Intel Security True Key: what is this program and how to remove it? Intel Security Assist, what is this program and is it needed? McAfee Software

Fighting remote control: how to disable Intel ME

Alexander Antipov


Intel ME Technology (or AMT, Active Management Technology) is one of the most mysterious and powerful elements modern x86 platforms. The tool was originally created as a solution for remote administration. However, it has such powerful functionality and is so beyond the control of users of Intel-based devices that many of them would like to disable this technology, which is not so easy to do.

At the Positive Hack Days VI forum held in Moscow on May 17 and 18, Positive Technologies researchers Maxim Goryachiy and Mark Ermolov presented several techniques for disabling Intel ME, accompanying the report with a video demonstration of the process.

What is it and why do you need to turn it off?

The Intel Management Engine (ME) subsystem is an additional "hidden" processor that is present in all devices based on Intel chipsets(not only in PCs and laptops, but also in servers). The ME runtime environment never “sleeps” and works even when the computer is turned off (in the presence of standby voltage), and also has access to random access memory, network interface, USB controller and built-in graphics adapter.

Despite such extensive capabilities, there are questions about the level of security of ME - previously, researchers have already found serious vulnerabilities and attack vectors. In addition, the subsystem contains potentially dangerous functions - remote control, NFC, hidden service partition. The ME subsystem interfaces are undocumented and the implementation is closed.

All these reasons lead many to view ME technology as a “hardware hack.” The situation is aggravated by the fact that, on the one hand, the device user does not have the ability to disable this functionality, and on the other hand, the equipment manufacturer may make errors in the ME configuration.

The good news is that there are still ways to disable ME.

Techniques for disabling Intel ME

Positive Technologies researchers Maxim Goryachiy and Mark Ermolov presented a report on disabling Intel ME during the Positive Hack Days VI forum held in Moscow. Experts have described several techniques for disabling this subsystem:
  1. Failure-based ME initialization;
  2. Through the ME firmware update mechanism;
  3. Undocumented Commands
  4. An undocumented mechanism intended for hardware developers - Manufacture Mode.
Researchers have found that hardware platform developers often forget to turn off Manufacture Mode, which allows the latter method to be used on a large number of computers without any additional costs in real time.

Most shutdown methods use built-in ME mechanisms designed for device vendors on Intel platform. All of them are described in detail in the presentation, which is published on GitHub. The link provides a demo video of disabling ME (it’s also below):

And yet, a reasonable question arises: “Does ME really stop working fully when using its built-in shutdown mechanisms?” As proof of the fact that ME is disabled, the researchers present the following argument: ME operates in two memory modes: SRAM only (built into ME) and SRAM + UMA. UMA is a part of the host memory that is used as paged memory (swap). Once the DRAM controller is initialized by the host, the ME always switches to SRAM + UMA mode.

Thus, if the ME is really turned off, then when the ME access to UMA memory is disabled at the hardware level at an arbitrary moment (via the VСm channel), hardware failures will not occur in the ME due to the lack of data and code that were forced out into the UMA memory (such hardware failures lead to an emergency power outage from the main hardware components of the platform). On the other hand, the use of these methods makes it possible to carry out DoS attacks on AMT technology if it is used for remote management.

McAfee offers comprehensive solutions for antivirus protection and safe work in the Internet. Download antivirus programs and protection programs against spyware McAfee to protect yourself from the latest web threats

List of programs

McAfee Endpoint Security
Corporate antivirus with all necessary functions: Threat Prevention, Firewall, Web Control and Adaptive Threat Defense

McAfee LiveSafe
Comprehensive antivirus, cross-platform solution to protect all your devices on Windows, Mac OS, Android and iOS platforms. Includes firewall, web protection, password manager, parental control and secure cloud storage

McAfee Total Protection
Comprehensive real-time protection: antivirus, antispyware, antispam, firewall and parental controls, as well as automatic cloud backup and encrypted data storage

McAfee AntiVirus Plus
Basic protection against viruses and Internet threats. Antivirus and antispyware, two-way firewall, web protection with SiteAdvisor, permanent data deletion and system cleanup

McAfee Internet Security
Comprehensive antivirus solution. The most complete and effective protection against viruses and Internet threats, computer optimization and online backup 1 GB

McAfee Security Scan Plus
A free scanner that checks the system for updated antivirus protection, firewall, and web protection. The utility also allows you to detect malicious threats in active processes

McAfee Stinger
A free, installation-free utility for detecting and removing from your computer known viruses, Internet worms and Trojans

McAfee Real Protect
Proactive zero-day threat protection that uses real-time behavioral detection technology to monitor suspicious system activity

McAfee WebAdvisor
Free plugin from Intel Security for Firefox browsers, Google Chrome And Internet Explorer, providing protection against malicious, phishing and fraudulent sites and malicious downloads

True Key
Intel Security True Key Password Manager Offers Support Windows platforms, Mac, Android, iOS and multiple multi-factor authentication methods for maximum security of your passwords

McAfee SiteAdvisor Live
Web McAfee antivirus SiteAdvisor Live provides protection against malicious sites and phishing, safe web searching, checking links in email and online chats

McAfee Rootkit Remover
A stand-alone utility designed to detect and remove a complex of rootkits and related threats. Currently, McAfee's anti-rootkit can detect and remove the ZeroAccess and TDSS families of rootkits

McAfee Mobile Security for Android
Free antivirus for Android, antispam, anti-theft with remote control With help SMS and through the web portal, secure mobile web surfing and protection Wi-Fi connections, cloud backup for smartphone or tablet

McAfee Mobile Security for iOS
Protection application iOS devices against viruses and internet threats with functions Reserve copy and theft protection

McAfee Mobile Innovations for Android
McAfee Mobile Innovations is a universal security application for Android devices. Key Features: Smart Perimeter, Secure QR Scanner and Secure Data Storage

McAfee GetSusp
The free McAfee GetSusp utility is designed to find unnoticed antivirus protection malware. Detection is made through a combination of heuristic technology and an online database safe files McAfee

McAfee FreeScan
Convenient and free product to check your computer for viruses, without installing any software

McAfee FakeAlert Stinger
A special version of Stinger that uses Super Scan mode to detect fake antiviruses and restore the system after their impact

McAfee Rootkit Detective
A free utility for detecting and removing hidden malicious modules (rootkits) running in the system

McAfee On-Demand VirusScan
On-demand virus scanner. Free version McAfee VirusScan antivirus, which allows you to scan and cure your computer from viruses, Internet worms, Trojans and other malware

McAfee virus database updates
Virus database files V2 DAT and V3 DAT, designed to update products installed on servers and workstations not connected to the Internet.

McAfee is a leader in cybersecurity, providing industry-leading security solutions to end users, small and small businesses. big business, corporations and government agencies. McAfee security technologies use unique feature forecasting powered by McAfee Global Threat Intelligence, allowing home users and businesses to stay one step ahead of the next wave of viruses, malware and other online threats.

McAfee offers comprehensive, integrated solutions to help you information security, protecting all environments. McAfee endpoint security solutions and mobile devices ensure the security of end user devices from threats such as viruses, phishing, malware, and include antivirus software and web security features. Network security solutions ensure the security of the network and its perimeter. McAfee solutions protect servers, databases, and data centers from threats targeting enterprise systems.

McAfee cloud security solutions provide industry-leading protection against online threats, whether your cloud computing technology is private, public, or hybrid. All security solutions are managed centrally from a single McAfee ePolicy Orchestrator console, allowing you to efficiently and quickly manage your security infrastructure.

Software McAfee:

  • Compliance with confidentiality requirements and maximum protection of critical data: McAfee Endpoint Encryption, McAfee Total Protection for Data And McAfee Total Protection for Data Loss Prevention.
  • Maximum protection databases of external and internal threats in order to reduce the possibility of information loss: McAfee Database User Identifier, McAfee Database Activity Monitoring, McAfee Virtual Patching for Databases And McAfee Integrity Monitoring for Databases.
  • Ensuring protection when working with by email and on the Internet: McAfee SaaS Web & Email Security with Archiving, McAfee Content Security Suite, McAfee Security for Email And McAfee Email Protection.
  • Endpoint protection: McAfee Endpoint Protection And McAfee Total Protection for Endpoint.
  • Network protection: McAfee Network Security Platform, McAfee Network Security Manager And McAfee Network Threat Response.
  • Ensure compliance and risk protection: McAfee Configuration Control, McAfee Application Control, McAfee Risk Advisor And McAfee Policy Auditor.
  • Cloud protection: McAfee SaaS Endpoint Protection, McAfee SaaS Email Encryption And McAfee SaaS Web Protection.
  • Management and control over the protection of enterprise information: McAfee ePolicy Orchestrator.

McAfee Antivirus is considered the most up-to-date and balanced antivirus. Availability, low resource consumption, simplicity - all this is about McAfee antivirus, which you can buy in our online store. To use this antivirus correctly, a license is required.

Hello everyone Today we will talk about the program from the great and mighty Intel, sometimes it seems to me that this best manufacturer iron, maybe that’s how it is? The name of the program Intel Security Assist already suggests that it is something related to security, and since this is Intel, it MAY be that the program is worthwhile. Intel Security Assist may appear on your computer on its own as additional application to the drivers. Windows itself can install it through the update center. I also found information that this program installed together with Intel Me (unfortunately I don’t know what it is).

This means I also found information on the Internet that Intel Security Assist is a security component and is of little use purely for a home PC. In principle, everything is correct, if you look at the name of the Intel Security Assist program, it turns out that this is an Intel security assistant. Something like this

Look guys, I found this interesting picture on the Internet:


You'll probably ask, so what's wrong with this, what kind of value did I find here? And I'll tell you what! You see there is the letter M, well, this little red icon, see? Well guys, this is the McAfee logo, this is something like a program that checks the security on your computer. That is, it looks to see if you have an antivirus and looks at something else, I don’t remember exactly, I only know that this program is not particularly useful. Although what I described refers to some McAfee program, but I don’t remember which one, the fact is that there are several of them! In any case, I can already conclude that if you remove Intel Security Assist from your computer, then in 98% of cases nothing will happen, the computer will continue to function as before

For example, do you know what kind of Intel Management Engine Components program this is? No? Well, it doesn’t matter, but when installing this application, look how much software will be installed, there is also Intel Security Assist:


This is all like additional software, it’s needed for advanced capabilities of some kind, but in practice we often simply don’t use such software

I also found this picture, here something is written in English:


But what did they want to tell us? I don’t know English, so I went into Google Translator and translated everything there and this is what it says:


So, here everything is more or less clearly stated that Intel Security Assist can help with updates to protect your device. But damn it, it also says here that Intel would like to somehow collect information about our device, well, here we mean a computer, a laptop, and if it collects all this information, then it will be able to turn on the service! Oh, damn it, what is this and what did Intel want to tell us about its program? Hey, Intel, you're telling us something wrong here, you know what, let's go ahead...

I also know this, I remember vaguely, but in general I somehow bought Intel processor about two years ago, the Pentium G3220 model, and in the box with the process there was also a piece of paper with something written about McAfee. Everything was in English, and the paper was black and white. In short, I think that McAfee is something like some kind of security product from Intel, and the company is quietly promoting it, so calmly and without bothering the user

How to completely remove Intel Security Assist from your computer? Look, press the Win + R buttons on the keyboard, then write the following command in the window:


Then a window will open with a list of all programs running on your computer, here you need to find Intel Security Assist, select the program and then click on Delete:


This above shows how to do this in Windows 10, but here it is shown almost the same thing, but in Windows 7:


In both the first and second cases, you can also right-click in that window, where the list of software is, using the Intel Security Assist program and select Delete. All guys, I wrote everything, good luck to you and I look forward to visiting you again

22.04.2017