Endpoint Protection

 View Only
  • 1.  to know the exception

    Posted Oct 30, 2014 02:26 AM

    Exception has been configure on the server, how to know that it work or not?



  • 2.  RE: to know the exception
    Best Answer

    Posted Oct 30, 2014 02:35 AM

    See below articles

    How to Verify if an Endpoint Client has Automatically Excluded an Application or Directory

    Article:TECH105814  | Created: 2008-01-05  | Updated: 2011-03-02  | Article URL http://www.symantec.com/docs/TECH105814

    See this thread also

    http://www.symantec.com/connect/forums/verify-all-exceptions-endpoint-client-are-applied



  • 3.  RE: to know the exception

    Posted Oct 30, 2014 02:50 AM

    Check the thread

    https://www-secure.symantec.com/connect/forums/verify-central-exclusion-policy-applying-end-point-clients



  • 4.  RE: to know the exception

    Posted Oct 30, 2014 03:34 AM

    Hello Raney,

    since you have already configured exceptions the best thing to do is to download a test virus on these folders and try to access it inside these folders.

    http://www.symantec.com/security_response/attacksignatures/detail.jsp?asid=24461

    Eicar is a test virus its used to check if your AV is working or not, it wont do any harm. Its just a test file

    download the file from 

     http://www.eicar.org/anti_virus_test_file.htm

    place it in the excluded folder, rigth click on the folder and select scan. the folder should come clean, if it finds it then symantec is acting on that folder

     



  • 5.  RE: to know the exception

    Posted Oct 30, 2014 07:52 AM
    1. Start > Run > Regedit
       
    2. Browse to the registry key:
      • HKEY_LOCAL_MACHINE\SOFTWARE\SYMANTEC\SYMANTEC ENDPOINT PROTECTION\AV\EXCLUSIONS
        Note: On 64bit window machines the registry path is:

        HKEY_LOCAL_MACHINE\Software\WOW6432Node\Symantec\Symantec Endpoint Protection\AV\Exclusions
         
    3. Expand the key to view the various applications listed there.
      • The 'File Exceptions' folder is where you can inspect the full list of exclusions associated with that product.


    This key is where both automatic and policy added exclusions are stored on the client. Inspecting this key reveals all exclusions applied to the client. If you do not see the exclusion you are trying to add listed in the registry, then it is not being added automatically. You must manually add it to a Centralized Exceptions policy.