0% found this document useful (0 votes)
117 views62 pages

PMT Hps Anti Virus Quick Reference Guide

The AntiVirus Quick Reference Guide outlines Honeywell's certification of Anti-Virus software for Windows-based HPS products, detailing the scope, intended audience, and certification matrix. It emphasizes the importance of using certified Anti-Virus solutions to mitigate vulnerabilities and provides guidelines for both traditional and ESXi host-based Anti-Virus solutions. The document also includes revision history and troubleshooting steps for specific configurations and software updates.

Uploaded by

Fernando
Copyright
© © All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd
0% found this document useful (0 votes)
117 views62 pages

PMT Hps Anti Virus Quick Reference Guide

The AntiVirus Quick Reference Guide outlines Honeywell's certification of Anti-Virus software for Windows-based HPS products, detailing the scope, intended audience, and certification matrix. It emphasizes the importance of using certified Anti-Virus solutions to mitigate vulnerabilities and provides guidelines for both traditional and ESXi host-based Anti-Virus solutions. The document also includes revision history and troubleshooting steps for specific configurations and software updates.

Uploaded by

Fernando
Copyright
© © All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd
You are on page 1/ 62

SUIT

RELEASE 9.1

AntiVirus Quick Reference Guide


XXDOC-X589-en
January 2024
DISCLAIMER
This document contains Honeywell proprietary information.

Information contained herein is to be used solely for the purpose submitted, and no part of
this document or its contents shall be reproduced, published, or disclosed to a third party
without the express permission of Honeywell International Sàrl.

While this information is presented in good faith and believed to be accurate, Honeywell
disclaims the implied warranties of merchantability and fitness for a purpose and makes
no express warranties except as may be stated in its written agreement with and for its
customer.

In no event is Honeywell liable to anyone for any direct, special, or consequential damages.
The information and specifications in this document are subject to change without notice.

Copyright 2024- Honeywell International Sàrl

Anti-Virus Quick Reference Guide 2


Table of contents
1 ABOUT THIS GUIDE ......................................................................................................................................... 4
1.1 Scope ............................................................................................................................................................................ 4

1.2 Revision history ....................................................................................................................................................... 4

1.3 Intended audience ................................................................................................................................................. 5


2 ANTI-VIRUS SOFTWARE OVERVIEW ........................................................................................................ 6
2.1 Traditional Anti-Virus ............................................................................................................................................ 6

2.2 ESXi Host Based virus scanners as Antivirus Solution........................................................................ 7


3 ANTI-VIRUS CERTIFICATION ...................................................................................................................... 9
3.1 Overview ...................................................................................................................................................................... 9
3.2 Anti-Virus Certification Matrix ...................................................................................................................... 11
4 DISABLING WINDOWS DEFENDER........................................................................................................ 28
5 SYMANTEC CONFIGURATIONS STEPS TO AVOID LARGE DISK SPACE ...................................... 30
5.1 Steps to disable Tamper Protection........................................................................................................... 31
5.1.1 On Symantec Manager .................................................................................................................................31
5.1.2 On Symantec Clients ......................................................................................................................................33

5.2 To disable SymQual's monitor for specific applications or processes: .................................... 34


6 TROUBLESHOOTING ................................................................................................................................... 36
6.1 Disabling IESec option in Windows Server 2008/2008R2/2012 .............................................. 36

6.2 Disabling IESec option in Windows Server 2016 ................................................................................ 37


7 PRIOR RELEASES REVISION HISTORY .................................................................................................. 39
NOTICES ............................................................................................................................................................................ 60

Anti-Virus Quick Reference Guide 3


ABOUT THIS GUIDE

1 About this guide

1.1 Scope
This document identifies Anti-virus software certified for currently supported Windows
based HPS products.

1.2 Revision history


This section consists of revision history for recent releases. For the revision history
information related to older releases than the ones that are listed in the following table, see
the Prior Releases revision history.

Revision Date Description

8.58 24/05/2023 Added Symantec 14.3 RU 7 (14.3.9681.7000 )


certification details to “Anti-Virus Certification
Matrix”.

SEPM 14.3 RU6 and earlier build numbers and


release dates match the Symantec Endpoint
Protection client for Windows.

Added the Note on "On Demand Scan policy".


8.59 11/07/2023 Added "Trellix ENS 10.7.0 May 2023 Update (Security
Common 10.7.0.5828, Threat Prevention client
10.7.0.5786), Trellix Agent (5.7.9 )" support to the
"Anti-Virus ENS Certification Matrix”.

Added Note Information for latest on-Premises Trellix


ePO server 5.10 Service Pack 1 "ePO 5.10
(EPO5100_ServicePack1_4098_LR1)" for clean/fresh
installation in "Anti-Virus Certification Matrix".

Note:
Due to the transition from McAfee to Trellix in 2023,
McAfee decided to keep the legacy product names
without changing it to the Trellix, and few places in
our SUIT Anti-Virus documents, we could still refer to
McAfee. Kindly ignore the name change (McAfee to
Trellix) and suggested to proceed for further
steps/procedure.
8.60 4/09/2023 Added "Trellix ENS 10.7.0 May 2023 Update (Security
Common 10.7.0.5828, Threat Prevention client
10.7.0.5786), Trellix Agent (5.7.9.139 ) and
ePO_5.10.0_Servicepack1Update1" support to the
"Anti-Virus ENS Certification Matrix".

Anti-Virus Quick Reference Guide 4


ABOUT THIS GUIDE

Revision Date Description

9.0 10/11/2023 Added Symantec 14.3 RU 8 (14.3.10148.8000 )


certification details to “Anti-Virus Certification
Matrix”.

Added PHD R430.x certification details to “Anti-virus


Certification Matrix”.

Removed unsupported releases EPKS


R430,R431,R432,R500,R501,HS R500,R501 and LX-
PC R500,R501 from "Anti-Virus Certification Matrix".

Removed VSE from "Anti-Virus Certification Matrix".


9.1 12/01/2024 Added "Trellix ENS 10.7.0 September 2023 Update
(Security Common 10.7.0.6149, Threat Prevention
client 10.7.0.6177), Trellix Agent (5.8.0.161 ) and
epo_5.10.0_Servicepack1update2" support to the
"Anti-Virus Certification Matrix".

1.3 Intended audience


This guide is primarily intended for Honeywell field personnel who install and
configure the product.

1.4 Target Platforms


The target platforms defined in this document are all Windows (Workstations and
Servers) based HPS products, as well as those running on VMware ESXi virtualized
platforms.

Anti-Virus Quick Reference Guide 5


ANTI-VIRUS SOFTWARE OVERVIEW

2 Anti-Virus Software Overview

2.1 Traditional Anti-Virus


Many of the products provided by HPS are based on open-systems technologies such as
Microsoft Windows based platforms. These platforms are vulnerable to virus and malware
attacks. To reduce this vulnerability, Anti-Virus software is required on all Windows based
process control nodes. The use of Anti-Virus software is one element of a comprehensive
cyber security strategy.

Traditional Anti-Virus software is effective in preventing the spread of a virus from an


infected system. It will flag the fact that a virus has been detected and will either prompt
for corrective action or attempt to clean the virus prior to the infected file being accessed
by the system running Anti-Virus software.

Once Anti-Virus software is deployed, it must be kept up to date in order to remain


effective.

This includes the DAT files that should be updated by customers independent of
Honeywell’s certification. For customers requiring qualified DAT files, Honeywell provides a
secure automated distribution service to move to site only those DAT files which pass
system testing. Contact your local Account Manager for more information.

McAfee has introduced DAT Reputation feature for the DAT Files. McAfee
included a “Reputation engine” in their repositories starting May 6th. This
NOTE means some binaries will be installed on clients what will check the “cloud”
before installing DAT files.

This engine is included in the DAT file. The McAfee DAT Reputation feature
will be automatically enabled on May 19, 2015 even if the policy is not yet
configured. Honeywell does not recommend the usage of this feature.
Hence, kindly remove this McAfee point product “DAT Reputation Engine”
from the Master repository of the ePO to disable this feature, by default this
feature is not present in the ePO for use.

Procedure to Disable DAT Reputation feature for McAfee unmanaged clients: Open
regedit.exe and navigate to the following registry location:
HKLM\Software\McAfee\DATReputation. Then please make sure that the value named
"dwDisableDATReputation" should be set to 1 (TRUE).

The table in Section Error! Reference source not found. provides certified versions of
the various Anti-Virus software packages and update agents for the supported HPS
releases. To facilitate the use of Anti-Virus software on HPS provided systems,
various versions of specific Anti-Virus software packages have been certified for use
with each release of HPS software. For virtualized systems there is also an option of

Anti-Virus Quick Reference Guide 6


ANTI-VIRUS SOFTWARE OVERVIEW

using an ESXi host based Anti-Virus solution that does not require Anti-Virus agent
software to be directly installed into each virtual machine.

HPS requires the installation and use of Anti-Virus software on all Windows
based HPS products or use of an ESXi host based solution for Windows
NOTE virtual machines on that host.

2.2 ESXi Host Based virus scanners as Antivirus Solution


In today’s cyber world - advanced persistent threats (APTs) and the sophistication of
malware are evolving day by day. Traditional Anti-Virus scanner engines run on each VM.
Still more to say a virtual machine is shutdown, definition files can’t be kept up to date.
This might lead to virus scanner storms. More over Significant amount of wasted
resources expended inspecting these VMs which reduces consolidation ratios.

Traditional Anti-Virus Is Resource Intensive and not a viable anymore. So, running
endpoints without Anti-Virus is not an option. In comparison to past, emerging needs for
constant

protection has actually increased with the consolidation of data centers because activity at
the endpoint is now closer to critical data and servers than ever before.

Host-based antivirus solutions can offer opportunities to simplify administration while


reducing the potential complications that may accompany in-guest endpoint security
agents (such as scanner storms). Host-based options also free resources on the guest
operating systems while making it easier to protect new virtual machines.

The host-based endpoint security solution allows the virus scanner to run at a host level
rather than a virtual machines level. This allows for just one agent per virtualization host
server, thus reducing the number of agents and repositories required to maintain virus
definition files. The solution utilizes a Security Virtual Appliance (SVA) to provide antivirus
services to the associated virtual machines, and this node is delivered as an Open
Virtualization Format (OVF) package for easy deployment. McAfee MOVE (Management
for Optimized Virtual Environments) is the host-based solution qualified by SUIT for
supported HPS Products (product releases as applicable in the certification matrix table)
that are certified to run in virtualized environment protected.

Anti-Virus Quick Reference Guide 7


ANTI-VIRUS SOFTWARE OVERVIEW

Refer the following link:

Anti-Virus Software Guidelines for Virtualization Environment

Network introspection captures networking events such as AD login/logout


and all other normal networking traffic.
NOTE
This driver can be safely removed and does not affect AV if the AV is not
configured to use network introspection.

Follow the below link procedure to uninstall the NSX Network introspection
driver.

Link: https://kb.vmware.com/s/article/2149764

Anti-Virus Quick Reference Guide 8


ANTI-VIRUS CERTIFICATION

3 Anti-Virus Certification

3.1 Overview
Honeywell Certification Policy:

Honeywell periodically evaluates and certifies Anti-Virus software updates for all
supported Windows based HPS Products. This document identifies the current certified
Anti-Virus updates (N) along with the two previously certified releases of the Anti-Virus
updates (N-1, N-2). In some cases, Honeywell may choose to skip Anti-Virus update
certifications where the released updates are too close chronologically, or testing uncovers
issues with an update.

Honeywell certifies the Anti-Virus products with the specific configurations stated in this
document. Any other configurations and/or 3rd party product offerings not specifically
mentioned, including those from McAfee and Symantec are NOT certified by default.

Honeywell will define, test, and certify new Anti-Virus versions released by the
manufacturer no later than six months (180 days) for major releases and three months (90
days) from a minor Anti-Virus update.

We strongly recommend default settings for Anti-Virus. All optional features


must be disabled.
NOTE

Experion PKS R430, R431, and R432 (collectively known as R43x) is now
phased-out, Honeywell AV testing (both McAfee and Symantec) for Experion
ATTENTION R43x releases will continue under the following conditions:

1. Experion PKS R43x AV testing is intended to be available for


customers who have purchased the Microsoft Windows Server
2008 R2 and Windows 7 Extended Security Update (ESU) program
from Honeywell, and testing is intended to continue until such date
when the Microsoft ESU program ceases on January 13, 2023.

2. Experion PKS R43x AV testing will continue only on those AV


engines which were available at the time of the Experion PS R43x
phase out. No new AV engines will be qualified after an Experion
PKS release is phased out.

3. Honeywell’s ability to continue AV testing is contingent on McAfee


and Symantec’s continued support for the legacy operating
systems.

4. Customers may need to purchase extended AV support from


McAfee or Symantec to continue to receive access to updates.

AV testing is unavailable and not supported for phased-out releases prior to


Experion PKS R43x.

Anti-Virus Quick Reference Guide 9


ANTI-VIRUS CERTIFICATION

The “Anti-Virus Certification Matrix” in Section 1.2 defines the supported Anti-Virus versions for
the Windows based HPS products.

If a particular HPS Product Release does not appear in the “Anti- Virus
Certification Matrix” Table, please refer to Honeywell Product Support Policy
NOTE or TAC to determine if it is no longer under standard HPS Product. This
document covers only those releases that are under standard HPS support
and does not cover releases that are on special extended or contractual
support.

Symantec currently offers three anti-malware protection products:


“Endpoint Protection Small Business Edition”, “Endpoint Protection. Cloud”,
NOTE and “Endpoint Protection”. Honeywell only qualifies “Endpoint Protection”
for use on HPS products.

Any further queries regarding Business Flex should be directed to the


product manager through Honeywell TAC.

For virtualized systems, there is also an option of using an ESXi host based
Anti-Virus solution that does not require Anti-Virus agent software to be
NOTE directly installed into each virtual machine.

Symantec has modified the structure of the daily signature file starting from
Symantec End Point Protection Manager (SEPM) 14.3, and the files are not
CAUTION compatible with legacy versions of SEPM (i.e., SEPM 14.0\14.1\14.2).

Starting from 1st January-2022, Honeywell will qualify signatures only for
SEPM 14.3, and will no longer qualify daily signature for legacy versions of
SEPM prior to 14.3 (i.e., 14.0, 14.1, 14.2).

Honeywell recommends updating legacy versions of qualified Symantec


Endpoint products to version 14.3 before the end of the qualification cycle
to maintain signature qualification. For more information, refer KSM2021-
009.

Anti-Virus Quick Reference Guide 10


ANTI-VIRUS CERTIFICATION

McAfee is ending support for McAfee VirusScan (VSE) effective 31st

December 2021. Honeywell will cease testing for VSE with Experion PKS
CAUTION
R5xx releases. Honeywell has qualified McAfee Endpoint Security (ENS) for

currently supported releases of Experion PKS, including Experion PKS R50x,

Experion PKS R51x, and Experion PKS R520. McAfee ENS is the successor

to McAfee VSE and provides new security features, product enhancements

and improved agent performance over McAfee VSE.

For more information, refer KSM2021 042 - McAfee VirusScan Enterprise

(VSE) End of Support.

Effective December 31, 2021, Honeywell will cease testing for VSE with Experion PKS
R5xx releases. Honeywell has qualified McAfee Endpoint Security (ENS) for currently
supported releases of Experion PKS, including Experion PKS R50x, Experion PKS
NOTE R51x, and Experion PKS R520. McAfee ENS is the successor to McAfee VSE and
provides new security features, product enhancements and improved agent
performance over McAfee VSE. For the latest qualified build details, please refer the
Section 5.2.1 ENS 10.7.x build information [Nth release] table in the Anti-Virus
Software guide.

For phased-out Experion PKS R43x systems, Honeywell intends to continue


testing VSE for systems which have purchased both Microsoft Extended
Security Updates (ESU) from Honeywell and VSE Extended Support from
McAfee. Additional details for this extended coverage can be found in the
Honeywell Anti-Virus Software Guidelines, and this extended VSE testing for
Experion PKS R43x is intended to continue to January 13, 2023. Continued
testing for antivirus products is unavailable for phased-out releases prior to
Experion PKS R43x.

Reference information:

• McAfee KB93335:
NOTE
https://kcm.trellix.com/corporate/index?page=content&id=KB93335&actp=
null&viewlocale=en_US&showDraft=false&platinum_status=false&locale=en_US

• KSM2021 042 - McAfee VirusScan Enterprise (VSE) End of Support"

3.2 Anti-Virus Certification Matrix


The table following the legend table lists all the certified and approved Anti-Virus
component combinations for Windows based HPS Products.

Anti-Virus Quick Reference Guide 11


ANTI-VIRUS CERTIFICATION

This document is for quick reference only; refer to the “Anti-Virus Software
Guidelines” document for complete installation, configuration,
CAUTION maintenance, and revision history details.

Table Legend
1. The release number for the Windows based HPS Products listed in the
matrix indicates the latest point release within the supported release
series, which is actively tested with the latest certified Anti-Virus software.
The certification results are however valid to the prior point releases, which
are currently supported even though those are not effectively tested.

2. The latest certified Anti-Virus software is indicated by the Blue shaded


rows.

3. Previously certified Anti-Virus software but no longer in test by Honeywell is


indicated by white background rows.

4. N/A means Not Applicable. For example, the release has not been tested
with prior versions of Anti-Virus software.

Honeywell recommends installing only the latest Honeywell qualified


Antivirus software as shown in this Certification Matrix. Customers are
NOTE requested to maintain their own copy latest Honeywell qualified Installation
Packages of McAfee or Symantec Anti-Virus, since these files will not be
available in AV vendors’ websites whenever newer packages yet to be
qualified by Honeywell are released.

Table. 1. Notation for Bunch of Hot fixes


Notation Bunch of Hot fixes
HF *A EPO988208, EPO983758

EPOHF988208, EPOHF983758-2, EPO511HF1,


EPOHF1014944, EPOHF1016843,
EPO511HF1038703, EPOHF1014944,
HF *B
EPOHF1016843

HF1080544, , EPO5xHF1147158,
HF *C EPO5xHF1151890, HF1159675

EPO5xHF1178101, EPO532HF1167013,
HF *D EPO5xHF1179774

Anti-Virus Quick Reference Guide 12


ANTI-VIRUS CERTIFICATION

Sl.No Product Family Latest


Point
Release (X)

1 Experion PKS/EAPP R520.x 2

2 Experion PKS/EAPP R511.x 5

3 Experion PKS/EAPP R510.x 2

4 SM 212.x 1

5 SM 211.x 1

6 SM 210.x 4

7 SM R162.x 7

8 SM R161.x 1

9 SM R153.x 3

10 SM R146.x 5

11 FSC R801.x 1

12 FSC R710.x 9

13 UPS R323.x 2

14 PHD R430.x 1

15 PHD R410.x 1

16 PHD R400.x 1

17 PBM R511.x 1

18 PBM R510.x 3

19 PBM R501.x 3

20 PBM R500.x 2

21 PBM R431.x 4

Anti-Virus Quick Reference Guide 13


ANTI-VIRUS CERTIFICATION

Sl.No Product Family Latest


Point
Release (X)

22 BMA R430.x 4

23 BMA R410.x 6

24 BMA R401.x 5

25 BMA R400.x 4

26 RAE R61X.x 1

27 Experion MX/MX Proline R704.x 1

28 Experion MX/MX Proline R720.x 1

29 RAE R700.x 5

30 RAE R701.x 4

31 RAE R702.x 3

32 RAE R703.x 1

33 QCS SE R1XX.x 1

34 PMD R800.x 3

35 PMD R830.x 1

36 PMD R831.x 2

37 PMD R900.x 2

38 PMD R910.x 2

39 PMD R920.x 2

40 APC Suite R513.x 1

41 Profit Suite R502.x 1

42 Profit Suite R442.x 1

43 CPA R610.x 1

Anti-Virus Quick Reference Guide 14


ANTI-VIRUS CERTIFICATION

Sl.No Product Family Latest


Point
Release (X)

44 CPM R603.x 1

45 CPM R602.x 1

The last supported VSE in ePO server using managed mode is ePO 5.10
update 10. From ePO 5.10 update 11 onwards, users should migrate to ENS
NOTE 10.7.x for manage mode.

1. After January 11th 2023, Honeywell will no longer qualify VSE DAT
file for EPKS R43x releases. Refer KSM20210 42 for more details.
NOTE
2. Broadcom Symantec has made changes in the naming convention
of their daily released signature files. Broadcom Symantec is
sharing signature files in the format “core3sdsi64.jdb/
core3sdssepv5i64.exe” for SEP 14.3 RU4 (Refresh) or prior, and for
SEP14.3 RU5, signature files are being released in the format
“core3sdsn64.jdb/core3sdssepn64v5i64.exe”. SUIT Team will start
sharing signature files for both SEP RU4 and RU5 versions from 1st
December 2022 onwards till 28th February 2023. From 1st March
2023 onwards, SUIT team will stop sharing signature files for SEP
14.3 RU4 and will continue to share signature files only for SEP
14.3 RU5.

Table. 2. Anti-Virus-Certification matrix


Certified Versions
Trellix Components
HPS Product Releases ENS 10.7.0 Symantec Broadcom
ePO and Agent
Security Platform Threat Prevention
ePO_5.10.0_Serv
ENS Security Threat
icepack1update SEP 14.3 RU 8
Common Prevention client
2 (14.3.10148.8000)
10.7.0.6149 10.7.0.6177
Experion PKS/EAPP and Agent 5.8.0
R520.x ePO_5.10.0_Serv
ENS Security Threat
icepack1Update SEP 14.3 RU 7
Common Prevention client
1 (14.3.9681.7000)
10.7.0.5828 10.7.0.5786
and Agent 5.7.9

Anti-Virus Quick Reference Guide 15


ANTI-VIRUS CERTIFICATION

Certified Versions
Trellix Components
HPS Product Releases ENS 10.7.0 Symantec Broadcom
ePO and Agent
Security Platform Threat Prevention
ENS Security Threat
ePO 5.10 U15 SEP 14.3 RU 6
Common Prevention client
and Agent 5.7.9 (14.3.9203.6000)
10.7.0.5828 10.7.0.5786
ePO_5.10.0_Serv
ENS Security Threat
icepack1update SEP 14.3 RU 8
Common Prevention client
2 (14.3.10148.8000)
10.7.0.6149 10.7.0.6177
and Agent 5.8.0
ePO_5.10.0_Serv
Experion PKS/EAPP ENS Security Threat
icepack1Update SEP 14.3 RU 7
R511.x Common Prevention client
1 (14.3.9681.7000)
10.7.0.5828 10.7.0.5786
and Agent 5.7.9
ENS Security Threat
ePO 5.10 U15 SEP 14.3 RU 6
Common Prevention client
and Agent 5.7.9 (14.3.9203.6000)
10.7.0.5828 10.7.0.5786
ePO_5.10.0_Serv
ENS Security Threat
icepack1update SEP 14.3 RU 8
Common Prevention client
2 (14.3.10148.8000)
10.7.0.6149 10.7.0.6177
and Agent 5.8.0
ePO_5.10.0_Serv
Experion PKS/EAPP ENS Security Threat
icepack1Update SEP 14.3 RU 7
R510.x Common Prevention client
1 (14.3.9681.7000)
10.7.0.5828 10.7.0.5786
and Agent 5.7.9
ENS Security Threat
ePO 5.10 U15 SEP 14.3 RU 6
Common Prevention client
and Agent 5.7.9 (14.3.9203.6000)
10.7.0.5828 10.7.0.5786
ePO_5.10.0_Serv
ENS Security Threat
icepack1update SEP 14.3 RU 8
Common Prevention client
2 (14.3.10148.8000)
10.7.0.6149 10.7.0.6177
and Agent 5.8.0
ePO_5.10.0_Serv
ENS Security Threat
Experion HS R520.x icepack1Update SEP 14.3 RU 7
Common Prevention client
1 (14.3.9681.7000)
10.7.0.5828 10.7.0.5786
and Agent 5.7.9
ENS Security Threat
ePO 5.10 U15 SEP 14.3 RU 6
Common Prevention client
and Agent 5.7.9 (14.3.9203.6000)
10.7.0.5828 10.7.0.5786
ePO_5.10.0_Serv
ENS Security Threat
icepack1update SEP 14.3 RU 8
Common Prevention client
2 (14.3.10148.8000)
10.7.0.6149 10.7.0.6177
Experion HS R511.x/R and Agent 5.8.0
510.x ePO_5.10.0_Serv
ENS Security Threat
icepack1Update SEP 14.3 RU 7
Common Prevention client
1 (14.3.9681.7000)
10.7.0.5828 10.7.0.5786
and Agent 5.7.9
Anti-Virus Quick Reference Guide 16
ANTI-VIRUS CERTIFICATION

Certified Versions
Trellix Components
HPS Product Releases ENS 10.7.0 Symantec Broadcom
ePO and Agent
Security Platform Threat Prevention
ENS Security Threat
ePO 5.10 U15 SEP 14.3 RU 6
Common Prevention client
and Agent 5.7.9 (14.3.9203.6000)
10.7.0.5828 10.7.0.5786
ePO_5.10.0_Serv
ENS Security Threat
icepack1update SEP 14.3 RU 8
Common Prevention client
2 (14.3.10148.8000)
10.7.0.6149 10.7.0.6177
and Agent 5.8.0
ePO_5.10.0_Serv
ENS Security Threat
SM R212.x icepack1Update SEP 14.3 RU 7
Common Prevention client
1 (14.3.9681.7000)
10.7.0.5828 10.7.0.5786
and Agent 5.7.9
ENS Security Threat
ePO 5.10 U15 SEP 14.3 RU 6
Common Prevention client
and Agent 5.7.9 (14.3.9203.6000)
10.7.0.5828 10.7.0.5786
ePO_5.10.0_Serv
ENS Security Threat
icepack1update SEP 14.3 RU 8
Common Prevention client
2 (14.3.10148.8000)
10.7.0.6149 10.7.0.6177
SM and Agent 5.8.0
R211.x/210.x/201.x/200 ePO_5.10.0_Serv
ENS Security Threat
.x/162.x icepack1Update SEP 14.3 RU 7
Common Prevention client
161.x/R160.x/R153.x/R 1 (14.3.9681.7000)
10.7.0.5828 10.7.0.5786
146.x and Agent 5.7.9
ENS Security Threat
ePO 5.10 U15 SEP 14.3 RU 6
Common Prevention client
and Agent 5.7.9 (14.3.9203.6000)
10.7.0.5828 10.7.0.5786
ePO_5.10.0_Serv
ENS Security Threat
icepack1update SEP 14.3 RU 8
Common Prevention client
2 (14.3.10148.8000)
10.7.0.6149 10.7.0.6177
and Agent 5.8.0
ePO_5.10.0_Serv
ENS Security Threat
FSC 801.x/R710.x icepack1Update SEP 14.3 RU 7
Common Prevention client
1 (14.3.9681.7000)
10.7.0.5828 10.7.0.5786
and Agent 5.7.9
ENS Security Threat
ePO 5.10 U15 SEP 14.3 RU 6
Common Prevention client
and Agent 5.7.9 (14.3.9203.6000)
10.7.0.5828 10.7.0.5786
ePO_5.10.0_Serv
ENS Security Threat
icepack1update SEP 14.3 RU 8
Common Prevention client
2 (14.3.10148.8000)
10.7.0.6149 10.7.0.6177
and Agent 5.8.0
LX/PC R520.x
ePO_5.10.0_Serv
ENS Security Threat
icepack1Update SEP 14.3 RU 7
Common Prevention client
1 (14.3.9681.7000)
10.7.0.5828 10.7.0.5786
and Agent 5.7.9
Anti-Virus Quick Reference Guide 17
ANTI-VIRUS CERTIFICATION

Certified Versions
Trellix Components
HPS Product Releases ENS 10.7.0 Symantec Broadcom
ePO and Agent
Security Platform Threat Prevention
ENS Security Threat
ePO 5.10 U15 SEP 14.3 RU 6
Common Prevention client
and Agent 5.7.9 (14.3.9203.6000)
10.7.0.5828 10.7.0.5786
ePO_5.10.0_Serv
ENS Security Threat
icepack1update SEP 14.3 RU 8
Common Prevention client
2 (14.3.10148.8000)
10.7.0.6149 10.7.0.6177
and Agent 5.8.0
ePO_5.10.0_Serv
ENS Security Threat
LX/PC R511.x/R510.x icepack1Update SEP 14.3 RU 7
Common Prevention client
1 (14.3.9681.7000)
10.7.0.5828 10.7.0.5786
and Agent 5.7.9
ENS Security Threat
ePO 5.10 U15 SEP 14.3 RU 6
Common Prevention client
and Agent 5.7.9 (14.3.9203.6000)
10.7.0.5828 10.7.0.5786
ePO_5.10.0_Serv
ENS Security Threat
icepack1update SEP 14.3 RU 8
Common Prevention client
2 (14.3.10148.8000)
10.7.0.6149 10.7.0.6177
and Agent 5.8.0
ePO_5.10.0_Serv
PA ENS Security Threat
icepack1Update SEP 14.3 RU 7
R520.x Common Prevention client
1 (14.3.9681.7000)
10.7.0.5828 10.7.0.5786
and Agent 5.7.9
ENS Security Threat
ePO 5.10 U15 SEP 14.3 RU 6
Common Prevention client
and Agent 5.7.9 (14.3.9203.6000)
10.7.0.5828 10.7.0.5786
ePO_5.10.0_Serv
ENS Security Threat
icepack1update SEP 14.3 RU 8
Common Prevention client
2 (14.3.10148.8000)
10.7.0.6149 10.7.0.6177
and Agent 5.8.0
ePO_5.10.0_Serv
PA ENS Security Threat
icepack1Update SEP 14.3 RU 7
R511.x/R510.x Common Prevention client
1 (14.3.9681.7000)
10.7.0.5828 10.7.0.5786
and Agent 5.7.9
ENS Security Threat
ePO 5.10 U15 SEP 14.3 RU 6
Common Prevention client
and Agent 5.7.9 (14.3.9203.6000)
10.7.0.5828 10.7.0.5786
ePO_5.10.0_Serv
ENS Security Threat
icepack1update SEP 14.3 RU 8
Common Prevention client
2 (14.3.10148.8000)
10.7.0.6149 10.7.0.6177
and Agent 5.8.0
FDM R520.x
ePO_5.10.0_Serv
ENS Security Threat
icepack1Update SEP 14.3 RU 7
Common Prevention client
1 (14.3.9681.7000)
10.7.0.5828 10.7.0.5786
and Agent 5.7.9
Anti-Virus Quick Reference Guide 18
ANTI-VIRUS CERTIFICATION

Certified Versions
Trellix Components
HPS Product Releases ENS 10.7.0 Symantec Broadcom
ePO and Agent
Security Platform Threat Prevention
ENS Security Threat
ePO 5.10 U15 SEP 14.3 RU 6
Common Prevention client
and Agent 5.7.9 (14.3.9203.6000)
10.7.0.5828 10.7.0.5786
ePO_5.10.0_Serv
ENS Security Threat
icepack1update SEP 14.3 RU 8
Common Prevention client
2 (14.3.10148.8000)
10.7.0.6149 10.7.0.6177
and Agent 5.8.0
ePO_5.10.0_Serv
ENS Security Threat
FDM R511.x icepack1Update SEP 14.3 RU 7
Common Prevention client
1 (14.3.9681.7000)
10.7.0.5828 10.7.0.5786
and Agent 5.7.9
ENS Security Threat
ePO 5.10 U15 SEP 14.3 RU 6
Common Prevention client
and Agent 5.7.9 (14.3.9203.6000)
10.7.0.5828 10.7.0.5786
ePO_5.10.0_Serv
ENS Security Threat
icepack1update SEP 14.3 RU 8
Common Prevention client
2 (14.3.10148.8000)
10.7.0.6149 10.7.0.6177
and Agent 5.8.0
ePO_5.10.0_Serv
ENS Security Threat
EBR R520.x icepack1Update SEP 14.3 RU 7
Common Prevention client
1 (14.3.9681.7000)
10.7.0.5828 10.7.0.5786
and Agent 5.7.9
ENS Security Threat
ePO 5.10 U15 SEP 14.3 RU 6
Common Prevention client
and Agent 5.7.9 (14.3.9203.6000)
10.7.0.5828 10.7.0.5786
ePO_5.10.0_Serv
ENS Security Threat
icepack1update SEP 14.3 RU 8
Common Prevention client
2 (14.3.10148.8000)
10.7.0.6149 10.7.0.6177
and Agent 5.8.0
ePO_5.10.0_Serv
ENS Security Threat
SH 202.x icepack1Update SEP 14.3 RU 7
Common Prevention client
1 (14.3.9681.7000)
10.7.0.5828 10.7.0.5786
and Agent 5.7.9
ENS Security Threat
ePO 5.10 U15
Common Prevention client NA
and Agent 5.7.9
10.7.0.5828 10.7.0.5786
ePO_5.10.0_Serv
ENS Security Threat
icepack1update SEP 14.3 RU 8
Common Prevention client
2 (14.3.10148.8000)
10.7.0.6149 10.7.0.6177
and Agent 5.8.0
SH 201.x/200.x
ePO_5.10.0_Serv
ENS Security Threat
icepack1Update SEP 14.3 RU 7
Common Prevention client
1 (14.3.9681.7000)
10.7.0.5828 10.7.0.5786
and Agent 5.7.9
Anti-Virus Quick Reference Guide 19
ANTI-VIRUS CERTIFICATION

Certified Versions
Trellix Components
HPS Product Releases ENS 10.7.0 Symantec Broadcom
ePO and Agent
Security Platform Threat Prevention
ENS Security Threat
ePO 5.10 U15 SEP 14.3 RU 6
Common Prevention client
and Agent 5.7.9 (14.3.9203.6000)
10.7.0.5828 10.7.0.5786
ePO_5.10.0_Serv
ENS Security Threat
icepack1update SEP 14.3 RU 8
Common Prevention client
2 (14.3.10148.8000)
10.7.0.6149 10.7.0.6177
and Agent 5.8.0
PHD 430.x
NA NA NA NA

NA NA NA NA

ePO_5.10.0_Serv
ENS Security Threat
icepack1update SEP 14.3 RU 8
Common Prevention client
2 (14.3.10148.8000)
10.7.0.6149 10.7.0.6177
and Agent 5.8.0
ePO_5.10.0_Serv
ENS Security Threat
PHD 410.x icepack1Update SEP 14.3 RU 7
Common Prevention client
1 (14.3.9681.7000)
10.7.0.5828 10.7.0.5786
and Agent 5.7.9
ENS Security Threat
ePO 5.10 U15 SEP 14.3 RU 6
Common Prevention client
and Agent 5.7.9 (14.3.9203.6000)
10.7.0.5828 10.7.0.5786
ePO_5.10.0_Serv
ENS Security Threat
icepack1update SEP 14.3 RU 8
Common Prevention client
2 (14.3.10148.8000)
10.7.0.6149 10.7.0.6177
and Agent 5.8.0
ePO_5.10.0_Serv
ENS Security Threat
PHD 400.x icepack1Update SEP 14.3 RU 7
Common Prevention client
1 (14.3.9681.7000)
10.7.0.5828 10.7.0.5786
and Agent 5.7.9
ENS Security Threat
ePO 5.10 U15 SEP 14.3 RU 6
Common Prevention client
and Agent 5.7.9 (14.3.9203.6000)
10.7.0.5828 10.7.0.5786
ePO_5.10.0_Serv
ENS Security Threat
icepack1update SEP 14.3 RU 8
Common Prevention client
2 (14.3.10148.8000)
10.7.0.6149 10.7.0.6177
UPS and Agent 5.8.0
R323.x ePO_5.10.0_Serv
ENS Security Threat
icepack1Update SEP 14.3 RU 7
Common Prevention client
1 (14.3.9681.7000)
10.7.0.5828 10.7.0.5786
and Agent 5.7.9

Anti-Virus Quick Reference Guide 20


ANTI-VIRUS CERTIFICATION

Certified Versions
Trellix Components
HPS Product Releases ENS 10.7.0 Symantec Broadcom
ePO and Agent
Security Platform Threat Prevention
ENS Security Threat
ePO 5.10 U15 SEP 14.3 RU 6
Common Prevention client
and Agent 5.7.9 (14.3.9203.6000)
10.7.0.5828 10.7.0.5786
ePO_5.10.0_Serv
ENS Security Threat
icepack1update
Common Prevention client SEP 14.3 RU 8
2
10.7.0.6149 10.7.0.6177
and Agent 5.8.0
ePO_5.10.0_Serv
Experion MX/MX Proline ENS Security Threat
icepack1Update
R720.x Common Prevention client SEP 14.3 RU 7
1
10.7.0.5828 10.7.0.5786
and Agent 5.7.9

NA NA NA SEP 14.3 RU 6

ePO_5.10.0_Serv
ENS Security Threat
icepack1update
Common Prevention client SEP 14.3 RU 8
2
10.7.0.6149 10.7.0.6177
and Agent 5.8.0
ePO_5.10.0_Serv
Experion MX/MX Proline ENS Security Threat
icepack1Update
R704.x Common Prevention client SEP 14.3 RU 7
1
10.7.0.5828 10.7.0.5786
and Agent 5.7.9
SEP 14.3 RU 6
NA NA NA
(Refresh)
ePO_5.10.0_Serv
ENS Security Threat
icepack1update
Common Prevention client SEP 14.3 RU 8
2
10.7.0.6149 10.7.0.6177
and Agent 5.8.0
ePO_5.10.0_Serv
Experion MX/MX Proline ENS Security Threat
icepack1Update
R703.x Common Prevention client SEP 14.3 RU 7
1
10.7.0.5828 10.7.0.5786
and Agent 5.7.9
ENS Security Threat
ePO 5.10 U15 SEP 14.3 RU 6
Common Prevention client
and Agent 5.7.8 (Refresh)
10.7.0.5162 10.7.0.5200
ENS Security Threat
ePO 5.10 U13 SEP 14.3 RU4
Common Prevention client
and Agent 5.7.6 (Refresh)
Experion MX/MX Proline 10.7.0.3255 10.7.0.3299
R700.x/R701.x/R702.x ENS Security Threat
ePO 5.10 U12 SEP 14.3 MP1
Common Prevention client
and Agent 5.7.5 (Refresh)
10.7.0.3199 10.7.0.3210

Anti-Virus Quick Reference Guide 21


ANTI-VIRUS CERTIFICATION

Certified Versions
Trellix Components
HPS Product Releases ENS 10.7.0 Symantec Broadcom
ePO and Agent
Security Platform Threat Prevention
ENS Security Threat
ePO 5.10 U11
Common Prevention client SEP 14.3 MP1
and Agent 5.7.4
10.7.0.3012 10.7.0.3113
ENS Security Threat ePO_5.10.0_Serv SEP 14.3 RU 8
Common Prevention client icepack1update (14.3.10148.8000)
10.7.0.6149 10.7.0.6177 2 and Agent
5.8.0
QCS SE R120.x NA NA NA NA

NA NA NA NA

ENS Security Threat ePO_5.10.0_Serv SEP 14.3 RU 8


Common Prevention client icepack1update (14.3.10148.8000)
10.7.0.6149 10.7.0.6177 2 and Agent
5.8.0
ENS Security Threat ePO 5.10 U13 SEP 14.3 RU4
QCS SE R110.x
Common Prevention client and Agent 5.7.6 (Refresh)
10.7.0.3255 10.7.0.3299
ENS Security Threat ePO 5.10 U12 SEP 14.3 RU4
Common Prevention client and Agent 5.7.5 (Refresh)
10.7.0.3199 10.7.0.3210
ePO_5.10.0_Serv
ENS Security Threat
icepack1update SEP 14.3 RU 8
Common Prevention client
2 (14.3.10148.8000)
10.7.0.6149 10.7.0.6177
and Agent 5.8.0
ePO_5.10.0_Serv
DynAMo D & E \ ACM ENS Security Threat
icepack1Update SEP 14.3 RU 7
R321(ACM, AEA, UA) Common Prevention client
1 (14.3.9681.7000)
10.7.0.5828 10.7.0.5786
and Agent 5.7.9
ENS Security Threat
ePO 5.10 U15 SEP 14.3 RU 6
Common Prevention client
and Agent 5.7.9 (14.3.9203.6000)
10.7.0.5828 10.7.0.5786
ePO_5.10.0_Serv
ENS Security Threat
icepack1update
Common Prevention client NA
2
10.7.0.6149 10.7.0.6177
and Agent 5.8.0
Dynamo M&R R221.x
NA NA NA NA

NA NA NA NA

Anti-Virus Quick Reference Guide 22


ANTI-VIRUS CERTIFICATION

Certified Versions
Trellix Components
HPS Product Releases ENS 10.7.0 Symantec Broadcom
ePO and Agent
Security Platform Threat Prevention
ePO_5.10.0_Serv
ENS Security Threat
icepack1update SEP 14.3 RU 8
Common Prevention client
2 (14.3.10148.8000)
10.7.0.6149 10.7.0.6177
and Agent 5.8.0
ePO_5.10.0_Serv
ENS Security Threat
icepack1Update SEP 14.3 RU 7
Dynamo M&R R220.x Common Prevention client
1 (14.3.9681.7000)
10.7.0.5828 10.7.0.5786
and Agent 5.7.9
SEP 14.3 RU 6
ENS Security Threat
ePO 5.10 U15 (14.3.9203.6000)
Common Prevention client
and Agent 5.7.9
10.7.0.5828 10.7.0.5786
ePO_5.10.0_Serv
ENS Security Threat
icepack1update SEP 14.3 RU 8
Common Prevention client
2 (14.3.10148.8000)
10.7.0.6149 10.7.0.6177
and Agent 5.8.0
ePO_5.10.0_Serv
ENS Security Threat
Dynamo M&R R120.x icepack1Update SEP 14.3 RU 7
Common Prevention client
1 (14.3.9681.7000)
10.7.0.5828 10.7.0.5786
and Agent 5.7.9
ENS Security Threat
ePO 5.10 U15 SEP 14.3 RU 6
Common Prevention client
and Agent 5.7.9 (14.3.9203.6000)
10.7.0.5828 10.7.0.5786
ePO_5.10.0_Serv
ENS Security Threat
icepack1update SEP 14.3 RU 8
Common Prevention client
2 (14.3.10148.8000)
10.7.0.6149 10.7.0.6177
and Agent 5.8.0
ePO_5.10.0_Serv
Dynamo M&R ENS Security Threat
icepack1Update SEP 14.3 RU 7
R20X.x\R21X.x Common Prevention client
1 (14.3.9681.7000)
10.7.0.5828 10.7.0.5786
and Agent 5.7.9
ENS Security Threat
ePO 5.10 U15 SEP 14.3 RU 6
Common Prevention client
and Agent 5.7.9 (14.3.9203.6000)
10.7.0.5828 10.7.0.5786
ePO_5.10.0_Serv
ENS Security Threat
icepack1update SEP 14.3 RU 8
Common Prevention client
2 (14.3.10148.8000)
10.7.0.6149 10.7.0.6177
Alarm Manager MoC and Agent 5.8.0
R306 ePO_5.10.0_Serv
ENS Security Threat
icepack1Update SEP 14.3 RU 7
Common Prevention client
1 (14.3.9681.7000)
10.7.0.5828 10.7.0.5786
and Agent 5.7.9

Anti-Virus Quick Reference Guide 23


ANTI-VIRUS CERTIFICATION

Certified Versions
Trellix Components
HPS Product Releases ENS 10.7.0 Symantec Broadcom
ePO and Agent
Security Platform Threat Prevention
ENS Security Threat
ePO 5.10 U15 SEP 14.3 RU 6
Common Prevention client
and Agent 5.7.9 (14.3.9203.6000)
10.7.0.5828 10.7.0.5786
ePO_5.10.0_Serv
ENS Security Threat
icepack1update SEP 14.3 RU 8
Common Prevention client
2 (14.3.10148.8000)
10.7.0.6149 10.7.0.6177
and Agent 5.8.0
ePO_5.10.0_Serv
ENS Security Threat
CPA R610.x icepack1Update SEP 14.3 RU 7
Common Prevention client
1 (14.3.9681.7000)
10.7.0.5828 10.7.0.5786
and Agent 5.7.9
ENS Security Threat
ePO 5.10 U15 SEP 14.3 RU 6
Common Prevention client
and Agent 5.7.9 (14.3.9203.6000)
10.7.0.5828 10.7.0.5786
ePO_5.10.0_Serv
ENS Security Threat
icepack1update SEP 14.3 RU 8
Common Prevention client
2 (14.3.10148.8000)
10.7.0.6149 10.7.0.6177
and Agent 5.8.0
ePO_5.10.0_Serv
ENS Security Threat
CPM R603.x icepack1Update SEP 14.3 RU 7
Common Prevention client
1 (14.3.9681.7000)
10.7.0.5828 10.7.0.5786
and Agent 5.7.9
ENS Security Threat
ePO 5.10 U15 SEP 14.3 RU 6
Common Prevention client
and Agent 5.7.9 (14.3.9203.6000)
10.7.0.5828 10.7.0.5786
ePO_5.10.0_Serv
ENS Security Threat
icepack1update SEP 14.3 RU 8
Common Prevention client
2 (14.3.10148.8000)
10.7.0.6149 10.7.0.6177
and Agent 5.8.0
ePO_5.10.0_Serv
ENS Security Threat
CPM R602.x icepack1Update SEP 14.3 RU 7
Common Prevention client
1 (14.3.9681.7000)
10.7.0.5828 10.7.0.5786
and Agent 5.7.9
ENS Security Threat
ePO 5.10 U15 SEP 14.3 RU 6
Common Prevention client
and Agent 5.7.9 (14.3.9203.6000)
10.7.0.5828 10.7.0.5786
ePO_5.10.0_Serv
ENS Security Threat
icepack1update SEP 14.3 RU 8
Common Prevention client
2 (14.3.10148.8000)
10.7.0.6149 10.7.0.6177
APCSuite and Agent 5.8.0
R513.x ePO_5.10.0_Serv
ENS Security Threat
icepack1Update SEP 14.3 RU 7
Common Prevention client
1 (14.3.9681.7000)
10.7.0.5828 10.7.0.5786
and Agent 5.7.9
Anti-Virus Quick Reference Guide 24
ANTI-VIRUS CERTIFICATION

Certified Versions
Trellix Components
HPS Product Releases ENS 10.7.0 Symantec Broadcom
ePO and Agent
Security Platform Threat Prevention
ENS Security Threat
ePO 5.10 U15 SEP 14.3 RU 6
Common Prevention client
and Agent 5.7.9 (14.3.9203.6000)
10.7.0.5828 10.7.0.5786
ePO_5.10.0_Serv
ENS Security Threat
icepack1update SEP 14.3 RU 8
Common Prevention client
2 (14.3.10148.8000)
10.7.0.6149 10.7.0.6177
and Agent 5.8.0
ePO_5.10.0_Serv
ENS Security Threat
Profit Suite R502.x icepack1Update SEP 14.3 RU 7
Common Prevention client
1 (14.3.9681.7000)
10.7.0.5828 10.7.0.5786
and Agent 5.7.9
ENS Security Threat
ePO 5.10 U15 SEP 14.3 RU 6
Common Prevention client
and Agent 5.7.9 (14.3.9203.6000)
10.7.0.5828 10.7.0.5786
ePO_5.10.0_Serv
ENS Security Threat
icepack1update SEP 14.3 RU 8
Common Prevention client
2 (14.3.10148.8000)
10.7.0.6149 10.7.0.6177
and Agent 5.8.0
ePO_5.10.0_Serv
ENS Security Threat
Profit Suite R442.x icepack1Update SEP 14.3 RU 7
Common Prevention client
1 (14.3.9681.7000)
10.7.0.5828 10.7.0.5786
and Agent 5.7.9
ENS Security Threat
ePO 5.10 U15 SEP 14.3 RU 6
Common Prevention client
and Agent 5.7.9 (14.3.9203.6000)
10.7.0.5828 10.7.0.5786
ENS Security Threat
ePO 5.10 U15
Common Prevention client SEP 14.3 RU 6
and Agent 5.7.9
10.7.0.5828 10.7.0.5786
ENS Security Threat
PMD ePO 5.10 U13
Common Prevention client NA
R920.x and Agent 5.7.6
10.7.0.3255 10.7.0.3299

NA NA NA NA

ENS Security Threat


ePO 5.10 U15
Common Prevention client SEP 14.3 RU6
and Agent 5.7.9
10.7.0.5828 10.7.0.5786
ENS Security Threat
PMD ePO 5.10 U13
Common Prevention client SEP 14.3 RU2
R910.x and Agent 5.7.6
10.7.0.3255 10.7.0.3299
SEP 14.3 RU1
NA NA NA
(Refresh)

Anti-Virus Quick Reference Guide 25


ANTI-VIRUS CERTIFICATION

Certified Versions
Trellix Components
HPS Product Releases ENS 10.7.0 Symantec Broadcom
ePO and Agent
Security Platform Threat Prevention
ENS Security Threat
ePO 5.10 U13 SEP 14.3 RU1
Common Prevention client
and Agent 5.7.6 (Refresh)
10.7.0.3255 10.7.0.3299
SEP 14.2 RU2
NA NA NA
MP1
PMD
SEP14.2.1.1 (14.2
R900.1x
RU1 MP1)

NA NA NA

ENS Security Threat


ePO 5.10 U11
Common Prevention client NA
and Agent 5.7.4
10.7.0.3012 10.7.0.3113

FBM520.1/EPKS 511.5 NA NA NA NA

NA NA NA NA

ENS Security Threat


ePO 5.10 U15
Common Prevention client NA
and Agent 5.7.8
10.7.0.5162 10.7.0.5200

PBM R511.x NA NA NA NA

NA NA NA NA

ENS Security Threat


ePO 5.10 U15 SEP 14.3 RU1
Common Prevention client
and Agent 5.7.8 (Refresh)
10.7.0.5162 10.7.0.5200

NA NA NA SEP 12 .1 RU2
PBM R510.x

SEP 12 .1 RU1
NA NA NA

Anti-Virus Quick Reference Guide 26


ANTI-VIRUS CERTIFICATION

Certified Versions
Trellix Components
HPS Product Releases ENS 10.7.0 Symantec Broadcom
ePO and Agent
Security Platform Threat Prevention
ENS Security Threat
ePO 5.10 U11 SEP 14.3 RU1
Common Prevention client
and Agent 5.7.4 (Refresh)
10.7.0.3012 10.7.0.3113
PBM
NA NA NA SEP 12 .1 RU2
R501.3/EPKS501.6

NA NA NA SEP 12 .1 RU1

Table. 3. Anti-Virus -Certification matrix


VSE + ASE 8.8 Patch5 & above and ePO Agent 5.0.0 & above & applicable for
RAE R612.4 & R614.3 point release onwards only.
NOTE

McAfee products like ePolicy Orchestrator (ePO) and Agent will be


rebranded to Trellix. For more informaiton please refere the below links
NOTE KB93773 and KB95905:

https://kcm.trellix.com/corporate/index?page=content&id=KB93773

https://kcm.trellix.com/corporate/index?page=content&id=KB95905

Whenever the user encounters the installation failure/rollback of VSE/ENS


packages using from managed or unmanaged mode to their client nodes,
NOTE verify whether the root certificates are updated and then continue to deploy
the VSE/ENS packages on these client nodes.

https://kc.mcafee.com/corporate/index?page=content&id=KB87096

Do not install VSE + ASE 8.8 Patch5 & above and ePO Agent 5.0.0 & above
prior to RAE R612.4 & R614.3 point release, RAE application will not work.
CAUTION
For details, Refer QCS Compatibility matrix.

Please refer section "5.2.3 McAfee Endpoint Security 10.7.x media


description" for the latest McAfee ENS build details.
CAUTION

Anti-Virus Quick Reference Guide 27


DISABLING WINDOWS DEFENDER

4 Disabling Windows Defender


Disabling to disable Windows Defender using Registry on each VM that is
protected by Antivirus, perform the following steps:

1. Use the Windows key + R keyboard shortcut to open the Run command.

2. Type regedit and click OK to open the Registry.

3. Browse the following path:


HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows Defender.

Quick Tip: You can now copy and paste the path in the new Registry's address bar to
quickly jump to the key destination.

4. If you don't see the DisableAntiSpyware DWORD, right-click the Windows Defender
(folder) key, select New, and click on DWORD (32-bit) Value. C

5. Name the key “DisableAntiSpyware” and press Enter.

Anti-Virus Quick Reference Guide 28


DISABLING WINDOWS DEFENDER

6. Double-click the newly created DWORD and set the value from 0 to 1.

7. Click OK.

After completing the steps, restart your device to apply the settings.

Result: Windows Defender is now disabled.

Disabling windows defender can also be enforced using Domain Controller policies.

NOTE

Anti-Virus Quick Reference Guide 29


SYMANTEC CONFIGURATIONS STEPS TO AVOID LARGE DISK SPACE

5 Symantec Configurations steps to avoid Large Disk Space


Whenever an application or process is crashed, files and folders are generated, and
data is sent to Symantec Manager. If the Symantec client is unable to transmit
collected data to Symantec Manager, these files and folders remain on disk and
consuming large disk space, resulting in system crash. To avoid this, user must disable
the submission to Symantec manager.

Location on Disk: C:\ProgramData\Symantec\Symantec Endpoint


Protection\CurrentVersion\Data\ErrMgmt\Queue\Incoming.

To fully disable submissions and prevent data accumulation follow the below procedure:

1. In the Symantec Endpoint Protection Manager, go to Admin > Servers > Local Site >
Edit Site Properties > Data Collection.

2. Uncheck "Let clients send troubleshooting information to Symantec to resolve


product issues faster”.

Even "Let clients send troubleshooting information to Symantec to resolve product


issues faster” options are unchecked, files after mentioned will still continue to
NOTE
accumulate the disk space. In such cases, please follow the below procedure to
disable the SymQual's monitor.

Anti-Virus Quick Reference Guide 30


SYMANTEC CONFIGURATIONS STEPS
TO AVOID LARGE DISK SPACE

5.1 Steps to disable Tamper Protection


5.1.1 On Symantec Manager
1. Click Clients in the Symantec Endpoint Protection (SEPM) console.

2. Select the client-group you want to modify.

3. Click the Policies tab.

4. Click General Settings.

5. Click the Tamper Protection tab.

6. Perform one of the following actions:

• Change the drop-down menu to Log only.

• Uncheck Protection Symantec security software from being tampered with


or shutdown. This disables Tamper Protection.

This setting leaves Tamper Protection enabled. However, Tamper Protection will no
longer block attempts to modify SEP files, folders, processes, or Registry values.
NOTE

7. Click OK. Tamper Protection is disabled for clients within this client-group, and for
clients within client-groups that inherit policies from this group. This occurs as

Anti-Virus Quick Reference Guide 31


SYMANTEC CONFIGURATIONS STEPS TO AVOID LARGE DISK SPACE

soon as the clients receive the updated policy from the SEPM.

Anti-Virus Quick Reference Guide 32


SYMANTEC CONFIGURATIONS STEPS
TO AVOID LARGE DISK SPACE

5.1.2 On Symantec Clients


1. In the SEP client interface, click Change Settings.

2. Next to Client Management, click Configure Settings.

3. Click the Tamper Protection tab.

4. Perform one of the following actions:

• Uncheck Protection Symantec security software from being tampered with


or shutdown. This disables Tamper Protection.

• Change the drop-down menu to Log only.

This setting leaves Tamper Protection enabled. However, Tamper Protection will no
longer block attempts to modify SEP files, folders, processes, or Registry values.
NOTE

5. Click OK. Tamper Protection is now disabled for this SEP client.

Anti-Virus Quick Reference Guide 33


SYMANTEC CONFIGURATIONS STEPS TO AVOID LARGE DISK SPACE

5.2 To disable SymQual's monitor for specific applications or processes:


1. Disable Tamper Protection.

2. At the command line, disable SEP with smc -stop.

3. Delete the files in the folder, C:\ProgramData\Symantec\Symantec Endpoint


Protection\CurrentVersion\Data\ErrMgmt\Queue\Incoming.

4. In the Windows Registry Editor, create a backup, and then navigate to the following key:

5. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error
Reporting\LocalDumps\.

6. Delete any unnecessary subkeys.

7. Note: Any subkeys that have a "DumpFolder'" value of "C:ProgramDataSymantecLocalDumps"


are the processes that we monitor.

8. At the command line, restart SEP with smc -start.

9. Re-enable Tamper Protection.

Anti-Virus Quick Reference Guide 34


SYMANTEC CONFIGURATIONS STEPS
TO AVOID LARGE DISK SPACE

Reference Links:

https://support.symantec.com/us/en/article.tech192023.html
NOTE

https://support.symantec.com/us/en/article.TECH239771.html

Anti-Virus Quick Reference Guide 35


TROUBLESHOOTING

6 Troubleshooting

6.1 Disabling IESec option in Windows Server 2008/2008R2/2012


On Windows Server 2008 or 2008 R2:

1. Open the Server Manager (Start > Server Manager).

2. In the Security Information section, click Configure IE ESC.

3. In the Internet Explorer Enhanced Security Configuration window, disable the IE ESC
for Administrators and Users, and click OK.

On Windows Server 2012:

1. Start the Server Manager (Server Manager > Local Server).

2. In the Properties section, scroll to the right until you see this option: IE Enhanced
Security Configuration, and toggle the setting to Off.

3. In the Internet Explorer Enhanced Security Configuration window, disable the IE ESC
for Administrators and Users, and click OK.

In the Server Manager, you will notice that the setting has not changed. Press F5 to
refresh the screen to see that the setting has turned off.
NOTE

Anti-Virus Quick Reference Guide 36


TROUBLESHOOTING

6.2 Disabling IESec option in Windows Server 2016


1. Click the Start Button and launch Server Manager.

2. In the Server Manager dashboard, click on Local Server on the left-side. In the right
pane, click the On link next to IE Enhanced Security Configuration.

Anti-Virus Quick Reference Guide 37


TROUBLESHOOTING

3. Select Off for both Administrators and Users and click OK.

4. Restart your Internet Explorer and you can now visit all websites without being
prompted to add them to IE trusted sites zone.

Anti-Virus Quick Reference Guide 38


PRIOR RELEASES REVISION HISTORY

7 Prior Releases revision history


This section consists of the revision history information related to older releases than the
ones that are listed in section 1.2 Revision history.

Revision Date Description


5.0 3/5/10 Major document format updated.
Added Clarification on Honeywell Anti-Virus
certification policies.
Added ‘SEP 11 + RU5’ certification details to “Anti-
Virus Certification Matrix”.
“Anti-Virus Certification Matrix” table shows history
progression for Anti-Virus certifications.
All HPS windows-based products Updated in the
“Anti-Virus Certification Matrix” table.
Added ‘Terms & Acronyms’ table to the Document.

5.1 3/11/10 Removed ‘VSE 8.0i’ Since EOL by March 2010 and
removed ‘ePO 3.6’ Since EOL by Dec 2009 from
“Anti-Virus Certification Matrix” Table.

5.2 3/29/10 Added Certification Details of ‘ePO 4.5 Patch1 and


VSE 8.7i Patch3’ to “Anti-Virus Certification Matrix”.
Removed ‘R3XX.1 and R3XX.2’ Certification details
since End of Life for Win XP SP2 by July 13th 2010.
R301.2 and R310.2 consider the Anti-Virus
Certification details only if R301.2 and R310.2 clients
are upgraded to XP SP3 platform, since Microsoft
end of life for XP SP2 from July 13, 2010.
Removed “Engine 5301” from “Anti-Virus
Certification Matrix” because Engine 5301 End of
Life by Feb 2010.

5.3 5/25/10 Added ‘SEP11 + RU6a’ Certification details to “Anti-


Virus Certification Matrix”.
Added ‘PHD 210’ Certification details to “Anti- Virus
Certification Matrix”.

Anti-Virus Quick Reference Guide 39


PRIOR RELEASES REVISION HISTORY

Revision Date Description


5.4 7/9/10 Added ‘VSE 8.7iPatch3’ (Cumulative Package)
Certification Details to “Anti-Virus Certification
Matrix”.
Added ‘BMA Product’ Anti-Virus certification details
to “Anti-Virus Certification Matrix”.

5.5 8/2/10 Added ‘ePO 4.5Patch3’ Certification details to “Anti-


Virus Certification Matrix”.

5.6 8/31/10 Added ‘EPKS R400.1’ Certification details to “Anti-


Virus Certification Matrix”.
Added ‘ePO’ Certification details to PHD product.

5.7 9/24/10 Added ‘EPKS R311.3’ Certification Details to “Anti-


Virus Certification Matrix”.

5.8 11/1/10 Added ‘VSE 8.7i Patch4’ Certification details to “Anti-


Virus Certification Matrix”.
Removed ‘Experion PKS R211.1, PMD R612 & RAE
R4.00’ Certification details since End of Life for Win
2000 SP4 by July 13th 2010.

5.9 5/26/11 Added ‘ePO 4.6 and VSE 8.8’ Qualification details to
“Anti-Virus Certification Matrix”.

6.0 6/28/11 Added Exclusion Folders for ‘TPS Products’ to Anti-


Virus Software Guideline document.

6.1 8/18/11 Added ‘VSE 8.8 and SEP11 RU6’ Certification Details
for EPKS R400.2, HS R400, HS R311,
FSC, SM and SOE to “Anti-Virus Certification Matrix”.
Added ‘VSE 8.8’ Certification Details to AM Products.
Removed ‘i’ from ‘VSE8.8’ in “Anti-Virus Certification
Matrix”.
Included Format changes.

6.2 10/10/11 Added ‘SEP11 RU7’ Certification details to “AV-


Certification Matrix”.

Anti-Virus Quick Reference Guide 40


PRIOR RELEASES REVISION HISTORY

Revision Date Description


6.3 12/6/11 Added ‘SEP12.1’ Certification details to “Anti- Virus
Certification Matrix”.
Added OptiVision, Quality Optimizer with OptiVision
and Field Advisor Products to “Anti- Virus
Certification Matrix”.

6.4 2/13/2012 Added ‘Note2’ which is highlighted with yellow under


“Anti-Virus Certification Matrix” for ‘VSE 8.7i Patch5
and SEP12.1 RU1’.

6.5 3/22/2012 Added ‘VSE8.8Patch1 and SEP12.1RU1’ Certification


details to “Anti-Virus Certification Matrix”.
Added ‘BF241, Profit Suite R410, FA R120 &
AM330.2’ Releases in “Anti-Virus Certification
Matrix”.
‘PHDR210, USD R400, AM 400.1 & AM330.3’ is.
no longer supported and is removed from
certification matrix.
The warning ‘Note2’ (Mentioned with Anti-Virus
Software Guidelines version 6.4) issued against
updating systems with ‘Symantec End Point
Protection 12.1 Release Update1’ has been removed
and is now certified to update systems as per the
“Anti-Virus certification matrix”.
Modified ‘Note2’ under section 1.2- “Anti-Virus
Certification Matrix”

6.6 4/6/2012 Added ‘VSE 8.8 Patch1’ in “Anti-Virus Certification


Matrix”, as ‘VSE 8.8’ was not available for P3
customers, Now BOM is updated with the latest
validated version of McAfee.
Removed ‘Note2’ under “3.1 Overview” section.
Added ‘EPKS R410.1, RAE602 & Plant Cruise R100.1’
Releases in “Anti-Virus Certification Matrix”.
Removed ‘RAE600’ Release in “Anti-Virus
Certification Matrix”.

Anti-Virus Quick Reference Guide 41


PRIOR RELEASES REVISION HISTORY

Revision Date Description


6.7 4/19/2012 Added ‘VSE8.8 and VSE8.7i Patch4’ Certification
details to “Anti-Virus Certification Matrix” for ‘EPKS
R400.2 and R410.1’ Releases.
Added ‘Note2’ under “3. Anti-Virus Certification”
section.

6.8 7/17/2012 Added ‘VSE8.7i Patch5’ Certification details to “Anti-


Virus Certification Matrix”.
Added ‘RAE R603’ Release in “Anti-Virus Certification
Matrix”.
Removed ‘Note2’ warning deployment of ‘VSE 8.7i
patch 5’ under Section “3.2 Anti-Virus Certification
Matrix”.

6.9 9/11/2012 Added ‘EPKS 400.3, SM133.3, SM145.1, SM150.1,


PCUS R400.1, PHD310, USD OTS 410
and USO 410.1P1’ Releases in “Anti-Virus
Certification Matrix”.
Added ‘SEP12.1 RU1 MP1’Certification details to
“Anti-Virus Certification Matrix”.
Added ‘VSE8.7i P5 & VSE 8.8P1’ Certification details
to “Anti-Virus Certification Matrix” for ‘EPKS R400.3’.
Added ‘VSE 8.8P1’ Certification details to “Anti- Virus
Certification Matrix” for ‘SM133.3, SM145.1,
SM150.1 and PCUS R400.1’.
Removed ‘SM132.1, SM140.2 & PHD215’
Releases in “Anti-Virus Certification Matrix”.

7.0 12/11/2012 Added ‘VSE 8.8P2’ Certification details to “Anti- Virus


Certification Matrix”.
Added ‘LS/HS R400 on Win7 SP1, RAE 610, FA
R200 and PCUS on Win7 SP1’ Releases to “Anti-
Virus Certification Matrix”.
Removed ‘BF 220, BF 230 and LS/HS R400’ on Win7
from “Anti-Virus Certification Matrix”.

Anti-Virus Quick Reference Guide 42


PRIOR RELEASES REVISION HISTORY

Revision Date Description


7.1 4/8/2013 Added ‘SEP 12.1 RU2’ Certification details to “Anti-
Virus Certification Matrix”.
Removed ‘EPKS R400.1’ from “Anti-Virus
Certification Matrix”.
Safety Manager R133.3 has been upgraded to Safety
Manager R133.4.

7.2 5/7/2013 Added ‘EPKS R410.2’ Certification details to “Anti-


Virus Certification Matrix”.

7.3 6/18/2013 Added ‘TPB R400, TPB R310.2, PA R410, PA


R400’ Certification details to “Anti-Virus Certification
Matrix”.
Added “SEP 12.1 RU2” certification details to ‘RAE
nodes’.
Added ‘Note’ under ‘Anti-Virus Certification Matrix’.

7.4 8/29/2013 Added ‘ePO 4.6.6 and VSE+AntiSpyware Enterprise


8.8 Patch2 HF 846582’ & ‘Engine 5600’Certification
details to “Anti-Virus Certification Matrix”.
Plant Cruise R100.1 has been upgraded to Plant
Cruise R100.3.
Added ‘PMD R800.1’and ‘BMA R410.1.’
Certification details to “Anti-Virus Certification
Matrix”.

Anti-Virus Quick Reference Guide 43


PRIOR RELEASES REVISION HISTORY

Revision Date Description


7.5 2/25/2014 Added ‘VSE+AntiSpyware Enterprise 8.8 Patch2 HF
805660’ Certification details to “Anti-Virus
Certification Matrix”.
Added ‘SEP 12.1 RU3’ Certification details to “Anti-
Virus Certification Matrix”.
Added ‘EPKS/EAPP R430.1, EPKS/EAPP R410.3
& HS R410’ Certification details to “Anti-Virus
Certification Matrix”.
Added ‘BMA product (OM&S50)’ Certification details
to Anti-Virus Certification Matrix”.
Removed Profit Suite R400 & R411 Certification
details from “Anti-Virus Certification Matrix”.
Added Profit Suite R411.1 Certification details to
“Anti-Virus Certification Matrix”.
Removed ‘USD R400OTS and USO R400.1.’
Certification details from “Anti-Virus Certification
Matrix”.
Added ‘TPA690’ Certification details to Anti-Virus
Certification Matrix”.
Added USOR430 Certification details to “Anti- Virus
Certification Matrix”.
Added ‘Alarm Manager MoC R306 & AnE R441
Certification details to “Anti-Virus Certification
Matrix”

Added ‘SEP 12.1 RU4’ Certification details to “Anti-


Virus Certification Matrix”.

7.6 4/1/2014 Added ‘McAfee VSE 8.8 Patch2’ installation


Procedure with workaround.
Added USDR430 Certification details to “Anti- Virus
Certification Matrix”.
Removed RAE R601&R602 Certification details from
“Anti-Virus Certification Matrix”.

Anti-Virus Quick Reference Guide 44


PRIOR RELEASES REVISION HISTORY

Revision Date Description


7.7 6/6/2014 Added ‘McAfee ePO (Heart bleed) HF960279’
Certification details to “Anti-Virus Certification
Matrix”.
Added ‘Symantec 12.1 RU4 MP1’ Certification details
to “Anti-Virus Certification Matrix”.
Added BF242, IKPI R101 and IMON R100
Certification details to “Anti-Virus Certification
Matrix”.
Safety Manager R133.4 and R145.1 has been
upgraded to Safety Manager R133.5 and R146.1.
Added procedure to remove the Script Scan feature
from VSE using MID package.
Added How to uninstall supported McAfee products
using the Consumer Products Removal tool (MCPR).

7.8 10/13/2014 Added ‘McAfee VSE 8.8 Patch4’ Certification details


to “Anti-Virus Certification Matrix”.
Added ‘ePO5.1.1’ Certification details to “Anti- Virus
Certification Matrix”.
Added Mandatory Procedure to be followed prior to
Upgrading/ Clean Installation of McAfee Virus Scan
Enterprise 8.8.0 Patch 4 on EPKS R430.x.
Added PHD320 and UPS320 Certification details to
“Anti-Virus Certification Matrix”.

Anti-Virus Quick Reference Guide 45


PRIOR RELEASES REVISION HISTORY

Revision Date Description


7.9 11/10/2014 Added ‘Symantec 12.1.RU5’ Certification details to
“Anti-Virus Certification Matrix”.
Alarm Manager AnE R441has been renamed to
DynAMo M&R R100 (AnE R441) in “Anti-Virus
Certification Matrix”.
Removed AAM310 (ACM, AEA, UA) Certification
details from “Anti-Virus Certification Matrix”.
Added Profit suit R430 Certification details to “Anti-
Virus Certification Matrix”.
Added AAM321 (ACM, AEA, UA) and DynAMo M&R
R110.2 (AnE R442) Certification details to “Anti-Virus
Certification Matrix”.
Replaced AMR410.1 Patch 1 with AMR410.2 in the
“Anti-Virus Certification Matrix”.
RAE 611.1 has been upgraded to RAE 612.1

8.0 1/27/2015 Added ‘ePO 5.1.1, McAfee Agent 5.0 and


VSE+AntiSpyware Enterprise 8.8 Patch4 ‘Engine
5700’Certification details to “Anti-Virus Certification
Matrix”.
Added Mandatory Hot Fixes to be applied on top of
ePO 5.1.1 refer page no.11.
Added New Acronym “TBQ, HF*1…n”.
Added PMD 830.1 Certification details to “Anti- Virus
Certification Matrix”.

8.1 6/17/2015 Added ‘ePO 5.1.1, McAfee Agent 5.0 and


VSE+AntiSpyware Enterprise 8.8 Patch5 ‘Engine
5700’Certification details to “Anti-Virus Certification
Matrix”.
Added EPKS 431, PCUS 430/431, FDM 440/450,
PMD 711.4, PHD 321, SH R200.2, SM R152.1,
FSC 710.7 Certification details to “Anti-Virus
Certification Matrix”.
Added New Acronym “X”
Removed SOE 141 from “Anti-Virus Certification
Matrix”.

Anti-Virus Quick Reference Guide 46


PRIOR RELEASES REVISION HISTORY

Revision Date Description


8.2 8/14/2015 Added ‘IKPI R110.’ Certification details to “Anti- Virus
Certification Matrix”.
Removed ‘IKPI R101’ from “Anti-Virus Certification
Matrix”.
Added ‘Symantec 12.1.RU6’ Certification details to
“Anti-Virus Certification Matrix”.
Added ‘US R500.1’ Certification details to “Anti- Virus
Certification Matrix”.
Added details for McAfee MOVE Agentless AV
solution for Virtualized systems.
Added a “Note1” for McAfee DAT Reputation Feature
in section 2.0

8.3 10/1/2015 Added Exclusions List for EPKS R431 Corrected typo
errors - Replaced ‘N\A’ with ‘N/A’

8.4 9/12/2015 Added ‘ePO 5.3.1, McAfee Agent 5.0.2 and


VSE+AntiSpyware Enterprise 8.8 Patch6 ‘Engine
5800’Certification details to “Anti-Virus Certification
Matrix”.
Corrected ‘N\A’ with ‘NA’
Updated Configuration / policy settings for SEPM
12.1 and SEP unmanaged client.
Added ‘IFORMS R200.1’, ‘ILOGBOOK R100’, & ‘PAR
R200.1.’
Certification details to “Anti-Virus Certification
Matrix”.
Added Low risk processes list for Experion nodes
running Mcafee AV.

8.5 1/21/2016 Added ‘Symantec 12.1.RU6 MP3’ Certification details


to “Anti-Virus Certification Matrix”.
Added Note2 in Page3

8.6 02/05/2016 Added Additional AV Exclusions for Symantec users -


EPKS 410, EPKS 430 and EPKS 431 in AV Software
Guidelines.

Anti-Virus Quick Reference Guide 47


PRIOR RELEASES REVISION HISTORY

Revision Date Description


8.7 08/19/2016 Added ‘ePO 5.3.1, McAfee Agent 5.0.3 and VSE+
AntiSpyware Enterprise 8.8 Patch7 ‘Engine
5800’Certification details to “Anti-Virus Certification
Matrix”.
Added ‘EPKS 432.X, DynAMo M&R R120.1, US.
R501.1, CPM 570.3, CPM563.1 Certification details
to “Anti-Virus Certification Matrix”.
Added EPKS 432.X with latest point release in
product family table.
Removed EPKS R311.X and EPKS 310.3 and updated
latest point release version in product family table.
Added (Note 10) under Notes section.

8.8 08/30/2016 Added ‘Symantec 12.1.RU6 MP5’ Certification details


to “Anti-Virus Certification Matrix”.
Added USD R450 and USD R441OTS
Certification details to “Anti-Virus Certification
Matrix”.

8.9 10/12/2016 Added ‘ePO 5.3.1, McAfee Agent 5.0.4 and VSE+
AntiSpyware Enterprise 8.8 Patch 8 ‘Engine
5800’Certification details to “Anti-Virus Certification
Matrix”.
Added PA 430.1, SM 153.3, USO R450 and OV
R54X certification details to “Anti-Virus Certification
Matrix”.
Added SM 153.X with latest point release in product
family table.
Updated Bunch of Hot fixes (EPO5xHF1151890
EPO5xHF1147158) for Notation Hf*c.
Updated the Note and Caution for the RAE R612.4 &
R614.3 releases under section 2.2

8.10 10/27/2016 Added ’SEP 12.1RU6 MP6’ Certification details to


“Anti-Virus Certification Matrix”.
Added HSR 430.1, and UPS 322 certification details
to “Anti-Virus Certification Matrix”.

8.11 01/23/2017 Added support MOVE 4.0 Agentless Certification


details to “Anti-Virus Certification Matrix”.

Anti-Virus Quick Reference Guide 48


PRIOR RELEASES REVISION HISTORY

Revision Date Description


8.12 02/23/2017 Added ’SEP 14’ Certification details to “Anti-Virus
Certification Matrix”.
Added EPKS R500.1, PMD 900.1, LXPC 120.1,
PBM500.1 and Profit Suite 440 certification details
to “Anti-Virus Certification Matrix”.
Removed PMD 711 and PMD 720 from the
certification matrix.

8.13 04/17/2017 Added Engine5900 and ePO 5.3.2’ Certification


details to “Anti-Virus Certification Matrix”.
Added DOS R 121.1, RAE R700.1 and BF 250.
certification details to “Anti-Virus Certification
Matrix”.

8.14 05/18/2017 Added ’SEP 12.1RU6 MP7’ Certification details to


“Anti-Virus Certification Matrix”.
Added UAS R500.2, UAS R501.1 and UAS.
R510.1certification details to “Anti-Virus Certification
Matrix”.
Removed AM 400.2 and AM 410.2 from the
certification matrix.

8.15 06/27/2017 Added ‘ePO 5.9, McAfee Agent 5.0.5 and VSE+
AntiSpyware Enterprise 8.8 Patch 9 ‘Engine
5900’Certification details to “Anti-Virus Certification
Matrix”.
Added UCS R452 and HSR500 certification details to
“Anti-Virus Certification Matrix”.

8.16 08/11/2017 Added SEP 14 MP2 (14.0.2415.0200) and MOVE


4.5.1 qualification details.
Added FDM 500 and DynAMo M&R R200.1
certification detail to “Anti-Virus Certification Matrix”.

8.17 10/03/2017 Added EPKS R505 certification details to “Anti- Virus


Certification Matrix”.

Anti-Virus Quick Reference Guide 49


PRIOR RELEASES REVISION HISTORY

Revision Date Description


8.18 11/02/2017 Added ’SEP 12.1RU6 MP8 (12.1.7266.6800)’
Certification details to “Anti-Virus Certification
Matrix”.
Added RM 160.2, ERM 160.2, Trace 120.1, PHD
340, PHD 330, UPS 321, Profit Suite 441 and Profit
Suite 431 certification details to “Anti-Virus
Certification Matrix”.
Removed PHD 320, PHD 310, UPS 310, UPS
300, Profit Suite 440 and Profit Suite 430 from the
certification matrix.

8.19 12/20/2017 Added ‘ePO 5.9.1(5.9.1.251), McAfee Agent


5.0.6(5.0.6.220) and VSE 8.8 Patch10(8.8.0.1906)
Certification details to “Anti-Virus Certification
Matrix”.
Added SIA R200.1, DOS R211, UAS R511.1,
Certification details to “Antivirus Certification Matrix
“.

8.20 02/16/2018 Added ’SEP 12.1RU6 MP9(12.1.7369.6900)’


Certification details to “Anti-Virus Certification
Matrix”.
Added Profit Suite R442, Certification details to
“Antivirus Certification Matrix “.

8.21 03/23/2018 Updated Symantec version mismatches in Anti- Virus


Certification Matrix table.
Added ’SEP14.0.1 RU1 MP1b (14.0.3897.1101)’
Certification details to “Anti-Virus Certification
Matrix”.
Added Exclusions for eServer.

8.22 03/27/2018 Added EPKS R501 in Anti-Virus Certification Matrix.


Updated Symantec version mismatches in Anti- Virus
Certification Matrix table.
Added ’SEP14.0.1 RU1 MP1b (14.0.3897.1101)’
Certification details to “Anti-Virus Certification
Matrix”.
Added Exclusions for eServer.

Anti-Virus Quick Reference Guide 50


PRIOR RELEASES REVISION HISTORY

Revision Date Description


8.23 05/25/2018 Added ’SEP12.1RU6 MP10 (12.1.7445.7000)’
Certification details to “Anti-Virus Certification
Matrix”.
Added SM 161.1, FSC 801.1, PA R500, RAE
R701 certification details to “Anti-Virus Certification
Matrix”.
Added Exclusions for EPKS R501 ELCN nodes.

8.24 06/19/2018 Added ’SEP14.0.1.2 RU1 MP2 (14.0.3929.1200)’


Certification details to “Anti-Virus Certification
Matrix”.
Added EPKS R510.x certification details to “Anti-
Virus Certification Matrix”.

8.25 10/18/2018 Added ‘ePO 5.9.1(5.9.1.251) Certification details to


“Anti-Virus Certification Matrix”.
Removed EPKS R505.x from the “Anti-Virus
Certification Matrix”.
Updated all “Low risk process” through McAfee e-
Policy Orchestrator-managed Clients.

Anti-Virus Quick Reference Guide 51


PRIOR RELEASES REVISION HISTORY

Revision Date Description


8.26 02/01/2019 McAfee
Added ‘ePO 5.10 ( 5.10.0.2428), McAfee Agent
5.6.0(5.6.0.702), VSE 8.8 Patch12(8.8.0.2024)
and Engine 6000 Certification details to “Anti- Virus
Certification Matrix”.
Added PMD R910.x certification details to “Anti- Virus
Certification Matrix”.
Removed Profit suite R441, R411.1, R410 from the
certification matrix.

Symantec
Added ’SEP 14.2.0.1 (14.2 MP1)
(14.2.1015.0100)’ Certification details to “Anti- Virus
Certification Matrix”.
Added PBM R501, Profit Suite R500,
CPM601.3\CPM601.4 certification details to “Anti-
Virus Certification Matrix”.
Removed CPM 563.1 from the certification matrix.
Updated Trace 120.1/121 (SEP 12.1 RU6 MP7)
Qualification details to “Anti-Virus Certification
Matrix”.
Added Exclusions For BMA-PBM.

8.27 03/27/2019 Separated exclusion list for McAfee and Symantec.


Added installation and configuration details for
Symantec 14.
Corrected the additional spaces “\@@@” from the
exclusion list.
Added details to RaeBrowser.exe and
NetworkProcessor.exe in the Symantec exclusion list.
Added Note information for using the exclusion or
policy.
Updated Note information in Basic configuration for
McAfee Anti-Virus, for archive scanning in EPO
during On-Access scan.
Corrected typo errors in to “Anti-virus Certification
Matrix.

Anti-Virus Quick Reference Guide 52


PRIOR RELEASES REVISION HISTORY

Revision Date Description


8.28 4/30/2019 McAfee
Added ‘ePO 5.10 Update 3 (5.10.0.2428), McAfee
Agent 5.6.0 hotfix-MA560HF1264214 (5.6.0.878),
VSE 8.8 Patch12 VSE88HF1262936 (8.8.0.2024),
and Engine 6000.8403 Certification details to “Anti-
Virus Certification Matrix”.
Note: If you are using Internet Explorer, disable IESec
option. To know how to disable, refer Troubleshooting
chapter.

8.29 06/03/2019 McAfee


Added support MOVE 4.8 Agentless Certification
details to “Anti-Virus Certification Matrix.”
Added a note in section “ESXi Host Based virus
scanners as Antivirus Solution”.

8.30 6/20/2019 McAfee


Added McAfee Agent 5.6.1 and McAfee Engine 6010
qualified certification details to “Anti-Virus
Certification Matrix”.
McAfee

8.31 7/31/2019 McAfee


Added EPKS R511.x certification details to “Anti-Virus
Certification Matrix”.
Added ‘’ePO 5.10 (5.10.0.2428) Update 4
(2.0.0.454), McAfee VSE 8.8.0 Patch13
VSE88HF1274352
(8.8.0.2114)
Certification details to “Anti-Virus Certification
Matrix”.
Added Steps to Disable windows Defender in Section
4

Anti-Virus Quick Reference Guide 53


PRIOR RELEASES REVISION HISTORY

Revision Date Description


8.32 9/27/2019 Symantec 14
Added ’SEP 14.2.1.1 (14.2 RU1 MP1)
(14.2.4814.1101)’ Certification details to
“Antivirus Certification Matrix”.
Added PHD 400 and CPM 602 certification details to
“Antivirus.
Certification Matrix”.
Removed UPS 321, PHD 330, from the certification
matrix.

8.33 18/11/2019 McAfee


Added ‘’ePO 5.10 (build 2428) Update 5
(2.0.0.751), McAfee Agent 5.6.2 Certification details
to “Anti-Virus Certification Matrix”.
Added Symantec Exclusions for BMA-PBM. “Anti-
Virus Certification Matrix”.

8.34 3/02/2020 Added ‘ePO 5.10 .0 Build 2428 Update 6


(2.0.0.831), VSE 8.8.0.2190, Agent: 5.6.3.157
Certification details to “Anti-Virus Certification
Matrix”
Added EPKS R511.x support to McAfee Exclusion List
Added McAfee MOVE 4.8.0 and VMware NSX
6.4.5 upgradation in “Anti-Virus-Software-
Guidelines-for-Virtualization-Environment”
Updated Symantec steps to clear the large disk usage
to the BW39161 under section 5

8.35 4/04/2020 Added ’SEP 14.2.2 (14.2 RU2 MP1) build 5569.
(14.2.5569.2100)’ Certification details to “Anti-virus
Certification Matrix”

Anti-Virus Quick Reference Guide 54


PRIOR RELEASES REVISION HISTORY

Revision Date Description


8.36 30/6/2020 Added ‘McAfee ePO 5.10.0.2428 update 7
(2.0.0.907), VSE 8.8.0.2190 Patch 14 HF116778,
Agent: 5.6.5.195 Certification details to “Anti- Virus
Certification Matrix”.
McAfee and Symantec exclusions list is updated in
Anti-Virus Guide.
Updated the McAfee minor version details in Anti-
Virus Certification Matrix.

8.37 17/7/2020 Symantec


Added 'SEP 14.3(14.3 14.3.558.0000**)’
Certification details to “Antivirus Certification Matrix”.

8.38 8/21/2020 McAfee


Added ‘McAfee ePO 5.10.0.2428 update 7.
(2.0.0.907), VSE 8.8.0.2232 Patch 15, Agent:
5.6.5.236 + HF2 Engine 6100.8979
Certification details to “Anti-Virus Certification
Matrix”.
Added Trace R130/140, EPKS R515.x certification
details to “Anti-virus Certification Matrix”.

8.39 9/21/2020 Symantec


Added 'SEP 14.3 MP1 build 1148 (14.3.1148.0100),
Certification details to "Anti-Virus Certification
Matrix".

8.40 10/20/2020 McAfee


Added ‘McAfee ePO 5.10.0.2428 update 8
(2.0.0.929), VSE 8.8.0.2232 Patch 15, Agent:
5.6.6.232 Engine 6100.8979 Certification details to
“Anti-Virus Certification Matrix”.

8.41 11/20/2020 Symantec


Added EPKS R516.x certification details to “Anti-virus
Certification Matrix”.
Added 'SEP 14.3 MP1(Refresh) build 1169
(14.3.1169.0100), Certification details to "Anti-Virus
Certification Matrix".

Anti-Virus Quick Reference Guide 55


PRIOR RELEASES REVISION HISTORY

Revision Date Description


8.42 01/20/2021 McAfee
Added ‘McAfee ePO 5.10.0.2428 update 9
(2.0.0.949), VSE 8.8.0.2300 Patch 16, Agent:
5.7.0.194 Engine 6100.8979 Certification details to
“Anti-Virus Certification Matrix”.
Added CPM R603.x and Profit Suite R510.x
certification details to “Anti-virus Certification
Matrix”.
Added QCS SE R100.x certification details to “Anti-
virus Certification Matrix”.

8.43 03/05/2021 Symantec


Added 'SEP 14.3 RU1(Refresh) build 3385
(14.3.3385.1000), Certification details to "Anti-Virus
Certification Matrix".
Added low risk process.
Plexus.exe in C:\Program Files
(x86)\Honeywell\Experion PKS\Server\run\
Spike.exe in C:\Program Files
(x86)\Honeywell\Experion PKS\Server\run
Certification details to “Anti-virus Certification
Matrix”.

8.44 03/17/2021 McAfee ENS 10.7.x is qualified by Honeywell, which


will replace the existing McAfee VSE 8. x.

8.45 04/05/2021 Added ‘McAfee ePO 5.10.0.2428 update 9


(2.0.0.949), VSE 8.8.0.2300 Patch 16, Agent:
5.7.0.194 Engine 6100.8979 for EPKS
R432.x/R431.x and R410.x Certification details to
“Anti-Virus Certification Matrix”.

8.46 05/20/2021 Added ‘McAfee ePO 5.10.0.2428 update 10


(2.0.0.1064), VSE 8.8.0.2300 Patch 16, Agent:
5.7.2.162 Engine 6200.9189 Certification details to
“Anti-Virus Certification Matrix”.
Removed EPKS R400, R410 And HS R400, HSR410
from the certification matrix.
Added note information for Stopping of Symantec
daily qualified 14.0\14.1\14.2 signature files starting
from 1st January 2022 onwards.

Anti-Virus Quick Reference Guide 56


PRIOR RELEASES REVISION HISTORY

Revision Date Description


8.47 06/08/2021 Added procedure for installation and migration to
latest Symantec 14.x release.
Added section 5.2.5 for Procedure to disable Buffer
Overflow Protection under Managed mode for ENS.

8.48 08/09/2021 Added 'SEP 14.3 RU2 build 4615 (14.3.4615.2000),


Certification details to "Anti-Virus Certification
Matrix".
Added SM 162,SM 210
certification details to “Anti-virus Certification
Matrix”.

Addressed BW-44902 for Symantec Exception

Addressed PAR - 1-D7OOBMZ details for McAfee


Exclusions and Symantec Exceptions by removing
the duplicate entries.

8.49 30/09/2021 Added EPKS R520.x certification details to “Anti-


Virus
Certification Matrix”.

Qualified SEP 14.3 RU2 build 4615


(14.3.4615.2000).

Added new section under McAfee Endpoint Security


10.7.x (ENS), 5.2.10 System Utilization and CPU
usage for McAfee ENS.

Addressed PAR - 1-DWEAFWF details for McAfee


Endpoint security “Configure system utilization”.

Added McAfee ENS 10.7.x with McAfee ePO


5.10.0.2428 update 10 (2.0.0.1064), Agent: 5.7.2.162
Engine 6200.9189 and qualified on EPKS nodes
R520.

Anti-Virus Quick Reference Guide 57


PRIOR RELEASES REVISION HISTORY

Revision Date Description


8.50 24/12/2021 Added qualification “McAfee ENS 10.7.0 September
2021 Update” details to “Anti-Virus ENS Certification
Matrix”.
Added Note information for McAfee VSE EOL in the
section 3.1.
Added Note information for stopping the Symantec
14.0.x/SEP 14.1.x/SEP 14.2.x DAT qualification in the
section 3.1.
Added detailed Steps for installation, Migration of
Endpoint Security 10.7.x in the AV guide.
Added detailed steps for configuring the policies
through the ePO server in the AV guide.
Added detailed steps for configuring the policies in
the ENS standalone in the AV guide.
Added detailed steps for migrating from VSE polices
to ENS using EMA in the AV guide.
Added Symantec required port configuration table in
the AV guide.

8.51 03/03/2022 Added Symantec 14.3 RU3 Refresh certification


details to “Anti- Virus Certification Matrix”.
Added “McAfee ENS 10.7.0 November 2021 Update”
details to “Anti-Virus ENS Certification Matrix”.
Removed the McAfee MOVE column from the “Anti-
Virus ENS Certification Matrix” and added these
McAfee MOVE & VMware NSX certification details to
SUIT-Anti-virus Virtualization Guide.

8.52 12/05/2022 Added Symantec 14.3 RU4 Refresh certification


details to “Anti- Virus Certification Matrix”.
Added McAfeee Agent 5.7.5 and McAfee Engine
6400.9594 for McAfee VSE Patch 16 qualification
details to the "Anti-Virus Certification Matrix", which is
applicable for EPKS R43x.x releases only.

8.54 27/09/2022 Added Symantec 14.3 RU5 (Refresh) 14.3


.8268.5000 certification details to “Anti-Virus
Certification Matrix”.

Anti-Virus Quick Reference Guide 58


PRIOR RELEASES REVISION HISTORY

Revision Date Description


8.55 01/12/2022 Added “McAfee ENS 10.7.0 ENS Security Common
10.7.0.3468 Threat Prevention Client 10.7.0.3497
with ePO 5.10 Update 14 (2.0.0.1272) and Agent
5.7.7 (378)” details to the “Anti-Virus ENS
Certification Matrix”.
Note:
• After January 11th 2023, Honeywell will no
longer qualify VSE DAT file for EPKS R43x releases.
Refer KSM20210 42 for more details.
• Broadcom Symantec has made changes in
the naming convention of their daily released
signature files. Broadcom Symantec is sharing
signature files in the format “core3sdsi64.jdb/
core3sdssepv5i64.exe” for SEP 14.3 RU4 (Refresh) or
prior, and for SEP14.3 RU5, signature files are being
released in the format
“core3sdsn64.jdb/core3sdssepn64v5i64.exe”. SUIT
Team will start sharing signature files for both SEP
RU4 and RU5 versions from 1st December 2022
onwards till 28th February 2023. From 1st March
2023 onwards, SUIT team will stop sharing signature
files for SEP 14.3 RU4 and will continue to share
signature files only for SEP 14.3 RU5.

8.56 24/02/2023 Added new configuration setting changes to


Trellix(McAfee) Endpoint Security(ENS) 10.7 for
performance optimization.

Added Symantec 14.3 RU6 (14.3.9203.6000 )


certification details to “Anti-Virus Certification
Matrix”.

Added SM 212.x,FDM R520.x certification details to


“Anti-virus Certification Matrix”.

8.57 01/04/2023 Added "Trellix ENS 10.7.0 November 2022 Update


Repost (Security Common 10.7.0.5162, Threat
Prevention Client 10.7.0.5200 ), Trellix Agent
(5.7.8.262 ) and ePO 5.10 Update 15 (2.0.0.1291)"
support to the "Anti-Virus ENS Certification Matrix”.

Anti-Virus Quick Reference Guide 59


NOTICES

Notices
Trademarks

Experion®, PlantScape®, SafeBrowse®, TotalPlant®, and TDC 3000® are registered


trademarks of Honeywell International, Inc.

ControlEdge™ is a trademark of Honeywell International, Inc.

OneWireless™ is a trademark of Honeywell International, Inc.

Matrikon® and MatrikonOPC™ are trademarks of Matrikon International. Matrikon


International is a business unit of Honeywell International, Inc.

Movilizer® is a registered trademark of Movilizer GmbH. Movilizer GmbH is a business unit


of Honeywell International, Inc.

Other trademarks

Microsoft and SQL Server are either registered trademarks or trademarks of Microsoft
Corporation in the United States and/or other countries.

Trademarks that appear in this document are used only to the benefit of the trademark
owner, with no intention of trademark infringement.

Third-party licenses

This product may contain or be derived from materials, including software, of third parties.
The third party materials may be subject to licenses, notices, restrictions and obligations
imposed by the licensor.

The licenses, notices, restrictions and obligations, if any, may be found in the materials
accompanying the product, in the documents or files accompanying such third party
materials, in a file named third_party_licenses on the media containing the product.

Documentation feedback

You can find the most up-to-date documents on the Honeywell Process Solutions support
website at:

https://process.honeywell.com/us/en/support/

If you have comments about Honeywell Process Solutions documentation, send your
feedback to: [email protected]

Use this email address to provide feedback, or to report errors and omissions in the
documentation. For immediate help with a technical problem, contact your local
Honeywell Process Solutions Customer Contact Center (CCC) or Honeywell Technical
Assistance Center (TAC).

Anti-Virus Quick Reference Guide 60


NOTICES

How to report a security vulnerability

For the purpose of submission, a security vulnerability is defined as a software defect or


weakness that can be exploited to reduce the operational or security capabilities of the
software.

Honeywell investigates all reports of security vulnerabilities affecting Honeywell products


and services.

To report a potential security vulnerability against any Honeywell product, please follow the
instructions at:

https://honeywell.com/pages/vulnerabilityreporting.aspx

Submit the requested information to Honeywell using one of the following methods:

• Send an email to [email protected]; or.

• Contact your local Honeywell Process Solutions Customer Contact Center (CCC) or
Honeywell Technical Assistance Center (TAC).

Support

For support, contact your local Honeywell Process Solutions Customer Contact Center
(CCC). To find your local CCC visit the website,
https://process.honeywell.com/us/en/support/customer-care-request-form.

Training classes

Honeywell holds technical training classes that are taught by process control systems
experts. For more information about these classes, contact your Honeywell representative,
or see http://www.automationcollege.com.

Anti-Virus Quick Reference Guide 61


Honeywell Process Solutions

1250 W Sam Houston Pkwy S #150, Houston,


TX 77042

Honeywell House, Skimped Hill Lane


Bracknell, Berkshire, RG12 1EB

Building #1, 555 Huanke Road, Zhangjiang


Hi-Tech Park,
Pudong New Area, Shanghai, China 201203
© 2024 Honeywell International Sàrl
https://process.honeywell.com

You might also like