McAfee TSA00M005PAA Processor Guide - Page 48

Virus and Spyware Protection, Option Definitions - General Settings Tab, Option Definitions - Advanced

Page 48 highlights

Hide the splash screen UDsiisnpglaythseupSpeocrtunriottyifCiceantitoenrs on client computers Management of security policies Disabled: The McAfee Total Protection Service splash screen is displayed when a computer is powered on and the client software starts running. Enabled: Notification dialog boxes warn client computer users when software upgrades and DAT file updates are being discontinued for their operating system. Virus and Spyware Protection No excluded files and folders or approved programs are configured. NOTE: With the default advanced settings for virus and spyware protection, it is possible for an ondemand scan to detect threats in archived files that are not detected during an on-access scan. This is because on-access scans do not look at compressed archives by default. If this is a concern for your organization, you should create a new policy where this option is enabled. Option Definitions - General Settings Tab Option Definition Scheduled Scan Settings Off: No on-demand scan is scheduled. On-access scans still occur every time users run, open, or download files. Spyware Protection Mode Prompt: Spyware scanning is enabled. When potentially unwanted programs are detected, virus and spyware protection asks users how to respond. NOTE: To prevent prompts from displaying, create a new policy with a different setting. For maximum protection, we recommend selecting Protect mode to automatically delete potentially unwanted programs. Option Definitions - Advanced Settings Tab Option Definition Virus Protection Settings Enable outbreak response Enabled: Client computers check for an outbreak detection definition (DAT) file every hour. Enable buffer overflow protection Enabled: Detect code starting to run from data in reserved memory and prevent that code from running. Enable script scanning Enabled: Detect harmful code embedded in web pages that would cause unauthorized programs to run on client computers. Scan email (before delivering to the Outlook Inbox) Enabled: Look for threats in email before it is placed into the user's Inbox. Scan all file types during on-access scans Enabled: Look for threats in all types of files, instead of only default types, when they are downloaded, opened, or run. (Default file types are defined in the DAT files.). Scan within archives during on-access scans (e.g., Disabled: Do not look for threats in compressed archive .zip, .rar, .tat, .tgz) files when the files are accessed. Scan within archives during on-demand scans (e.g., Enabled: Look for threats in compressed archive files .zip, .rar, .tat, .tgz) when files are scanned manually and during scheduled scans. Enable Artemis heuristic network check for suspicious files Enabled: Send information about unrecognized threat detections to McAfee Avert Labs for analysis. Scan mapped network drives during on-access scans Disabled: Do not look for threats in files on mapped network drives when they are accessed. Enable on-access scanning (if disabled) the next time client computers check for an update Enabled: If on-access scanning is disabled on a client computer, it is re-enabled when the computer checks for updates. Maximum percentage of CPU time allocated for on-demand and scheduled scans High: These scans are allowed to use a high percentage of CPU time. (Scans should be requested during non-peak hours, when users are not performing tasks on their computers.) Spyware Protection Settings Detect ... Enabled: Detect all types of spyware threats during scans. 48 McAfee Total Protection Service Product Guide

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134

48
McAfee Total Protection Service Product Guide
Virus and Spyware Protection
No excluded files and folders or approved programs are configured.
NOTE:
With the default advanced settings for virus and spyware protection, it is possible for an on-
demand scan to detect threats in archived files that are not detected during an on-access scan. This
is because on-access scans do not look at compressed archives by default. If this is a concern for
your organization, you should create a new policy where this option is enabled.
Option Definitions — General Settings Tab
Option Definitions — Advanced Settings Tab
Definition
Option
Off
: No on-demand scan is scheduled.
On-access scans still occur every time users run, open,
or download files.
Scheduled Scan Settings
Prompt
: Spyware scanning is enabled. When potentially
unwanted programs are detected, virus and spyware
protection asks users how to respond.
NOTE:
To prevent prompts from displaying, create a new
policy with a different setting. For maximum protection,
Spyware Protection Mode
we recommend selecting Protect mode to automatically
delete potentially unwanted programs.
Definition
Option
Virus Protection Settings
Enabled
: Client computers check for an outbreak
detection definition (DAT) file every hour.
Enable outbreak response
Enabled
: Detect code starting to run from data in reserved
memory and prevent that code from running.
Enable buffer overflow protection
Enabled
: Detect harmful code embedded in web pages
that would cause unauthorized programs to run on client
computers.
Enable script scanning
Enabled
: Look for threats in email before it is placed into
the user’s Inbox.
Scan email (before delivering to the Outlook Inbox)
Enabled
: Look for threats in all types of files, instead of
only default types, when they are downloaded, opened,
or run. (Default file types are defined in the DAT files.).
Scan all file types during on-access scans
Disabled
: Do not look for threats in compressed archive
files when the files are accessed.
Scan within archives during on-access scans (e.g.,
.zip, .rar, .tat, .tgz)
Enabled
: Look for threats in compressed archive files
when files are scanned manually and during scheduled
scans.
Scan within archives during on-demand scans (e.g.,
.zip, .rar, .tat, .tgz)
Enabled
: Send information about unrecognized threat
detections to McAfee Avert Labs for analysis.
Enable Artemis heuristic network check for
suspicious files
Disabled
: Do not look for threats in files on mapped
network drives when they are accessed.
Scan mapped network drives during on-access
scans
Enabled
: If on-access scanning is disabled on a client
computer, it is re-enabled when the computer checks for
updates.
Enable on-access scanning (if disabled) the next
time client computers check for an update
High
: These scans are allowed to use a high percentage
of CPU time. (Scans should be requested during non-peak
Maximum percentage of CPU time allocated for
on-demand and scheduled scans
hours, when users are not performing tasks on their
computers.)
Spyware Protection Settings
Enabled
: Detect all types of spyware threats during scans.
Detect ...
Using the SecurityCenter
Management of security policies