- EXCLUSIONES DE ANTIVIRUS

Transcripción

- EXCLUSIONES DE ANTIVIRUS
- EXCLUSIONES DE ANTIVIRUS Microsoft Exchange:
%ProgramFiles%\Microsoft\Exchange Server
IIS:
%WINDIR%\system32\inetsrv
%WINDIR%\IIS Temporary Compressed Files
Controlador de Dominio:
%WINDIR%\SYSVOL
%WINDIR%\NTDS
%WINDIR%\ntfrs
Exclusiones Adicionales:
%WINDIR%\SoftwareDistribution\DataStore
%WINDIR%\system32\dhcp
%WINDIR%\system32\wins
%WINDIR%\system32\NtmsData
SBS Exclusiones Autorizadas
%windir%\system32\licstr.cpa
%windir%\system32\lls
NOTA: Se debe ejecutar el asistente de Licencias y generar un backup en otro
directorio.
Terminal de Servicios Exclusiones Autorizadas
%WINDIR%\System32\LServer:
edb.log, edb.chk, res1.log, res2.log, TLSLic.edb y temp.edb
Servicios de Bases de Datos
%ProgramFiles%\Microsoft SQL Server\MSSQL$SBSMONITORING\Data
%ProgramFiles%\Microsoft SQL Server\MSSQL$SHAREPOINT\Data
%ProgramFiles%\Microsoft SQL Server\MSSQL\Data
Exclusiones de los servicios de Windows Share Point:
%WINDIR%\temp\FrontPageTempDir
SBS POP3 connector Failed Mail:
%ProgramFiles%\Microsoft Windows Small Business
Server\Networking\POP3\Failed Mail
SBS POP3 connector Incoming Mail:
%ProgramFiles%\Microsoft Windows Small Business
Server\Networking\POP3\Incoming Mail
SAAZ application Exclusions for DPMA (Desktop):
64 Bit
%ProgramFiles(X86)%\SAAZOD
%ProgramFiles(X86)%\SAAZExmonScripts
%ProgramFiles(X86)%\Microsoft SQL Server
%ProgramFiles(X86)%\LogMeIn
%ProgramFiles(X86)%\zenith
%ProgramFiles(X86)%\SAAZSBE
32 Bit
%ProgramFiles%\Zenith
%ProgramFiles%\Logmein
%ProgramFiles%\SAAZOD
%ProgramFiles%\Microsoft SQL Server
%ProgramFiles%\SAAZExmonScripts
%ProgramFiles%\SAAZSBE
Exclusión de archivos y procesos para servidores de 64bit:
%ProgramFiles(X86)%\Zenith\Zenith Infotech\ShadowProtectSvc.exe
%ProgramFiles(X86)%\Zenith\Zenith Infotech\sbrun.exe
%ProgramFiles(X86)%\Zenith\Zenith Infotech\sbtailck.exe
%ProgramFiles(X86)%\Zenith\Zenith Infotech\vssins64.exe
%ProgramFiles(X86)%\SAAZOD\RMHLPDSK.exe
%ProgramFiles(X86)%\SAAZOD\RmIp.exe
%ProgramFiles(X86)%\SAAZOD\wodTunnel.dll
%ProgramFiles(X86)%\SAAZOD\zSECHK.exe
%WINDIR%\SysWOW64\vsnapvss.exe
%WINDIR%\System32\vssVC.exe
%WINDIR%\System32\dfssvc.exe
%ProgramFiles(X86)%\Zenith
%ProgramFiles(X86)%\Logmein
%ProgramFiles(X86)%\SAAZOD
%ProgramFiles(X86)%\SAAZSBE
Exclusión de archivos y procesos para servidores de 32bit:
%ProgramFiles%\Zenith\Zenith Infotech\ShadowProtectSvc.exe
%ProgramFiles%\Zenith\Zenith Infotech\sbrun.exe
%ProgramFiles%\Zenith\Zenith Infotech\sbtailck.exe
%ProgramFiles%\Zenith\Zenith Infotech\vssins64.exe
%ProgramFiles%\SAAZOD\RMHLPDSK.exe
%ProgramFiles%\SAAZOD\RmIp.exe
%ProgramFiles%\SAAZOD\wodTunnel.dll
%ProgramFiles%\SAAZOD\zSECHK.exe
%ProgramFiles%\System32\vsnapvss.exe
%ProgramFiles%\System32\vssVC.exe
%ProgramFiles%\System32\dfssvc.exe
%ProgramFiles%\Zenith
%ProgramFiles%\Logmein
%ProgramFiles%\SAAZOD
Base de Datos de Windows Update:
%windir%\SoftwareDistribution\Datastore\datastore.edb
Archivos de transacción diarios:
%windir%\SoftwareDistribution\Datastore\Logs\edb*.log
Res1.log y Res2.log
Edb.chk y Tmp.edb
815623
Excluir:
%systemroot%\sysvol
%systemroot%\sysvol\domain\DO_NOT_REMOVE_NtFrs_PreInstall_Directory
%systemroot%\sysvol\staging
%systemroot%\sysvol\staging areas
%systemroot%\sysvol\sysvol
Analizar:
%systemroot%\sysvol\domain
%systemroot%\sysvol\domain\Policies
%systemroot%\sysvol\domain\Scripts
Directorios
%systemroot%\System32\Spool
%systemroot%\SoftwareDistribution\Datastore
%systemroot%\Sysvol
%systemroot%\system32\dhcp
%systemroot%\system32\dns
%systemroot%\ntds
%systemroot%\ntfrs
%systemroot%\IIS Temporary Compressed Files
%systemroot%\system32\inetsrv
%systemroot%\Cluster
*\Exchsrvr
%Program Files%\SharePoint Portal Server
%Program Files%\Common Files\Microsoft Shared\Web Storage System
*:\MSDEDatabases
%systemroot%\Temp\Frontpagetempdir
*\SMS\Inboxes
*\SMS_CCM\ServiceData
*:\Documents and Settings\All Users\Application Data\Microsoft\Microsoft
Operations Manager
%Program Files%\Microsoft Operations Manager 2005
%Program Files%\Microsoft ISA Server\ISALogs
*:\MSSQL$WSUS
*:\WSUS
%Program Files%\Microsoft\Exchange Server
%Program Files%\Microsoft ForeFront Security
%Program Files%\Microsoft SQL Server
*:\MSSQL
%Program Files%\System Center Operations Manager 2007\
Extensiones
*.log
*.dit
*.mdf
*.ldf
*.ndf
*.edb
*.chk
*.stm
*.cab
*.jdb
*.config
*.dia
*.wsb
*.jrs
*.que
*.lzx
*.ci
*.dir
*.wid
*.000
*.001
*.002
*.cfg
*.grxml
*.lst
*.set
*.vdb
*.def
*.dat
*.wkf
*.pqf
*.pqf0
*.pqf1
Ejecutables o Procesos
Eseutil.exe
Lsass.exe
Cdb.exe
Cidaemon.exe
Store.exe
Emsmta.exe
Mad.exe
Mssearch.exe
Inetinfo.exe
W3wp.exe
Microsoft.Exchange.Search.Exsearch.exe
Microsoft.Exchange.Servicehost.exe
Msexchangeadtopologyservice.exe
Msexchangefds.exe
Dsamain.exe
Edgecredentialsvc.exe
Msexchangemailboxassistants.exe
Msexchangemailsubmission.exe
Edgetransport.exe
Msexchangetransport.exe
Galgrammargenerator.exe
Msexchangetransportlogsearch.exe
Msftefd.exe
Msftesql.exe
Microsoft.Exchange.Antispamupdatesvc.exe
Microsoft.Exchange.Contentfilter.Wrapper.exe
Oleconverter.exe
Microsoft.Exchange.Cluster.Replayservice.exe
Powershell.exe
Sesworker.exe
Microsoft.Exchange.Edgesyncsvc.exe
Microsoft.Exchange.Imap4.exe
Speechservice.exe
Microsoft.Exchange.Imap4service.exe
Microsoft.Exchange.Infoworker.Assistants.exe
Transcodingservice.exe
Umservice.exe
Microsoft.Exchange.Monitoring.exe
Umworkerprocess.exe
Microsoft.Exchange.Pop3.exe
Microsoft.Exchange.Pop3service.exe
Adonavsvc.exe
Fscstatsserv.exe
Fsccontroller.exe
Fscutility.exe
Fsctransportscanner.exe
Fscdiag.exe
Fsemailpickup.exe
Fscexec.exe
Fssaclient.exe
Fscimc.exe
Getenginefiles.exe
Fscmanualscanner.exe
Perfmonitorsetup.exe
Fscmonitor.exe
Scanenginetest.exe
Fscrealtimescanner.exe
Semsetup.exe
Fscstarter.exe
momhost.exe
monitoringhost.exe
https://*.itsupport247.net
http://*.itsupport247.net

Documentos relacionados