Knowledge Center

FAQs for GetSusp
Technical Articles ID:   KB69385
Last Modified:  9/19/2019


McAfee GetSusp


This article is a consolidated list of common questions and answers. It is mainly intended for users who are new to the GetSusp tool, but can be of use to all users.

General For product information covering miscellaneous topics.
Installation             Installation requirements for GetSusp, and deployment with ePolicy Orchestrator
Usage Information about using GetSusp.
Functionality Product features and functions, including offline scanning. 
Sample submissions  Ways to submit samples.

What is GetSusp?
GetSusp is a free tool that helps you find and log undetected malware, and allows you to automatically submit samples to McAfee Labs. To find suspicious files, GetSusp uses heuristics and compares samples against the Global Threat Intelligence (GTI) database of known clean files. When you analyze a suspect computer, use GetSusp first.

For the GetSusp Product Guide, see KB91941.

How is GetSusp different from other anti-malware tools? 
There are many free diagnostic tools available, but you must analyze their output, isolate a suspect sample, and work out how to submit the files to the anti-virus vendor. With GetSusp there is no need for advanced technical knowledge to isolate undetected malware.

What is the difference between GetSusp and GetClean? 
GetSusp helps you find and isolate undetected malware, and is available to all McAfee customers.

GetClean is a tool that helps you minimize false positives in your environment, reducing the number of files you have to submit to McAfee Labs and eliminating duplicate submissions. For more details about GetClean, see KB73044

Where can I get information about upcoming releases of GetSusp and additional release information?
See the GetSusp <current_version> post in Communities at: https://community.mcafee.com/message/216447

Where can I send feedback regarding GetSusp? 
You can provide feedback on the GetSusp Community Forum page at: https://community.mcafee.com/groups/getsusp30-beta-feedback.

Back to Contents

What are the connectivity requirements for GetSusp?
GetSusp requires an Internet connection to perform optimally. Outbound UDP port 53 and TCP port 80 must be allowed for GTI and known file database lookups to happen. The known file database is a McAfee Labs IT supported back end server. 

Where can I download the latest version of GetSusp?
The latest version is available from http://www.mcafee.com/us/downloads/free-tools/getsusp.aspx.

Can I deploy GetSusp.exe to my end nodes with ePolicy Orchestrator?
Yes. You can download the ePolicy Orchestrator deployable version from http://downloadcenter.mcafee.com/products/mcafee-avert/getsusp/getsusp-ePO.zip.
For further details on how to deploy the tool, see KB70405.

Back to Contents 

How do I use GetSusp?
For instructions, see http://www.mcafee.com/us/downloads/free-tools/how-to-use-getsusp.aspx.

Does GetSusp support command line switches?
Yes. For a list of all GetSusp switches, type getsusp.exe --? or getsusp.exe --Help from the command prompt, and press ENTER.

After I launch GetSusp, it creates a GetSusp.opt file. What is this file?
When you launch GetSusp, it creates a GetSusp.opt file with your GetSusp user preferences. These preferences are loaded the next time you use GetSusp, on the condition that GetSusp.opt is present in the same directory as GetSusp.exe.

What do I do if GetSusp.exe gets infected when I run it on a computer infected with a file infector such as W32/Sality or W32/Virut?
GetSusp does not run as expected, and you see the following message:
GetSusp may be infected, cannot continue 
GetSusp.exe is digitally signed and does an integrity check before it runs. To run GetSusp on a computer infected with a file infector, run it using the getsusp.exe --nc switch. This hidden switch disables integrity checking.

What user or system details are collected?
Email address, computer name, IP address, operating system and service pack, file location, and information about installed McAfee products are collected. Users who do not want to transmit samples, system data, or share their email address with McAfee Labs, can choose the option within the GetSusp tool to not submit results to McAfee Labs. Your email address will enable McAfee Labs to communicate with you regarding the results of the scan.

Can I prevent GetSusp from sending samples or information from my computer? 
GetSusp connects to Global Threat Intelligence (GTI) to match files found on your computer. If you do not want files and logs to be submitted to McAfee Labs, run the scan in offline mode. The files and logs harvested will not be uploaded to McAfee Labs. However, because there are no online lookups to the whitelist database, results will be degraded.

How does GetSusp complete most system scans in three to five minutes? 
System scans generally take between three and five minutes, irrespective of the size of the hard disk. This is because GetSusp scans are limited to running processes, the Windows registry, and file locations utilized by malware.

Why does GetSusp not identify my suspected malware?
The malware must be actively running on your computer or have an associated registry startup entry for GetSusp to identify it. GetSusp identifies only suspicious executable files. GetSusp does not scan documents, scripts, media, and other file formats. McAfee plans to add Rootkit scanning to GetSusp in a future release. 

Back to Contents
Sample submissions
How can I send a GetSusp submission larger than 10 MB to McAfee Labs? 
McAfee Labs supports only .zip files up to 10 MB. For GetSusp submissions larger than 10 MB, please contact Technical Support. 

How can I manually submit a file using GetSusp?
You can use the UPLOAD option in GetSusp to manually point to suspect files and send these to McAfee Labs.

How do I follow up with McAfee Labs for support on a GetSusp submission?
For tracking purposes, you will receive an email with a Reference Work Item ID from Virus_Research@avertlabs.com. McAfee Labs uses the email address you provided under GetSusp Preferences. Use the Work Item ID to follow up with Technical Support.

Rate this document

Beta Translate with

Select a desired language below to translate this page.

Glossary of Technical Terms

 Highlight Glossary Terms

Please take a moment to browse our Glossary of Technical Terms.