64
McAfee Total Protection Service Product Guide
How detections are handled
The type of threat and the policy settings determine how virus and spyware protection handles
a detection.
Spyware protection mode and detections
Spyware protection monitors programs that attempt to install or run on client computers.
When it detects an unrecognized program, it either allows or blocks it. The response is based
on the spyware protection mode selected in the policy assigned to the client computer.
For all modes, detections are reported to the SecurityCenter, where you can view information
about them in reports.
NOTE:
To prevent popup prompts from appearing on client computers when potentially unwanted
programs are detected, and for highest security, we recommend using Protect mode.
How virus and spyware protection handles the detections
Items with detections
Virus detections
: Virus and spyware protection attempts to clean the
file. If it can be cleaned, the user is not interrupted with an alert. If it
Files and programs
cannot be cleaned, an alert appears, and the detected file is deleted. A
copy is placed in the quarantine folder.
Potentially unwanted program detections
: In Protect mode,
detections are cleaned or deleted. In Prompt mode, users must select the
response.
How virus and spyware protection handles the detections
Items with detections
In all cases, a backup copy of the original item is saved in a quarantine
folder, in a proprietary binary format. Data for all activity is uploaded to
the SecurityCenter for use in reports.
NOTE:
Files are placed into the quarantine folder in a format that is no
longer a threat to the client computer. It is not necessary to view or delete
them, but you might occasionally want to do so. In these situations, you
must view files on the client computer by using the Quarantine Viewer.
Only users logged on as an administrator can access the Quarantine Viewer.
After 30 days, these files are deleted.
Detections initially appear as Detected. Cleaning detected files also cleans
their associated registry keys and cookies. Their status is then reported
as Cleaned.
Registry keys and cookies
Spyware protection does this...
In this mode...
Checks the list of allowed and blocked programs created by the administrator for computers
using the policy. If the program is not on the list, spyware protection blocks the potentially
unwanted program.
Protect
Checks the list of approved and blocked programs created by the administrator for
computers using the policy. Checks the list of programs the user has approved. If the
Prompt
program is not on either list, spyware protection displays a prompt with information about
the detection and allows the user to select a response. This setting is the default.
Checks the list of approved and blocked programs created by the administrator for
computers using the policy. If the program is not on the list, it sends information about
the potentially unwanted program to the SecurityCenter and takes no additional action.
Report
Behavior of virus and spyware protection
Mode
Report
•
Users are not prompted about detections.
•
Detections are reported to the SecurityCenter.
•
Administrator can select approved programs, which are not reported as detections.
•
Can be used as a "learn" mode to discover which programs to approve and block.
Prompt
•
Users are prompted about detections.
•
Detections are reported to the SecurityCenter.
•
Administrator can select approved programs. These programs are not reported as
detections, and users are not prompted for a response to them.
How virus and spyware protection handles the detections
Items with detections
In all cases, a backup copy of the original item is saved in a quarantine
folder, in a proprietary binary format. Data for all activity is uploaded to
the SecurityCenter for use in reports.
NOTE:
Files are placed into the quarantine folder in a format that is no
longer a threat to the client computer. It is not necessary to view or delete
them, but you might occasionally want to do so. In these situations, you
must view files on the client computer by using the Quarantine Viewer.
Only users logged on as an administrator can access the Quarantine Viewer.
After 30 days, these files are deleted.
Detections initially appear as Detected. Cleaning detected files also cleans
their associated registry keys and cookies. Their status is then reported
as Cleaned.
Registry keys and cookies
Spyware protection does this...
In this mode...
Checks the list of allowed and blocked programs created by the administrator for computers
using the policy. If the program is not on the list, spyware protection blocks the potentially
unwanted program.
Protect
Checks the list of approved and blocked programs created by the administrator for
computers using the policy. Checks the list of programs the user has approved. If the
Prompt
program is not on either list, spyware protection displays a prompt with information about
the detection and allows the user to select a response. This setting is the default.
Checks the list of approved and blocked programs created by the administrator for
computers using the policy. If the program is not on the list, it sends information about
the potentially unwanted program to the SecurityCenter and takes no additional action.
Report
Behavior of virus and spyware protection
Mode
Report
•
Users are not prompted about detections.
•
Detections are reported to the SecurityCenter.
•
Administrator can select approved programs, which are not reported as detections.
•
Can be used as a "learn" mode to discover which programs to approve and block.
Prompt
•
Users are prompted about detections.
•
Detections are reported to the SecurityCenter.
•
Administrator can select approved programs. These programs are not reported as
detections, and users are not prompted for a response to them.
Using Virus and Spyware Protection
How detections are handled
CBS100083_McAfeeProdGde_12-10 64
12/20/10 8:51 AM