We had McAfee too. I had extend my audit.vbs with some Reg-Keys. After Scan, the analysis (Pattern and Engine) can be done at the Software-View.
[code] wscript.echo "Custom Software"
' Add McAffe Pattern-Version to the Software Register strKeyPath = "SOFTWARE\Network Associates\TVD\VirusScan Enterprise\CurrentVersion" strValueName = "szVirDefVer" display_name = "McAfee Virus-Definition-Version" oReg.GetStringValue HKEY_LOCAL_MACHINE,strKeyPath,strValueName,McAfeeVirDef_Version form_input = "software^^^" & display_name & "^^^" _ & McAfeeVirDef_Version & "^^^" _ & "" & "^^^" _ & "" & "^^^" _ & OSInstall & "^^^" _ & "McAfee^^^^^^^^^^^^^^^^^^" _ & "" & "^^^" _ & "" & "^^^" _ & "" & "^^^ " entry form_input,comment,objTextFile,oAdd,oComment form_input = ""
' Add McAffe Scan-Engine-Version to the Software Register strKeyPath = "SOFTWARE\Network Associates\TVD\VirusScan Enterprise\CurrentVersion" strValueName = "szEngineVer" display_name = "McAfee Scan-Engine-Version" oReg.GetStringValue HKEY_LOCAL_MACHINE,strKeyPath,strValueName,McAfeeEngine_Version form_input = "software^^^" & display_name & "^^^" _ & McAfeeEngine_Version & "^^^" _ & "" & "^^^" _ & "" & "^^^" _ & OSInstall & "^^^" _ & "McAfee^^^^^^^^^^^^^^^^^^" _ & "" & "^^^" _ & "" & "^^^" _ & "" & "^^^ " entry form_input,comment,objTextFile,oAdd,oComment form_input = "" [/code]
|