DISCLAIMER:
Use at your own risk. I take no responsibility for damages that are caused from using these exclusions. Past performances is not a reliable indicator of future results. Always check with application vendors for up to date recommendations.
BEST PRACTICE:
Set all exclusions at the smallest scope. Do not make Global exclusions unless all endpoints have the application installed. Create Groups, apply exclusions to the Group scope, and only move endpoints into the Group that requires the exclusions.
Create separate exclusions for each path. Do not use 'and', 'or'.
If you can exclude specific files rather than a path, that is safer.
Exclusion modes can range from highest security to least secure. Use the most secure exclusion mode that resolves interoperability. Least secure will remove data from logs making it harder to troubleshoot.
After adding exclusions, restart all services related to the application being excluded. If services are not restarted, AV may continue blocking components. Or reboot all affected endpoints to apply or remove exclusions. Some AVs cannot unhook from a running process so it is always recommended to reboot, because if all associated processes are not restarted then an interoperability issue may still occur.
TIPS:
Use \Device\HarddiskVolume*\ format to wildcard exclusions for multiple drive paths (recommended).
Use \Device\MUP\ format if excluding a non local drive path.
MUP= multiple UNC provider.
UNC= Universal Naming Convention.
MUP is not involved during an operation that creates a mapped drive letter.
Acronis - CYBER BACKUP / CYBER PROTECT CLOUD
These recommendations are based on: https://kb.acronis.com/content/36429
\Device\HarddiskVolume*\Program Files*\Acronis\
\Device\HarddiskVolume*\Program Files*\Common Files*\Acronis\
\Device\HarddiskVolume*\ProgramData\Acronis\
\Device\HarddiskVolume*\Program Files\BackupClient\
For Virtual Machines: \Device\HarddiskVolume*\Users*\AppData\Local\Temp\AcronisGuestService\
Adbackup
\Device\HarddiskVolume*\Program Files\HDS\Backup\
*\Recovery\Base\ADBackup.exe
Adobe - Photoshop
\Device\HarddiskVolume*\Adobe\Adobe Photoshop*\
\Device\HarddiskVolume*\Program Files*\Common Files\Adobe\Adobe Desktop Common\ADS\Adobe Desktop Service.exe
\Device\HarddiskVolume*\Program Files*\Common Files\Adobe\Adobe Desktop Common\HDBox\HDHelper.exe
Altaro Backup
These recommendations are based on: https://help.altaro.com/support/solutions/articles/43000577861-which-altaro-directories-do-i-need-to-exclude-from-antivirus-software-
\Device\HarddiskVolume*\ProgramData\Altaro\
\Device\HarddiskVolume*\Program Files\Altaro\
Autodesk - AutoCAD
These recommendations are based on: https://knowledge.autodesk.com/support/autocad/troubleshooting/caas/sfdcarticles/sfdcarticles/Are-there-antivirus-exclusions-I-can-implement-to-make-programs-run-better.html
\Device\HarddiskVolume*\Program Files\Autodesk\
\Device\HarddiskVolume*\Program File*\Common Files\Autodesk Shared\
\Device\HarddiskVolume*\Program Files\common Files\Autodesk\
\Device\HarddiskVolume*\Program Files (x86)\Autodesk\
\Device\HarddiskVolume*\Program Files (x86)\common Files\Autodesk\
\Device\HarddiskVolume*\ProgramData\Flexnet\
\Device\HarddiskVolume*\ProgramData\Autodesk\
\Device\HarddiskVolume*\Program File*\AutoCAD*\
\Device\HarddiskVolume*\Users\*\AppData\Roaming\Autodesk\
\Device\HarddiskVolume*\Users\*\AppData\Local\Autodesk\
\Device\Mup\*\ifs\_.Data\ict\Software\Autocad\
\Device\HarddiskVolume*\temp\AutoDeskViewer\
Turn off Kernel File Protection for interoperability, on AutoCAD endpoints only:
If you have a small number of endpoints with AutoCAD, use sentinelctl: sentinelctl config agent.preventProtectedFilesKernelModification false -k "Passphrase"
If you have a larger number of endpoints with AutoCAD, and you have Policy Override permissions, add this line to the policy override of the group of endpoints: { "preventProtectedFilesKernelModification": false }
Bentley - ProjectWise
These recommendations are based on: https://communities.bentley.com/products/projectwise/content_management/w/wiki/7894/projectwise-list-of-services-and-folders-to-exclude-from-a-virus-scan
\Device\HarddiskVolume*\Program Files\Bentley\
Bentley - ProjectWise
These recommendations are based on: https://communities.bentley.com/products/projectwise/content_management/w/wiki/7894/projectwise-list-of-services-and-folders-to-exclude-from-a-virus-scan
\Device\HarddiskVolume*\Program Files\Bentley\
Bitdefender
\Device\HarddiskVolume*\WINDOWS\Temp\bdcore_tmp\*\tmp*\tmp*\
Camworks
\Device\HarddiskVolume*\Program Files (x86)\Gamewell-FCI\
\Device\HarddiskVolume*\Program Files (x86)\Common Files\Trimble\
\Device\HarddiskVolume*\Program Files (x86)\Common Files\SafeNet Sentinel\
\Device\HarddiskVolume*\Program Files (x86)\Common Files\Aladdin Shared\HASP\
\Device\HarddiskVolume*\Windows\System32\hasplms.exe
Carbonite
These recommendations are based on: https://support.carbonite.com/articles/Personal-Pro-Windows-Avast
\Device\HarddiskVolume*\Program*\Carbonite\Carbonite Backup\
Cisco Anyconnect VPN
\Device\HarddiskVolume*\Program Files (x86)\cisco\cisco anyconnect vpn client\vpnagent.exe
\Device\HarddiskVolume*\Program Files (x86)\cisco\cisco anyconnect vpn client\vpnui.exe
\Device\HarddiskVolume*\Program Files (x86)\cisco\cisco anyconnect Secure Mobility Client\vpnagent.exe
\Device\HarddiskVolume*\Program Files (x86)\cisco\cisco anyconnect Secure Mobility Client\vpnui.exe
Citrix
These recommendations are based on: https://docs.citrix.com/en-us/tech-zone/build/tech-papers/antivirus-best-practices.html, and https://support.citrix.com/article/CTX127030
\Device\HarddiskVolume*\Program File*\Citrix\
\Device\HarddiskVolume*\ProgramData\Citrix*\
\Device\HarddiskVolume*\Windows\Temp\StoreFront\
\Device\HarddiskVolume*\Windows\ServiceProfiles\NetworkService\
Cloudberry
These recommendations are based on: https://www.cloudberrylab.com/resources/blog/slow-backup-how-to-speed-up/
CBBackupPlan.exe, CloudBerry Online Backup.exe (or CloudBerry Backup Server Edition.exe, CloudBerry Backup for MS SQL Server.exe, CloudBerry Backup Enterprise Edition.exe, CloudBerry Backup Bare Metal Edition.exe, CloudBerry Backup for MS Exchange Server.exe)Cloud.Backup.Scheduler.exe,cbb.exe
Commvault Backup and Recovery
These recommendations are based on: https://documentation.commvault.com/commvault/v11/article?p=8665.htm
\Device\HarddiskVolume*\Program Files\Commvault\ContentStore\*\
\Device\HarddiskVolume*\Program Files\Commvault\ContentStore\SoftwareCache\
\Device\HarddiskVolume*\Program Files\Commvault\CS_DR\
\Device\HarddiskVolume*\Program Files\Commvault\ContentStore\iDataAgent\JobResults\
\Device\HarddiskVolume*\Program Files\Commvault\ContentStore\IndexCache\
\Device\HarddiskVolume*\*\CV_MAGNETIC\*
Note: If you use a UNC path to access the magnetic libraries, exclude the UNC path as well.
Get the deduplication database location from the CommCell Console, in the Copy Properties dialog box of the primary copy, on the Deduplication tab.
\Device\HarddiskVolume*\Users\Commvault Services account\AppData\Local\Temp\
\Device\HarddiskVolume*\Program Files\Commvault\ContentStore\CIServer\
\Device\HarddiskVolume*\Program Files\Commvault\ContentStore\CVCIEngine\
\Device\HarddiskVolume*\Program Files\Commvault\ContentStore\CVCIEngine\solr\
\Device\HarddiskVolume*\Program Files\Commvault\ContentStore\CVCIEngine\solr\CIIndex\
Connectwise - Automate / Screen Connect
These recommendations are based on: https://docs.connectwise.com/ConnectWise_Automate_Documentation/060/040/010, and https://docs.connectwise.com/ConnectWise_Control_Documentation/Get_started/Knowledge_base/False_positive_from_antivirus_software
\Device\HarddiskVolume*\Windows\LTSvc\LTSVC.exe
\Device\HarddiskVolume*\windows\ltsvc\ltsvcmon.exe
\Device\HarddiskVolume*\LTshare\Transfer\Tools\produkey.exe
\Device\HarddiskVolume*\LTshare\Transfer\Tools\produkey64.exe
\Device\HarddiskVolume*\Windows\Temp\ltcache\
\Device\HarddiskVolume*\Windows\Temp\_ltupdate\
\Device\HarddiskVolume*\LTSHARE\
\Device\HarddiskVolume*\LTshare\Transfer\Tools\
\Device\HarddiskVolume*\Windows\LTSvc\scripts\
\Device\HarddiskVolume*\ProgramData\MySQL\
\Device\HarddiskVolume*\ProgramFiles\MySQL\
\Device\HarddiskVolume*\Windows\Temp\LTInstall\
\Device\HarddiskVolume*\Program Files (x86)\LabTech\
\Device\HarddiskVolume*\Program Files (x86)\LabTech Client\
CODE 42 - Crashplan
These recommendations are based on: https://support.code42.com/Administrator/5/Planning_and_installing/Best_practices_for_Code42_and_antivirus
For Crashplan 8.2 and higher, add:
\Device\HarddiskVolume*\Program File*\Code42\
\Device\HarddiskVolume*\Program File*\CrashPlan\
\Device\HarddiskVolume*\ProgramData\CrashPlan\
\Device\HarddiskVolume*\Users\*\AppData\Local\CrashPlan\
\Device\HarddiskVolume*\Users\*\AppData\Roaming\CrashPlan\
If Crashplan is installed on Windows Legacy, also add:
\Device\HarddiskVolume*\Documents and Settings\All Users\Application Data\CrashPlan\
CorelDRAW
\Device\HarddiskVolume*\Program Files\Corel\
Datto
These recommendations are based on: https://help.datto.com/s/article/KB213994246
\Device\HarddiskVolume*\Program Files\Datto\
Dentrix
*\DENTRIX\Server Files\Faircom_bin\ctreesql.exe
*\Dentrix\DB\
*\Dentrix\Common\
*\Dentrix\
Dr backup
These recommendations are based on: https://drbackup.net/whitepapers/DrBackup-AntivirusExclusions.pdf
\Device\HarddiskVolume*\Program Files*\Remote Backup\
\Device\HarddiskVolume*\BMR\VHDBackup-64.exe (if you are using the Full Image Backup service)
\Device\HarddiskVolume*\Drbackup\
\Device\HarddiskVolume*\DrbKey\
\Device\HarddiskVolume*\BMR\
Drake Accounting
*\DrakeAccounting*\DrakeAccounting2019.exe
\Device\HarddiskVolume*\Program Files*\IDriveWindows\id_service.exe
\Device\Mup\*\drake\DrakeAccounting*\DrakeAccounting2019.exe
\Device\Mup\App\Drake\DrakeAccounting*\updater.exe
\Device\Mup\App\Drake\DrakeAccounting*\DrakeAccounting2020.exe
\Device\Mup\App\Drake\DrakeAccounting*DrakeAccounting2020.exe.config
Egnyte
These recommendations are based on: https://helpdesk.egnyte.com/hc/en-us/articles/218926917
Add Egnyte Desktop App processes including EgnyteClient.exe, EgnyteDrive.exe, EgnyteSyncService.exe, EgnyteUpdate.exe to the whitelist of Antivirus software.
Exclude the Egnyte drive or volume from Antivirus scanning by adding exclusions in the Antivirus software (e.g., Windows Defender) as below.
Intuit
These recommendations are based on: https://proconnect.intuit.com/community/data-security/help/firewall-and-anti-virus-software-configuration-for-lacerte-tax/00/5165
C:\Program Files\Common Files\Lacerte Shared
C:\Program Files (x86)\Common Files\Lacerte Shared - (64-Bit Operating Systems)
C:\Program Files\Common Files\Intuit Shared
C:\Program Files (x86)\Common Files\Intuit Shared - (64-Bit Operating Systems)
Lacerte Program Path for each year (C:\Lacerte\YYTax)
Lacerte System File Path (C:\Lacerte\YYTax for standalone, or X:\Lacerte\YYTax for network)
Lacerte Option Path* (C:\Lacerte\YYTax)
Lacerte Data Paths, up to nine of them (X:\Lacerte\YYTax\?data -where ? is a single letter of the tax type)
C:\ProgramData\Lacerte (for tax years 2008 and later)
Lacerte folders inside the users Application Data folder (for TY2010 and later) and Local Application Data folder (for TY2009) should be excluded.
For 2010 and later the path is as follows: (<username> refers to the appropriate Windows user ID.)
For Windows XP, C:\Documents and Settings\<username>\Application Data\Lacerte
For Windows 7/8/10/Vista C:\USERS\<username>\Appdata\Roaming\Lacerte
The locations for the DMS program are very reliant on what version of Windows you are using, and whether your computer is either 32 or 64 bit:
For Windows Vista, 7, 8, & 10:
%USERPROFILE%\AppData\Local\Temp\DMSTemp
For Windows XP:
%USERPROFILE%\local settings\temp\DMSTemp
For 32-bit operating systems:
C:\Program Files\Intuit\DMS
For 64-bit operation systems:
C:\Program Files (x86)\Intuit\DMS
Your DMS database folder:
The Current Database Path is listed at the end of the DMS program window.
Generally, if you leave all locations the default, you may exclude the entire C:\Lacerte and X:\Lacerte (if network) folders to cover all years. You can verify the actual paths in the program by pressing the F10 button to open the Technical Support Information window under the System Information tab. You'll need to check each tax module separately to confirm the data paths.
If you aren't sure how to configure your antivirus software, contact your IT professional or the software vendor.
If your antivirus won't allow the exclusion of entire directories, these are the files that must be excluded:
wYYtax.exe, located inside of the corresponding YYtax folder.
All of the WebSetupYY.exe files, located inside of the Lacerte shared directory.
All of the WYYSetup.exe files, located inside of the Lacerte shared directory.
DMS.exe, located inside of the DMS folder.
JumpCloud
\Device\HarddiskVolume*\Program Files*\JumpCloud\
Kaseya
These recommendations are based on: https://helpdesk.kaseya.com/hc/en-gb/articles/229014948-Anti-Virus-Exclusions-Trusted-Apps
\Device\HarddiskVolume*\Program Files*\Kaseya\
\Device\HarddiskVolume*\Program Files*\Kaseya Remote Control\
\Device\HarddiskVolume*\ProgramData\Kaseya\
\Device\HarddiskVolume*\Program Files*\Kaseya Live Connect\
\Device\HarddiskVolume*\PCBP (for KDCB)
Liongard
These recommendations are based on: https://docs.liongard.com/docs/upgrade-liongard-agent
\Device\HarddiskVolume*\Program Files*\liongardinc\liongardagent\
\Device\HarddiskVolume*\Program Files*\liongardinc\roaragent\
Malwarebytes
These recommendations are based on: https://support.malwarebytes.com/hc/en-us/articles/360038479234
\Device\HarddiskVolume*\ProgramData\Malwarebytes Endpoint Agent\
\Device\HarddiskVolume*\ProgramData\Malwarebytes\MBAMService\
\Device\HarddiskVolume*\Program Files*\Malwarebytes Endpoint Agent\
\Device\HarddiskVolume*\Program Files*\Malwarebytes Endpoint Agent\Plugins\Incident Response\Logs\
\Device\HarddiskVolume*\Program Files*\Malwarebytes\Anti-malware\
\Device\HarddiskVolume*\Windows\System32\drivers\ESProtectionDriver.sys
\Device\HarddiskVolume*\Windows\System32\drivers\MBAMChameleon.sys
\Device\HarddiskVolume*\Windows\System32\drivers\MBAMSwissArmy.sys
\Device\HarddiskVolume*\Windows\System32\drivers\farflt.sys
\Device\HarddiskVolume*\Windows\System32\drivers\flightrecorder.sys
\Device\HarddiskVolume*\Windows\System32\drivers\mbae.sys (mbae64.sys on an x64 system)
\Device\HarddiskVolume*\Windows\System32\drivers\mbam.sys
\Device\HarddiskVolume*\Windows\System32\drivers\mwac.sys
Microsoft
These recommendations are based on: https://social.technet.microsoft.com/wiki/contents/articles/953.microsoft-anti-virus-exclusion-list.aspx
App-V
BizTalk Server
See recommendations in BizTalk performance optimization guides:
http://msdn.microsoft.com/en-us/library/cc558617(BTS.10).aspx
http://msdn.microsoft.com/en-us/library/ee377064(BTS.70).aspx
Mentioned executables used by BizTalk includes EntSSO.exe, MSDTC.exe, BTSNTSvc.exe, BTSNTSvc64.exe, SQLServr.exe, but also others as IIS, Customer WCF services, MSMQ, Rule Engine, SQL Agent, SSIS, SSNS and other applications used in integration scenarios.
Cluster
DHCP
Dynamics CRM
Dynamics AX 2009
For versions up to AX 2009 exclude:
All the AOD, AOI, ADD, ADI, KHD & KHI files, or alternatively, the whole application folder
See for instance: http://blogs.msdn.com/b/czdaxsup/archive/2010/05/13/ax-application-files-locked-by-another-process.aspx
Doing this helps make sure that the files are not locked when the AOS must use them. However, if these files become infected, your antivirus software will not be able to detect the infection.
Dynamics AX 2012
During AOS startup XPPIL (CIL) files are generated to by default: C:\Program Files\Microsoft Dynamics AX\60\Server\MicrosoftDynamicsAX\bin\XppIL>
Exclude XppIL and all subfolders
alternatively, you may want to exclude C:\Program Files\Microsoft Dynamics AX\60\Server\MicrosoftDynamicsAX\bin\Application\Appl>, which is the local AOS store of the label files.
Exchange
Exchange 2019: https://docs.microsoft.com/en-us/Exchange/antispam-and-antimalware/windows-antivirus-software?view=exchserver-2019
Exchange 2016: https://technet.microsoft.com/EN-US/library/bb332342(v=exchg.160).aspx
Exchange 2013: http://technet.microsoft.com/en-us/library/bb332342%28v=exchg.150%29.aspx
Exchange 2010: http://technet.microsoft.com/en-us/library/bb332342%28v=exchg.141%29.aspx
Exchange 2007: http://technet.microsoft.com/en-us/library/bb332342%28EXCHG.80%29.aspx
http://technet.microsoft.com/en-us/library/bb332342%28EXCHG.80%29.aspx
Forefront
FRS
Hyper-V, System Center Virtual Machine Manager (SCVMM)
IIS
ISA
Lync 2010
Lync 2013
MED-V
Office Online
Orchestrator
SBS
SCCM 2012
SCCM Current Branch (CB)
SCOM / MOM
SCDPM
SharePoint
Skype for Business 2015
SMS
SQL
Team Foundation Server 2010/2012/2013
Terminal Services
Virtual PC / Virtual Server
Windows
KB822158 Virus scanning recommendations for Enterprise computers that are running currently supported versions of Windows
Windows / Active Directory
Windows Update
WSUS (Windows Server Update Services)
Mimecast
\Device\HarddiskVolume*\Program Files*\Mimecast\Security Agent\Container.Runtime.exe
\Device\HarddiskVolume*\Program Files*\Mimecast\Security Agent\Supervisor.Runtime.exe
Perch
\Device\HarddiskVolume*\Program Files*\Perch\
Prosystem Tax
These recommendations are based on: https://support.cch.com/kb/solution/000038244/sw688
\Device\Mup\*\data\wfx32\CTXTP20.exe
\Device\Mup\*\data\wfx32\
Quest Rapid Recovery
These recommendations are based on: https://support.quest.com/kb/117680/best-practices-enabling-anti-virus-exclusions
\Device\HarddiskVolume*\Program Files*\AppRecovery\Core\CoreService\*\Core.Service.exe
\Device\HarddiskVolume*\Program Files*\AppRecovery\Agent\*\Agent.Service.exe
\Device\HarddiskVolume*\Program Files*\AppRecovery\*
\Device\HarddiskVolume*\ProgramData\AppRecovery\*
*:\System Volume Information\*
*:\System Volume Information\MountPointManagerRemoteDatabase
*:\System Volume Information\WindowsImageBackup
\Device\HarddiskVolume*\Windows\System32\drivers\aavdisk.sys
\Device\HarddiskVolume*\Windows\System32\drivers\aavstor.sys
\Device\HarddiskVolume*\Windows\System32\drivers\aavolflt.sys
\Device\HarddiskVolume*\Windows\System32\drivers\aafsflt.sys
*:\System Volume Information\AAData.md
*:\System Volume Information\AAFailover.md
*:\System Volume Information\tracking.log
*:\System Volume Information\AALog_*.log
Ransim
\Device\HarddiskVolume*\KB4\Rassim\MainLauncher.exe
\Device\HarddiskVolume*\KB4\Rassim\Collector.exe
Replibit
These recommendations are based on: https://support.efolder.net/hc/en-us/articles/360047210094-BRC-AntiVirus-on-this-device-is-preventing-backups-from-completing-
\Device\HarddiskVolume*\Program Files*\Replibit\
Rocketcyber
\Device\HarddiskVolume*\Program Files\RocketAgent\
\Device\HarddiskVolume*\Program Files (x86)\RocketAgent\
\Device\HarddiskVolume*\Users\admin\AppData\Local\Temp\RocketAgent\
\Device\HarddiskVolume*\Windows\Temp\RocketAgent\
Sage
These recommendations are based on: https://support.na.sage.com/selfservice/viewContent.do?externalId=79671&sliceId=1 and https://support.na.sage.com/selfservice/viewContent.do?externalId=17258&sliceId=1
C:\ProgramData\Sage\Sage 100 Contractor SQL
C:\ProgramData\Aatrix Software
C:\Program Files (x86)\Sage\Sage 100 Contractor SQL
C:\Program Files (x86)\Aatrix Software
C:\%LocalAppData%\Sage\Sage 100 Contractor SQL
The network location of Sage 100 Contractor data. For example, [Installation Drive Letter]:\Sage100Con\Company.
WORKSTATION:
Sage 300 CRE and Sage Estimating program files (include all):
9.7.x and later
32-bit: C:\Program Files (x86)\Sage or
64-bit: C:\Program Files\Sage
9.5.x and later
XP/2003: C:\Documents and Settings\All Users\Application Data\Sage or
Vista/Win7/2008: C:\ProgramData\Sage
32-bit
C:\Program Files (x86)\Timberline Office and
C:\Program Files (x86)\Common Files\Sage
64-bit
C:\Program Files\Timberline Office and
C:\Program Files\Common Files\Sage
Any mapped drives or network locations mapping back to Sage 300 CRE (Timberline) data and program files
Pervasive/Actian:
16.1 and Later:
32-bit: C:\Program Files (x86)\Pervasive Software or C:\Program Files (x86)\Actian.
64-bit: C:\Program Files\Pervasive Software or C:\Program Files\Actian.
9.7.x - 15.1:
32-bit: C:\Program Files (x86)\Pervasive Software or C:\Program Files (x86)\Pervasive
64-bit: C:\Program Files\Pervasive Software or C:\Program Files\Pervasive
Vista/Win7/2008
C:\ProgramData\Pervasive Software or C:\ProgramData\Pervasive Software\Actian.
9.6.x and earlier
C:\Pvsw
Crystal Reports:
9.5.x and later, using Crystal XI
32-bit: C:\Program Files (x86)\Business Objects or
64-bit: C:\Program Files\Business Objects
9.4.x and earlier, using Crystal 10
C:\Program Files\Common Files\Crystal Decisions
Aatrix:
9.7.x and later
32-bit: C:\Program Files (x86)\Aatrix Software or
64-bit: C:\Program Files\Aatrix Software
Event 1:
9.7.x and later
32-bit: C:\Program Files (x86)\Event 1 or
64-bit: C:\Program Files\Event 1
9.4.x and earlier
C:\Windows\system32\srvany.exe or
C:\Winnt\system32\srvany.exe (for a terminal server that is not the file server)
SERVER:
Sage 300 CRE and Sage Estimating program files (include all):
9.7.x and later
32-bit: C:\Program Files (x86)\Sage or
64-bit: C:\Program Files\Sage
9.5.x and later
XP/2003: C:\Documents and Settings\All Users\Application Data\Sage or
Vista/Win7/2008: C:\ProgramData\Sage
32-bit
C:\Program Files (x86)\Timberline Office and
C:\Program Files (x86)\Common Files\Sage
64-bit
C:\Program Files\Timberline Office and
C:\Program Files\Common Files\Sage
Sage 300 CRE (Timberline) data files
Any mapped drives mapping to back to Sage 300 CRE (Timberline) data and program files
Pervasive:
9.7.x and later
32-bit: C:\Program Files (x86)\Pervasive Software or C:\Program Files (x86)\Actian.
64-bit: C:\Program Files\Pervasive Software or C:\Program Files\Actian.
XP/2003
C:\Documents and Settings\All Users\Application Data\Pervasive Software.
Vista/Win7/2008
C:\ProgramData\Pervasive Software or C:\ProgramData\Actian.
9.6.x and earlier
C:\Pvsw
Crystal:
9.5.x and later, using Crystal XI
32-bit: C:\Program Files (x86)\Business Objects or
64-bit: C:\Program Files\Business Objects
9.4.x and earlier, using Crystal 10
C:\Program Files\Common Files\Crystal Decisions
Aatrix:
9.7.x and later
32-bit: C:\Program Files (x86)\Aatrix Software or
64-bit: C:\Program Files\Aatrix Software
Event 1:
9.7.x and later
32-bit: C:\Program Files (x86)\Event 1 or
64-bit: C:\Program Files\Event 1
Solidworks
\Device\HarddiskVolume*\ProgramData\SOLIDWORKS\
\Device\HarddiskVolume*\Program Files\SolidWorks Corp\SolidWorks\
Storagecraft
These recommendations are based on: https://support.storagecraft.com/s/article/How-To-Adding-the-StorageCraft-Antivirus-Exceptions?language=en_US
ShadowProtect Legacy versions
32-bit Systems
Executables, files, and services to exclude:
C:\Program Files\StorageCraft\ShadowProtect\ShadowProtectsvc.exe
C:\Program Files\StorageCraft\ShadowProtect\stcvsm.sys
C:\Program Files\StorageCraft\ShadowProtect\stcinst.exe
C:\Windows\System32\drivers\sbmount.sys
DiskRoot\*.IDX
Directories to exclude:
Any backup destination from on-access scanning. It is recommended that a scheduled scan is run during off-peak hours.
C:\Program Files\StorageCraft
64-bit Systems
Executables, files, and services to exclude:
C:\Program Files (x86)\StorageCraft\ShadowProtect\ShadowProtectsvc.exe
C:\Program Files (x86)\StorageCraft\ShadowProtect\stcvsm.sys
C:\Program Files (x86)\StorageCraft\ShadowProtect\stcinst.exe
C:\Windows\System32\drivers\sbmount.sys
DiskRoot\*.IDX
Directories to exclude:
Any backup destination from on-access scanning. It is recommended that a scheduled scan is run during off-peak hours.
C:\Program Files (x86)\StorageCraft\
ShadowProtect SPX versions
Executables, files, and services to exclude:
C:\Windows\System32\drivers\stcvsm.sys
Stcinst.exe
C:\Program Files\StorageCraft\spx\spx_gui.exe
C:\Program Files\StorageCraft\spx\vsnapvss.exe
C:\Program Files\StorageCraft\spx\spx_gui_mount.exe
C:\Program Files\StorageCraft\spx\spx_service.exe
DiskRoot\*.IDX
Directories to exclude:
C:\ProgramData\StorageCraft\
C:\Program Files\StorageCraft\
Any backup destination from on-access scanning. It is recommended that a scheduled scan is run during off-peak hours.
REST API Exclusions (Console Connections):
https://127.0.0.1:13581/
Proxy Exceptions:
localhost
127.0.0.1
ShadowXafe versions
Executables, files, and services to exclude:
C:\Windows\System32\drivers\stcvsm.sys
C:\Program Files\StorageCraft\Xafe\StorageCraftAgent.exe
C:\Program Files\StorageCraft\Xafe\vsnapvss.exe
DiskRoot\*.IDX
Directories to exclude:
C:\ProgramData\StorageCraft\
C:\Program Files\StorageCraft\
Any backup destination from on-access scanning. It is recommended that a scheduled scan is run during off-peak hours.
StorageCraft ImageManager
32-bit Systems (7.1.0 and earlier)
Executables, files, and services to exclude:
C:\Program Files\StorageCraft\ImageManager\ImageManager.exe
Directories to exclude:
Any managed destination from on-access scanning. It is recommended that a scheduled scan is run during off-peak hours.
C:\Program Files\StorageCraft\
64-bit Systems
Executables, files, and services to exclude:
C:\Program Files (x86)\StorageCraft\ImageManager\ImageManager.exe
Directories to exclude:
Any managed destination from on-access scanning. It is recommended that a scheduled scan is run during off-peak hours.
C:\Program Files (x86)\StorageCraft\
Thompson Reuters
These recommendations are based on: https://cs.thomsonreuters.com/ua/account-and-application-mgmt/cs_us_en/systems/antivirus-guidelines-for-cs-professional-suite.htm
Veeam
These recommendations are based on: https://www.veeam.com/kb1999
Veriato
These recommendations are based on: https://help.veriato.com/products/veriato-investigator/win/en/v76/deployment/Antivirus/Antivirus_Client.htm
VMWARE - Carbon Black
These recommendations are based on: https://community.carbonblack.com/t5/Knowledge-Base/Carbon-Black-Cloud-Recommended-Third-Party-Anti-virus-Exclusions/ta-p/47533
\Device\HarddiskVolume*\Program Files\Confer\
\Device\HarddiskVolume*\ProgramData\CarbonBlack\
\Device\HarddiskVolume*\Windows\System32\drivers\ctifile.sys
\Device\HarddiskVolume*\Windows\System32\drivers\ctinet.sys
\Device\HarddiskVolume*\Windows\System32\drivers\cbelam.sys
\Device\HarddiskVolume*\Windows\Syswow64\ctintev.dll
Webroot
These recommendations are based on: https://docs.webroot.com/us/en/business/administratorguide/administratorguide.htm#Policies/Overrides.htm
\Device\HarddiskVolume*\Program Files\Webroot\WRSA.exe
\Device\HarddiskVolume*\Program Files (x86)\Webroot\WRSA.exe
Zabbix
*\zabbix_agentd.exe