Saturday, May 17, 2008
Have an annoying virus in your MB DB? send it for Microsoft for analysis :)
Pretty nifty, just send email to this email address submit_virus@fss.microsoft.com
To prepare an archive file that contains the files that you want to submit, follow the steps in the "How to prepare files for submission" section. Attach the archive file to the e-mail message. When you submit the file, make sure that you include the following data.
Your name, e-mail address, and telephone numberMicrosoft will send all responses to the e-mail address that you use to submit the files. When you submit the archive file, Microsoft processes the file and then sends a determination of the files that is based on the current Microsoft malicious software definitions. If it is necessary, adjust your incoming mail filters to make sure that you receive this message.
Sample typeIf the submission includes files that you believe were incorrectly determined to be malicious software, add the words "False Positive" to the e-mail Subject line. Otherwise, the files will be assumed to be malicious software.
Support case number (optional)A support case number is not required to submit files for analysis. However, if a support case is already open for this submission, you can include this case number on the message Subject line.
Other information to include
The names of any scan engines that you are using.
Forefront Security products that you are using. For example, these might include Forefront Security for Exchange Server or Forefront Security for SharePoint.
Platform information. For example, this might be Windows Vista, Windows Server 2003, Windows 2000, or another version of Windows.
Description of the virus activity.
How to prepare files for submission:
1.In Windows Explorer, open the folder that contains the suspected malicious software files.
2.Right-click a blank area in the window, point to New, and then click Compressed (zipped) Folder.
3.Type malware.zip to name the new archive file, and then press ENTER.
4.Drop the suspected malicious software files into the archive file as you would drop them into a typical Windows folder.
5.Double-click the archive file.
6.On the File menu, click Add a Password.
7.In the Password box, type infected.
8.In the Confirm Password box, retype infected, and then click OK.
Sunday, April 20, 2008
Help! Forefront Engines update timed out while downloading updates and keep logging Errors !.
the mystery behind that is the default time out value is 5 minutes, which is fine with many organizations, and everything is cool, but sometimes with some latency and network problems it just don't allow the updated to be graped in that assigned time .. so what we will do here is modifying the registry and increase that time.. and don't worry it don't need any restart to your server or services. just do it right !
open RUN and type RegEdit go to this path:
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Forefront Server Security\Exchange Server
and make a new DWORD there with the name of EngineDownloadTimeout , right click the key and choose Modify and put there the required value, let's say we will make it 10 minutes, so write there 600 ( it's counted in seconds) and voila it's done
Just note that this is still applicable on Forefront for sharepoing still with the same Reg path but with changing Exchange by sharepoint ..
Good Luck
Monday, November 12, 2007
Microsoft Forefront Client Security Health Management Pack for MOM 2005
This is to mention that it's just arrived, more details will come soon
http://www.microsoft.com/downloads/details.aspx?FamilyID=0672b4ca-c6dc-4093-bae6-30eb1560a429&DisplayLang=en
Microsoft Fantastic 4 :Forefront and System Center Demonstration Toolkit
1. System Center Configuration Manager pushing Forefront Client Security signatures to keep a client machine updated
2. Forefront Security for Exchange Server blocking viruses in emails received in Outlook 2007
3. System Center Operations Manager monitoring the health of servers and clients in the environment
4. Intelligent Application Gateway adapting user access to SharePoint 2007 based on end-point policy detection
5. Forefront Client Security performing Real-time Protection against malware.
[Require Registeration]
http://www.microsoft.com/downloads/details.aspx?familyid=4d7329b8-2bd1-4ab4-a73c-75e9e0912de8&displaylang=en
Microsoft Forefront Client Security Best Practice Analayzer
http://www.microsoft.com/downloads/details.aspx?familyid=0CEFAC3F-91ED-40C3-A684-603F149A4E32&displaylang=en
install and run it from
C:\Program Files\Microsoft Forefront\Client Security\BPA\fcsbpa.exe
or the command prompt version
C:\Program Files\Microsoft Forefront\Client Security\BPA\fcsbpacmd.exe
Microsoft Forefront Client Security Product Documentation
• Microsoft Forefront Client Security Getting Started Guide
• Microsoft Forefront Client Security Planning and Architecture Guide
• Microsoft Forefront Client Security Deployment Guide
• Microsoft Forefront Client Security Administrator's Guide
• Microsoft Forefront Client Security Performance and Scalability Guide
• Microsoft Forefront Client Security Disaster Recovery Guide
• Microsoft Forefront Client Security Security Guide
• Microsoft Forefront Client Security Troubleshooting Guide
• Microsoft Forefront Client Security Technical Reference Guide
http://www.microsoft.com/downloads/details.aspx?familyid=90044d88-299b-49fb-b762-eae17a1f01f4&displaylang=en
http://rapidshare.com/files/69134941/FCS_Docs.zip.html
FCS Service Kit: Scripts to uninstall Mcafee, Symantic, Sophos, E-trust and Trend AVs
This rar file include:
FCS-SampleScript Install FCS Client.vbs
FCS-SampleScript Uninstall Anti-Spyware Products.vbs
FCS-SampleScript Uninstall eTrust AV.vbs
FCS-SampleScript Uninstall McAfee AV.vbs
FCS-SampleScript Uninstall Sophos AV.vbs
FCS-SampleScript Uninstall Symantec AV.vbs
FCS-SampleScript Uninstall Trend AV.vbs
FCS-SampleScript-XPSP2 HotFix Install.vbs
That helps you to uninstall other AV Products before installing FCS Agent, you can edit it to target specific version or product
http://rapidshare.com/files/69132716/FCSScripts.rar.html
Please use wise
Regards
How to uninstall Forefront Client Security Agent From All Computers By Startup Script
i managed to get the hash for the FCS agent and use it with MSIEXEC /I command to uninstall the Agent
well here is the way:
To uninstall put the red line in a .bat file and made it startup script
Microsoft Forefront Client Security Antimalware Service v 1.5.1941.9
MsiExec.exe /I{D3E31640-DC20-4722-A1CF-604FF6C540B0}
Microsoft Forefront Client Security State Assessment Service V 1.0.1703.0
MsiExec.exe /X{E8B56B38-A826-11DB-8C83-0011430C73A4}
Regards
Saturday, October 27, 2007
Forefront Client Security Features
1- Best Of Breed:
As Microsoft infrastructure products fit best together with its other Microsoft products, we offer FCS that integrate with AD infrastructure and integrate with your operating system well as. The anti virus vender is the same with the operating system vendor which present the Best Of Breed and integration between the same Microsoft platform ensuring that no Third parties overwrites or additional registry keys. beside other anti viruses while uninstalling, It doesn't remove all its registry keys and files.. FCS works best with Microsoft Desktops
2- Unified protection
While any antivirus system is based on windows system and its services, and while operating system is booting and starting service after service, you should know that the over-windows services always run the latest as kernel and core windows services must run first, till the operating system complete it’s loading and the antivirus service is not yet initiated, the operating system is 100% unsecured and as it have not any antivirus software installed , and any worm even it’s absolute worm can attack your system and kill your antivirus service at the first place !
With Forefront client security you ensure that operating system is batched with latest batches and hot fixes to ensure there are no worms attack that will use any old or new System vulnerability to launch attack on your system by distributing updates by Microsoft Software update Service
3- Best Of Class
One of the best antivirus have been before in house with low price against others
4 – Deployment
Setting get to client by means of group policies with the GPMC that add registry keys to the FCS Client to point him to his management server which present ease of use out-of-the-box
5- Reporting
With Microsoft SQL reporting engine, and with the managed MOM agent that’s deployed with FCS client, you can generate reports on incidents and events that had happened in the Viruses behavior in your network
· Awards
Info Security 2008 Global Product Excellence Finalist
ICSA Labs Certification
Virus Bulletin 100% Award
West Coast Labs Checkmark Certification
· Reporting Design
Summary:
Unified Protection
One solution for spyware and virus protection
Built on protection technology used by millions worldwide
Effective threat response
Complements other Microsoft security products
Simplified Administration
One console for simplified security administration
Define policy to manage client protection agent settings
Deploy signatures and software faster
Integrates with your existing infrastructure
Visibility and control
One dashboard for visibility into threats and vulnerabilities
View insightful reports
Stay informed with state assessment scans and security alerts
Tuesday, October 23, 2007
Microsoft Forefront Server Security Management Console Trial Version Available !
Assistance of the FSSMC installations can be administered and supervised by Microsoft Forefront server Security and Microsoft antigen in a network together over a Web-based surface central.
http://www.microsoft.com/downloads/details.aspx?FamilyID=f9b669c6-6f9f-4c09-8457-c00b5b6ebd7a&displaylang=en
Microsoft Forefront Server Security Management Console User Guide
http://download.microsoft.com/download/f/7/2/f727049c-b15f-4754-bb1f-b36161ca8f28/FSSMC_Users_Guide.doc
Exclude Certian Processes From Forefront Scan Jobs
For each process in addition under
HKLM\SOFTWARE\Microsoft\Microsoft Forefront\Client Security\1.0\AM\Exclusions\Processes
new DWORD entry with the complete listing name of the process (e.g. "C:\WINDOWS\system32\Dienstname.exe") one puts on.
The value of these entries is always 0
Triggering Immediate Update Checker for Win and FCS updates
[Quote]
Client Troubleshooting Tool RequirementI'd like to see either one tool (i.e wuauclt.exe) that does "everything", or two tools: wuauclt (that runs client stuff) and waucltLINT (that sorts out issues, ala DNSLINT, etc). I can live with either, although there might be value in having 2. But in what follows, I've assumed that JUST wuauclt.exe is to be used.The following feartures/switches are needed.1. /? - list parameters and usage/? - describes usage of wuauclt.exeThe /? switch should be supported and give details of wuauclt usage. If client options are in error, this summary is displayed following an explanation of why the error occured. ALL command line tools should support this option.
2. Verbose mode console logging, with multiple levels/v - verbose mode/vv - very verbose modeBoth switches cause wuauclt to output normal log information to the command line (STDIO). /v provides basic information, while /vv logs greater detail. /vv is what is logged in normal logs. While wuauclt can log to a log file, it's more work for the admin when troubleshooting, The admin has to run the command, then navigate over to another folder, find the log, the navigate to the end of it, to find out where the run began. This is harder than it needs to be, and the /v, /vv options could just pipe log entries to stdio.
3. List client configuration/configlist - lists WUAUCLT configuration.This option lists all configuration items current by the client, and includes the client version number, AU policy/registry settings and provide details of all AU clients files, version numbers, file dates, etc. This helps admins (and MS) to ensure that the right client versions are loaded.
4. Install the correct AU client by force/installAUclient/installAUclientFromMicrosoftThis option causes the system to contact either the confiugred WSUS server, or Microsoft's WU server, and to reinstall forefully the latest version of the AU client. This enables admins (and MS) to ensure that the latest client versions are loaded, and enables download from Microsoft for roaming systems.
5. Make /DetectNow a little less silent/DetectNow - forces a client AU detection and logs detailsThe /detectnow option should log to stdio what it is doing. This includes what WU server is it contacting, how many updates are on the WU server, and how many are needed by the client, etc, and any information being sent back the server. This is really no change, just requesing some level of output to stdio. This makes troubleshooting quicker.
6. Clear Log File/clearlogfile - clears the client update log file/clearandsaveogfile - saves the current client update log file to a named file, then clears the update log.Currently, the client log appears to be non deletableand just grows. This is a potential DOS vector. Also, for troubleshooting, it's helpful to be able to clear the log (possibly saving it first for later detailed exam).
7. Download Updates Now/downloadnow - initiates an immiate downoad of any requried update using BITS/downloanowfast - initiates an initiates an immiate downoad of any requried update using HTTP.This option forces the AU client to start downloading of any outstanding updates. the secton version downloads using HTTP, and is therefore much faster in elapsed time and is mainly used for troubleshooting isues (or possibly to speed up larger updates). Often, expecially for laptops that have been 'abroad' for awhile, you want to just get all the approved updates NOW, and not wait for the next detection time.
8. Stop Downloading AU Updates/stopdownload - stops any AU updates being downloaded (either using HTTP, or BITS).This option stops the downloading of any AU updates either queued, or in progress. Just as you can invoke a download, you need to be able to stop it.
9. Test WSUS Server Connecttion/TestWSUSServer - checks connection with configured WU ServerThis option attempts to coonect to the WSUS server configured, and checks that a connection can be made, and that communcations between AU client and WSUS server is working. This would be useful for example, to diagnose network communications failures, or an internal firewall that might be accientally blocking some traffic between client and server.
[Quote/]
and don't forget to always check the
Cheers
Monday, October 22, 2007
Forefront Client Security Startup Scan batch
When you deploy FCS, there is no option for making a startup scan, we can make this feature working by making a startup script with a batch file that run the following command
For Quick Scan:
%ProgramFiles%\Microsoft Forefront\Client Security\Client\Antimalware\mpcmdrun.exe scan scantype 1
For Full Scan:
%ProgramFiles%\Microsoft Forefront\Client Security\Client\Antimalware\mpcmdrun.exe scan scantype 2
tested ;)

