DTAM154 - McAfee VirusScan On-Demand scan must be configured to scan memory for rootkits.

Information

A rootkit is a stealthy type of software, usually malicious, and is designed to mask the existence of processes or programs from normal methods of detection. Rootkits will often enable continued privileged access to a computer. Scanning and handling detection of rootkits will mitigate the likelihood of rootkits being installed and used maliciously on the system.

Solution

Access the local VirusScan console by clicking Start->All Programs->McAfee->VirusScan Console.
In the console window, under Task, with the assistance of the System Administrator, identify the weekly on-demand client scan task.
Right-click the Task and select Properties.

Under the Scan Locations tab, in the box under the 'Specify where scanning takes place.' label, select 'Memory for rootkits' from the drop-down selection box.


Click OK to Save.

See Also

https://dl.dod.cyber.mil/wp-content/uploads/stigs/zip/U_McAfee_VirusScan88_Local_Client_V6R1_STIG.zip

Item Details

Category: SYSTEM AND INFORMATION INTEGRITY

References: 800-53|SI-3c.1., CAT|II, CCI|CCI-001241, Rule-ID|SV-243428r722623_rule, STIG-ID|DTAM154, STIG-Legacy|SV-55285, STIG-Legacy|V-42557, Vuln-ID|V-243428

Plugin: Windows

Control ID: d11304d0532c73675a761eb8101fd450ca07d4d8e4c25660d4dad8346a61871a