SV-55277r2_rule
V-42549
DTAM138 - Access Protection McAfee services protection
DTAM138
CAT I
10
Access the local VirusScan console by clicking Start->All Programs->McAfee->VirusScan Console.
Under the Task column, select Access Protection, right-click, and select Properties.
Under the Access Protection tab, select the "Prevent McAfee services from being stopped" option.
Click OK to save.
Note: If the HIPS signature 3892 is enabled to provide the "Prevent termination of McAfee processes" protection, this check is not applicable.
Access the local VirusScan console by clicking Start->All Programs->McAfee->VirusScan Console.
Under the Task column, select Access Protection, right-click, and select Properties.
Under the Access Protection tab, ensure the "Prevent McAfee services from being stopped" option is selected.
Criteria: If the "Prevent McAfee services from being stopped" option is selected, this is not a finding.
On the client machine, use the Windows Registry Editor to navigate to the following key:
HKLM\Software\McAfee\ (32-bit)
HKLM\Software\Wow6432Node\McAfee\ (64-bit)
SystemCore\VSCore\On Access Scanner\BehaviourBlocking
Criteria: If the value of PVSPTEnabled is REG_DWORD = 1, this is not a finding.
V-42549
False
DTAM138
Note: If the HIPS signature 3892 is enabled to provide the "Prevent termination of McAfee processes" protection, this check is not applicable.
Access the local VirusScan console by clicking Start->All Programs->McAfee->VirusScan Console.
Under the Task column, select Access Protection, right-click, and select Properties.
Under the Access Protection tab, ensure the "Prevent McAfee services from being stopped" option is selected.
Criteria: If the "Prevent McAfee services from being stopped" option is selected, this is not a finding.
On the client machine, use the Windows Registry Editor to navigate to the following key:
HKLM\Software\McAfee\ (32-bit)
HKLM\Software\Wow6432Node\McAfee\ (64-bit)
SystemCore\VSCore\On Access Scanner\BehaviourBlocking
Criteria: If the value of PVSPTEnabled is REG_DWORD = 1, this is not a finding.
M
605