About the automatic exclusion of files and folders for Microsoft Exchange server and Symantec products
| Article:TECH102400 | | | Created: 2007-01-02 | | | Updated: 2013-01-04 | | | Article URL http://www.symantec.com/docs/TECH102400 |
Problem
What file and folder exclusions are created automatically when Symantec Endpoint Protection client is installed on a server that runs Microsoft Exchange server or certain Symantec gateway scanning products?
Solution
If Microsoft Exchange servers are installed on a computer with Symantec Endpoint Protection client, the client software automatically detects the presence of Exchange. When the client software detects a Microsoft Exchange server, it creates the appropriate file and folder exclusions for File System Auto-Protect and all other scans. Microsoft Exchange servers can include clustered servers. The client software checks for changes in the location of the appropriate Exchange files and folders at regular intervals. If Exchange is installed on a computer where the client software is already installed, the exclusions are created when the client checks for changes. The client excludes both files and folders; if a single file is moved from an excluded folder, the file remains excluded.
The Symantec Endpoint Protection client software creates file and folder scan exclusions for the following Microsoft Exchange server versions:
- Exchange 5.5
- Exchange 2000
- Exchange 2003
- Exchange 2007
- Exchange 2010
Symantec recommends that the Exchange server's OS always be protected by the latest available release of SEP. The Exchange server's message flow and Information Store must be protected by a dedicated mail security product, such as Symantec Mail Security for Microsoft Exchange.
For Exchange 2007 and 2010, see the user documentation for information about compatibility with antivirus software. It may be necessary to create scan exclusions for some Exchange folders manually. For example, cluster servers or non-default locations for folders require specific exclusions. See Preventing Symantec Endpoint Protection from scanning the Microsoft Exchange 2007 directory structure.
The client also creates appropriate file and folder scan exclusions for the following Symantec products when they are detected:
- Symantec Mail Security for Microsoft Exchange (SMSMSE) 4.0, 4.5, 4.6, 5.0, 6.0 and 6.5
- Symantec AntiVirus/Filtering 3.0 for Microsoft Exchange
- Norton AntiVirus 2.x for Microsoft Exchange
-
Symantec Endpoint Protection Manager embedded database and logs
Note: To see the exclusions that the client creates, examine the contents of the HKEY_LOCAL_MACHINE\Software\Symantec\Symantec Endpoint Protection\AV\Exclusions registry. Do not edit this registry key directly. Any additional exclusions can be configured by using centralized exceptions.
On a 64 bit server using Exchange 2007 or 2010, the path in the registry to confirm auto exclusions is slightly different. The path includes the WOW6432node key.
HKLM\Software\WOW6432node\Symantec\Symantec Endpoint Protection\AV\Exclusions\.
The client does not exclude the system temporary folders from scans because doing so can create a significant security vulnerability on a computer.
If client email applications use a single inbox
The applications that store all email in a single file include Outlook Express, Eudora, Mozilla, and Netscape. If client computers use any email applications that use a single inbox, create a centralized exception to exclude the Inbox file. The exception applies to all antivirus and antispyware scans as well as Auto-Protect.
The Symantec Endpoint Protection client quarantines the entire Inbox and users cannot access their email if the following statements are true:
- The client detects a virus in the Inbox file during an on-demand or scheduled scan.
- The action that is configured for the virus is Quarantine.
Symantec does not usually recommend excluding files from scans. When you exclude the Inbox file from scans, the Inbox cannot be quarantined; however, if the client detects a virus when a user opens an email message, it can safely quarantine or delete the message.
References
This document is available in the following languages:
- Brazilian-Portuguese at: http://service1.symantec.com/support/INTER/ent-securityintl.nsf/br_docid/20070904133511935
- French at: http://service1.symantec.com/support/INTER/ent-securityintl.nsf/fr_docid/20070904133642935
- German at: http://service1.symantec.com/support/INTER/ent-securityintl.nsf/de_docid/20070904134008935
- Italian at: http://service1.symantec.com/support/INTER/ent-securityintl.nsf/it_docid/20070904134244935
- Spanish at: http://service1.symantec.com/support/INTER/ent-securityintl.nsf/es_docid/20070904134325935
- Simplified Chinese: http://service1.symantec.com/support/INTER/ent-securitysimplifiedchinesekb.nsf/cn_docid/20071008132929968
|
|
Related Articles
Legacy ID
2007090220241148
Article URL http://www.symantec.com/docs/TECH102400
Terms of use for this information are found in Legal Notices









Thank you.