- Products
- Learn
- Local User Groups
- Partners
- More
Access Control and Threat Prevention Best Practices
5 November @ 5pm CET / 11am ET
Firewall Uptime, Reimagined
How AIOps Simplifies Operations and Prevents Outages
Overlap in Security Validation
Help us to understand your needs better
CheckMates Go:
Spark Management Portal and More!
Hi guys,
I have issue - when I install endpoint (recommended / latest) and run Thunderbird on various windows versions, epam_svc.exe uses 25-60% CPU while Thunderbird not responding.
https://wiki.mozilla.org/Thunderbird:Testing:Antivirus_Related_Performance_Issues)
[warni] Unhandled callback event EVENT_MAILBASE [AMEngine::Kav::KavScanner::KavCallbackMethod], nothing else unusual
Do you have it working / tested with Thunderbird?
This helps: excluded from AntiMalware - on access - scan mail messages.
We are trying to isolate problem now with removing previous generic exclusions and define new in AntiMalware blade only for thunderbird.exe process.
I'll keep you posted.
I would open a TAC case here.
Thanks man. I'll keep you posted about solution
Please, take into consideration these additional notes:
This helps: excluded from AntiMalware - on access - scan mail messages.
We are trying to isolate problem now with removing previous generic exclusions and define new in AntiMalware blade only for thunderbird.exe process.
I'll keep you posted.
thank you for sharing this information. It helps a lot
Hi
I have the same problem - how can I exclude "scan mail messages" in cloud-based Harmony Endpoint -> Policy - > Threat Prevention -> Exclusion Center?
There is no "AntiMalware - on access - scan mail messages". I can exclude process (like thunderbird.exe) only.
Regards
Chris
Hello,
Same problem here.
Did you solved the issue or still using the workaround of disabling scan mail messages?
Thanks
Hi
I'd exluded process "thunderbird.exe" in this setting:
Scan all files upon access .. -> Add Location -> Process Name (full path to thunderbird.exe)
Hello,
OK, I wouldn't like to exclude the whole process so I think I'm going to open a TAC case to check it...
Thanks
Hi
Please let me (and us 😉) know, what they proposed/did.
I had opened TAC. Result was in Thread prevention -> Exclussion center -> Exclussion settings - > Process exclussion (on-access only) -> thunderbird.exe
So the solution from the TAC was exclude "thunderbird.exe" from being analyzed? It seems a workaround....
Did they tell you if in a future release could fix the problem to not exclude it from protections?
correct, this was answer from TAC. Yes, they did tell me they don't plan to fix it for the future releases as this is known bug of thunderbird, which is minor email client. Many other vendors fixed it by default exception not visible to admins.
the security is not broken too much as the mails are scanned on network level and the attachments are scanned on touch. Just the core thunderbird.exe is excluded.
OK, thanks for your answer
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 5 | |
| 3 | |
| 2 | |
| 2 | |
| 1 | |
| 1 | |
| 1 | |
| 1 | |
| 1 | |
| 1 |
Wed 05 Nov 2025 @ 11:00 AM (EST)
TechTalk: Access Control and Threat Prevention Best PracticesThu 06 Nov 2025 @ 10:00 AM (CET)
CheckMates Live BeLux: Get to Know Veriti – What It Is, What It Does, and Why It MattersTue 11 Nov 2025 @ 05:00 PM (CET)
Hacking LLM Applications: latest research and insights from our LLM pen testing projects - AMERTue 11 Nov 2025 @ 10:00 AM (CST)
Hacking LLM Applications: latest research and insights from our LLM pen testing projects - EMEAAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY