0% found this document useful (0 votes)
111 views3 pages

Testing Antivirus Scanning Exceptions

Download as pdf or txt
Download as pdf or txt
Download as pdf or txt
You are on page 1/ 3

1/8/2021 KB Article | Forcepoint Support

(http://www.forcepoint.com) 
MY ACCOUNT (/MYACCOUNT) HENDRY RAHARDJA (LOGOUT (/LOGOUT)) COMMUNITY (/COMMUNITY)

Home (Home) : Knowledgebase (Knowledgebase)

Testing Antivirus Scanning Exceptions for

Forcepoint Products
■ Article Number: 000016264

■ Products: Forcepoint DLP, Forcepoint DLP Endpoint, Forcepoint Email Security, Forcepoint Email Security Cloud, Forcepoint One Endpoint,

Forcepoint Security Appliance Manager, Forcepoint URL Filtering, Forcepoint Web Security, Forcepoint Web Security Endpoint, Forcepoint Web

Security Endpoint Cloud, TRITON AP-DATA, TRITON AP-EMAIL, TRITON AP-ENDPOINT DLP, TRITON AP-ENDPOINT Web, Websense Email

Security

■ Version: 8.7, 8.6, 8.5, 8.4, 8.3, 8.2, 8.1, 8.0, 20, 19, 18

■ Last Published Date: July 14, 2020

NOTES & WARNINGS


Important Performing this test may trigger an antivirus noti cation or incident alert.


Note Antivirus software is capable of corrupting the con guration or properties files used by Forcepoint which may affect performance. Forcepoint
recommends to exclude the required directories and files from antivirus scanning prior to installation.

PROBLEM DESCRIPTION

Forcepoint recommends to exclude installation folders from Antivirus scanning

(http://www.websense.com/content/support/library/deployctr/v85/dic_av_exclude.aspx).  In the event where antivirus is suspected to still be

a ffecting Forcepoint product functionality, is there a way to verify that the antivirus exceptions are working as expected? 

RESOLUTION

https://support.forcepoint.com/KBArticle?id=000016264 1/3
1/8/2021 KB Article | Forcepoint Support
To con firm antivirus exceptions are working, use the EICAR test:
Note The files are not required to be named test, however for troubleshooting purposes, naming it test will make it easier to locate.
. Navigate to respective Forcepoint product folder. Examples include:

■ Data: C:\Program Files (x86)\Websense\Data Security

■ EIP: C:\Program Files (x86)\Websense\EIP Infrastructure

■ Email: C:\Program Files (x86)\Websense\Email Security

■ Web: C:\Program Files (x86)\Websense\Web Security

■ FSAM: C:\Program Files\Forcepoint

■ Endpoints: C:\Program Files\Websense

. Open Notepad as administrator.

. Paste the below antivirus test script into Notepad:

X5O!P%@AP[4\PZX54(P^)7CC)7}$EICAR-STANDARD-ANTIVIRUS-TEST-FILE!$H+H*

Note The third character (X5O is a capital letter 'O', not a zero.)

. Save this file at test.txt in the respective product folder.


fication happens.
. Wait for a minute and see whether test.txt disappears or an antivirus noti

. If test.txtfile does not disappear and no notification happens, rename test.txt to test.com.
. Wait for a minute and see whether test.com disappears or an antivirus notification happens.

If the test.txt or test.com file disappears or an antivirus notification happens, the antivirus is still scanning the folder and the exceptions needs to
be properly con figured by the antivirus administrator.

Not all antivirus solutions work with the EICAR test, though most of the popular antivirus solutions do. For a list, see the red results at  Virus Total

EICAR test (https://www.virustotal.com/en/ file/275a021bbfb6489e54d471899f7db9d1663fc695ec2fe2a2c4538aabf651fd0f/analysis/1425909746/).

keywords: EICAR; av; anti-virus; av test; anti-virus test; av exception; anti-virus exception; scanning exception; exclude endpoint files; Antivirus
Exclusion Test; Monitoring Software;

Article Feedback

Is the article related to the topic you are looking for?

Yes No

Comments

Cancel Submit 

Tools & Links

  Featured Articles Home (https://support.forcepoint.com/KBArticle?id=000015996)

  Product Support Life Cycle (https://support.forcepoint.com/productsupportlifecycle)

  Certified Product Matrix (https://support.forcepoint.com/KBArticle?id=000014011)

  Upgrade Centers (https://support.forcepoint.com/KBArticle?id=Upgrade-Center)

https://support.forcepoint.com/KBArticle?id=000016264 2/3
1/8/2021 KB Article | Forcepoint Support

  Support Videos (https://support.forcepoint.com/KBArticle?id=000019124)

Want 24/7 Tech Support?

Learn more  (TechnicalSupportPrograms)

Give Feedback 

Contact Us (https://www.forcepoint.com/company/contact-us)

Free Trials & Demos (https://www.forcepoint.com/free-trials-demos) Careers (https://www.forcepoint.com/company/careers)

Case Studies (https://www.forcepoint.com/resources/case-studies)

 (https://www.linkedin.com/company/forcepoint?trk=fc_badge)
 (https://www.facebook.com/ForcepointLLC)  (https://twitter.com/forcepointsec)
 (https://www.youtube.com/channel/UC4MbQECdktvwewRlAFwT_-w)
 (http://blogs.forcepoint.com)
Legal Information (https://www.forcepoint.com/website-terms-and-conditions) Privacy Policy (https://www.forcepoint.com/privacy-policy)

© 2020 Forcepoint LLC. All Rights Reserved

https://support.forcepoint.com/KBArticle?id=000016264 3/3

You might also like

pFad - Phonifier reborn

Pfad - The Proxy pFad of © 2024 Garber Painting. All rights reserved.

Note: This service is not intended for secure transactions such as banking, social media, email, or purchasing. Use at your own risk. We assume no liability whatsoever for broken pages.


Alternative Proxies:

Alternative Proxy

pFad Proxy

pFad v3 Proxy

pFad v4 Proxy