WelcomeProductsViruses & RisksSupportDownloadsStore
Home & Home Office
Symantec.com > Home & Home Office > Support > Knowledge Base


Server Group exclusions created in Symantec System Center are not pushed to client computers

Question/Issue:
You are using Symantec System Center to configure Realtime Protection options at the server group level to exclude folders from scanning. Not all of the exclusions have taken effect on the clients. For example, you have excluded the following folders: C:\Temp C:\Program Files\test When you open the Symantec AntiVirus Corporate Edition client user interface and examine the configuration, you find that none of the exclusions is present. You may have also placed the Eicar.com test file in an excluded folder, but Realtime Protection attempts to clean and quarantine the file, which confirms that the exclusion is not enforced.


Solution:
This situation is usually caused by a configuration problem. When you configure Server Group exclusions in the Symantec System Center, it is important to remember the following:


If you have verified all of the above conditions, but the exclusion is still not in place, then go on to the next section.

To verify that the exclusion settings are in place
  1. On the primary server of the server group, verify that the excluded folders are listed in the following two registry keys:

    HKEY_LOCAL_MACHINE\SOFTWARE\INTEL\LANDesk\VirusProtect6\CurrentVersion\DomainData\ClientConfig\Storages\FileSystem\RealTimeScan\NoScanDir
    HKEY_LOCAL_MACHINE\SOFTWARE\INTEL\LANDesk\VirusProtect6\CurrentVersion\Storages\FileSystem\RealTimeScan\NoScanDir
  2. On secondary servers, verify that the excluded folders are listed in the following registry key:

    HKEY_LOCAL_MACHINE\SOFTWARE\INTEL\LANDesk\VirusProtect6\CurrentVersion\ClientConfig\Storages\FileSystem\RealTimeScan\NoScanDir
  3. On the client, verify that the excluded folders are listed in the following registry key:

    HKEY_LOCAL_MACHINE\SOFTWARE\INTEL\LANDesk\VirusProtect6\CurrentVersion\Storages\FileSystem\RealTimeScan\NoScanDir
  4. Verify that the exclusion information was recorded in the Grc.dat file on the primary server. Look for lines similar to the following (using the example from the Situation above):

    !KEY!=$REGROOT$\Storages\FileSystem\RealTimeScan\NoScanDir
    GRC-State-Counter=D2
    C:\temp=D1
    C:\Program Files\test=D2
  5. Verify that the exclusion information was recorded in the Grcsrv.dat file on the primary server. Look for lines similar to the following:

    !KEY!=$REGROOT$\ClientConfig\Storages\FileSystem\RealTimeScan\NoScanDir
    C:\temp=D1
    C:\Program Files\test=D2

If you have verified all of the above conditions and have found no problems, you may be experiencing an issue that was resolved in a new build of Symantec AntiVirus 8.1. Read the article How to obtain an update or an upgrade for your Symantec Corporate product for instructions on receiving the latest inline release.


RATE THIS SOLUTION
Was this solution helpful to you?
Yes
No
If any information was unclear, or the information you were seeking was not provided, please let us know. Your feedback will help us improve this service.

NOTE: Comments entered here will NOT recieve a personal email response.


Document ID: 2002122305320148
Last Modified: 06/16/2008
Date Created: 12/23/2002
Operating System(s): Windows 98, Windows Me, Windows NT 4.0 SP6a, Windows 2000 Professional, Windows XP Home, Windows XP Professional Edition
Product(s): Symantec AntiVirus Corporate Edition 8.0
Release(s): SAV 8.0, SAV 8.01


Site Index · Legal Notices · Privacy Policy · · Contact Us · Global Sites · License Agreements
©1995 - 2009 Symantec Corporation