Page 1 of 1

Antivirus Exclusions

Published: March 27, 2018 - 10:29
by agauvrit
Good morning,

We have observed that the Antivirus solutions installed at our clients' sites tend to prevent the WAPT agent or WAPT Setup installer from functioning correctly.

We have listed some paths to include in the exclusion paths of your Antivirus management console:

Code: Select all

"C:\Program Files (x86)\wapt\waptservice\win32\nssm.exe"
"C:\Program Files (x86)\wapt\waptservice\win64\nssm.exe"
"C:\Program Files (x86)\wapt\waptagent.exe"
"C:\Program Files (x86)\wapt\waptconsole.exe"
"C:\Program Files (x86)\wapt\waptexit.exe"

"C:\wapt\waptservice\win32\nssm.exe"
"C:\wapt\waptservice\win64\nssm.exe"
"C:\wapt\waptagent.exe"
"C:\wapt\waptconsole.exe"
"C:\wapt\waptexit.exe"
We would also like you to contribute to this exclusion list via this topic.

If you have encountered the problem and have found working exclusion paths for the agent/agent installation, please feel free to reply to this message.

Sincerely,

Alexander

Re: Antivirus Exclusions

Published: April 11, 2018 - 2:40 PM
by Alesk
Hello,

Referring to the morning post titled "WAPT 1.5 vs Antivirus" viewtopic.php?f=10&t=1134, here are the elements we have integrated to unlock the situation on a Trend Micro Officescan XG.

# Detection 1: The detected malware is Mal_Mlwr-13 https://www.trendmicro.com/vinfo/us/thr ... al_Mlwr-13
Solution: https://success.trendmicro.com/solution/000019446 to be applied to all scans on Scan Exclusion List (Directories) c:\wapt


# Detection 2: Unauthorized file encryption C:\Windows\Temp\is-L7N1A.tmp\waptagent.tmp (triggered by "c:\windows\temp\waptagent.exe")
Solution: http://docs.trendmicro.com/en-us/enterp ... ing-1.aspx on c:\windows\temp\waptagent.exe

# Detection 3: waptconsole.exe
Solution: http://docs.trendmicro.com/all/ent/offi ... -List.html to be applied to all workstations on c:\wapt\waptconsole.exe

Re: Antivirus Exclusions

Published: August 2, 2019 - 09:12
by Minus
Hello,

on Node32, during agent installation via GPO:

Object URI: file:///C:/Program Files (x86)/wapt/waptservice/win32/is-2ISAL.tmp
Threat name: Win32/NSSM.D
Process name: C:\Windows\Temp\is-0INQQ.tmp\waptagent.tmp

Therefore, the threat was simply excluded.