DTAM148 - McAfee VirusScan Access Protection: Anti-Spyware Maximum Protection must be set to block and log scripts from the Temp folder.

Warning! Audit Deprecated

This audit has been deprecated and will be removed in a future update.

View Next Audit Version

Information

This rule prevents the Windows scripting host from running VBScript and JavaScript scripts from the Temp directory. This would protect against a large number of trojans and questionable web installation mechanisms that are used by many adware and spyware applications.

NOTE: Nessus has not performed this check. Please review the benchmark to ensure target compliance.

Solution

Access the local VirusScan console by clicking Start >> All Programs >> McAfee >> VirusScan Console.
Under the Task column, select Access Protection, right-click, and select Properties.

Under the Access Protection tab, locate the 'Access protection rules:' label. In the 'Categories' box, select 'Anti-Spyware Maximum Protection'. Select the 'Prevent execution of scripts from the Temp folder' (Block and Report) option.

Click OK to save.

See Also

https://iasecontent.disa.mil/stigs/zip/U_McAfee_VirusScan88_Local_Client_V5R16_STIG.zip

Item Details

References: CAT|II, CCI|CCI-001243, Rule-ID|SV-55287r6_rule, STIG-ID|DTAM148, Vuln-ID|V-42559

Plugin: Windows

Control ID: 8c022fae7e507ba4a10653f08a2df01d1c996f3b181d5322ae2ac69084f6d25b