Endpoint Protection

 View Only
Expand all | Collapse all

User-Defined Exceptions not working

  • 1.  User-Defined Exceptions not working

    Posted Oct 26, 2009 10:25 AM
    I'm running SEP 11.0.4202.  Over the weekend SEP started flagging a critical program file in our payroll system as a trojan horse, and I believe this is a false positive.  (I've submitted the file to Symantec).  In order to be able to use our software, we need the file.

    On the server in question, I disabled Auto Protect, then went into Centralized Exceptions and added the file in question.  For what it's worth, the file is AFWREG.FLL.  Now, my understanding is that SEP should ignore that file and not scan it anymore, but it quarantined it again.  I went through the process again, and this time it seems to be left alone, for now at least.







  • 2.  RE: User-Defined Exceptions not working

    Posted Oct 26, 2009 11:14 AM
     Are you entering the exceptions in the SEP client, or from the SEPM console?  If you're trying to do it from the client, perhaps you have a policy enforced from SEPM that is preventing your exception from taking effect?  

    I would probably add the exception to a policy from SEPM and assign it to the server group.  Update policy on the client, and then SEP should ignore that file.


  • 3.  RE: User-Defined Exceptions not working

    Posted Oct 26, 2009 11:36 AM
    I had the same problem with this file. After adding the exception and updating the policy, the problem was resolved.


  • 4.  RE: User-Defined Exceptions not working

    Posted Oct 26, 2009 11:48 AM
    Just wanted to point you towards our guide on creating centralized exceptions in case you haven't seen it yet. It is here: http://service1.symantec.com/support/ent-security.nsf/854fa02b4f5013678825731a007d06af/f7602d481cc0cb8e882574020062b021?OpenDocument. You can also find more information when you view our "About centralized Eceptions Polcies" guide found here: http://seer.entsupport.symantec.com/docs/331021.htm.

    Thanks
    Grant



  • 5.  RE: User-Defined Exceptions not working

    Posted Oct 26, 2009 11:54 AM
    We had the same issue after receiving new def files yesterday. Also have a case open with Symantec. Hoping they get their signatures fixed soon, but the exception seems to be working for now.


  • 6.  RE: User-Defined Exceptions not working



  • 7.  RE: User-Defined Exceptions not working

    Posted Oct 26, 2009 12:17 PM
    Please check if the client  is getting the exceptions or not

    To see the exclusions that the client creates on 32-bit computers, you canexamine the contents of the
     
    HKEY_LOCAL_MACHINE\Software\Symantec\Symantec Endpoint
    Protection\AV\Exclusions  
    64-bit computers, look in
     
    HKEY_LOCAL_MACHINE\Software\Wow6432Node\Symantec\SymantecEndpoint Protection\AV\Exclusion


  • 8.  RE: User-Defined Exceptions not working
    Best Answer

    Posted Oct 26, 2009 02:22 PM
    OK, I'll call this "resolved", thanks for the replies everyone.  I created an exception for the file, however, the exception is specific to the folder that the file resides in.  I copied the false positive file to another location, and it yanked it into quarantine.  I was thinking the exception would apply to the entire drive on the computer in question.  In any case, Symantec is going to be releasing corrected virus defs for the false positive in the next release.

    Thanks all!


  • 9.  RE: User-Defined Exceptions not working

    Posted Oct 26, 2009 03:20 PM
    Will the next def file correct this false positive? I've gotten no feedback on my open case. Thanks!


  • 10.  RE: User-Defined Exceptions not working

    Posted Oct 26, 2009 03:25 PM
     @Julie --Did you submit your False Positive file to symantec false postive site if yes then you must have a tracking number you call either call support or ask aSymantec employee and they can give update on that tracking number.


  • 11.  RE: User-Defined Exceptions not working

    Posted Oct 26, 2009 04:37 PM
    We have the same problem. Running Symantec Coroprate Antivirus.
    I was able to get our Metaframe working, but it even sees the file on the authentic install cd as a virus.

    As soon as any of our updated clients try to run the software, it kills the file.


  • 12.  RE: User-Defined Exceptions not working

    Posted Oct 26, 2009 04:44 PM
    Any false positive issues please submit the file here..you'll get a tracking number then follow up with symantec till you get a solution.
    https://submit.symantec.com/dispute/false_positive/