Thursday, November 3, 2011

McAfee GetSusp and GetClean

McAfee recently released two tools GetSusp and GetClean.  These two tools are very helpful to detect and clean malware

https://kc.mcafee.com/corporate/index?page=content&id=KB69385

  • McAfee GetSusp
    GetSusp is intended for users who suspect undetected malware on their computer. GetSusp eliminates the need for deep technical knowledge of computer systems to isolate undetected malware. It does this by using a combination of heuristics and querying the McAfee Global Threat Intelligence (GTI) database of known clean files to gather suspicious files. GetSusp is recommended as a first tool of choice when analyzing a suspect computer. However, you must follow the McAfee support process for escalating suspicious files it finds. See Related Information.
     
  • McAfee GetClean
    GetClean is a McAfee Labs initiative to reduce false positives in the field. It utilizes the standalone GetClean tool that you can run on common operating environment image files to submit clean files to McAfee. GetClean leverages Global Threat Intelligence (GTI) file reputation to report only files that are unknown to McAfee. This greatly reduces the number of files a customer has to submit to us and eliminates duplicate submissions. You can leverage GetClean to tune up the GTI settings in McAfee point products to Medium or Very High with confidence as your image files become part of the McAfee GTI whitelist.