Recommended file and folder exclusions for Microsoft Forefront Client Security, Forefront Endpoint Protection 2010, and Microsoft System Center 2012 Endpoint Protection

Article translations Article translations
Article ID: 943556 - View products that this article applies to.
Expand all | Collapse all

On This Page

INTRODUCTION

Microsoft Forefront Client Security, Forefront Endpoint Protection 2010, and Microsoft System Center 2012 Endpoint Protection scan the files and folders on your computer for malicious programs that are known as malware. By default, all files and folders are included when the programs scan your computer. However, you can configure Forefront Client Security, Forefront Endpoint Protection 2010, and System Center 2012 Endpoint Protection to skip certain files or folders when they scan the computer. We recommend that you do not perform a malware scan on the files for certain programs or for operating system roles. This is to help prevent the following issues: 
  • An antimalware program could incorrectly determine that a program file is malware. This would be considered to be a false positive.
  • The antimalware scan operation could decrease performance for a particular program when that program tries to access its program files.
This article contains links to articles and to websites that identify files and folders for certain Microsoft products. We recommend that you exclude these files and folders from Forefront Security and System Center 2012 Endpoint Protection scan operations.

Note The information in this article also applies to other antivirus or antimalware programs that you may use. Also, if you run an antivirus or antimalware program on a computer that is running a third-party program or service, we recommend that you contact the program vendor. The program vendor can help determine whether certain files or folders should be excluded from antivirus or antimalware scan operations.

More information

The following sections contain information about the files and folders that we recommend be excluded from scanning by antimalware programs. The information is categorized by the operating system role or by program name.

Both Forefront Endpoint Protection and System Center Endpoint Protection have preconfigured policy templates for the different server roles. For more information regarding these templates, see http://technet.microsoft.com/en-us/library/gg412475.aspx.

Domain controllers

815263 Antivirus, backup, and disk optimization programs that are compatible with the File Replication Service
837932 Event ID 2108 and Event ID 1084 occur during inbound replication of Active Directory in Windows 2000 Server and in Windows Server 2003
822158 Virus scanning recommendations for Enterprise computers that are running currently supported versions of Windows

For more information, go to the following Microsoft websites:
Managing Domain Controllers
http://technet2.microsoft.com/windowsserver/en/library/7e56fd5d-a6a2-44eb-8915-4a47bae41fda1033.mspx
Managing Antivirus Software on Active Directory Domain Controllers
http://technet.microsoft.com/en-us/library/cc816917(v=ws.10).aspx

Microsoft Exchange Server

328841 Exchange and antivirus software
245822 Recommendations for troubleshooting an Exchange Server computer with antivirus software installed
For more information, go to the following Microsoft website:
http://technet.microsoft.com/en-us/library/9fb755f5-5f0b-4817-a584-70c76a62eae2.aspx

Forefront Endpoint Protection

For more information, go to the following Microsoft website:

http://technet.microsoft.com/en-us/forefront/ee822838

Internet Information Server (IIS)

817442 IIS 6.0: Antivirus scanning of IIS compression directory may result in 0-byte file

Microsoft Internet Security and Acceleration (ISA) Server

For more information, go to the following Microsoft website:
http://technet.microsoft.com/en-us/library/cc707727.aspx

Microsoft SharePoint Portal Server

320111 Random errors may occur when antivirus software scans Microsoft Web Storage System in SharePoint Portal Server 2001 and in SharePoint Portal Server 2003
322941 Microsoft's position on antivirus solutions for Microsoft SharePoint Portal Server

Microsoft SQL Server

309422 Guidelines for choosing antivirus software to run on the computers that are running SQL Server

Microsoft Systems Management Server (SMS)

327453 Antivirus programs may contribute to file backlogs in SMS 2.0 and in SMS 2003

Microsoft Virtual Server 2005 or Microsoft Virtual PC 2004

840193 Virtual machines run very slowly in Virtual PC 2004 or in Virtual Server 2005

Windows operating systems

822158 Virus scanning recommendations for Enterprise computers that are running currently supported versions of Windows

General information

900638 Multiple symptoms occur if an antivirus scan occurs while the Wsusscan.cab file or the Wsusscn2.cab file is copied

References

For more information about Forefront Client Security policy-based exclusions, go to the following Microsoft website:
Planning your policies
http://technet.microsoft.com/en-us/library/bb418804.aspx
For more information about how to use Forefront Client Security, see the Forefront Client Security product documentation. This documentation contains the following guides:
  • Microsoft Forefront Client Security Getting Started Guide
  • Microsoft Forefront Client Security Planning and Architecture Guide
  • Microsoft Forefront Client Security Deployment Guide
  • Microsoft Forefront Client Security Administrator's Guide
  • Microsoft Forefront Client Security Performance and Scalability Guide
  • Microsoft Forefront Client Security Disaster Recovery Guide
  • Microsoft Forefront Client Security Security Guide
  • Microsoft Forefront Client Security Troubleshooting Guide
  • Microsoft Forefront Client Security Technical Reference Guide
To obtain this documentation, go to the following Microsoft website:
http://www.microsoft.com/downloads/details.aspx?FamilyId=90044D88-299B-49FB-B762-EAE17A1F01F4

Properties

Article ID: 943556 - Last Review: June 25, 2014 - Revision: 5.0
Applies to
  • Microsoft Forefront Client Security
  • Microsoft System Center 2012 Endpoint Protection
Keywords: 
kbexpertiseadvanced kbinfo kbhowto KB943556

Give Feedback

 

Contact us for more help

Contact us for more help
Connect with Answer Desk for expert help.
Get more support from smallbusiness.support.microsoft.com