McAfee MTP08EMB3RUA Product Guide - Page 70

How detections are handled, Spyware protection mode and detections, Items with, detections

Page 70 highlights

4 Using Virus and Spyware Protection How detections are handled How detections are handled The type of threat and the policy settings determine how virus and spyware protection handles a detection. Items with detections Files and programs How virus and spyware protection handles the detections Virus detections: Virus and spyware protection attempts to clean the file. If it can be cleaned, the user is not interrupted with an alert. If it cannot be cleaned, an alert appears, and the detected file is deleted. A copy is placed in the quarantine folder. Potentially unwanted program detections: In Protect mode, detections are cleaned or deleted. In Prompt mode, users must select the response. In all cases, a backup copy of the original item is saved in a quarantine folder, in a proprietary binary format. Data for all activity is uploaded to the SecurityCenter for use in reports. Files are placed into the quarantine folder in a format that is no longer a threat to the client computer. It is not necessary to view or delete them, but you might occasionally want to do so. In these situations, you must view files on the client computer by using the Quarantine Viewer. Only users logged on as an administrator can access the Quarantine Viewer. After 30 days, these files are deleted. Registry keys and cookies Detections initially appear as Detected. Cleaning detected files also cleans their associated registry keys and cookies. Their status is then reported as Cleaned. Spyware protection mode and detections Spyware protection monitors programs that attempt to install or run on client computers. When it detects an unrecognized program, it either allows or blocks it. The response is based on the spyware protection mode selected in the policy assigned to the client computer. In this mode... Protect Prompt Report Spyware protection does this... Checks the list of allowed and blocked programs created by the administrator for computers using the policy. If the program is not on the list, spyware protection blocks the potentially unwanted program. Checks the list of approved and blocked programs created by the administrator for computers using the policy. Checks the list of programs the user has approved. If the program is not on either list, spyware protection displays a prompt with information about the detection and allows the user to select a response. This setting is the default. Checks the list of approved and blocked programs created by the administrator for computers using the policy. If the program is not on the list, it sends information about the potentially unwanted program to the SecurityCenter and takes no additional action. For all modes, detections are reported to the SecurityCenter, where you can view information about them in reports. To prevent popup prompts from appearing on client computers when potentially unwanted programs are detected, and for highest security, we recommend using Protect mode. 70 McAfee Total Protection Service 5.1.5 Product Guide

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175

How detections are handled
The type of threat and the policy settings determine how virus and spyware protection handles a
detection.
Items with
detections
How virus and spyware protection handles the detections
Files and
programs
Virus detections
: Virus and spyware protection attempts to clean the file. If it can
be cleaned, the user is not interrupted with an alert. If it cannot be cleaned, an
alert appears, and the detected file is deleted. A copy is placed in the quarantine
folder.
Potentially unwanted program detections
: In Protect mode, detections are
cleaned or deleted. In Prompt mode, users must select the response.
In all cases, a backup copy of the original item is saved in a quarantine folder, in a
proprietary binary format. Data for all activity is uploaded to the SecurityCenter for
use in reports.
Files are placed into the quarantine folder in a format that is no longer a threat to
the client computer. It is not necessary to view or delete them, but you might
occasionally want to do so. In these situations, you must view files on the client
computer by using the Quarantine Viewer. Only users logged on as an administrator
can access the Quarantine Viewer. After 30 days, these files are deleted.
Registry keys
and cookies
Detections initially appear as
Detected
. Cleaning detected files also cleans their
associated registry keys and cookies. Their status is then reported as
Cleaned
.
Spyware protection mode and detections
Spyware protection monitors programs that attempt to install or run on client computers. When it
detects an unrecognized program, it either allows or blocks it. The response is based on the spyware
protection mode selected in the policy assigned to the client computer.
In this
mode...
Spyware protection does this...
Protect
Checks the list of allowed and blocked programs created by the administrator for
computers using the policy. If the program is not on the list, spyware protection blocks
the potentially unwanted program.
Prompt
Checks the list of approved and blocked programs created by the administrator for
computers using the policy. Checks the list of programs the user has approved. If the
program is not on either list, spyware protection displays a prompt with information
about the detection and allows the user to select a response. This setting is the default.
Report
Checks the list of approved and blocked programs created by the administrator for
computers using the policy. If the program is not on the list, it sends information about
the potentially unwanted program to the SecurityCenter and takes no additional action.
For all modes, detections are reported to the SecurityCenter, where you can view information about
them in reports.
To prevent popup prompts from appearing on client computers when
potentially unwanted programs are detected, and for highest security,
we recommend using Protect mode.
4
Using Virus and Spyware Protection
How detections are handled
70
McAfee Total Protection Service 5.1.5 Product Guide