SV-55270r1_rule
V-42542
DTAM166-McAfee VirusScan on-access unwanted program first action
DTAM166
CAT II
10
From the ePO server console System Tree, select the Systems tab, select the asset to be checked, select Actions, select Agent, and select Modify Policies on a Single System. From the product pull down list, select VirusScan Enterprise 8.8.0. Select from the Policy column the policy associated with the On-Access Default Processes Policies.
Under the Actions tab, locate the "When an unwanted program is found:" label. From the "Perform this action first:" pull down menu, select "Clean files automatically".
Click OK to Save.
From the ePO server console System Tree, select the Systems tab, select the asset to be checked, select Actions, select Agent, and select Modify Policies on a Single System. From the product pull down list, select VirusScan Enterprise 8.8.0. Select from the Policy column the policy associated with the On-Access Default Processes Policies.
Under the Actions tab, locate the "When an unwanted program is found:" label. Ensure that for the "Perform this action first:" pull down menu, "Clean files automatically" is selected.
Criteria: If "Clean files automatically" is selected from "Perform this action first", this is not a finding.
On the client machine, use the Windows Registry Editor to navigate to the following key:
HKLM\Software\McAfee\ (32-bit)
HKLM\Software\Wow6432Node\McAfee\ (64-bit)
SystemCore\VSCore\On Access Scanner\McShield\Configuration\Default
Criteria: If the uAction_Program does not have a value of 5, this is a finding.
V-42542
False
DTAM166
From the ePO server console System Tree, select the Systems tab, select the asset to be checked, select Actions, select Agent, and select Modify Policies on a Single System. From the product pull down list, select VirusScan Enterprise 8.8.0. Select from the Policy column the policy associated with the On-Access Default Processes Policies.
Under the Actions tab, locate the "When an unwanted program is found:" label. Ensure that for the "Perform this action first:" pull down menu, "Clean files automatically" is selected.
Criteria: If "Clean files automatically" is selected from "Perform this action first", this is not a finding.
On the client machine, use the Windows Registry Editor to navigate to the following key:
HKLM\Software\McAfee\ (32-bit)
HKLM\Software\Wow6432Node\McAfee\ (64-bit)
SystemCore\VSCore\On Access Scanner\McShield\Configuration\Default
Criteria: If the uAction_Program does not have a value of 5, this is a finding.
M
2266