Endpoint Protection

 View Only

Symantec Antivirus - How to create exclusions for unmount harddrive

  • 1.  Symantec Antivirus - How to create exclusions for unmount harddrive

    Posted Mar 31, 2009 10:31 AM
    Hello ,
    (please excuse my english )

    For our software we need to create an exclusion on symantec antivirus corporation.

    This exclusion is an unmount harddrive  ( no letter or drive path)
    (my hard drive name is : \\?\Volume{d47f56e3-1d58-11de-9b5e-00155d000000}\disque\  )

    I have tried to add an exclusion in the 'RealTimeScan' folder in regedit 

    ( i added a key " \\?\Volume{d47f56e3-1d58-11de-9b5e-00155d000000}\disque\"  set at "1"  )

    But Symantec antivirus corporation still scan this folder !

    How could i make my unmont harddrive as an exclusion ???

    thanks in advance for your help !

    PS :
    1) my volume name is the right name
    2) i'm on windows 2008 64 bits
    3) i'm using symantec antivirus corporation version 10.2.0.298
    3) i have follow this documentation :
    On the Parent Server:
    1. Open the registry by clicking Start> Run
    2. Type REGEDIT
    3. Go to HKLM\Software\Intel\Landdesk\VirusProtect6\CurrentVersion\ClientConfig\Storages\FileSystem\RealTimeScan
      • If the client is in a client group go to HKLM\Software\Intel\Landdesk\VirusProtect6\CurrentVersion\Groups\<group_name>\ClientConfig\RealTimeScan
    4. In the right hand pane, verify that the value of "HaveExceptionsDirs and HaveExceptionFiles" is "1". If not, change it to "1".
    5. Expand RealTimeScan
    6. Go to NoScanDir Key
    7. In the pane on the right, you will see the folders added above of REG_DWORD values.
    8. The title of each value will show the complete folder added above. Make sure that each of these has a value of 1 if it is not please change them to 1.
    9. Go to FileExeptions Key. (if this doesn't exist, create it)
    10. Right click on the right and go NEW, then DWORD Value.
    11. Name the Value the path to the file. Example: C:\windows\eicar.com
    12. Double click the DWORD value and set it to 1
    13. Exit registry editor.
    14.