McAfee Stinger is a portable malware scanner for a defined collection of prevalent threats. It runs as a standalone executable, checks the selected parts of a Windows system, and can repair, remove, quarantine, or report detections according to its settings. McAfee Stinger is intended for focused investigation and cleanup. It does not install a permanent protection layer, watch every new file continuously, or replace a full antivirus product.
Targeted threat list
The Threat List defines the malware families that McAfee Stinger knows how to detect in that build. It is a reference list, not a record of what the current computer contains. A clean Stinger scan therefore means that the scan did not find its targeted threats in the inspected locations. It does not prove that the computer is free of every malicious file or unwanted program.
The normal scan checks active processes, loaded modules, registry locations, WMI data, and directories associated with known malware. A custom scan can add chosen drives or folders. That distinction matters when a suspicious archive or secondary disk sits outside the default locations. The narrower default saves time, while a deliberate custom target expands the work to storage that the first pass may not read.
Choose the response
McAfee Stinger can take action when it identifies a target. The normal action attempts to repair an infected file. Quarantine separates a detected object into the Stinger quarantine folder so it no longer remains in its original location. Report-only mode records the detection without changing the file, which is useful when the system needs review before cleanup.
Action choice affects recoverability. Repair may alter an infected executable or document, and removal can break a program that depended on the file. A first Report-only pass exposes the file path and detection name before any change. Important documents should already have backups; quarantine is not a substitute for a tested copy stored away from the affected machine.
Rootkits and sensitivity
Rootkit scanning is disabled by default. A user investigating boot-level or hidden activity must enable that scan option rather than assuming an ordinary run included it. Rootkit inspection can take longer and interacts more deeply with the running system, so the computer should not be interrupted during the pass.
McAfee Stinger also uses cloud reputation and network heuristics. Higher sensitivity can classify less certain activity. The publisher advises using Report-only mode for an initial scan when sensitivity is set to High or Very High, then reviewing the results before deletion or repair. Treating every high-sensitivity report as confirmed malware can remove a legitimate file.
Logs and settings
The Log tab opens scan records as HTML, and McAfee Stinger stores the log beside its executable by default. The entry shows what the scan inspected and which action followed a detection. Quarantined objects go under C:\Quarantine\Stinger. Anyone running the scanner from removable media should remember that the log, settings, and quarantine data may end up in different locations rather than traveling together.
McAfee Stinger also saves previous configuration in Stinger.opt beside the executable. Reusing the same folder can therefore reuse earlier choices instead of returning to untouched defaults. A scan launched by another technician may have rootkit checks, action rules, or custom targets set differently.
A custom blacklist accepts MD5 hashes for a limited set of known files. It does not accept SHA-1 or SHA-256 entries, and it ignores files with a valid signature or clean cloud reputation. That makes the blacklist a narrow incident-response control, not a general policy engine for every suspicious filename or newer hash record.






