Select the product you need help with
Forefront Client Security anti-malware client update: April 2010Article ID: 979536 - View products that this article applies to. On This PageINTRODUCTIONThis article describes the Microsoft Forefront Client Security (FCS) anti-malware client issues that are fixed in this hotfix package. Issues that this hotfix package fixesIssue 1Forefront Client Security real-time protection detects, suspends, and takes action against malware threats. After a threat is suspended, the user is notified. The user may be given an option to decide which action is taken, depending on the configuration of the client. If no action is taken after 10 minutes, then a default action that is defined either by policy or by definitions is executed. During this time, the malware threats are suspended and cannot be read or executed by other applications.This real-time protection delay period is implemented by a user interface process. If a user does not log on to the computer, then this process does not run. Therefore, FCS does not take action on the suspended malware. WorkaroundWhen malware is detected by real-time protection, the malware is suspended and cannot be read or executed by other applications. This behavior occurs both when a user is logged on to the computer and when a user is not logged on to the computer. Therefore, the computer is under protection. However, the malware still resides on the disk.If a user logs on to the computer after the malware is detected, they are notified in the user interface and the real-time protection delay period begins. When you deploy a policy to client computers, FCS takes action automatically on malware detected during scheduled scans. If you perform a scheduled full scan of the computer, action is taken against any malware that is detected and suspended after the scan is finished. A full scan includes all hard disk drives on the computer and takes action regardless of whether a user is logged on to the computer during the scan. ResolutionThis update adds an additional timer to the malware protection service. This additional timer implements the real-time protection delay period. Therefore, the default action that is defined either by policy or by definitions is executed when no user is logged on to the computer.Issue 2A change to the libraries of the Driver Install Frameworks (DIFx) for Applications is described under the "Issue 1" heading in the "Resolution" section of the following article Knowledge Base (KB) article:976668 Many automated installation methods install updates by using the LocalSystem account. For example, Automatic Updates and System Center Configuration Manager use the LocalSystem account for updates. When the hotfix 976668 is installed by using the LocalSystem account on a Windows 2000-based computer, the update fails and the following error is logged in the Mp_ambits.log file:
(http://support.microsoft.com/kb/976668/
)
Forefront Client Security anti-malware client update: December 2009
WorkaroundTo install the update that is described in KB 976668 on a Windows 2000-based Computer, log on the computer as an interactive user, and then run the update. To obtain the update, use the Microsoft Update Web site by using a Web browser, or download and then run the update from the Microsoft Update catalog that is described in KB 976668.ResolutionThis update no longer uses DIFx for Applications during installation. The update uses a custom installation technology that can be used on all currently supported FCS operating systems.Issue 3The FCS anti-malware service exits unexpectedly on a computer that is running Windows Vista, Windows Server 2008, Windows 7, or Windows Server 2008 R2.ResolutionThis update corrects a problem in the FCS anti-malware service on the on a computer that is running Windows Vista, Windows Server 2008, Windows 7, or Windows Server 2008 R2.MORE INFORMATIONHotfix informationA supported hotfix is available from Microsoft.Note This hotfix is available from Microsoft Update and from Windows Server Update Services. Additionally, the hotfix can be obtained by following these steps:
PrerequisitesThere are no prerequisites for installing this hotfix.Restart requirementYou may have to restart the computer after you apply this hotfix.Hotfix replacement informationThis hotfix replaces the anti-malware client that is deployed by using the Forefront Client Security deployment package (1.0.1725.0) on a computer.976669 This hotfix replaces the following hotfixes:
(http://support.microsoft.com/kb/976669/
)
Forefront Client Security deployment package (1.0.1725.0): December 2009
976668
(http://support.microsoft.com/kb/976668/
)
Forefront Client Security anti-malware client update: December 2009
971026
(http://support.microsoft.com/kb/971026/
)
A hotfix is available to resolve some problems with the Forefront Client Security anti-malware client
952265
(http://support.microsoft.com/kb/952265/
)
Data corruption may occur on a computer that has Forefront Client Security installed
938054
(http://support.microsoft.com/kb/938054/
)
A hotfix is available to resolve some problems with the Forefront Client Security client
956280
(http://support.microsoft.com/kb/956280/
)
The Forefront Client Security kernel-mode mini-filter unloads when you browse a network file share that contains many malicious files
File informationThe English version of this hotfix has the file attributes (or later file attributes) that are listed in the following table. The dates and times for these files are listed in Coordinated Universal Time (UTC). When you view the file information, it is converted to local time. To find the difference between UTC and local time, use the Time Zone tab in the Date and Time item in Control Panel.Forefront Client Security, 32-bit versionsCollapse this table
Forefront Client Security, 64-bit versionsCollapse this table
Known issuesIf you perform the workaround that is described under the "Issue 2" heading by installing hotfix 976668 as an interactive user on a computer that is running Windows 2000, you must also run this update as an interactive user. This requirement is necessary because this update uninstalls the update that is described in KB article 976668 before this update is installed. If you install this update by using the LocalSystem account, the same issues that are described in KB article 976668 occur during that uninstall stage of the update. STATUSMicrosoft has confirmed that this is a problem in the Microsoft products that are listed in the "Applies to" section. PropertiesArticle ID: 979536 - Last Review: March 22, 2011 - Revision: 4.0
|


Back to the top








