Select any two versions of this STIG to compare the individual requirements
Select any old version/release of this STIG to view the previous requirements
Procedure: Use the Windows Registry Editor to navigate to the following key: HKLM\Software\Network Associates\TVD\Shared Components\ On Access Scanner\mcshield\Configuration Criteria: If the value of bStartDisabled is 0, this is not a finding. If the value is 1, this is a finding
Change the value of registry key HKLM\Software\Network Associates\TVD\Shared Components\ On Access Scanner\mcshield\Configuration so that the value of bStartDisabled is 0.
Procedure: Use the Windows Registry Editor to navigate to the following key: HKLM\Software\Network Associates\TVD\Shared Components\ On Access Scanner\mcshield\Configuration Criteria: If the value of bDontScanBootSectors is 0, this is not a finding. If the value is 1, this is a finding
Change the registry key HKLM\Software\Network Associates\TVD\Shared Components\ On Access Scanner\mcshield\Configuration so that the value of bDontScanBootSectors is 0.
Procedure: Use the Windows Registry Editor to navigate to the following key: HKLM\Software\Network Associates\TVD\Shared Components\On Access Scanner\mcshield\Configuration Criteria: If the value of bScanFloppyonShutdown is 1, this is not a finding. If the value is 0, this is a finding
Change the registry key HKLM\Software\Network Associates\TVD\Shared Components\On Access Scanner\mcshield\Configuration so that the value of bScanFloppyonShutdown is 1.
Procedure: Use the Windows Registry Editor to navigate to the following key: HKLM\Software\Network Associates\TVD\Shared Components\ On Access Scanner\mcshield\Configuration Criteria: If the value of Alert_AutoShowList is 1, this is not a finding. If the value is 0, this is a finding
Change the registry key HKLM\Software\Network Associates\TVD\Shared Components\On Access Scanner\mcshield\Configuration so that the value of Alert_AutoShowList is 1.
Procedure: Use the Windows Registry Editor to navigate to the following key: HKLM\Software\Network Associates\TVD\Shared Components\ On Access Scanner\mcshield\Configuration Criteria: If the value of Alert_UsersCanRemove is 0, this is not a finding. If the value is 1, this is a finding
Change the registry key HKLM\Software\Network Associates\TVD\Shared Components\ On Access Scanner\mcshield\Configuration so that the value of Alert_UsersCanRemove is 0.
Procedure: Use the Windows Registry Editor to navigate to the following key: HKLM\Software\Network Associates\TVD\Shared Components\ On Access Scanner\mcshield\Configuration Criteria: If the value of Alert_UsersCanClean is 1, this is not a finding. If the value is 0, this is a finding
Change the registry key HKLM\Software\Network Associates\TVD\Shared Components\ On Access Scanner\mcshield\Configuration so that the value of Alert_UsersCanClean is 1.
Procedure: Use the Windows Registry Editor to navigate to the following key: HKLM\Software\Network Associates\TVD\Shared Components\On Access Scanner\mcshield\Configuration Criteria: If the value of Alert_UsersCanDelete is 1, this is not a finding. If the value is 0, this is a finding.
Change the registry key HKLM\Software\Network Associates\TVD\Shared Components\On Access Scanner\mcshield\Configuration so that the value of Alert_UsersCanDelete is 1.
Procedure: Use the Windows Registry Editor to navigate to the following key: HKLM\Software\Network Associates\TVD\Shared Components\On Access Scanner\mcshield\Configuration Criteria: If the value of Alert_UsersCanQuarantine is 1, this is not a finding. If the value is 0, this is a finding.
Change the registry key HKLM\Software\Network Associates\TVD\Shared Components\On Access Scanner\mcshield\Configuration so that the value of Alert_UsersCanQuarantine to 1.
Procedure: Use the Windows Registry Editor to navigate to the following key: HKLM\Software\Network Associates\TVD\Shared Components\On Access Scanner\mcshield\Configuration Criteria: If the value of bLogtoFile is 1, this is not a finding. If the value is 0, this is a finding.
Change the registry key HKLM\Software\Network Associates\TVD\Shared Components\On Access Scanner\mcshield\Configuration so that the value of bLogtoFile is 1.
Procedure: Use the Windows Registry Editor to navigate to the following key: HKLM\Software\Network Associates\TVD\Shared Components\On Access Scanner\mcshield\Configuration Criteria: If the value of bLimitSize is 1, and the dwMaxLogSizeMB is at least Hex 64 or bLimitSize is 0 this is not a finding. If the bLimitSize is 0 and dwMaxLogSizeMB is less than Hex 64, this is a finding.
Change the registry key HKLM\Software\Network Associates\TVD\Shared Components\On Access Scanner\mcshield\Configuration so that the value of bLimitSize is 1, and the value of dwMaxLogSizeMB is equal to or greater than Hex 64 or bLimitSize is 0.
Procedure: Use the Windows Registry Editor to navigate to the following key: HKLM\Software\Network Associates\TVD\Shared Components\On Access Scanner\mcshield\Configuration Criteria: If the value of bLogSummary is 1, this is not a finding. If the value is 0, this is a finding.
Change the registry key HKLM\Software\McAfee\VSCore\On Access Scanner\mcshield\Configuration so that the value of bLogSummary is 1.
Use the Windows Registry Editor to navigate to the following key: HKLM\Software\McAfee\VSCore\On Access Scanner\mcshield\Configuration Criteria: If the value ReportEncryptedFiles is 1, this is not a finding. If the value is 0, this is a finding.
Change the registry key HKLM\Software\McAfee\VSCore\On Access Scanner\mcshield\Configuration so that the value of ReportEncryptedFiles is 1.
Procedure: Use the Windows Registry Editor to navigate to the following key: HKLM\Software\McAfee\VSCore\On Access Scanner\mcshield\Configuration Criteria: If the value bLogUserName is 1, this is not a finding. If the value is 0, this is a finding.
Change the registry key HKLM\Software\McAfee\VSCore\On Access Scanner\mcshield\Configuration so that the value of bLogUserName is 1.
Procedure: Use the Windows Registry Editor to navigate to the following key: HKLM\Software\McAfee\DesktopProtection\Tasks\{A14CD6FC-3BA8-4703-87BF-e3247CE382F5} Criteria: If bSchedEnabled=1 and eScheduleType=0 the schedule is daily, this is not a finding. If bSchedEnabled=1 and eScheduleType=1 the schedule is weekly, this is not a finding. If bSchedEnabled=0, no schedule is set, then this is a finding.
On the VirusScan console, Double click the AutoUpdate item, click the Schedule button. On the TASK tab, check the Enable box, and enable the schedule. On the Schedule tab, create a DAILY or WEEKLY schedule to run.
Procedure: Use the Windows Registry Editor to navigate to the following key: HKLM\Software\McAfee\VSCore\Email Scanner\Outlook\OnDelivery\GeneralOptions Criteria: If the value bEnabled is 1, this is not a finding.
Change the registry key HKLM\Software\McAfee\VSCore\Email Scanner\Outlook\OnDelivery\GeneralOptions so that the value of bEnabled is 1.
Procedure: Use the Windows Registry Editor to navigate to the following key: HKLM\Software\McAfee\VSCore\Email Scanner\Outlook\OnDelivery\DetectionOptions Criteria: If the value dwProgramHeuristicsLevel is 1, this is not a finding. If the value is 0, this is a finding.
Change the registry key HKLM\Software\McAfee\VSCore\Email Scanner\Outlook\OnDelivery\DetectionOptions so that the value of dwProgramHeuristicsLevel is 1.
Procedure: Use the Windows Registry Editor to navigate to the following key: HKLM\Software\McAfee\VSCore\EMail scanner\Outlook\OnDelivery\DetectionOptions Criteria: If the value dwMacroHeuristicsLevel is 1, this is not a finding. If the value is 0, this is a finding.
Change the registry key HKLM\Software\McAfee\VSCore\EMail Scanner\Outlook\OnDelivery\DetectionOptions so that the value of dwMacroHeuristicsLevel is 1.
Procedure: Use the Windows Registry Editor to navigate to the following key: HKLM\Software\McAfee\VSCore\EMail scanner\Outlook\OnDelivery\DetectionOptions Criteria: If the value ScanArchives is 1, this is not a finding. If the value is 0, this is a finding.
Change the registry key HKLM\Software\McAfee\VSCore\eMail Scanner\Outlook\OnDelivery\DetectionOptions so that the value of ScanArchives is 1.
Procedure: Use the Windows Registry Editor to navigate to the following key: HKLM\Software\McAfee\VSCore\Email Scanner\Outlook\OnDelivery\DetectionOptions Criteria: If the value ScanMime is 1, this is not a finding. If the value is 0, this is a finding.
Change the registry key HKLM\Software\McAfee\VSCore\EMail Scanner\Outlook\OnDelivery\DetectionOptions so that the value of ScanMime is 1.
Procedure: Use the Windows Registry Editor to navigate to the following key: HKLM\Software\McAfee\VSCore\Email scanner\outlook\onDelivery\DetectionOptions Criteria: If the value ScanMessageBodies is 1, this is not a finding. If the value is 0, this is a finding.
Change the registry key HKLM\Software\McAfee\VSCore\Email Scanner\Outlook\OnDelivery\DetectionOptions so that the value of ScanMessageBodies is 1.
Procedure: Use the Windows Registry Editor to navigate to the following key: HKLM\Software\McAfee\VSCore\Email Scanner\Outlook\OnDelivery\ActionOptions Criteria: If the value uAction is 2, this is not a finding. If the value is other than 2, this is a finding.
Change the registry key HKLM\Software\McAfee\VSCore\Email scanner\Outlook\Ondelivery\ActionOptions so that the value of uAction is 2.
Procedure: Use the Windows Registry Editor to navigate to the following key: HKLM\Software\McAfee\VSCore\Email scanner\Outlook\OnDelivery\ActionOptions Criteria: If the value dwPromptButton is x1F (31), this is not a finding. If the value is not x1F (31), this is a finding.
Change the registry key HKLM\Software\McAfee\VSCore\Email scanner\Outlook\OnDelivery\ActionOptions so that the value of dwPromptButton is x1F (31).
Procedure: Use the Windows Registry Editor to navigate to the following key: HKLM\Software\McAfee\VSCore\Email Scanner\Outlook\OnDelivery\AlertOptions Criteria: If the value bDisplayMessage is 1, this is not a finding. If the value is 0, this is a finding.
Change the registry key HKLM\Software\McAfee\VSCore\Email Scanner\Outlook\Ondelivery\AlertOptions so that the value of bDisplayMessage is 1.
Procedure: Use the Windows Registry Editor to navigate to the following key: HKLM\Software\McAfee\VSCore\Email Scanner\Outlook\OnDelivery\AlertOptions -- Criteria: If the value szCustomMessage contains an appropriate alert message, this is not a finding. If the value is blank or does not convey an alert, this is a finding.
Change the registry key HKLM\Software\McAfee\VSCore\Email Scanner\Outlook\Ondelivery\AlertOptions so that the value of szCustomMessage contains an appropriate alert message.
Procedure: Use the Windows Registry Editor to navigate to the following key: HKLM\Software\McAfee\VSCore\Email Scanner\Outlook\OnDelivery\ReportOptions -- Criteria: If the value bLogToFile is 1, this is not a finding. If the value is 0, this is a finding.
Change the registry key HKLM\Software\McAfee\VSCore\Email Scanner\Outlook\OnDelivery\ReportOptions so that the value of bLogToFile is 1.
Procedure: Use the Windows Registry Editor to navigate to the following key: HKLM\Software\McAfee\VSCore\Email Scanner\Outlook\OnDelivery\ReportOptions -- Criteria: If the value of bLimitSize is 1, and the dwMaxLogSizeMB is at least Hex 64 (100) or bLimitSize is 0 this is not a finding. If the bLimitSize is 0 or if dwMaxLogSizeMB is less than Hex 64, (100) this is a finding.
Change the registry key HKLM\Software\McAfee\VSCore\Email Scanner\Outlook\OnDelivery\ReportOptions so that the value of bLimitSize is 1 and dwMaxLogSizeMB is at least Hex64 OR bLimitSize is 0.
Procedure: Use the Windows Registry Editor to navigate to the following key: HKLM\Software\McAfee\VSCore\Email Scanner\Outlook\OnDelivery\ReportOptions Criteria: If the value dwLogEvent is x120 (288), this is not a finding. If the value is not x120 (288), this is a finding.
Change the registry key HKLM\Software\McAfee\VSCore\Email Scanner\Outlook\OnDelivery\ReportOptions so that the value of dwLogEvent is x120 (288).
Procedure: Use the Windows Registry Editor to navigate to the following key: HKLM\Software\McAfee\DesktopProtection\Tasks\{21221C11-A06D-4558-B833-98E8C7 F6C4D2} Criteria: For the values of szScanItemx (where x>=0), an entry for Fixed Drives and Special memory must exist. For example, if the following entries exist, this is not a finding. szScanItem0: FixedDrives szScanItem1: SpecialMemory The entries can be in any order and assigned to any number as long as the number is less than the value of UscanNumItems. If either of these entries are not present or the number of szScanItem is > UscanNumItems, this is a finding.
Change the registry key HKLM\Software\Network Associates\TVD\VirusScan Enterprise\CurrentVersion\Tasks\{818C7543-358A-4C84-899A-14334EMS4BGS} so that entries exist for Fixed Drives and Special Memory. For example, szScanItem0: FixedDrives and szScanItem1: SpecialMemory. The entries can be in any order and assigned to any number as long as the number is less than the value of UscanNumItems.
Procedure: Use the Windows Registry Editor to navigate to the following key: HKLM\Software\Network Associates\TVD\VirusScan Enterprise\CurrentVersion\Tasks\{818C7543-358A-4C84-899A-14334EMS4BGS} Criteria: If the value bScanSubDirs is 1, this is not a finding. If the value is 0, this is a finding.
Change the registry key HKLM\Software\Network Associates\TVD\VirusScan Enterprise\CurrentVersion\Tasks\{818C7543-358A-4C84-899A-14334EMS4BGS} so that the value of bScanSubDirs is 1.
Procedure: Use the Windows Registry Editor to navigate to the following key: HKLM\Software\Network Associates\TVD\VirusScan Enterprise\CurrentVersion\Tasks\{818C7543-358A-4C84-899A-14334EMS4BGS} Criteria: If the value bSkipBootScan is 0, this is not a finding. If the value is 1, this is a finding.
Change the registry key HKLM\Software\Network Associates\TVD\VirusScan Enterprise\CurrentVersion\Tasks\{818C7543-358A-4C84-899A-14334EMS4BGS} so that the value of bSkipBootScan is 0.
Procedure: Use the Windows Registry Editor to navigate to the following key: HKLM\Software\Network Associates\TVD\VirusScan Enterprise\CurrentVersion\Tasks\{818C7543-358A-4C84-899A-14334EMS4BGS} Criteria: If the value bScanAllFiles is 1, this is not a finding. If the value is 0, this is a finding.
Change the registry key HKLM\Software\Network Associates\TVD\VirusScan Enterprise\CurrentVersion\Tasks\{818C7543-358A-4C84-899A-14334EMS4BGS} so the value of bScanAllFiles is 1.
Procedure: Use the Windows Registry Editor to navigate to the following key: HKLM\Software\Network Associates\TVD\VirusScan Enterprise\ CurrentVersion\Tasks\{818C7543-358A-4C84-899A-14334EMS4BGS} Criteria: If the value is > 0 this is a finding. If the value is > 0, ensure the justification for exclusions found have been documented with the IAO/IAM. If exclusions are documented with the IAO/IAM, this is not a finding. If exclusions have not been documented, this is a finding.
Change the registry key HKLM\Software\Network Associates\TVD\VirusScan Enterprise\CurrentVersion\Tasks\{818C7543-358A-4C84-899A-14334EMS4BGS} so that the value of NumExcludeItems is 0. If not set to 0, all exclusions must be documented and approved with the IAO/IAM.
Procedure: Use the Windows Registry Editor to navigate to the following key: HKLM\Software\Network Associates\TVD\VirusScan Enterprise\CurrentVersion\Tasks\{818C7543-358A-4C84-899A-14334EMS4BGS} Criteria: If the value ScanArchives is 1, this is not a finding. If the value is 0, this is a finding.
Change the registry key HKLM\Software\Network Associates\TVD\VirusScan Enterprise\CurrentVersion\Tasks\{818C7543-358A-4C84-899A-14334EMS4BGS} so that the value of ScanArchives is 1.
Procedure: Use the Windows Registry Editor to navigate to the following key: HKLM\Software\Network Associates\TVD\VirusScan Enterprise\CurrentVersion\Tasks\{818C7543-358A-4C84-899A-14334EMS4BGS} Criteria: If the value ScanMime is 1, this is not a finding. If the value is 0, this is a finding.
Change the registry key HKLM\Software\Network Associates\TVD\VirusScan Enterprise\CurrentVersion\Tasks\{818C7543-358A-4C84-899A-14334EMS4BGS} so that the value of ScanMime is 1.
Procedure: Use the Windows Registry Editor to navigate to the following key: HKLM\Software\Network Associates\TVD\VirusScan Enterprise\CurrentVersion\Tasks\{818C7543-358A-4C84-899A-14334EMS4BGS} Criteria: If the value dwProgramHeuristicsLevel is 1, this is not a finding. If the value is 0, this is a finding.
Change the registry key HKLM\Software\Network Associates\TVD\VirusScan Enterprise\CurrentVersion\Tasks\{818C7543-358A-4C84-899A-14334EMS4BGS} so that the value of dwProgramHeuristicsLevel is 1.
Procedure: Use the Windows Registry Editor to navigate to the following key: HKLM\Software\Network Associates\TVD\VirusScan Enterprise\CurrentVersion\Tasks\{818C7543-358A-4C84-899A-14334EMS4BGS} Criteria: If the value dwMacroHeuristicsLevel is 1, this is not a finding. If the value is 0, this is a finding.
Change the registry key HKLM\Software\Network Associates\TVD\VirusScan Enterprise\CurrentVersion\Tasks\{818C7543-358A-4C84-899A-14334EMS4BGS} so that the value of dwMacroHeuristicsLevel is 1.
Procedure: Use the Windows Registry Editor to navigate to the following key: HKLM\Software\Network Associates\TVD\VirusScan Enterprise\CurrentVersion\Tasks\{818C7543-358A-4C84-899A-14334EMS4BGS} Criteria: If the value uAction is 5, this is not a finding. If the value is other than 5, this is a finding.
Change the registry key HKLM\Software\Network Associates\TVD\VirusScan Enterprise\CurrentVersion\Tasks\{818C7543-358A-4C84-899A-14334EMS4BGS} so that the value of uAction is 5.
Procedure: Use the Windows Registry Editor to navigate to the following key: HKLM\Software\Network Associates\TVD\VirusScan Enterprise\CurrentVersion\Tasks\{818C7543-358A-4C84-899A-14334EMS4BGS} Criteria: If the value uSecAction is 3, this is not a finding. If the value is other than 3, this is a finding.
Change the registry key HKLM\Software\Network Associates\TVD\VirusScan Enterprise\CurrentVersion\Tasks\{818C7543-358A-4C84-899A-14334EMS4BGS} so that the value of uSecAction is 3.
Procedure: Use the Windows Registry Editor to navigate to the following key: HKLM\Software\Network Associates\TVD\VirusScan Enterprise\CurrentVersion\Tasks\{818C7543-358A-4C84-899A-14334EMS4BGS} Criteria: If the value bLogToFile is 1, this is not a finding. If the value is 0, this is a finding.
Change the registry key HKLM\Software\Network Associates\TVD\VirusScan Enterprise\CurrentVersion\Tasks\{818C7543-358A-4C84-899A-14334EMS4BGS} so that the value of bLogToFile is 1.
Procedure: Use the Windows Registry Editor to navigate to the following key: HKLM\Software\Network Associates\TVD\VirusScan Enterprise\CurrentVersion\Tasks\{818C7543-358A-4C84-899A-14334EMS4BGS} Criteria: If the value of bLimitSize is 1, and the uKilobytes is at least 19000 or bLimitSize is 0 this is not a finding. If the bLimitSize is 0 and uKilobytes is less than 19000, this is a finding.
Change the registry key HKLM\Software\Network Associates\TVD\VirusScan Enterprise\CurrentVersion\Tasks\{818C7543-358A-4C84-899A-14334EMS4BGS} so that the value of bLimitSize is 1 and uKilobytes is >= 19000 OR bLimitSize is 0.
Procedure: Use the Windows Registry Editor to navigate to the following key: HKLM\Software\Network Associates\TVD\VirusScan Enterprise\CurrentVersion\Tasks\{818C7543-358A-4C84-899A-14334EMS4BGS} Criteria: If the value bLogSummary is 1, this is not a finding. If the value is 0, this is a finding.
Change the registry key HKLM\Software\Network Associates\TVD\VirusScan Enterprise\CurrentVersion\Tasks\{818C7543-358A-4C84-899A-14334EMS4BGS} so that the value of bLogSummary is 1.
Procedure: Use the Windows Registry Editor to navigate to the following key: HKLM\Software\Network Associates\TVD\VirusScan Enterprise\CurrentVersion\Tasks\{818C7543-358A-4C84-899A-14334EMS4BGS} Criteria: If the value bLogScanEncryptFail is 1, this is not a finding. If the value is 0, this is a finding.
Change the registry key HKLM\Software\Network Associates\TVD\VirusScan Enterprise\CurrentVersion\Tasks\{818C7543-358A-4C84-899A-14334EMS4BGS} so that the value of bLogScanEncryptFail is 1.
Procedure: Use the Windows Registry Editor to navigate to the following key: HKLM\Software\Network Associates\TVD\VirusScan Enterprise\CurrentVersion\Tasks\{818C7543-358A-4C84-899A-14334EMS4BGS} Criteria: If the value bLogUserName is 1, this is not a finding. If the value is 0, this is a finding.
Change the registry key HKLM\Software\Network Associates\TVD\VirusScan Enterprise\CurrentVersion\Tasks\{818C7543-358A-4C84-899A-14334EMS4BGS} so that the value of bLogUserName is 1.
Procedure: Use the Windows Registry Editor to navigate to the following key: HKLM\Software\Network Associates\TVD\VirusScan Enterprise\CurrentVersion\Tasks\{818C7543-358A-4C84-899A-14334EMS4BGS} Criteria: If the value bSchedEnabled is 1 and eScheduletype is 0 or 1, this is not a finding. If the value bSchedEnabled is 0 or eScheduletype is not 0 or not 1 this is a finding.
Change the registry key HKLM\Software\Network Associates\TVD\VirusScan Enterprise\CurrentVersion\Tasks\{818C7543-358A-4C84-899A-14334EMS4BGS} so that the value of bSchedEnabled is 1 and eScheduletype is 0 or 1.
Procedure: Use the Windows Registry Editor to navigate to the following key: HKLM\Software\Network Associates\TVD\Shared Components\On Access Scanner\ScriptScan Criteria: If the value of ScriptScanEnabled is 1, this is not a finding. This finding applies to Version 8.0 only.
Procedure: Use the Windows Registry Editor to navigate to the following key: HKLM\Software\Network Associates\TVD\Shared Components\On Access Scanner\ScriptScan Criteria: Set the value of ScriptScanEnabled to 1. This finding applies to Version 8.0 only.
Procedure: Use the Windows Registry Editor to navigate to the following key: HKLM\Software\Network Associates\TVD\Shared Components\On Access Scanner\BehaviourBlocking Criteria: If the value of VSIDBlock is 1, this is not a finding.
Procedure: Use the Windows Registry Editor to navigate to the following key: HKLM\Software\Network Associates\TVD\Shared Components\On Access Scanner\BehaviourBlocking Criteria: Set the value of VSIDBlock to 1.
Procedure: Use the Windows Registry Editor to navigate to the following key: HKLM\Software\Network Associates\TVD\Shared Components\On Access Scanner\BehaviourBlocking Criteria: If the value of VSIDBlockTimeout >= to HEX 1E, this is not a finding.
Procedure: Use the Windows Registry Editor to navigate to the following key: HKLM\Software\Network Associates\TVD\Shared Components\On Access Scanner\BehaviourBlocking Criteria: Set the value of VSIDBlockTimeout >= to HEX 1E.
Procedure: Use the Windows Registry Editor to navigate to the following key: HKLM\Software\Network Associates\TVD\Shared Components\On Access Scanner\BehaviourBlocking Criteria: If the value of VSIDBlockOnNonVirus is 1, this is not a finding.
Procedure: Use the Windows Registry Editor to navigate to the following key: HKLM\Software\Network Associates\TVD\Shared Components\On Access Scanner\BehaviourBlocking Criteria: Set the value of VSIDBlockOnNonVirus to 1.
Procedure: Use the Windows Registry Editor to navigate to the following key: HKLM\Software\Network Associates\TVD\Shared Components\On Access Scanner\McShield\Configuration Criteria: If the value OnlyUseDefaultConfig is 1, this is not a finding.
Procedure: Use the Windows Registry Editor to navigate to the following key: HKLM\Software\Network Associates\TVD\Shared Components\On Access Scanner\McShield\Configuration Criteria: Set the value OnlyUseDefaultConfig to 1.
Procedure: Use the Windows Registry Editor to navigate to the following key: HKLM\Software\Network Associates\TVD\Shared Components\On Access Scanner\McShield\Configuration\Default Criteria: If the value bScanIncoming is 1, this is not a finding.
Procedure: Use the Windows Registry Editor to navigate to the following key: HKLM\Software\Network Associates\TVD\Shared Components\On Access Scanner\McShield\Configuration\Default Criteria: Set the value bScanIncoming to 1.
Procedure: Use the Windows Registry Editor to navigate to the following key: HKLM\Software\Network Associates\TVD\Shared Components\On Access Scanner\McShield\Configuration\Default Criteria: If the value bScanOutgoing is 1, this is not a finding.
Procedure: Use the Windows Registry Editor to navigate to the following key: HKLM\Software\Network Associates\TVD\Shared Components\On Access Scanner\McShield\Configuration\Default Criteria: Set the value bScanOutgoing to 1.
Procedure: Use the Windows Registry Editor to navigate to the following key: HKLM\Software\Network Associates\TVD\Shared Components\On Access Scanner\McShield\Configuration\Default Criteria: If the value LocalExtensionMode is 1 and the value of NetworkExtensionMode is 1 this is not a finding. If either of these is not 1, this is a finding.
Procedure: Use the Windows Registry Editor to navigate to the following key: HKLM\Software\Network Associates\TVD\Shared Components\On Access Scanner\McShield\Configuration\Default Criteria: Set the value LocalExtensionMode to 1and the value of NetworkExtensionMode to 1.
Procedure: Use the Windows Registry Editor to navigate to the following key: HKLM\Software\Network Associates\TVD\Shared Components\On Access Scanner\McShield\Configuration\Default Criteria: If the value dwProgramHeuristicsLevel is 1, this is not a finding.
Procedure: Use the Windows Registry Editor to navigate to the following key: HKLM\Software\Network Associates\TVD\Shared Components\On Access Scanner\McShield\Configuration\Default Criteria: Set the value dwProgramHeuristicsLevel to 1.
Procedure: Use the Windows Registry Editor to navigate to the following key: HKLM\Software\Network Associates\TVD\Shared Components\On Access Scanner\McShield\Configuration\Default Criteria: If the value dwMacroHeuristicsLevel is 1, this is not a finding.
Procedure: Use the Windows Registry Editor to navigate to the following key: HKLM\Software\Network Associates\TVD\Shared Components\On Access Scanner\McShield\Configuration\Default Criteria: Set the value dwMacroHeuristicsLevel to 1.
Procedure: Use the Windows Registry Editor to navigate to the following key: HKLM\Software\Network Associates\TVD\Shared Components\On Access Scanner\McShield\Configuration\Default Criteria: If the value ScanArchives is 1, this is not a finding.
Procedure: Use the Windows Registry Editor to navigate to the following key: HKLM\Software\Network Associates\TVD\Shared Components\On Access Scanner\McShield\Configuration\Default Criteria: Set the value ScanArchives to 1.
Procedure: Use the Windows Registry Editor to navigate to the following key: HKLM\Software\Network Associates\TVD\Shared Components\On Access Scanner\McShield\Configuration\Default Criteria: If the value UAction_Program is 1, 3, 4, or 5, this is not a finding.
Procedure: Use the Windows Registry Editor to navigate to the following key: HKLM\Software\Network Associates\TVD\Shared Components\On Access Scanner\McShield\Configuration\Default Criteria: Set the value UAction_Program to 1, 3, 4, or 5.
Procedure: Use the Windows Registry Editor to navigate to the following key: HKLM\Software\Network Associates\TVD\Shared Components\On Access Scanner\McShield\Configuration\Default Criteria: If the value USecAction_Program is 1, 3, 4, or 5, this is not a finding. If the value is 0, this is a finding.
Procedure: Use the Windows Registry Editor to navigate to the following key: HKLM\Software\Network Associates\TVD\Shared Components\On Access Scanner\McShield\Configuration\Default Criteria: Set the value USecAction_Program to 1, 3, 4, or 5.
Procedure: Use the Windows Registry Editor to navigate to the following key: HKLM\Software\Network Associates\TVD\Shared Components\On Access Scanner\Vshield\E-Mail Scan\DetectionOptions Criteria: If the value ApplyNVP is 1, this is not a finding.
Procedure: Use the Windows Registry Editor to navigate to the following key: HKLM\Software\Network Associates\TVD\Shared Components\On Access Scanner\Vshield\E-Mail Scan\DetectionOptions Criteria: Set the value ApplyNVP to 1.
Procedure: Use the Windows Registry Editor to navigate to the following key: HKLM\Software\Network Associates\TVD\Shared Components\On Access Scanner\Vshield\E-Mail Scan\ActionOptions Criteria: If the value uAction_Program is 5, this is not a finding.
Procedure: Use the Windows Registry Editor to navigate to the following key: HKLM\Software\Network Associates\TVD\Shared Components\On Access Scanner\Vshield\E-Mail Scan\ActionOptions Criteria: Set the value uAction_Progam to 5.
Procedure: Use the Windows Registry Editor to navigate to the following key: HKLM\Software\Network Associates\TVD\VirusScan Enterprise\ CurrentVersion\Tasks\{818C7543-358A-4C84-899A-14334EMS4BGS} Criteria: If the value ApplyNVP is 1, this is not a finding.
Procedure: Use the Windows Registry Editor to navigate to the following key: HKLM\Software\Network Associates\TVD\VirusScan Enterprise\ CurrentVersion\Tasks\{818C7543-358A-4C84-899A-14334EMS4BGS} Criteria: Set the value ApplyNVP to 1.
Procedure: Use the Windows Registry Editor to navigate to the following key: HKLM\Software\Network Associates\TVD\Shared Components\ On Access Scanner\BehaviourBlocking Criteria: If the value EnterceptEnabled is 1, this is not a finding.
Procedure: Use the Windows Registry Editor to navigate to the following key: HKLM\Software\Network Associates\TVD\Shared Components\ On Access Scanner\BehaviourBlocking Criteria: Set the value EnterceptEnabled to 1.
Procedure: Use the Windows Registry Editor to navigate to the following key: HKLM\Software\Network Associates\TVD\Shared Components\ On Access Scanner\BehaviourBlocking Criteria: If the value EnterceptMode is 1, this is not a finding.
Procedure: Use the Windows Registry Editor to navigate to the following key: HKLM\Software\Network Associates\TVD\Shared Components\ On Access Scanner\BehaviourBlocking Criteria: Set the value EnterceptMode to 1.
Procedure: Use the Windows Registry Editor to navigate to the following key: HKLM\Software\Network Associates\TVD\Shared Components\ On Access Scanner\BehaviourBlocking Criteria: If the value EnterceptShowMessages is 1, this is not a finding.
Procedure: Use the Windows Registry Editor to navigate to the following key: HKLM\Software\Network Associates\TVD\Shared Components\ On Access Scanner\BehaviourBlocking Criteria: Set the value EnterceptShowMessages to 1.
Procedure: Use the Windows Registry Editor to navigate to the following key: HKLM\Software\Network Associates\TVD\Shared Components\On Access Scanner\BehaviourBlocking Criteria: If the value bLogToFile_Ent is 1, this is not a finding.
Procedure: Use the Windows Registry Editor to navigate to the following key: HKLM\Software\Network Associates\TVD\Shared Components\On Access Scanner\BehaviourBlocking Criteria: Set the value bLogToFile_Ent to 1.
Procedure: Use the Windows Registry Editor to navigate to the following key: HKLM\Software\Network Associates\TVD\Shared Components\On Access Scanner\BehaviourBlocking Criteria: If the value bLimitSize_Ent is 1 and the value of dwMaxLogSizeMB_Ent is at least hex 64, this is not a finding.
Procedure: Use the Windows Registry Editor to navigate to the following key: HKLM\Software\Network Associates\TVD\Shared Components\On Access Scanner\BehaviourBlocking Criteria: Set the value bLimitSize_Ent to 1and the value of dwMaxLogSizeMB_Ent to at least hex 64.
Procedure: Use the Windows Registry Editor to navigate to the following key: HKLM\Software\Network Associates\TVD\Shared Components\NVP Criteria: If the value DetectSpyware is 1, this is not a finding.
Procedure: Use the Windows Registry Editor to navigate to the following key: HKLM\Software\Network Associates\TVD\Shared Components\NVP Criteria: Set the value DetectSpyware to 1.
Procedure: Use the Windows Registry Editor to navigate to the following key: HKLM\Software\Network Associates\TVD\Shared Components\NVP Criteria: If the value DetectAdware is 1, this is not a finding.
Procedure: Use the Windows Registry Editor to navigate to the following key: HKLM\Software\Network Associates\TVD\Shared Components\NVP Criteria :Set the value DetectAdware to 1.
Locate McAfee icon in system tray. Right click to open and choose VirusScan Console. Select Help then choose About VirusScan Enterprise. Displayed will be a date for "DAT Created On:. Criteria: If the "DAT Created On:" date is older than 7 calendar days from the current date, this is a finding. Note: If the vendor or trusted site’s files are also older than 7 days and match the date of the signature files on the machine, this is not a finding.
Update antivirus signature file as your local process describes e.g autoupdate or runtime executable.
-8.7 Local Configured Client: Procedure: Use the Windows Registry Editor to navigate to the following key: HKLM\Software\McAfee\VSCore\On access scanner Criteria: If the value of ArtemisEnabled is REG_DWORD = 1, this is not a finding. AND Procedure: Use the Windows Registry Editor to navigate to the following key: HKLM\Software\McAfee\VSCore\On access scanner Criteria: If the value of ArtemisLevel is REG_DWORD = 2, this is not a finding. NOTE: This setting applies to product versions of 8.7i and above only.
-8.7 Local Configured Client: Change the registry keys HKLM\Software\McAfee\VSCore\On Access Scanner so that the value of ArtemisEnabled is REG_DWORD = 1 and ArtemisLevel is REG_DWORD = 2. NOTE: This setting applies to product versions of 8.7i and above only.