Sign in with Microsoft
Sign in or create an account.
Hello,
Select a different account.
You have multiple accounts
Choose the account you want to sign in with.

INTRODUCTION

Microsoft Forefront Client Security, Forefront Endpoint Protection 2010, and Microsoft System Center 2012 Endpoint Protection scan the files and folders on your computer for malicious programs that are known as malware. By default, all files and folders are included when the programs scan your computer. However, you can configure Forefront Client Security, Forefront Endpoint Protection 2010, and System Center 2012 Endpoint Protection to skip certain files or folders when they scan the computer. We recommend that you do not perform a malware scan on the files for certain programs or for operating system roles. This is to help prevent the following issues:

  • An antimalware program could incorrectly determine that a program file is malware. This would be considered to be a false positive.

  • The antimalware scan operation could decrease performance for a particular program when that program tries to access its program files.

This article contains links to articles and to websites that identify files and folders for certain Microsoft products. We recommend that you exclude these files and folders from Forefront Security and System Center 2012 Endpoint Protection scan operations.

Note The information in this article also applies to other antivirus or antimalware programs that you may use. Also, if you run an antivirus or antimalware program on a computer that is running a third-party program or service, we recommend that you contact the program vendor. The program vendor can help determine whether certain files or folders should be excluded from antivirus or antimalware scan operations.

More information

The following sections contain information about the files and folders that we recommend be excluded from scanning by antimalware programs. The information is categorized by the operating system role or by program name.

Both Forefront Endpoint Protection and System Center Endpoint Protection have preconfigured policy templates for the different server roles. For more information about these templates, see http://technet.microsoft.com/en-us/library/gg412475.aspx.

Domain controllers

815263 Antivirus, backup, and disk optimization programs that are compatible with the File Replication Service

837932 Event ID 2108 and Event ID 1084 occur during inbound replication of Active Directory in Windows 2000 Server and in Windows Server 2003

822158 Virus scanning recommendations for Enterprise computers that are running currently supported versions of Windows
For more information, go to the following Microsoft websites:

Managing Domain Controllers
http://technet2.microsoft.com/windowsserver/en/library/7e56fd5d-a6a2-44eb-8915-4a47bae41fda1033.mspx

Managing Antivirus Software on Active Directory Domain Controllers
http://technet.microsoft.com/en-us/library/cc816917(v=ws.10).aspx

Microsoft Exchange Server

328841 Exchange and antivirus software

245822 Recommendations for troubleshooting an Exchange Server computer with antivirus software installed

For more information, go to the following Microsoft website:

http://technet.microsoft.com/en-us/library/9fb755f5-5f0b-4817-a584-70c76a62eae2.aspx

Forefront Endpoint Protection

For more information, go to the following Microsoft website:

http://technet.microsoft.com/en-us/forefront/ee822838

Internet Information Server (IIS)

817442 IIS 6.0: Antivirus scanning of IIS compression directory may result in 0-byte file

Microsoft Internet Security and Acceleration (ISA) Server

For more information, go to the following Microsoft website:

http://technet.microsoft.com/en-us/library/cc707727.aspx

Microsoft SharePoint Portal Server

320111 Random errors may occur when antivirus software scans Microsoft Web Storage System in SharePoint Portal Server 2001 and in SharePoint Portal Server 2003

322941 Microsoft's position on antivirus solutions for Microsoft SharePoint Portal Server

Microsoft SQL Server

309422 Guidelines for choosing antivirus software to run on the computers that are running SQL Server

Microsoft Systems Management Server (SMS)

327453 Antivirus programs may contribute to file backlogs in SMS 2.0 and in SMS 2003

Microsoft Virtual Server 2005 or Microsoft Virtual PC 2004

840193 Virtual machines run very slowly in Virtual PC 2004 or in Virtual Server 2005

Windows operating systems

822158 Virus scanning recommendations for Enterprise computers that are running currently supported versions of Windows

General information

900638 Multiple symptoms occur if an antivirus scan occurs while the Wsusscan.cab file or the Wsusscn2.cab file is copied

References

For more information about Forefront Client Security policy-based exclusions, see Planning your policies.

For more information about how to use Forefront Client Security, see the Forefront Client Security product documentation. This documentation contains the following guides:

  • Microsoft Forefront Client Security Getting Started Guide

  • Microsoft Forefront Client Security Planning and Architecture Guide

  • Microsoft Forefront Client Security Deployment Guide

  • Microsoft Forefront Client Security Administrator's Guide

  • Microsoft Forefront Client Security Performance and Scalability Guide

  • Microsoft Forefront Client Security Disaster Recovery Guide

  • Microsoft Forefront Client Security Security Guide

  • Microsoft Forefront Client Security Troubleshooting Guide

  • Microsoft Forefront Client Security Technical Reference Guide

Need more help?

Want more options?

Explore subscription benefits, browse training courses, learn how to secure your device, and more.

Communities help you ask and answer questions, give feedback, and hear from experts with rich knowledge.

Was this information helpful?

What affected your experience?
By pressing submit, your feedback will be used to improve Microsoft products and services. Your IT admin will be able to collect this data. Privacy Statement.

Thank you for your feedback!

×