Creating exceptions to security risk scanning in Symantec AntiVirus 10.0 and Symantec Client Security 3.0
Question/Issue:
You need to know how to prevent Symantec Client Security 3.0 or Symantec AntiVirus 10.0 from scanning for specific security risks.
Solution:
Before you begin: If you use Symantec AntiVirus 10.1 or Symantec Client Security 3.1, use the new global security risk exclusions feature instead of the steps in this document.
For directions, read
Configuring global security risk exclusions in Symantec AntiVirus 10.1 and Symantec Client Security 3.1.
Follow the directions for each type of computer in your environment.
Servers
Follow all of the steps in this section to make sure that Symantec AntiVirus does not quarantine or delete components of a specific security risk.
To prevent Auto-Protect from detecting a security risk
- Start Symantec System Center.
- Unlock the server group.
- Right-click the server group, and then click All Tasks > Symantec AntiVirus > Server Auto-Protect Options.
- Click Actions.
- In the left pane, click the type of security risk.
- On the Exceptions tab, click Add.
- In the left pane, find and click the name of the security risk.
- Click the >> button.
The security risk entry moves to the right pane.
- Click Next.
- In the First Action drop-down list, click Exclude.
- Click Finish.
- Click OK, and then click OK again.
To prevent a scheduled scan from detecting a security risk
- Start Symantec System Center.
- Unlock the server group.
- Right-click the server, and then click All Tasks > Symantec AntiVirus > Scheduled Scans.
- On the Server Scans tab, select an existing scan, and then click Edit.
- Click Scan Settings.
- Select the drives and folders to scan.
- Click Options.
- Click Actions.
- In the left pane, click the type of security risk.
- On the Exceptions tab, click Add.
- In the left pane, find and click the name of the security risk.
- Click the >> button.
The security risk entry moves to the right pane.
- Click Next.
- In the First Action drop-down list, click Leave alone (log only).
- Click Finish.
- Repeat steps 3-15 for all of the server's scheduled scans.
WARNING: A common mistake is to set exceptions for Scheduled Scans, but to forget to set exceptions for manual scans and virus sweeps. You must set exceptions for all on-demand scans.
After you update virus definitions, Symantec AntiVirus Corporate Edition 10.0 runs a Defwatch Quick Scan. Symantec AntiVirus quarantines security risks for which you created an exception during this Quick Scan. To fix this problem, disable the Defwatch Quick Scan.
To disable the Defwatch Quick Scan
Managed clients
To ensure that Symantec AntiVirus does not quarantine or delete components of a specific security risk, follow all of the steps in this section that apply to your version of Symantec AntiVirus.
Note: You cannot perform these steps for managed clients whose parent server runs NetWare. To work around the problem, use a computer that runs Windows as the parent server, or configure exceptions directly on the managed clients.
To prevent Auto-Protect from detecting a security risk
- Start Symantec System Center.
- Unlock the server group.
- Right-click a server, a server group, or a client group, and then click All Tasks > Symantec AntiVirus > Client Auto-Protect Options.
- Click Actions.
- In the left pane, click the type of security risk.
- On the Exceptions tab, click Add.
- In the left pane, find and click the name of the security risk.
- Click the >> button.
The security risk entry moves to the right pane.
- Click Next.
- In the First Action drop-down list, click Exclude.
- Click Finish.
- On the Actions tab, check Override actions configured for Security Risks, and then click the lock icon so that it appears as locked.
- Click OK.
- Click Reset All.
- Click OK.
To prevent a scheduled scan from detecting a security risk
- Start Symantec System Center.
- Unlock the server group.
- Right-click the parent server or client group, and then click All Tasks > Symantec AntiVirus > Scheduled Scans.
- On the Client Scans or Client Group Scans tab, click an existing scan to select it, and then click Edit.
- Click Scan Settings.
- Select the drives and folders to scan.
- Click Options.
- Click Actions.
- In the left pane, click the type of security risk.
- On the Exceptions tab, click Add.
- In the left pane, find and click the name of the security risk.
- Click the >> button.
The security risk entry moves to the right pane.
- Click Next.
- In the First Action drop-down list, click Leave alone (log only).
- Click Finish.
- Repeat steps 3-15 for all scheduled scans.
WARNING: A common mistake is to set exceptions for Scheduled Scans, but to forget to set exceptions for manual scans and virus sweeps. You must set exceptions for all on-demand scans.
To disable the startup Quick Scan in Symantec AntiVirus 10.0.1 or later
- Start Symantec System Center.
- Unlock the server group.
- Right-click a server group, a client group, or a server, and then click All Tasks > Symantec AntiVirus > Client Administrator Only Options.
- On the General tab, under Scan Options, uncheck Run startup scan(s) when user logs in.
- Click OK.
To remove the startup Quick Scan on Symantec AntiVirus 10.0.0 clients
Notes:
Using the RemoveStartScan.reg file on a Symantec AntiVirus client removes all user-created scans. After users import the registry file, they must re-create any scans that they created.
This file works only for the user that is currently logged on. On computers that have more than one user, each user must log on and import the file.
After you update virus definitions, Symantec AntiVirus Corporate Edition 10.0 runs a Defwatch Quick Scan. Symantec AntiVirus quarantines security risks for which you created an exception during this Quick Scan. To fix this problem, disable the Defwatch Quick Scan.
To disable the Defwatch Quick Scan
Unmanaged clients
Follow all of the steps in this section to make sure that Symantec AntiVirus does not quarantine or delete components of a specific security risk.
To prevent Auto-Protect from detecting a security risk
- On the Windows taskbar, click Start > Programs > Symantec Client Security > Symantec AntiVirus.
- Click Configure > File System Auto-Protect.
- Click Actions.
- In the left pane, click the type of security risk.
- On the Exceptions tab, click Add.
- In the left pane, find and click the name of the security risk.
- Click the >> button.
The security risk entry moves to the right pane.
- Click Next.
- In the First Action drop-down list, click Exclude.
- Click Finish.
- Click OK, and then click OK again.
To prevent a scheduled scan from detecting a security risk
- On the Windows taskbar, click Start > Programs > Symantec Client Security > Symantec AntiVirus.
- In the left pane, expand Scheduled Scans, and then click an existing scan to select it.
- In the right pane, click Edit.
- Click Options.
- Click Actions.
- In the left pane, click the type of security risk.
- On the Exceptions tab, click Add.
- In the left pane, find and click the name of the security risk.
- Click the >> button.
The security risk entry moves to the right pane.
- Click Next.
- In the First Action drop-down list, click Leave alone (log only).
- Click Finish.
- Repeat steps 3-12 for all scheduled scans.
WARNING: A common mistake is to set exceptions for Scheduled Scans, but to forget to set exceptions for manual scans. You must set exceptions for all on-demand scans.
To remove the startup Quick Scan on Symantec AntiVirus clients
Notes:
Using the RemoveStartScan.reg file on a Symantec AntiVirus client removes all user-created scans. After users import the registry file, they must re-create any scans that they created.
This file works only for the user that is currently logged on. On computers that have more than one user, each user must log on and import the file.
After you update virus definitions, Symantec AntiVirus Corporate Edition 10.0 runs a Defwatch Quick Scan. Symantec AntiVirus quarantines Security Risks for which you created an Exception during this Quick Scan. To fix this problem, disable the Defwatch Quick Scan.
To disable the Defwatch Quick Scan
Restoring quarantined files by using Symantec System Center
After you prevent Auto-Protect from detecting the security risk, you can restore the files by using Symantec System Center. Follow the directions for the type of computer in your environment. To restore quarantined files on managed clients, you must first enable configuration of individual clients in Symantec System Center.
To enable configuration of individual clients in Symantec System Center
- In Symantec System Center, on the Tools menu, click SSC Console Options.
- On the Client Display tab, check Allow direct configuration of individual clients.
- Click OK.
To restore quarantined files on a managed client by using Symantec System Center
- In Symantec System Center, click the client's parent server.
- In the right pane, right-click the client, and then click All Tasks > Symantec AntiVirus > Logs > Threat History.
- In the Threat History pane, right-click the quarantined file that you want to restore, and then click Undo Action Taken.
- In the Take Action window, click Start Undo.
Note: Other configuration actions should not be performed at the client level in Symantec System Center. Perform other configuration actions at the server group, parent server, or client group level.
To restore quarantined files on a server by using Symantec System Center
- In Symantec System Center, right-click the server, and then click All Tasks > Symantec AntiVirus > Logs > Threat History.
- In the Threat History pane, right-click the quarantined file that you want to restore, and then click Undo Action Taken.
- In the Take Action window, click Start Undo.
Technical Information:
Preventing the creation of the startup Quick Scan before you install Symantec AntiVirus 10.0.0 clients
Before you install or migrate managed clients, download and import the PreventStartScan.reg file onto each client. This file works only for the user that is currently logged on. On computers that have more than one user, each user must log on and import the file. In Symantec AntiVirus 10.0.1 and later, the startup Quick Scan is disabled by default.
References:
For information about types of security risks, see the Symantec Web site.
Document ID: 2005060614225348
Last Modified: 06/29/2006
Date Created: 06/06/2005
Operating System(s): Windows 2000, Windows XP Home, Windows XP Professional Edition, Windows XP Tablet PC, NetWare 5.1, NetWare 6.0, NetWare 6.5, Windows XP 64-Bit Edition 2003, Windows Server 2003 32-bit Edition, Windows Server 2003 64-bit Edition, Windows XP Media Center Edition 2005
Product(s): Symantec AntiVirus Corporate Edition 10.0, Symantec Client Security 3.0
Release(s): SAV 10.0 [All Releases], Symantec Client Security 3.x [All versions]