Issue
- You have SpectorSoft installed on the same system as ESET
- You are using ESET Remote Administrator version 5
Solution
If SpectorSoft is not installed
The following instructions are for new deployments of SpectorSoft with ESET already installed.
- If both SpectorSoft and ESET are not installed, we recommend that you install SpectorSoft first and then deploy ESET with the exclusions listed in the section below.
To install SpectorSoft with ESET installed, set your ERA policy to match the settings below (Windows desktop V5 is used as an example below):
A. Windows desktop v5 → Real-time file system protection → Settings
- Use advanced heuristics on file execution. [Default is No]
- Additional ThreatSense parameters for newly created and modified files → Advanced Heuristics. [Default is Yes]
- Additional ThreatSense parameters for Removable media → Use advanced heuristics on executing files from removable media. [Default is Yes]
Windows desktop v5 → Real-time file system protection → Scanner
- Options → Heuristics. [Default is Yes]
- Options → Advanced heuristics/DNA/Smart signatures. [Default is No]
B. Windows desktop v5 → Kernel → Scanner (Startup scanner) → Options
- Heuristics. [Default is Yes]
- Advanced heuristics/DNA/Smart signatures. [Default is Yes]
C. Prior to deploying of the SpectorSoft recording client, find all of the systems you plan to deploy to in the ERA Clients tab.
-
Right-click on these and select Set policy (you can use Shift or CTRL to select multiple clients).
-
In the new window, select the policy you created above. Allow time for the clients to check in and receive the new policy.
-
Deploy the SpectorSoft client software and restart the system.
- Right-click the clients again, select Set policy and then select the policy with the exclusions you have set.
If SpectorSoft is already installed
A. Set exclusions in Spectorsoft client
-
Copy and paste the standard exclusions below into a text file and save it to your system.
-
In ERA version 5, open the policy connected to the systems that you need to set exclusions on. Go to the section in the policy for your ESET product installed on those systems.
- Kernel → Settings → Exclusions → Exclusions → Edit.
- Kernel → Settings → Exclusions → Exclusions → Edit.
- In the new window click + List, drill down to the text file you saved with the exclusions added to it and import the list.
You should now see the full list in the window under "Folders and files."
B. Manually add additional exclusions
-
Manually add the following exclusion:
C:* @NAME=Win32/Urlbot.NAT@TYPE=Backdoor
-
Add the exclusion for C:* as shown above and then add the @NAME section to the Only threat section below New item. You will need to deselect the Exclude all threats box to add the threat.
-
Add C:* with each variant listed below:
@NAME=Win32/Urlbot.NAO@TYPE=Backdoor
@NAME=Win32/Urlbot.NAX@TYPE=Backdoor
@NAME=Win32/Urlbot.NAM@TYPE=Backdoor
List of standard exclusions for the SpectorSoft client
C:Windowswinipbin cxaemap.dll.1
C:Windowswinipbinquasimo.dll.1
C:Windowswinipbinmossimo.dll.1
C:Windowswinipbineanipw.dll.1
C:Windowswinipbinimepulib32.dll.1
C:Windowswinipbin
cxaemap.dll
C:Windowswinipbinquasimo.dll
C:Windowswinipbinmossimo.dll
C:Windowswinipbineanipw.dll
C:Windowswinipbinimepulib32.dll
C:WindowsSYSTEM32cenotify.dll
C:WindowsSYSTEM32cnecdll3.dll
C:WindowsSYSTEM32cnecdll4.dll
C:WindowsSYSTEM32cnecommdll.dll
C:WindowsSYSTEM32cnesvrmgr.exe
C:WindowsSYSTEM32LicensingWebServiceProxyWrapper.dll
C:WindowsSYSTEM32Serialization.dll
C:WindowsSYSTEM32SPDataServer.exe
C:WindowsSYSTEM32SPDataServer.log
C:WindowsSYSTEM32Spector360DataObjects.dll
C:WindowsSYSTEM32SpectorLogging.dll
C:WindowsSYSTEM32Spectorsoft.WebServices.CommonBase.dll
C:WindowsSYSTEM32Spectorsoft.WebServices.DataTransfer.dll
C:WindowsSYSTEM32SpectorSoftWebServiceProxy.dll
C:WindowsSYSTEM32SpectorSoftWorkflowServiceInterfaces.dll
C:WindowsSYSTEM32SPLicenseManager.exe
C:WindowsSYSTEM32SPLicenseManager.log
C:WindowsSysWOW64cenotify.dll
C:WindowsSysWOW64cnecdll4.dll
C:WindowsSysWOW64cnesvrmgr.exe
C:WindowsSysWOW64LicensingWebServiceProxyWrapper.dll
C:WindowsSysWOW64Serialization.dll
C:WindowsSysWOW64SPDataServer.exe
C:WindowsSysWOW64SPDataServer.log
C:WindowsSysWOW64Spector360DataObjects.dll
C:WindowsSysWOW64SpectorLogging.dll
C:WindowsSysWOW64Spectorsoft.WebServices.CommonBase.dll
C:WindowsSysWOW64Spectorsoft.WebServices.DataTransfer.dll
C:WindowsSysWOW64SpectorSoftWebServiceProxy.dll
C:WindowsSysWOW64SpectorSoftWorkflowServiceInterfaces.dll
C:WindowsSysWOW64SPLicenseManager.exe
C:WindowsSysWOW64SPLicenseManager.log
C:Program FilesSpectorSoft*
C:Program Files (x86)SpectorSoft*