Solved

Need to disable mcsheild.exe so I can run ComboFix

Posted on 2010-08-20
16
2,309 Views
Last Modified: 2013-12-09
How can I disable mcsheild.exe from starting up. I have tried the services and msconfig and I get an error when trying to stop it. I know it is a protection setting in there software so no other malware turns it off, but I need to run ComboFix to make sure the system is clean. Should I just run it anyways with Mcsheild.exe active?  I have disabled all other services in Mcafee.
0
Comment
Question by:calitech
  • 3
  • 3
  • 2
  • +6
16 Comments
 

Expert Comment

by:djhayu
Comment Utility
Try this:

http://www.bleepingcomputer.com/forums/topic114351.html

There are instructions for a lot of different AV's
0
 
LVL 35

Expert Comment

by:torimar
Comment Utility
Hit CTRL+ALT+DEL, click the 'Processes' tab, select 'mcshield.exe' in the process list, and select 'End process'.

0
 
LVL 35

Expert Comment

by:torimar
Comment Utility
ps:

After terminating the McShield process in the task manager, you are of course free to disable the McShield service:
Start > Run > services.msc

But that will only affect Windows after a restart, whereas the service's currently running instance (interfering with Combofix when you would run it now) has already been aborted by the task manager.
0
 

Author Comment

by:calitech
Comment Utility
Access denied if i try and end task.
0
 
LVL 1

Expert Comment

by:austchipmunk
Comment Utility
if like that, u have to get admin right first before kill the mcafee..

are you administrator of the pc's?
0
 
LVL 23

Expert Comment

by:Mohammed Hamada
Comment Utility
You can't end end the mentioned task becoz it has some integrated Dlls along with it and you have to terminate all these processes to successfully end it.

"mcshield.exe" is the McAfee On-Access Antivirus Scanner from Network Associates, Inc. It monitors your computer's processes, files and registry to attempt to detect and prevent virus infection.

So I would say in this case that Mcshield is a process and service in the same time which as a service has other dependencies which you will have to stop as well.

0
 
LVL 23

Expert Comment

by:Mohammed Hamada
Comment Utility
Try using autoruns to stop it if nothing worked, Or as a last resort you could uninstall Mcafee run combofix then reinstall it.

http://www.filehippo.com/download_autoruns/
0
How your wiki can always stay up-to-date

Quip doubles as a “living” wiki and a project management tool that evolves with your organization. As you finish projects in Quip, the work remains, easily accessible to all team members, new and old.
- Increase transparency
- Onboard new hires faster
- Access from mobile/offline

 
LVL 35

Expert Comment

by:torimar
Comment Utility
Start > Programs > McAfee > VirusScan Console.
Right-click 'Access Protection' and select 'Properties'.
Deselect 'Prevent McAfee services from being stopped'.
Click 'Apply'.
Close the VirusScan Console.

Then disable the service or end the task.
0
 
LVL 22

Expert Comment

by:optoma
Comment Utility
What version of mcafee?
0
 
LVL 4

Expert Comment

by:AimToPlease
Comment Utility
First, stop the McAfee Framework Service. This is especially important if your system is managed by ePolicy Orchestrator or Protection Pilot, since the McAfee Agent will reset Access Protection settings and restart the McShield Service every time it enforces policies (every 5 minutes by default).

Then, you need to disable the McShield.exe service from the VirusScan Enterprise console. Open the console, double-click Access Protection Settings, deselect Prevent McAfee Services from being stopped and click OK.

Now you have services stopped. Are you going to scan the system with a third party tool? You have some other options as well:

Enable Artemis technology in the On-Access Scanner Properties (available only in VSE 8.7)
You can also use the VirusScan Enterprise Command-Line scanner along with the latest SuperDAT, depending on the McAfee Suite you are using.

Uhm, well, the best of luck.
0
 
LVL 12

Accepted Solution

by:
Rant32 earned 250 total points
Comment Utility
torimar is probably right with post #33489998 (disable Access Protection)

However, I have encountered situations where McAfee VSE blocked configuration attempts despite of being completely disabled.

For example, configuring a 2003 Server with Security Configuration Wizard. Applying the policy fails when VSE is installed in the default configuration. I have to completely remove VSE to be able to apply the SCW policy.
0
 
LVL 47

Expert Comment

by:rpggamergirl
Comment Utility
Try this to disable McAfee shield: (credit to b0lsc0tt)

Open McAfee Security Center, go to the Advanced menu, click on 'Configure'
and then run through "computer and files", "internet", and "email and IM" categories;
in each on there is a manual option to turn off the protection (click the off bubble).
0
 

Author Comment

by:calitech
Comment Utility
Sorry, nothing worked and I just used Mcafee's removal tool to remove it.
0
 
LVL 12

Expert Comment

by:Rant32
Comment Utility
Post #33508942 suggests removing VirusScan completely, because it can block configuration attempts despite being disabled. Do not agree with the points distribution.
0
 

Author Closing Comment

by:calitech
Comment Utility
Close enough
0

Featured Post

Highfive + Dolby Voice = No More Audio Complaints!

Poor audio quality is one of the top reasons people don’t use video conferencing. Get the crispest, clearest audio powered by Dolby Voice in every meeting. Highfive and Dolby Voice deliver the best video conferencing and audio experience for every meeting and every room.

Join & Write a Comment

Suggested Solutions

Getting hacked is no longer a matter or "if you get hacked" — the 2016 cyber threat landscape is now titled "when you get hacked." When it happens — will you be proactive, or reactive?
Transferring data across the virtual world became simpler but protecting it is becoming a real security challenge.  How to approach cyber security  in today's business world!
This video discusses moving either the default database or any database to a new volume.
When you create an app prototype with Adobe XD, you can insert system screens -- sharing or Control Center, for example -- with just a few clicks. This video shows you how. You can take the full course on Experts Exchange at http://bit.ly/XDcourse.

762 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

12 Experts available now in Live!

Get 1:1 Help Now