Endpoint Protection Small Business Edition

 View Only
  • 1.  AV is deleting the required exe files used for Remote sharing

    Posted Aug 30, 2010 05:41 AM
    Hello Team,

    I am facing issue with the remote desktop sharing application exe because AV automatically deleting the required exe files ie. 'radmin.exe' and 'r_server.exe'.
     
    "radmin.exe"  is used  to access the clients desktop & "r_server.exe" is install in client PC's.

    Can we exclude such exe's fron the scanning? If yes, how can we do it?

    Regards,
    Harshal.
     


  • 2.  RE: AV is deleting the required exe files used for Remote sharing

    Posted Aug 30, 2010 11:48 AM

    Centralized Exceptions Policies contain exceptions for the following types of scans:
    AntiVirus and antispyware scans
    TruScan proactive threat scans
    Tamper Protection scans
     
    Follow the instructions below for the type of exception you would like to make.
     
     
     
    Note: Security Risk Exceptions are global, and apply to all Scheduled Scans as well as Realtime AutoProtect.
     
    Log into the SEPM and click Policies.
    Under View Policies click Centralized Exceptions.
    Under Tasks click Add a Centralized Exception policy... This will create and open a new Centralized Exceptions Policy.
    In the left pane, click Centralized Exceptions.
    Click the Add button to open a drop-down menu. Move the cursor over Security Risk Exceptions to open a second drop-down menu.
    Select one of the four options: Known Risks, File, Folder, Extensions.
     
    Note: Wildcard variables such as * and ? are not supported.
     
    Note: For File and Folder-based exclusions, the Full Path to the file must be specified, unless a "Prefix Variable" is selected. If a "Prefix Variable" is selected, the path specified should be relative to the selected "Prefix Variable" 
     
     
     
    Note: if you are unsure about what type of exception to make please see the chapter entitled "Configuring Centralized Exceptions Policies" in the "Administration Guide for Symantec™ Endpoint Protection and Symantec Network Access Control".
     
    Enter the appropriate information for the known risk, file, folder, or extension you would like to exclude.
    (Optional) Repeat steps 5 through 7 to add any other Security Risk Exceptions you would like to the policy.
    (Optional) Follow the appropriate steps under "Creating exceptions for TruScan proactive threat scans" or "Creating exceptions for Tamper Protection scans" to add those types of exceptions to this policy.
    Click OK.


     
    Creating Centralized Exception policies in Symantec Endpoint Protection Manager.
    http://service1.symantec.com/SUPPORT/ent-security.nsf/docid/2008030423280248


  • 3.  RE: AV is deleting the required exe files used for Remote sharing
    Best Answer

    Posted Aug 30, 2010 11:51 AM




  • 4.  RE: AV is deleting the required exe files used for Remote sharing

    Posted Aug 30, 2010 11:55 AM
    Radmin is known security risk for Symantec for years
    You can create security risk exception for
    It is called " Remaac.Radmin"

    Check this
    https://www-secure.symantec.com/connect/forums/remaccradmin-sep-115

    Here is how to do it
    http://service1.symantec.com/SUPPORT/ent-security.nsf/docid/2007121808365448




  • 5.  RE: AV is deleting the required exe files used for Remote sharing

    Posted Sep 01, 2010 04:49 AM

    Thanks Sandip & Vikram, solution provided by  you was very simple to follow.

    I was able to exclude the exe's by using 'Centrealized Exceptations'.



  • 6.  RE: AV is deleting the required exe files used for Remote sharing

    Posted Sep 01, 2010 01:48 PM
    You need to exclude "Remaac.Radmin" in security risk..Excluding exe might not help