<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: I need to allow UltraVNC on the endpoint client in Endpoint</title>
    <link>https://community.checkpoint.com/t5/Endpoint/I-need-to-allow-UltraVNC-on-the-endpoint-client/m-p/78710#M2137</link>
    <description>&lt;P&gt;the last place I added the exclusion to was on SmartEndpoint in the Policy tab.&amp;nbsp; under the Anti-Malware policy.&amp;nbsp; Right click the Periodically scan local-hard drives only and select edit shared action.&amp;nbsp; Click on the link at the bottom that says Configure files and folders exclusions.&amp;nbsp; Click add and add the folder of where the executable is stored.&amp;nbsp; But I also added it to many other areas first.&amp;nbsp; I am not sure if it needs all of them or not but I will also list the other locations.&lt;/P&gt;&lt;P&gt;SmartEndpoint---&amp;gt;Policy---&amp;gt;Anti-Malware...right click Scan all files upon access and select edit shared action.&amp;nbsp; Add the folder location with the Add button under the Processes to exclude from scan.&amp;nbsp; I also added the specific process just as a precaution.&amp;nbsp; I assume if just the folder is there it will still work.&lt;/P&gt;&lt;P&gt;SmartEndpoint---&amp;gt;Policy---&amp;gt;Sandblast Agent Threat Extraction, Emulation and Anti-Exploit...right click on Inspect all domains and files and add the folder location to the Exclusions list in that window.&lt;/P&gt;&lt;P&gt;SmartEndpoint---&amp;gt;Policy---&amp;gt;Sandblast Agent Anti-Ransomware, Behavioral Guard and Forensics...right click on Default File Quarantine Settings and add the file location into the Items excluded from quarantine list.&amp;nbsp; I added the location and process.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I hope this helps someone.&amp;nbsp; It was a pain trying to find any of this information anywhere.&amp;nbsp; I basically just had to keep poking around in the policy until I found the locations. &amp;nbsp; But I found them one at a time and not all at once so I am assuming all need to be in place in order for it to work.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Tim&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Wed, 18 Mar 2020 17:08:41 GMT</pubDate>
    <dc:creator>TimLofgren</dc:creator>
    <dc:date>2020-03-18T17:08:41Z</dc:date>
    <item>
      <title>I need to allow UltraVNC on the endpoint client</title>
      <link>https://community.checkpoint.com/t5/Endpoint/I-need-to-allow-UltraVNC-on-the-endpoint-client/m-p/78580#M2132</link>
      <description>&lt;P&gt;Hello all,&lt;/P&gt;&lt;P&gt;I have searched quite a bit on this and have not found a way to allow Ultra VNC (winvnc.exe) on the client endpoint.&amp;nbsp; The anti-malware keeps detecting it as a threat and removing it.&amp;nbsp; I have already added it to exception lists in anti-malware and SandBlast policies in SmartEndpoint.&amp;nbsp; I am not sure why it keeps removing it as it is in like 4 exception lists.&amp;nbsp; Any help would be much appreciated.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Tim&lt;/P&gt;</description>
      <pubDate>Tue, 17 Mar 2020 17:51:18 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/I-need-to-allow-UltraVNC-on-the-endpoint-client/m-p/78580#M2132</guid>
      <dc:creator>TimLofgren</dc:creator>
      <dc:date>2020-03-17T17:51:18Z</dc:date>
    </item>
    <item>
      <title>Re: I need to allow UltraVNC on the endpoint client</title>
      <link>https://community.checkpoint.com/t5/Endpoint/I-need-to-allow-UltraVNC-on-the-endpoint-client/m-p/78593#M2133</link>
      <description>What version of the Endpoint client?&lt;BR /&gt;What precise logs are showing when it is removed?</description>
      <pubDate>Tue, 17 Mar 2020 20:09:27 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/I-need-to-allow-UltraVNC-on-the-endpoint-client/m-p/78593#M2133</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2020-03-17T20:09:27Z</dc:date>
    </item>
    <item>
      <title>Re: I need to allow UltraVNC on the endpoint client</title>
      <link>https://community.checkpoint.com/t5/Endpoint/I-need-to-allow-UltraVNC-on-the-endpoint-client/m-p/78693#M2135</link>
      <description>&lt;P&gt;Thanks for the reply.&amp;nbsp; I found where I needed to add it.&amp;nbsp; I had it in many exception lists but apparently I needed it also in the one that does the periodic scan.&amp;nbsp; Once it was added to that one, it stopped deleting it.&amp;nbsp; I appreciate the efforts.&amp;nbsp; It just took longer than I expected to find the right place to add it, or it needed it in multiple places.&amp;nbsp; but it is now working.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Tim&lt;/P&gt;</description>
      <pubDate>Wed, 18 Mar 2020 14:32:09 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/I-need-to-allow-UltraVNC-on-the-endpoint-client/m-p/78693#M2135</guid>
      <dc:creator>TimLofgren</dc:creator>
      <dc:date>2020-03-18T14:32:09Z</dc:date>
    </item>
    <item>
      <title>Re: I need to allow UltraVNC on the endpoint client</title>
      <link>https://community.checkpoint.com/t5/Endpoint/I-need-to-allow-UltraVNC-on-the-endpoint-client/m-p/78709#M2136</link>
      <description>For the folks following along, can you detail where you added it?</description>
      <pubDate>Wed, 18 Mar 2020 16:48:12 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/I-need-to-allow-UltraVNC-on-the-endpoint-client/m-p/78709#M2136</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2020-03-18T16:48:12Z</dc:date>
    </item>
    <item>
      <title>Re: I need to allow UltraVNC on the endpoint client</title>
      <link>https://community.checkpoint.com/t5/Endpoint/I-need-to-allow-UltraVNC-on-the-endpoint-client/m-p/78710#M2137</link>
      <description>&lt;P&gt;the last place I added the exclusion to was on SmartEndpoint in the Policy tab.&amp;nbsp; under the Anti-Malware policy.&amp;nbsp; Right click the Periodically scan local-hard drives only and select edit shared action.&amp;nbsp; Click on the link at the bottom that says Configure files and folders exclusions.&amp;nbsp; Click add and add the folder of where the executable is stored.&amp;nbsp; But I also added it to many other areas first.&amp;nbsp; I am not sure if it needs all of them or not but I will also list the other locations.&lt;/P&gt;&lt;P&gt;SmartEndpoint---&amp;gt;Policy---&amp;gt;Anti-Malware...right click Scan all files upon access and select edit shared action.&amp;nbsp; Add the folder location with the Add button under the Processes to exclude from scan.&amp;nbsp; I also added the specific process just as a precaution.&amp;nbsp; I assume if just the folder is there it will still work.&lt;/P&gt;&lt;P&gt;SmartEndpoint---&amp;gt;Policy---&amp;gt;Sandblast Agent Threat Extraction, Emulation and Anti-Exploit...right click on Inspect all domains and files and add the folder location to the Exclusions list in that window.&lt;/P&gt;&lt;P&gt;SmartEndpoint---&amp;gt;Policy---&amp;gt;Sandblast Agent Anti-Ransomware, Behavioral Guard and Forensics...right click on Default File Quarantine Settings and add the file location into the Items excluded from quarantine list.&amp;nbsp; I added the location and process.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I hope this helps someone.&amp;nbsp; It was a pain trying to find any of this information anywhere.&amp;nbsp; I basically just had to keep poking around in the policy until I found the locations. &amp;nbsp; But I found them one at a time and not all at once so I am assuming all need to be in place in order for it to work.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Tim&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 18 Mar 2020 17:08:41 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/I-need-to-allow-UltraVNC-on-the-endpoint-client/m-p/78710#M2137</guid>
      <dc:creator>TimLofgren</dc:creator>
      <dc:date>2020-03-18T17:08:41Z</dc:date>
    </item>
  </channel>
</rss>

