Mcafee Virusscan - Documentation for Bmc Discovery Content Reference

McAfee has branched their VirusScan product into different products, each of them relating to a specific computing environment, whether it's home, small business, or enterprise. We have focused our attention on a product called McAfee VirusScan Enterprise, which focuses its scope on Enterprise Business, and combines virus detection and elimination, intrusion prevention and firewall technology in a single solution for PCs and file servers.

This documentation refers to the model for the Windows version. The Linux version is documented here

Product ComponentOS TypeVersioningPattern Depth
McAfee VirusScanWindowsPackageInstance-based

The pattern identifies instances of McAfee VirusScan on the Windows platform.

Software Instance Triggers

Product ComponentOS TypeTrigger NodeAttributeConditionArgument
McAfee VirusScanWindowsDiscoveredProcesscmdmatches

regex '(?i)\bvstskmgr\.exe$'

or

regex '(?i)\bVirusScan[^\\]*\\scan32\.exe$'

or
regex '(?i)\bmcshield\.exe$'

Simple Identification Mappings

The following processes are identified by the pattern, the identification is performed at two levels - processes listed below are identified through the use of Simple Identifiers and in addition, they are modeled within a full Software Instance for McAfee VirusScan (See Application Model Produced by Software Pattern for more details about the approach taken to model this product).

There are Simple Identifiers for the following processes:

Component NameOS TypeCommand
Alert ManagerWindows(?i)\bamgrsrvc\.exe$
VirusScan Framework Service(?i)\bframeworkservice\.exe$
VirusScan On-demand Virus Scanner process

(?i)\bVirusScan[^\\]*\\scan32\.exe$

VirusScan Shield (Internet Security On-Access scanner)(?i)\bmcshield\.exe$
VirusScan Updater UI(?i)\bUpdaterUI\.exe$
VirusScan Enterprise Console(?i)\bmcconsol\.exe$
VirusScan Shstat(?i)\bshstat\.exe$
VirusScan Task Manager(?i)\bvstskmgr\.exe$
Error Reporting Service(?i)\btbmon\.exe$
Common Framework Script Engine(?i)\bmcscript_inuse\.exe$
ePolicy Orchestrator Product Manager(?i)\bnaprdmgr\.exe$
ePolicy Orchestrator System Compliance Profiler Microsoft Patch Scan(?i)\bptchscan\.exe$
James H. Sterling

James H. Sterling

Environmental Science & Climate Journalist

James Sterling reports on renewable energy developments, climate policy, ecological conservation, and green tech innovations around the globe.

Share this article
Twitter Facebook Pinterest