    VirusScan Enterprise for Offline Virtual Image is currently not supported on Microsoft Hyper-V if configured to a SAN or NAS as the backend storage.

  • Issue

    A local scan of a Virtual Hard Disk (VHD) file does not perform the clean or delete action. Disk images, for example VHD files, and ISO images are scanned as read only, so any detections found can not be cleaned or deleted.

  • Issue

    Copying host DAT files of the same version fails after downgrading the VirusScan Enterprise DATs manually or using SuperDAT on the virtual machine.

    Workaround — If you use SuperDAT to downgrade DATs on the virtual machine you should also delete the following VirusScan Enterprise for Offline Virtual Image special registry entries on the virtual machine:
    • LastCopiedDATVersion
    • LastCopiedDATVersionMinor
  • Issue

    The preferred method to scan images on a Hyper-V server is to install the Offline Virtual Images software on the Hyper-V server and create the scans on that server.

    If you want to scan the Hyper-V virtual machines from a different machine you must access the Hyper-V machine through a uniform naming convention (UNC) path.

    The failure occurs because the paths to the virtual hard drive (VHD) files used by the virtual machine are stored as absolute paths. These absolute paths include the drive letter which causes the remote machine to fail to locate the VHD files.

  • Issue

    VMware gives you the option to have a virtual machine use a physical drive rather than a virtual disk file. A machine using this configuration cannot be scanned by VirusScan Enterprise for Offline Virtual Image. Since the machine is pointing to a physical drive, you can still scan the drive by creating a virtual image scan (ODS) to scan it.

  • Issue

    Do not run concurrent scans of images with multiple partitions having the same name. For example, if you run multiple virtual image scan (ODS) tasks simultaneously on two images and both have three partitions (for example, C, E, and F) the scan that first assigns the drive letters E and F to the partitions will be completed successfully. The other task cannot mount the partitions E and F of the second image and displays the error, "E and F may be removable drives on the host that are empty."

    Either run the scans serially or use more than one physical machine with VirusScan Enterprise for Offline Virtual Image installed to run parallel scans.

  • Issue
    When scanning a virtual image that has multiple drive letters, if one of those drive letters is the same as a removable drive on the host system, the virtual drive is not scanned if there is no media in the drive. To reliably scan a virtual image, ensure that none of the drive letters in the virtual image maps to any removable drive letters on their host. We recommend that you:
    • Reassign duplicate drive letters to make them unique. For example, you can move the host CD/DVD drive from letter D: to Z:.

    • Install VirusScan Enterprise for Offline Virtual Image to a virtual machine that has no removable drives configured.

  • Issue

    Password protection is not available for this product. When you configure the VirusScan Console Tools | User Interface Options for this product, password protection cannot be configured.

  • Issue
    An Access Protection rule trigger occurs when a Virtual Images Scan task is configured with a UNC path pointing to the VMware Images that cleans or deletes detected threats. To prevent this type of Access Protection rule trigger, create an exclusion for system:remote.
    NOTE: Creating an exclusion for system:remote causes a security risk. The Virtual Machine Protection rules cannot guard the virtual machine's files and settings from being altered from a remote system when this exclusion is in place.
  • Issue

    If you run VirusScan Enterprise Repair Installation from the VirusScan Console, you must run the VirusScan Enterprise for Offline Virtual Image VSEOVISetup.exe again and select Repair from the Program Maintenance dialog box.

  • Issue

    Scanning an ESX image connected to SAN or NAS storage fails from a standalone system, if the Copy DATs optionis enabled.

    Workaround — To resolve this issue, refer to the McAfee KnowledgeBase articles:

    Operating system KB article URL
    Microsoft Windows XP

    http://support.microsoft.com/kb/330174

    http://support.microsoft.com/kb/870894

    Microsoft Windows 2003 Server

    http://support.microsoft.com/kb/818408

Recommendations

We recommend that you keep images backed up to avoid potential data loss or corruption in case of power outage or crashes.

Where to find McAfee enterprise product information

The McAfee documentation is designed to provide you with the information you need during each phase of product implementation, from evaluating a new product to maintaining existing ones. Depending on the product, additional documents might be available. After a product is released additional information regarding the product is entered into the online Knowledgebase available on McAfee ServicePortal.

Installation Phase

Setup Phase

Maintenance Phase

Before, during, and after installation.

Release Notes

  • Known issues in the current release.
  • Issues resolved since the last release.
  • Last-minute changes to the product or its documentation.

Product Guide

  • Preparing for, installing and deploying software in a production environment.

Getting up-and-running with the product.

Product Guide and Online Help

  • Setting up and customizing the software for your environment.

Online Help

  • Managing and deploying products through ePolicy Orchestrator.
  • Managing and deploying products through VirusScan Console.
  • Detailed information about options in the product.

Maintaining the software.

Online Help

  • Maintaining the software.
  • Reference information.
  • All information found in the product guide.

Knowledgebase (knowledge.mcafee.com)

  • Release notes and documentation.
  • Supplemental product information.
  • Workarounds to known issues.

Finding release notes and documentation for McAfee enterprise products

Use this task to go to the release notes and other product documentation for McAfee enterprise products.

  1. Go to knowledge.mcafee.com and select Product Documentation under Useful links.
  2. Select <Product Name> | <Product Version> and select the required document from the list of documents.

COPYRIGHT