SV-55271r2_rule
V-42543
DTAM167-McAfee VirusScan on-access unwanted program second action
DTAM167
CAT II
10
From the ePO server console System Tree, select the Systems tab, select the asset to be checked, select Actions, select Agent, and select Modify Policies on a Single System. From the product pull down list, select VirusScan Enterprise 8.8.0. Select from the Policy column the policy associated with the On-Access Default Processes Policies.
Under the Actions tab, locate the "When an unwanted program is found:" label. From the "If the first action fails, then perform this action:" pull down menu, select "Delete files automatically".
Click OK to Save.
From the ePO server console System Tree, select the Systems tab, select the asset to be checked, select Actions, select Agent, and select Modify Policies on a Single System. From the product pull down list, select VirusScan Enterprise 8.8.0. Select from the Policy column the policy associated with the On-Access Default Processes Policies.
Under the Actions tab, locate the "When an unwanted program is found:" label. Ensure the "If the first action fails, then perform this action:" has "Delete files automatically" selected.
Criteria: If "Delete files automatically" is selected from the "If the first action fails, then perform this action:" drop-down list, this is not a finding.
On the client machine, use the Windows Registry Editor to navigate to the following key:
HKLM\Software\McAfee\ (32-bit)
HKLM\Software\Wow6432Node\McAfee\ (64-bit)
SystemCore\VSCore\On Access Scanner\McShield\Configuration\Default
Criteria: If the uSecAction_Program does not have a value of 4, this is a finding.
V-42543
False
DTAM167
From the ePO server console System Tree, select the Systems tab, select the asset to be checked, select Actions, select Agent, and select Modify Policies on a Single System. From the product pull down list, select VirusScan Enterprise 8.8.0. Select from the Policy column the policy associated with the On-Access Default Processes Policies.
Under the Actions tab, locate the "When an unwanted program is found:" label. Ensure the "If the first action fails, then perform this action:" has "Delete files automatically" selected.
Criteria: If "Delete files automatically" is selected from the "If the first action fails, then perform this action:" drop-down list, this is not a finding.
On the client machine, use the Windows Registry Editor to navigate to the following key:
HKLM\Software\McAfee\ (32-bit)
HKLM\Software\Wow6432Node\McAfee\ (64-bit)
SystemCore\VSCore\On Access Scanner\McShield\Configuration\Default
Criteria: If the uSecAction_Program does not have a value of 4, this is a finding.
M
2266