• No se han encontrado resultados

ANÁLISIS E INTERPRETACIÓN DE LOS CASOS ESTUDIADOS

P: Con ellos tuvimos una amistad muy cercana y nos ayudaron a tomar la decisión de educar en casa También conocemos al Pastor Gerald Klinbeil que vivió un tiempo en

3.3. Identificación numérica de las unidades lexicales de interpretación 1 Familia

A process is a program in execution. A program may initiate one or more processes. When deciding what risk or scanning policy to assign to a process, remember that only the child processes of the defined parent process adhere to the scanning policy. For example, if you define the Microsoft Word executable file, WINWORD.EXE, as a high-risk scanning process, any Microsoft Word documents that are accessed would be scanned based on the high-risk scanning policy. However, when the parent process, Microsoft Word, is launched the WINWORD.EXE file would be scanned based on the policy of the process that launched it.

You can assign two types of risks to processes:

„ Low-risk processes are defined as those processes that have a lower possibility of being infected. These can be processes that access a lot of files, but do so in a way that has a lower risk of spreading viruses. Some examples are:

Š

Backup software.

Š

Compiling processes.

„ High-risk processes are defined as those processes that have a higher possibility of being infected. Some examples are:

Š

Processes that launch other processes. For example, Microsoft Windows Explorer, or the command prompt.

Š

Processes that execute. For example, WINWORD or CSCRIPT.

Š

Processes used for downloading from the Internet. For example, browsers, instant messengers, and mail clients.

NOTE

When you install VirusScan Enterprise with default settings, the Use the settings on these tabs for all processes option is selected. If you select Use different settings for high-risk and low-risk processes some processes are predefined as high-risk. You can change this list to meet your needs.

Any process that is not defined as either low-risk or high-risk is considered to be a

To determine which risk to assign to which processes, complete these steps: 1 Decide why you want to have different scanning policies. The two most

common reasons when balancing performance against risk are:

Š

To scan some processes, such as web downloads, more thoroughly than is accomplished by the default scanning policy.

Š

To scan some processes to a lesser extent based on the risk and impact on performance that occurs during scanning. For example, capturing streaming media such as video has little risk, but is very resource intensive. 2 Decide which processes are low-risk and which are high-risk. First determine

which program is responsible for each process, then decide what risk is associated with that process. Use the Windows Task Manager or Windows Performance Monitor to help you understand which processes are using the most CPU time and memory. Once you have this information you can associate each process with a scanning policy based on the processes’ performance and risk.

3 Configure the scanning policies for each of the three levels: default, low-risk and high-risk.

NOTE

We do not recommend reducing the level of scanning for high-risk processes. The high-risk scanning policy is initially set the same as default processes to ensure that high-risk processes maintain an in-depth level of scanning.

Process properties

Use the options on the Processes tab to define processes as either low-risk or high-risk:

NOTE

Any process that is not defined as either low-risk or high-risk is considered to be a default process and is scanned with the properties that you set for default processes.

1 Open the On-Access Scan Properties dialog box, then select All Processes in the left pane.

2 Select Use different settings for high-risk and low-risk processes. NOTE

When you select this option, the All Processes icon changes to

Default Processes, and both the Low-Risk Processes and

High-Risk Processes icons become available in the left pane. 3 Select either Low-Risk Processes or High-Risk Processes.

4 Select the Processes tab.

The list shows the current list of processes, in alphabetical order by file name. Each process is shown with its application icon, file name, and description if available. The default settings are:

Š

TheLow-Risk Processes list is empty.

Š

The High-Risk Processes list is populated with processes that McAfee Security considers to be high-risk. You can add or remove processes from this list to meet your security needs.

NOTE

The steps you take to add or select processes are identical for low-risk and high-risk processes.

5 To add applications, click Add. The Select Application dialog box appears.

a Select application(s) that you want to add, using these methods:

b When you have finished selecting applications, click OK to save your selections and return to the Processes tab.

6 To remove applications, highlight one or more applications in the list, then click Remove.

7 Click Apply to save your changes.

8 Repeat Step 3 through Step 7 to define applications as either low-risk or high-risk.

Figure 3-13. Select Application

Š

Select application(s) from the list.

Use CTRL + SHIFT to select more than one application.

Š

Click Browse to locate an application on the network.

Detection properties

Use the options on the Detection tab to specify what types of files you want the on-access scanner to examine, and when you want to scan them.

1 Open the On-Access Scan Properties dialog box, then select All Processes in the left pane.

2 Select Use different settings for high-risk and low-risk processes.

NOTE

When you select this option, the All Processes icon changes to

Default Processes, and both the Low-Risk Processes and

High-Risk Processes icons become available in the left pane. 3 Select either Low-Risk Processes or High-Risk Processes.

4 Select the Detection tab.

NOTE

After you select the process icon from the left pane, the steps you take to set Detection options are identical for low-risk and high-risk processes.

5 Under Scan Files, select any combination of these scanning options:

Š

When writing to disk. This option is selected by default. Scan all files as they are written to or modified on the server, workstation, or other data storage device.

Š

When reading from disk. This option is selected by default. Scan all files as they are read from the server, workstation, or other data storage device.

Š

On network drives. Include network resources during on-access scans. This

is a convenient way to extend virus protection. NOTE

Including network resources could have a negative effect on the overall performance of the system that is running the scan. WARNING

If you are copying or moving a file from one computer to another, and the on-access scan properties on both computers have been configured to scan files both written to disk and files read from disk, scanning occurs when the file is read by the source computer and again when it is written to the

destination computer.

If the prevailing traffic pattern on your network is copying or moving files from one computer to another, you may want to configure your scanning properties to scan only files written to disk, and not to scan files read from disk. This eliminates double-scanning of the same file. It is possible to achieve the same result by configuring all computers to scan only files read from them, and not files written to them.

If you use either of these configuration patterns, it is important that allcomputers be configured identically. Do not configure some computers to scan only files written to disk, and others to scan files only read from disk. This would allow an infected file to be copied from a computer that scans only files written to disk to a computer that scans only files read from disk.

6 Under What to scan, select from these options:

Š

All files. This option is selected by default. Scan all files regardless of extension.

Š

Default + additional file types. Scan the default list of extensions plus any

additions you specify. The default list of file type extensions is defined by the current DAT file. You can add or remove user-specified file type extensions, but you cannot delete any file type extensions from the default list. You can, however, exclude extensions that appear in the default list. See Excluding files, folders, and driveson page 70 for more information.

Š

Specified file types. Scan only the extensions you specify.

7 Under What not to scan, click Exclusions to specify the files, folders, and drives you want to exclude from scanning. See Excluding files, folders, and driveson page 70 for detailed instructions.

8 Click Apply to save your changes.

9 Repeat Step 3 through Step 8 to specify detection settings for low-risk or high-risk processes.

Š

Additions. If you selected Default + additional file types, click Additions

to add or remove user-specified file type extensions. See Adding file type extensionson page 68 for detailed instructions.

The maximum number of additional extensions that the on-access scanner can list is 1,000.

Š

Also scan for macro viruses in all files. Scan all files, regardless of extension, for macro viruses. This option is only available when the

Default + additional file types option is selected. NOTE

Scanning for macro viruses in all files could affect performance.

Š

Specified. If you selected Specified file types, click Specified to add or remove user-specified file type extensions. You can also set the list of file type extensions to the default list. See Adding user-specified file type extensionson page 69 for detailed instructions.

The maximum number of specified extensions that the on-access scanner can list is 1,000.

Adding file type extensions

Add user-specified file types to the default list of file types. You can also use this feature to remove any user-specified file types you added. The default list plus any user-specified file types are scanned during scanning operations.

NOTE

You cannot change or remove file types from the default list of file types. The default list is defined by the latest DAT file you downloaded. To prevent an extension from being scanned, exclude it. See Excluding files, folders, and driveson page 70 for more information.

1 Click Additions to open the Additional File Types dialog box.

2 Under Add File Type, you can add user-specified file type extensions in two ways:

Š

Type a file type extension in the text box, then click Add. NOTE

You only need to type the first three letters of the file type extension. If you type an HTM file extension, the scanner searches for HTM and HTML files. You can use a wildcard or a combination of characters with a wildcard.

Š

Click Select to open the Select File Type dialog box. Select one or more file type extensions from the list, then click OK.

Use CTRL + SHIFT to select more than one file type extension.

The file type extensions you added appear in the User-specified additional file types list.

3 You can remove user-specified file type extensions from the user-specified list in two ways:

Š

Select one or more file type extensions in the User specified additional file types list, then click Remove.

Š

Click Clear to remove all items from the User specified additional file types

list.

Adding user-specified file type extensions

Create a list of user-specified file type extensions to be scanned during scanning operations. You can also use this feature to remove any of the user-specified file type extensions you added previously.

1 Click Specified to open the Specified File Types dialog box.

2 Under Add File Type, you can add user-specified file type extensions in two ways:

Š

Type a file type extension in the text box, then click Add. NOTE

You only need to type the first three letters of the file type extension. If you type an HTM file extension, the scanner searches for HTM and HTML files. You can use a wildcard or a combination of characters with a wildcard.

Š

Click Select to open the Select File Type dialog box. Select one or more file type extensions from the list, then click OK.

3 You can remove user-specified file type extensions from the list in two ways:

Š

Select one or more file type extensions in the list under Only files of these

types will be scanned, then click Remove.

Š

Click Clear to remove all items from the list under Only files of these types will be scanned.

4 Click Set to Default to replace the current list of user-specified file type extensions with the default list. The default list of file type extensions is defined by the current DAT file.

5 Click OK to save your changes and return to the Detection tab. Excluding files, folders, and drives

Specify files, folders, and drives to exclude from scanning operations. You can also use this feature to remove any of the exclusions you specified previously.

1 Click Exclusions to open the Set Exclusions dialog box.

2 Add or edit files, folders, or drives. Windows File Protection is listed by default.

Š

To add an item, click Add to open the Add Exclusion Item dialog box.

Š

To edit an item, double-click the item or select it, then click Edit to open the

Edit Exclusion Item dialog box. NOTE

The exclusion options are the same whether you are adding an exclusion item or editing it.

3 Under What to exclude, select one of these options:

Š

By name/location. This option is selected by default. Specify the name or location. This can include wildcards * and ?. You can type specific information in the text box or click Browse to locate a name or location.

NOTE

You can specify full pathnames such as C:\WINNIT\SYSTEM*, file names such as PAGEFILE.SYS, or PAGEFILE.*, or P*.*, or *.SYS, or folder names such as BACKUP. For example, specifying BACKUP folder excludes all folders named BACKUP, where ever they are located.

When using wildcards, these limitations apply:

Figure 3-18. Add Exclusion Item

Š

Valid wildcards are ? for excluding single characters and * for excluding multiple characters.

Š

A \ cannot follow wildcard characters. For example, C:\ABC\WWW?is valid, but C:\ABC\WWW?\123 is not valid.

Š

An exclusion that does not begin with a path or \ such as WWW* is

treated as a file only.

Š

An exclusion containing ? characters applies if the number of characters matches the length of the file or folder name. For example, the exclusion W?? excludes WWW, but does not exclude

Š

By file type. Specify a file extension by type. Type a file extension in the text box or click Select to open the Select File Type dialog box, where you can select one or more extensions from the list. Click OK to save your entries and close the dialog box.

NOTE

The file extension that you specify can include wildcards. Valid wildcards are ? for excluding single characters and * for excluding multiple characters.

Š

By file age. Specify whether you want to exclude files by age.

Š

Files protected by Windows File Protection. Specify that this exclusion is based on a file’s Windows File Protection status.

4 Under When to exclude, specify when to exclude the items from scanning:

Š

On read. This option is selected by default. Specify that the exclusion items are

excluded from scans when read from disk.

Š

On write. This option is selected by default. Specify that the exclusion items are excluded from scans when written to disk.

NOTE

The On read and On write options are not available for on-demand scan tasks.

5 Click OK to save your changes and return to the Set Exclusions dialog box. 6 You can remove user-specified file type extensions from the item list in two

ways:

Š

Select one or more file type extensions in the list, then click Remove.

Š

Click Clear to remove all items from the list.

7 Click OK to save your changes and return to the Detection tab. 8 Click Apply to save your changes.

Š

Also exclude subfolders. If you selected By name/location, you can exclude the subfolders of the folders that match the specified pattern.

Š

Access type. If you selected By file age, click to specify an access type of Modified or Created.

Š

Minimum age in days. If you selected By file age, specify the minimum number age of the file in days. The file must be at least this many days old before it is excluded.

Advanced properties

Use the options on the Advanced tab to specify advanced scan options for heuristics, non-virus program files, and compressed files.

1 Open the On-Access Scan Properties dialog box, then select All Processes in the left pane.

2 Select Use different settings for high-risk and low-risk processes.

NOTE

When you select this option, the All Processes icon changes to

Default Processes, and both the Low-Risk Processes and

High-Risk Processes icons become available in the left pane. 3 Select either Low-Risk Processes or High-Risk Processes.

4 Select the Advanced tab.

.

NOTE

After you select the process icon from the left pane, the steps you take to set Advanced options are identical for low-risk and high-risk processes.

5 Under Heuristics, specify whether you want the scanner to evaluate the probability that an unknown piece of code or a Microsoft Office macro is a virus. When this feature is enabled, the scanner analyzes the likelihood that the code is a variant of a known virus. Select any combination of these options:

Š

Find unknown program viruses. This option is selected by default for default

processes and high-risk processes. Treat executable files that have code resembling a virus as if they were infected. The scanner applies the action you choose on the Actions tab.

Š

Find unknown macro viruses. This option is selected by default for default processes and high-risk processes. Treat embedded macros that have code resembling a virus as if they were infected. The scanner applies the action you choose on the Actions tab to those files.

NOTE

This option is not the same as Also scan for macro viruses in all files on the Detection tab, which instructs the scanner to find