To resolve the issue, add the following exclusions:
- Real-Time Scan Exclusions:
C:\Program Files (x86)\SFirmVX\
- Behavior Monitoring Exclusions:
C:\Program Files (x86)\SFirmVX\SFUpdateProvider.exe
C:\Program Files (x86)\SFirmVX\SFirm.exe
C:\Program Files (x86)\SFirmVX\50\P031.0\sfinfocenter.exe
or
C:\Program Files (x86)\SFirmVX\*
Change "X" to your SFirm version. If you have multiple versions, add them all to exclusions. Please also verify if the SFirm is installed on Disk C.
Do not add SFirm to manual and scheduled scan exclusions for the directory to be scanned during the scanning process.
For Behavior Monitoring Exclusion, the asterisk (*) serves as a wildcard value indicating that all programs on SFirmV3 and SFirmV4 are excluded.
To verify if the agent got the new configuration, check the following:
- Real-Time Scan
- (64-bit) "HKLM\SOFTWARE\Wow6432Node\TrendMicro\PC-cillinNTCorp\CurrentVersion\Real Time Scan Configuration" - entries ExcludedExt, ExcludedFile or ExcludedFolder
- (32-bit) "HKLM\SOFTWARE\TrendMicro\PC-cillinNTCorp\CurrentVersion\Real Time Scan Configuration"- entries ExcludedExt, ExcludedFile or ExcludedFolder
- Behavior Monitoring
- (64-bit) "HKLM\SOFTWARE\Wow6432Node\TrendMicro\PC-cillinNTCorp\CurrentVersion\AEGIS\AEGISServerExtLis"
- You can only view the count of the exclusion as image path is encrypted. If the count is equal to the count in console, this means the exclusion is applied.
