Issue:
- DeepGuard blocks an application. This was determined to be a high-risk application by system control heuristics.
- After the file SHA-1 hash and file path is excluded in WithSecure Client Security or Server Security DeepGuard feature continues to block the application
Resolution:
You can exclude the network drivers from being scanned, by doing the following:
- Log into Policy Manager Console
- Select a host or policy domain from the domain tree
- Click on Settings
- Select Standard view
- Select Real-time scanning
- Scroll down to Files and applications excluded from scanning
- Select Do not scan the following files and applications
- Click Add
- Enter the full path for each files, folder or SHA-1 of the application. Example:
- Select File path if the file that you want to exclude always uses the same path.
- Select Folder path if you want to exclude all files in a specific folder.
- Select Application SHA-1 if the path for the file that you want to exclude may vary across different hosts.
NOTE:
If the file or folder is located in share drive, you need to add the exclusion in UNC format.
Example:
\\servername\share\folder\to\the\app.exe
If this location is also mapped to a drive letter (e.g. N:\), then another exclusion must also be added in the mapped format as the following:
N:\folder\to\the\app.exe
For more information on using wildcards in exclusions, refer here
10. Click the icon to distribute the policy (Ctrl + D)
Article no: 000005580