Hi Guys,
hope you could help me out. We have a small tool called nettool.exe which is searching for some network printers. Our employees need this tool every day. since a few weeks or months the tool will be deleted by VSE.
How is it possible to exclude this file from detection? If tried to add some exclusion for on-access scanner and so on without success.
Thanks in advance,
Tobi
Solved! Go to Solution.
@toto1988 This file is not being detected as a PUP, and so excluding it in your PUP-policy isn't going to resolve the issue. This type of detection is a "generic" threat detection driver that encompasses a wide range of files underneath its scope, and as such, it would not be advised that you do an exclusion for this detection name as you could then be vulnerable to a "real" threat, even if you could exclude it in this way.
Instead, you need to engage Support by opening a ticket with the Malware team for potential false positive investigation. You can submit the file as a sample for this purpose by following the instructions in KB85567. They will be able to assist you in validating the reputation of this file, and resolving the detection in your environment.
Was my reply helpful?
If this information was helpful in any way, or answered your question, will you please select "Accept as Solution" in my reply, or give kudos as appropriate, so together we can help other members?
These type questions should be posted under the ENS/VSE team group. However, my suggestion would be to submit it as a sample as a false positive. Is it being detected as a virus or as an unwanted program? Your exclusions would depend on how it is being detected.
I will also be transferring this over to the appropriate team.
Was my reply helpful?
If this information was helpful in any way or answered your question, will you please select Accept as Solution in my reply and together we can help other members?
Hi,
I did like described in KB50383 (see screenshot below). I set the exclusion on our ePO.
Nettool.exe is detected as RDN/Generic.RP and I add a exclusion for RDN/Generic.RP without success.
is there any other way to fix?
@toto1988 This file is not being detected as a PUP, and so excluding it in your PUP-policy isn't going to resolve the issue. This type of detection is a "generic" threat detection driver that encompasses a wide range of files underneath its scope, and as such, it would not be advised that you do an exclusion for this detection name as you could then be vulnerable to a "real" threat, even if you could exclude it in this way.
Instead, you need to engage Support by opening a ticket with the Malware team for potential false positive investigation. You can submit the file as a sample for this purpose by following the instructions in KB85567. They will be able to assist you in validating the reputation of this file, and resolving the detection in your environment.
Was my reply helpful?
If this information was helpful in any way, or answered your question, will you please select "Accept as Solution" in my reply, or give kudos as appropriate, so together we can help other members?
We had the similar issue for some time. In our case, we contacted the malware team and submitted the file. McAfee helped us with a negative Extra DAT. That fixed our issue permanently.
So submit the file and get the solution....
New to the forums or need help finding your way around the forums? There's a whole hub of community resources to help you.
Thousands of customers use our Community for peer-to-peer and expert product support. Enjoy these benefits with a free membership: