Recommended Virus Scanning Exclusions

DC187

New member
Power User
Local time
9:44 PM
Messages
79
Location
Hampshire, UK
Incase some of you are not aware Microsoft have a recommended list files/folders that should be excluded from On-Access Anti Virus scanning.

You can find the article here: Virus scanning recommendations for computers that are running Windows Server 2008 R2, Windows Server 2008, Windows Server 2003, Windows 2000, Windows XP, Windows Vista, or Windows 7

Here's their recommendations for Windows 2000, XP, Vista, 7, Server 2003 and Server 2008 and 2008 R2:

Microsoft Windows Update or Automatic Update related files
  • The Windows Update or Automatic Update database file. This file is located in the following folder: %windir%\SoftwareDistribution\Datastore
    Exclude the Datastore.edb file.
  • The transaction log files. These files are located in the following folder:%windir%\SoftwareDistribution\Datastore\Logs
    Exclude the following files:
    • Edb*.log

      Note The wildcard character indicates that there may be several files.
    • Res1.log. The file is named Edbres00001.jrs for Windows Vista, Windows 7, Windows Server 2008, and Windows Server 2008 R2.
    • Res2.log. The file is named Edbres00002.jrs for Windows Vista, Windows 7, Windows Server 2008, and Windows Server 2008 R2.
    • Edb.chk
    • Tmp.edb
    • The following files in the %windir%\security path should be added to the exclusions list:
      • *.edb
      • *.sdb
      • *.log
      • *.chk
      Note If these files are not excluded, security databases are typically corrupted, and Group Policy cannot be applied when you scan the folder. The wildcard character indicates that there may be several files. Specifically, you must exclude the following files:
      • Edb.chk
      • Edb.log
      • *.log
      • Security.sdb in the <drive>:\windows\security\database folder

Group Policy related files
  • Group Policy user registry information. These files are located in the following folder: %allusersprofile%\
    Exclude the following file: NTUser.pol
  • Group Policy client settings file. These files are located in the following folder:%Systemroot%\system32\GroupPolicy\
    Exclude the following file: registry.pol
Hope this info is helpful to some people :)
 

My Computer

OS
Windows 7 Ultimate x64
CPU
2x AMD FX-74 @ 3GHz
Motherboard
ASUS L1N64-SLI WS
Memory
4GB
Graphics Card(s)
2x BFG 8800GTX OC
Sound Card
Creative X-Fi Fatal1ty
Monitor(s) Displays
HP L2045w
Hard Drives
2x Samsung Spinpoint
PSU
Enermax 1000W
Case
Armor Extreme ATX
Cooling
Air
Nice find DC187, thanks. :)
 

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Airbot 2.0
OS
Windows 7 Ultimate x64 SP1
CPU
Core i7 920 (D0) @ 4Ghz, *26c idle *65c full load on air
Motherboard
Asus P6X58D Premium - Sata 6Gb/s - USB 3.0
Memory
12GB DDR3 Corsair Dominator -CMD12GX3M6A1600C8 at 1600MHz
Graphics Card(s)
Zotac Geforce GTX 770
Sound Card
ASUS Xonar D2X
Monitor(s) Displays
1 LG 24" Flatron W2453V-PF 1 Samsung 24" P2450H both 2ms RT
Screen Resolution
1920x1080@60hz
Hard Drives
1 Samsung 250GB 840 Evo SSD
1 OCZ Vertex2 180GB SSD
1 TB Samsung Spinpoint F1 7200RPM 32MB cache
2 500GB WD Caviar Blacks 7200RPM 32MB cache (WD5001AALS)

Pioneer DVD Burner DVR-S18M
PSU
Corsair HX1000W
Case
Cooler Master HAF 932
Cooling
Case Fans *3 230mm, *1 140mm/CPU - *Tuniq Tower 120 Extreme
Keyboard
Logitech Wireless MK700
Mouse
Logitech Wireless MK700
Internet Speed
DL 15 Mbps UL 0.98 Mbps
Antivirus
None
Browser
Firefox Nightly
Other Info
Processor-7.7 *RAM- 7.9 *Graphics-7.9 *Gaming Graphics- 7.9 *SSD- 7.8 W.E.I final score= 7.7
*Phone- LG Nexus 5
This is nice. But has anybody figured out how to do that in a convenient way - e.g. with Norton or SuperAntiSpyware.
 

My Computer

Computer Manufacturer/Model Number
HP, Dell, Gateway, Toshiba - 4 laptops and 2 desktops
OS
Vista, Windows7, Mint Mate, Zorin, Windows 8
CPU
from 1.6GHz Duo to i7
Monitor(s) Displays
2x HP w2207
Hard Drives
5x HDD, 7x SSD, 12x Externals
Keyboard
with trackball - no mices
Mouse
Trackball mice
Internet Speed
DSL 6000
I'm unfamiliar with those products, I use McAfee VirusScan Enterprise myself and it's just a simple case of adding them in on an Exclusions tab.
Considering this is an article published by Microsoft I would have thought it would make sense for AntiVirus products to automatically detect the version of Windows running and apply the exclusions by default.
By adding these exclusions you reduce the chance of corrupting some of the above databases, I wonder if it due to Virus Scanning that causes some of the Windows Update errors some people suffer?

Maybe this thread should be stickied, not enough people are aware of these recommendations!
 

My Computer

OS
Windows 7 Ultimate x64
CPU
2x AMD FX-74 @ 3GHz
Motherboard
ASUS L1N64-SLI WS
Memory
4GB
Graphics Card(s)
2x BFG 8800GTX OC
Sound Card
Creative X-Fi Fatal1ty
Monitor(s) Displays
HP L2045w
Hard Drives
2x Samsung Spinpoint
PSU
Enermax 1000W
Case
Armor Extreme ATX
Cooling
Air
Yeah, I know. All those programs have exclusion tabs. But you have to scout one by one for all those files and put them into the list - and that is the cumbersome part.
 

My Computer

Computer Manufacturer/Model Number
HP, Dell, Gateway, Toshiba - 4 laptops and 2 desktops
OS
Vista, Windows7, Mint Mate, Zorin, Windows 8
CPU
from 1.6GHz Duo to i7
Monitor(s) Displays
2x HP w2207
Hard Drives
5x HDD, 7x SSD, 12x Externals
Keyboard
with trackball - no mices
Mouse
Trackball mice
Internet Speed
DSL 6000
True it is cumbersome but with Eset AV and SS, and probably some others, once you have it set up, there is a setting that allows one to export one's customized settings (including the exclusion list) to an .xml file and reapply (i.e., import) them with a click or two when upgrading or reinstalling. So at least if that option is available, one only has to go through this pain once.
 

My Computer

Computer Manufacturer/Model Number
HP DV8t quad
OS
Windows 7 Ultimate x64 (Retail)
CPU
i7-Q 720
Motherboard
Motherboard Chipset Intel Ibex Peak-M PM55, Intel Lynnfield
Memory
6 GB
Graphics Card(s)
nVidia GeForce GT 230M (1GB)
Sound Card
IDT High Definition Audio CODEC
Monitor(s) Displays
18.4 inch HP Infinity FHD (Samsung 184HT03-001)
Screen Resolution
1920 x 1080
Hard Drives
Hitachi 500GB 7200 rpm (x2)
Seagate FreeAgent 1.5 TB External USB (x2)
Thermaltake BlacX eSATA/USB 2.0 3.5/2.5 HD dock
Cooling
Zalman NC-2000 notebook cooling pad
Keyboard
laptop
Mouse
Logitech VX Revolution
Other Info
Backup Unit: Lenovo T61p
Back
Top