McAfee TSA00M005PAA Processor Guide - Page 64

How detections are handled, Spyware protection mode and detections

Page 64 highlights

Using Virus and Spyware Protection How detections are handled How detections are handled The type of threat and the policy settings determine how virus and spyware protection handles a detection. Items with detections Files and programs Items with detections Items with detections Registry keys and cookies Registry keys and cookies How virus and spyware protection handles the detections Virus detections: Virus and spyware protection attempts to clean the file. If it can be cleaned, the user is not interrupted with an alert. If it cannot be cleaned, an alert appears, and the detected file is deleted. A copy is placed in the quarantine folder. Potentially unwanted program detections: In Protect mode, Hdreoeswtpeocvtniiosreun.ss aarnedclsepanyewdaorredperleotteedc.tIinonPrhoamnpdtlmesodthe,eudseertsemctuiostnsselect the In all cases, a backup copy of the original item is saved in a quarantine Hfoolwderv,iirnuas parnodprsieptyawryabrienaprryoftoermctaiot.nDhaatandfolresallthacetidvietyteisctuioplnosaded to tIhneaSlleccausreitsy,Caenbtaecrkufopr cuospeyinofrethpeorotsri.ginal item is saved in a quarantine NfoOldTeEr,: iFnilaesparoreprpielatacreydbinintaortyhfeorqmuaarta. nDtaintae ffoorldaelrl ainctaivfiotyrmisautptlhoaatdiesdntoo ltohnegSeercautrhitryeCaetnttoerthfeorcluiesnetincormeppourttesr.. It is not necessary to view or delete tNhOeTmE,:bFuilteysoaurempiglahcteodcicnatsoiotnhaellqyuwaaranntttinoedfoolsdoe.rIinn tahefosremsaittutahtaiotniss,nyoou mlonugsterviaewthrfeileast toonththeeclcieliennt tcocommppuutetre.rItbiys unsoitngnetcheessQaurayrtaonvtiineewVoirewdeelre. te Othnelmy u, sbeurts yloogugmedigohnt aosccaansaiodnmailnlyiswtraantotrtcoadnoacscoe.sIsnththeeQseuasriatunatitnioenVsi,eywoeur. mAfutesrt 3vi0ewdafyilse,sthoenstehefileclsieanrtecdoemleptuetde.r by using the Quarantine Viewer. Only users logged on as an administrator can access the Quarantine Viewer. ADfetteerc3ti0ondsaiynsit,iathllyesaeppfieleasr aarseDdeetleetcetde.d. Cleaning detected files also cleans their associated registry keys and cookies. Their status is then reported aDsetCelcetiaonnesdin.itially appear as Detected. Cleaning detected files also cleans their associated registry keys and cookies. Their status is then reported as Cleaned. Spyware protection mode and detections Spyware protection monitors programs that attempt to install or run on client computers. When it detects an unrecognized program, it either allows or blocks it. The response is based on the spyware protection mode selected in the policy assigned to the client computer. In this mode... Spyware protection does this... Protect In this mode... Checks the list of allowed and blocked programs created by the administrator for computers uSspinygwtahreepporliocyt.eIcfttiohen pdrooegrsatmhiiss.n..ot on the list, spyware protection blocks the potentially Protect uCnhwecaknstethdeplirsotgorfamall.owed and blocked programs created by the administrator for computers Prompt Cushiencgktshtehepolilsictyo. fIfatphperopvreodgraanmdisblnoockt eodn pthroeglrisatm, sspcyrweaatreedpbroytethcteioandbmloinciksstrathtoerpfootrentially cuonmwapnutteedrspursoignrgamth.e policy. Checks the list of programs the user has approved. If the Prompt cpCthorheomegcdprkeaustmteetchritsseiounlnisosittannoogdnftahaepeliltpohprweoorsvliecltiysdh.te,aCsnuhpdseyecbwrklaostorctekhsepeedlreloipcsttterocoagtfirropaenmsropdsgoisrncaprsmleeaa.ystsTethhdaeispburysosetmethtreipnhtgaawdsismitahtipnhipiensrftodorvaeremtfoadaru.tlfIitoof. rnthaebout Report pCrhoegcrkasmthise nliostt oonf aepitphreorvelisdt,asnpdywblaorcekepdropterocgtiroanmdsiscprleaaytseda pbryotmheptawdmithiniinsftorarmtoartfioonr about cthoemdpeutteecrtsiounsianngdthaellopwoslictyh.eIfutsheer tporosgerleacmt aisrneostpoonnsteh.eTlhisist,siet tsteinngdsisinthfoermdeaftaiuonlt.about Report tChheecpkostetnhteiallilsyt uonf wapapnrtoevdepdroagnrdamblotcoktehdepSreocgurarimtysCecrnetaetreadnbdytathkeesandomaindisdtirtaiotnoar lfoarction. computers using the policy. If the program is not on the list, it sends information about For all modes, detectiothnespaortenrtieapllyourtnewdanttoedthpreogSraemcutroittyhCe eSnectuerri,tywCehneterreaynodutackeasnnvoiaedwditiinonfoarl macatiotino.n about them in reports. NOTE: To prevent popup prompts from appearing on client computers when potentially unwanted programs are detected, and for highest security, we recommend using Protect mode. Mode Behavior of virus and spyware protection 64 McAfee Total Protection Service Product Guide MReopdoert B• ehaUvsieorrs oafrevinroutsparonmdpstpedywabaoruetpdreotteectcitoinosn. Report •• UDseetersctaiorensnaorteprreopmoprtteedd taobothuet dSeetceucrtiitoynCse.nter.

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134

64
McAfee Total Protection Service Product Guide
How detections are handled
The type of threat and the policy settings determine how virus and spyware protection handles
a detection.
Spyware protection mode and detections
Spyware protection monitors programs that attempt to install or run on client computers.
When it detects an unrecognized program, it either allows or blocks it. The response is based
on the spyware protection mode selected in the policy assigned to the client computer.
For all modes, detections are reported to the SecurityCenter, where you can view information
about them in reports.
NOTE:
To prevent popup prompts from appearing on client computers when potentially unwanted
programs are detected, and for highest security, we recommend using Protect mode.
How virus and spyware protection handles the detections
Items with detections
Virus detections
: Virus and spyware protection attempts to clean the
file. If it can be cleaned, the user is not interrupted with an alert. If it
Files and programs
cannot be cleaned, an alert appears, and the detected file is deleted. A
copy is placed in the quarantine folder.
Potentially unwanted program detections
: In Protect mode,
detections are cleaned or deleted. In Prompt mode, users must select the
response.
How virus and spyware protection handles the detections
Items with detections
In all cases, a backup copy of the original item is saved in a quarantine
folder, in a proprietary binary format. Data for all activity is uploaded to
the SecurityCenter for use in reports.
NOTE:
Files are placed into the quarantine folder in a format that is no
longer a threat to the client computer. It is not necessary to view or delete
them, but you might occasionally want to do so. In these situations, you
must view files on the client computer by using the Quarantine Viewer.
Only users logged on as an administrator can access the Quarantine Viewer.
After 30 days, these files are deleted.
Detections initially appear as
Detected
. Cleaning detected files also cleans
their associated registry keys and cookies. Their status is then reported
as
Cleaned
.
Registry keys and cookies
Spyware protection does this...
In this mode...
Checks the list of allowed and blocked programs created by the administrator for computers
using the policy. If the program is not on the list, spyware protection blocks the potentially
unwanted program.
Protect
Checks the list of approved and blocked programs created by the administrator for
computers using the policy. Checks the list of programs the user has approved. If the
Prompt
program is not on either list, spyware protection displays a prompt with information about
the detection and allows the user to select a response. This setting is the default.
Checks the list of approved and blocked programs created by the administrator for
computers using the policy. If the program is not on the list, it sends information about
the potentially unwanted program to the SecurityCenter and takes no additional action.
Report
Using Virus and Spyware Protection
How detections are handled