Endpoint Protection

 View Only
Expand all | Collapse all

Scan - Files Approved but Exception Policy

ℬrίαη

ℬrίαηFeb 11, 2014 09:04 AM

Rafeeq

RafeeqFeb 11, 2014 09:23 AM

ℬrίαη

ℬrίαηFeb 11, 2014 09:25 AM

  • 1.  Scan - Files Approved but Exception Policy

    Posted Feb 10, 2014 11:11 AM

    Hi all,

    I have created a Virus and Spyware protection Policy that makes scheduled full scan.

    I also created a test Exception Policy which exclude a folder to scheduled and on-demand scans.

    I have desactivated Insight in Virus Policy and in Group Settings.

    When the scan finished, I see 97 approved files not scanned but in my Exception Policy, the folder excluded contains just one file.

     

    What is the problem ?

     

    Thanks a lot in advance.

     

    Regards,

     

    Kevin.

     

     



  • 2.  RE: Scan - Files Approved but Exception Policy

    Posted Feb 10, 2014 11:12 AM

    Does it say approved or Files Trusted?

    Can you share a screenshot?

    Verify the exclusion is set on the client, see here:

    About the files and folders that Symantec Endpoint Protection excludes from virus and spyware scans

    http://www.symantec.com/docs/HOWTO80947

    https://www-secure.symantec.com/connect/forums/auto-protect-trusted-processes



  • 3.  RE: Scan - Files Approved but Exception Policy

    Posted Feb 10, 2014 11:22 AM

    It is written File Approved : 97.

     

    scan.png

     

    How I can access the HKEY_LOCAL ?



  • 4.  RE: Scan - Files Approved but Exception Policy

    Posted Feb 10, 2014 11:22 AM

    Have you enabled system lock down?

    These might be files from the approved list ( virus defs files which are approved)

     



  • 5.  RE: Scan - Files Approved but Exception Policy

    Posted Feb 10, 2014 11:26 AM

    In which log are these appearing on the SEP client? Or SEPM?



  • 6.  RE: Scan - Files Approved but Exception Policy

    Posted Feb 10, 2014 11:30 AM

    @ _Brian : This log is providen by Application Event Viewer in SEP client.

     

    @ Rafeeq : I don't know. I'm searching.



  • 7.  RE: Scan - Files Approved but Exception Policy

    Posted Feb 10, 2014 11:32 AM

    Hello Kevin,

     

    is the folder in the network or local?

    Check in the registry as per this document

    http://www.symantec.com/business/support/index?page=content&id=TECH207935



  • 8.  RE: Scan - Files Approved but Exception Policy

    Posted Feb 10, 2014 11:35 AM

    In the client group, on the Policies tab, the system lockdown is disabled.

    The folder with one file is local. It is just a test.

    ps : I work on VMs.



  • 9.  RE: Scan - Files Approved but Exception Policy

    Posted Feb 10, 2014 11:36 AM

    So, to confirm, you have the policy configured to exclude one single folder? Is there anything in it? Is this folder on root of C:?



  • 10.  RE: Scan - Files Approved but Exception Policy

    Posted Feb 10, 2014 11:40 AM

    Use regedit.exe to access the registry to check to see what file exclusions are set per my link above.



  • 11.  RE: Scan - Files Approved but Exception Policy

    Posted Feb 10, 2014 11:45 AM

    So, to confirm, you have the policy configured to exclude one single folder? Is there anything in it? Is this folder on root of C:?

    Yes, I exclude one folder to scheduled and on-demand scan. In this one, there is one file.

    You are right, the folder is on root of C:.

    I use regedit.exe on the client or on the manager ?



  • 12.  RE: Scan - Files Approved but Exception Policy

    Posted Feb 10, 2014 11:51 AM

    I am here 

    • HKEY_LOCAL_MACHINE\Software\Symantec\Symantec Endpoint Protection\AV\Exclusions

    What do you want to know ? There are lots of folders.



  • 13.  RE: Scan - Files Approved but Exception Policy

    Posted Feb 10, 2014 12:01 PM

    Navigate to all the folders below exclusions, you will see all the folders which are excluded from scanning, how many exclusions do you see for the same path?



  • 14.  RE: Scan - Files Approved but Exception Policy
    Best Answer

    Posted Feb 10, 2014 03:14 PM

    To add Enable vpdebug it will tell you about files it scanned

    How to enable "Vpdebug Logging" on Symantec Endpoint Protection 11.0, 12.1, and 12.1 RU1

     

    http://www.symantec.com/business/support/index?page=content&id=TECH102939



  • 15.  RE: Scan - Files Approved but Exception Policy

    Posted Feb 11, 2014 04:24 AM
      |   view attached

    Hi all,

    So in Exclusions\ScanningEngines\Directory\Admin :

    The first is Directory Name C:\Test\ and ThreatName  C:\Test\.

    It is the folder I excluded from scheduled and on-demand scan.

    I activate vpdebug through GUI.

    I have launched a full scan to see the results as you suggest.

    So I have this  on the file : CExclusionScanSink::OnNewDirectory - Excluding folder - c:\Test.

    That is OK but i have lots of C:\Windows\.....\.... and C:\Windows32\.......

    Why ? I do not make exceptions for those folders or files.

    Attachment(s)

    txt
    vpdebug_5.txt   3.65 MB 1 version


  • 16.  RE: Scan - Files Approved but Exception Policy

    Posted Feb 11, 2014 05:19 AM

    Exception is applied thats sure from the logs, it did not scan any file inside the c:\test folder

    09:38:13.508056[_1412][_916]|Processing directory 'C:\Test'.
    09:38:13.509022[_1412][_916]|Skipping directory C:\Test

    since you scanned the entire C drive, all files in the c drive as scanned

    approved files are symantec definition files

    IsTrustedCallback(C:\Documents and Settings\All Users\Application Data\Symantec\Symantec Endpoint Protection\12.1.3001.165.105\Data\Definitions\VirusDefs\20140112.020\catalog.dat, ...): file trusted. (File = defverify.cpp, Line = 1162)09:29:48.074364[_1412][_916]|

    I could see 93 such files, 



  • 17.  RE: Scan - Files Approved but Exception Policy

    Posted Feb 11, 2014 05:29 AM

    You could see 93 approved files that are symantec definition files, ok.

     

    But in the event 2, i see 101 files approved.

    scan_0.png

    So there are 8 files added.



  • 18.  RE: Scan - Files Approved but Exception Policy

    Posted Feb 11, 2014 05:43 AM

    it also Skips files that are accessed by Windows Search index

    http://www.symantec.com/business/support/index?page=content&id=HOWTO55233



  • 19.  RE: Scan - Files Approved but Exception Policy

    Posted Feb 11, 2014 07:02 AM

    Is that possible to only approved files or folders that are in Exception Policy, in my case one folder which contains one file.

    He do not want the others files.



  • 20.  RE: Scan - Files Approved but Exception Policy

    Posted Feb 11, 2014 08:15 AM

    By default windows search index files are excluded from scanning and symantec def files these are always on C:\ or OS root drive.

    Your file is not scanned or you just ignore the others 



  • 21.  RE: Scan - Files Approved but Exception Policy

    Posted Feb 11, 2014 08:32 AM

    Oh sorry, I make a mistake with the personal pronoun.

    I want to write "I do not want the others files"

    May I can adjust the general behaviour to scan windows search index files and symantec def files ?

    or 

    May I can just delete these files on the scan event, that is to say may i can have only my exception policy written on the scan event like my image show.

    So I will have File trusted ignore : 1.

     



  • 22.  RE: Scan - Files Approved but Exception Policy

    Posted Feb 11, 2014 08:39 AM

    According to this post by Mithun, Windows Search Indexer is considered trusted and will be ignored by the scan.

    https://www-secure.symantec.com/connect/forums/auto-protect-trusted-processes

    There is an option to ignore this.

    In the AV policy on the Auto-Protect tab click Advanced scanning and monitoring and uncheck "Do not scan when trusted processes access the files"



  • 23.  RE: Scan - Files Approved but Exception Policy

    Posted Feb 11, 2014 08:44 AM

    Not possible that in log, Symantec has its own way of identifying files and writing out in logs

    You may need to uncheck that if you want those files to be scanned

    trusted process.PNG



  • 24.  RE: Scan - Files Approved but Exception Policy

    Posted Feb 11, 2014 09:02 AM

    Ok, I uncheck "Do not scan when trusted processes access the files".

    But It is available just for Auto protect. Is Scheduled and on-demand scan affected by ?



  • 25.  RE: Scan - Files Approved but Exception Policy

    Posted Feb 11, 2014 09:04 AM

    This applies to auto-protect only



  • 26.  RE: Scan - Files Approved but Exception Policy

    Posted Feb 11, 2014 09:11 AM

    Trusted files will be treated same by scans too

    Trusted files

    Virus and spyware scans include a feature that is called Insight that lets scans skip trusted files. You can choose the level of trust for the files that you want to skip, or you can disable the option. If you disable the option, you might increase scan time.

    Auto-Protect can also skip the files that are accessed by trusted processes such as Windows Search.

    http://www.symantec.com/business/support/index?page=content&id=HOWTO80947



  • 27.  RE: Scan - Files Approved but Exception Policy

    Posted Feb 11, 2014 09:18 AM

    Insight is desactivated in Scans and in Communication Settings.

    To sum up, I am forced to have symantec defintion files and Windows Search in approved files when I see the results of a scheduled scan ?

     



  • 28.  RE: Scan - Files Approved but Exception Policy

    Posted Feb 11, 2014 09:23 AM

    Yes .. No way to turn those off.



  • 29.  RE: Scan - Files Approved but Exception Policy

    Posted Feb 11, 2014 09:25 AM

    Correct



  • 30.  RE: Scan - Files Approved but Exception Policy

    Posted Feb 11, 2014 09:43 AM

    Ok, thanks a lot for your patience and skills.

    Numerous posts are really interesting.

    Unfortunately, I cannot tag more than one as solution.

    See you for others questions.