cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 

McAfee Endpoint agent for Linux is deleting important library files.

When I am deploying Mvision endpoint agent for linux server, it's deleting important library files like "libtsr.so" after scanning. After which I cannot connect to the linux server through ssh and it's affecting the network connect and our monitoring tools like zabbix. Kindly tell me the configuration/steps so that endpoint don't delete libarary files like libtsr.so or something like this in future. I am currently testing it on my linux test server centos 7. It will get deployed in production after.
14 Replies

Re: McAfee Endpoint agent for Linux is deleting important library files.

Hi User90649964

Thank you for reaching out.

Regarding the event, could you please let us know the exact product name/version? (Example ENS for Linux)

Also share a snippet/screenshot that confirms that the file was deleted after scanning. 

Re: McAfee Endpoint agent for Linux is deleting important library files.

Unfortunately I cannot provide the screenshot of deleted library file because I removed the linux server from EPO. Here is the screenshot of product and it's version.

 

trellix.JPG

Re: McAfee Endpoint agent for Linux is deleting important library files.

Hi @User90649964 ,

The version seems to be ENS for Windows Platform.

 

Re: McAfee Endpoint agent for Linux is deleting important library files.

That said, Could you reproduce the issue on a Linux Platform (Test Machine) with ENS for Linux and share some snippets? 

Re: McAfee Endpoint agent for Linux is deleting important library files.

libtsr.so file got deleted.libtsr.so file got deleted.The  Trellix agent versionThe Trellix agent version

Re: McAfee Endpoint agent for Linux is deleting important library files.

Hi @User90649964 , 

Thank you for sharing the screenshot. 

As per the first screenshot, the analyzer is OAS and probably you are using ENSLTP. The product is not showing in the second screenshot, which would mean that the point product properties are not collected. But that is a different issue.

Regarding the detection and deletion of libtsr.so, could you share the output of the below commands to check which rpm owns the library file (If the OS is an rpm distro)?

# rpm -qf /lib64/libtsr.so
# lsof /lib64/libtsr.so

You might have to compress and submit the file to Trellix Lab for analysis.

 

 

Re: McAfee Endpoint agent for Linux is deleting important library files.

Those are the output of both commandsThose are the output of both commands

Re: McAfee Endpoint agent for Linux is deleting important library files.

Hi @User90649964 

This seems to be strange. It does look like a rootkit and you should get it investigated asap, as keyutils-libs doesn't provide that library on RHEL7

The keyutils lib should be something like the below.

------------
[alwin@localhost ~]$ rpm -ql keyutils-libs
/lib64/libkeyutils.so.1
/lib64/libkeyutils.so.1.5
/usr/share/doc/keyutils-libs-1.5.8
/usr/share/doc/keyutils-libs-1.5.8/LICENCE.LGPL
[alwin@localhost ~]$
------------

Please open a Service Request and submit /usr/lib64/libtsr.so file for analysis.

Re: McAfee Endpoint agent for Linux is deleting important library files.

@User90649964 , Additionally check with OS vendor too, on the keyutils-libs provided for RHEL 7

You Deserve an Award
Don't forget, when your helpful posts earn a kudos or get accepted as a solution you can unlock perks and badges. Those aren't the only badges, either. How many can you collect? Click here to learn more.

Community Help Hub

    New to the forums or need help finding your way around the forums? There's a whole hub of community resources to help you.

  • Find Forum FAQs
  • Learn How to Earn Badges
  • Ask for Help
Go to Community Help

Join the Community

    Thousands of customers use our Community for peer-to-peer and expert product support. Enjoy these benefits with a free membership:

  • Get helpful solutions from product experts.
  • Stay connected to product conversations that matter to you.
  • Participate in product groups led by employees.
Join the Community
Join the Community