- CheckMates
- :
- Products
- :
- Harmony
- :
- Endpoint
- :
- Re: Harmony Endpoint <> Mozilla Thunderbird
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Mute
- Printer Friendly Page
Are you a member of CheckMates?
×- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Harmony Endpoint <> Mozilla Thunderbird
Hi guys,
I have issue - when I install endpoint (recommended / latest) and run Thunderbird on various windows versions, epam_svc.exe uses 25-60% CPU while Thunderbird not responding.
- defined exclusion to Anti-Malware on access scan for "C:\users\*\AppData\Roaming\Thunderbird\Profiles\" (
https://wiki.mozilla.org/Thunderbird:Testing:Antivirus_Related_Performance_Issues)
- The Thunderbird profile is not huge - ~20 GB, 622 files
- internal log viewer shows nothing (not literally)
- sysinternals procemon points lot of EPMA_SVC pointing to thunderbird profiles even the exclusion is set
- windows various versions (from 7 till 10 enterprise latest build, fully patched)
- cpda.log does not show unusual activity.
- AntimalwareBlade.log some strange messages:
[warni] Unhandled callback event EVENT_MAILBASE [AMEngine::Kav::KavScanner::KavCallbackMethod], nothing else unusual
Do you have it working / tested with Thunderbird?
Accepted Solutions
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
This helps: excluded from AntiMalware - on access - scan mail messages.
We are trying to isolate problem now with removing previous generic exclusions and define new in AntiMalware blade only for thunderbird.exe process.
I'll keep you posted.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
I would open a TAC case here.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Thanks man. I'll keep you posted about solution
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Please, take into consideration these additional notes:
- Thunderbird "Deleted Items" folder is corrupted after the endpoint installation.
- Thunderbird "Sent Items" folder, is corrupted also.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
This helps: excluded from AntiMalware - on access - scan mail messages.
We are trying to isolate problem now with removing previous generic exclusions and define new in AntiMalware blade only for thunderbird.exe process.
I'll keep you posted.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
thank you for sharing this information. It helps a lot
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hi
I have the same problem - how can I exclude "scan mail messages" in cloud-based Harmony Endpoint -> Policy - > Threat Prevention -> Exclusion Center?
There is no "AntiMalware - on access - scan mail messages". I can exclude process (like thunderbird.exe) only.
Regards
Chris
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hello,
Same problem here.
Did you solved the issue or still using the workaround of disabling scan mail messages?
Thanks
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hi
I'd exluded process "thunderbird.exe" in this setting:
Scan all files upon access .. -> Add Location -> Process Name (full path to thunderbird.exe)
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hello,
OK, I wouldn't like to exclude the whole process so I think I'm going to open a TAC case to check it...
Thanks
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hi
Please let me (and us 😉) know, what they proposed/did.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
I had opened TAC. Result was in Thread prevention -> Exclussion center -> Exclussion settings - > Process exclussion (on-access only) -> thunderbird.exe
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
So the solution from the TAC was exclude "thunderbird.exe" from being analyzed? It seems a workaround....
Did they tell you if in a future release could fix the problem to not exclude it from protections?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
correct, this was answer from TAC. Yes, they did tell me they don't plan to fix it for the future releases as this is known bug of thunderbird, which is minor email client. Many other vendors fixed it by default exception not visible to admins.
the security is not broken too much as the mails are scanned on network level and the attachments are scanned on touch. Just the core thunderbird.exe is excluded.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
OK, thanks for your answer
