2 Replies Latest reply on Mar 5, 2014 2:01 PM by awbattelle

    HIPS DAT content causes deployment?

    awbattelle

      EPO 4.66
      Windows Server 2012 R2

      HIPS V 8.0.0.2151-2482

       

      For reasons I won't go into, not all systems in our enterprise have HIPS installed. They all have VSE and all the laptops have EEPC.  So of course, we do distribute the HIPS content from the current branch to all systems. The ones with HIPS use it, and the ones without it don't.

      We don’t have any HIPS deployment tasks at all, although we do, or we did have a version of HIPS in the current branch (.2482) as we do have a task to remove HIPS on occasion. In addition,our Global update task is configured to only deliver HIPS content with Patches and service packs turned off for HIPS.

       

      So you can imagine my surprise, when I am alerted yesterday morning that HIPS is being installed on all systems. I check all the tasks (Perhaps one is mislabeled). Nope, there are no HIPS deployment tasks. Maybe it’s being delivered as a patch or service pack from one of our update tasks? Nope both update tasks have HIPS unchecked in Patches and service packs. Could there be something with an agent policy? Pointing to the eval branch or something? Nope, only a small test group at a bottom level folder is getting anything from Eval.

       

      What could it be? In a panic, I remove anything to do with HIPS from the current branch AND disable HIPS DAT distribution. It stops. OK, time to find out why, when this happened.

      I create a report, “HIPS product deployment History” It looks like the image below.

       

      Funny thing is, when I run the report. I don't show any installs prior to actions I've taken recently after the issue was discovered yesterday morning..No installs except like 2 I did months ago. If I remove the event ID part ofthis query, I see plenty of DAT updates (2401). The only uninstalls I can see are ones I did to remediate the issue.

       

      So, am I to deduce that somehow, a recent DAT update caused an installation action on systems without HIPS? Could it be that the DAT itself. triggered a dependency installation from the version of HIPS located in the current branch?? Has anyone else seen this? Any ideas? At this time, I have suspended all HIPS Dat distributions till I can flush this out on our dev server. Perhaps I will have to configure EPO to only expose systems with HIPS to HIP Dats?

       

      Message was edited by: awbattelle on 3/5/14 10:47:33 AM CST
        • 1. Re: HIPS DAT content causes deployment?
          Kary Tankink

          Update tasks (for HIPS content deployment) cannot deploy a product.  Product deployments are done via an ePO Deployment task.

           

          Review the McAfee Agent logs, along with the HIPS install log (c:\windows\temp\mcafeelogs\mcafeehip8_install_xxxxxx.log) to determine how HIPS got installed.

          • 2. Re: HIPS DAT content causes deployment?
            awbattelle

            So, OK, there is an installation that took place here:

            === Verbose logging started: 3/4/2014  12:44:57  Build type: SHIP UNICODE 5.00.7601.00  Calling process: C:\Windows\SysWOW64\MSIEXEC.EXE ===

            MSI (c) (80:70) [12:44:57:645]: Resetting cached policy values

            MSI (c) (80:70) [12:44:57:645]: Machine policy value 'Debug' is 0

            MSI (c) (80:70) [12:44:57:645]: ******* RunEngine:

                       ******* Product: C:\ProgramData\McAfee\Common Framework\Evaluation\HOSTIPS_8000\Install\0000\McAfeeHIP_ClientSetup_X64.msi

             

            It seems to be pulling from its own local evaluation branch, which I take it means that the package came from the eval branch on the server.

             

            Then, the agent log;

            The only tasks I can find about HIPS. are removal tasks, which we had running routinely in this particular folder. However, this didn't seem to stop HIPS from installing. I am thinking, if you look at the log, that it is somehow related to an update task.

            At 11:52 we have a successful uninstall, and I can easily see the task;

             

            2014-03-04 11:52:52.611 i #3476 Sched The task Remove HIPS 2589 is successful

            2014-03-04 11:52:52.611 i #3476 Sched Scheduler: Task [Remove HIPS 2589] is finished

             

            But then, as we get closer to the target time. I see this!

             

            2014-03-04 12:44:43.984 i #10028 Updater Verifying vcredist_x64.exe.

            2014-03-04 12:44:43.984 I #10028 Uec Done processing progress information

            2014-03-04 12:44:43.987 I #10028 Uec Received ipc data from mue

            2014-03-04 12:44:43.987 I #10028 Uec Processing progress information

            2014-03-04 12:44:43.987 i #10028 Updater Downloading vcredist_x64.exe.

            2014-03-04 12:44:43.988 I #10028 Uec Done processing progress information

            2014-03-04 12:44:57.154 I #10028 Uec Received ipc data from mue

            2014-03-04 12:44:57.154 I #10028 Uec Processing event information

            2014-03-04 12:44:57.154 I #10028 Uec Done processing event  information

            2014-03-04 12:45:50.509 I #3240 Manage Plugin registry change detected

            2014-03-04 12:45:50.509 I #3240 Manage Plugin registry change detected

            2014-03-04 12:45:50.511 I #3240 Manage Plugin registry change detected

            2014-03-04 12:45:50.512 I #3240 Manage Plugin registry change detected

            2014-03-04 12:45:50.513 I #3240 Manage Plugin registry change detected

            2014-03-04 12:45:50.514 I #3240 Manage Plugin registry change detected

            2014-03-04 12:45:50.516 I #3240 Manage Plugin registry change detected

            2014-03-04 12:45:50.517 I #3240 Manage Plugin registry change detected

            2014-03-04 12:45:50.518 I #3240 Manage Plugin registry change detected

            2014-03-04 12:45:50.519 I #3240 Manage Plugin registry change detected

            2014-03-04 12:45:50.520 I #3240 Manage Plugin registry change detected

            2014-03-04 12:45:52.547 I #3240 Manage Immediate plugin list reload requested

            2014-03-04 12:45:52.613 I #3240 Manage New plugin <HOSTIPS_8000> found

            2014-03-04 12:45:52.613 I #3240 Sched >>--CSchedule::RegisterProduct

            2014-03-04 12:45:52.926 I #3476 Sched Plugin DLL for HOSTIPS_8000 has been registered

             

            So, No "Task" ran. The software installed for some other reason. Believe me I searched the entire log for task names.

            as previously stated, I checked all tasks to make sure none were misnamed.

             

            2014-03-04 12:36:07.867 I #3476 Sched The task Remove HIPS 2589 is still running

            Searching for anything with "task" at the target time, I find nothing.

             

            Message was edited by: awbattelle on 3/5/14 2:01:01 PM CST