Quest recommends disabling Antivirus or excluding the following Change Auditor components and monitored processes from any antivirus software that uses technology similar to “Buffer Overrun Protection” or “On Access Scanner”.
Please exclude the following paths, as well as the subfolders and files contained therein:
C:\Program Files\Common Files\Quest\
C:\Program Files\Quest\ChangeAuditor\Agent\
Also, Lsass.EXE must be whitelisted due to agent injection for event collection.
If the Antivirus program utilized requires direct file paths, below is a list of all Change Auditor agent processes that need to be excluded:
C:\Program Files\Common Files\Quest\Detoured.dll
C:\Program Files\Common Files\Quest\NPDTWrap.dll
C:\Program Files\Quest\ChangeAuditor\Agent\NPSrvHost.exe
C:\Program Files\Quest\ChangeAuditor\Agent\DNSS\CADnsSup.dll
C:\Program Files\Quest\ChangeAuditor\Agent\CASupport.dll
C:\Program Files\Quest\ChangeAuditor\Agent\Plug-in for Active Directory\CAADEventMsg.dll
C:\Program Files\Quest\ChangeAuditor\Agent\Plug-in for Active Directory\CAADFlt.sys
C:\Program Files\Quest\ChangeAuditor\Agent\Plug-in for Active Directory\CAADHook.dll
C:\Program Files\Quest\ChangeAuditor\Agent\Plug-in for Active Directory\CAADMain.dll
C:\Program Files\Quest\ChangeAuditor\Agent\Plug-in for Active Directory\CAADPerfCount.dll
C:\Program Files\Quest\ChangeAuditor\Agent\Plug-in for Active Directory\CAADService.dll
C:\Program Files\Quest\ChangeAuditor\Agent\Plug-in for Active Directory\FSLogonMonitor.dll
C:\Program Files\Quest\ChangeAuditor\Agent\Plug-in for Windows File Servers\FSEventMsg.dll
C:\Program Files\Quest\ChangeAuditor\Agent\Plug-in for Windows File Servers\FSLogonMonitor.dll
C:\Program Files\Quest\ChangeAuditor\Agent\Plug-in for Windows File Servers\FSPerfCount.dll
C:\Program Files\Quest\ChangeAuditor\Agent\Plug-in for Windows File Servers\FSServiceMonitor.dll
C:\Program Files\Quest\ChangeAuditor\Agent\Plug-in for Windows File Servers\FSService.dll
C:\Program Files\Quest\ChangeAuditor\Agent\Plug-in for Windows File Servers\Driver\FSDriver.sys
C:\Program Files\Quest\ChangeAuditor\Agent\SCM\ServicesHook.dll
C:\Program Files\Quest\ChangeAuditor\Agent\Plug-in for ADAM\CAADEventMsg.dll
C:\Program Files\Quest\ChangeAuditor\Agent\Plug-in for ADAM\CAADADAMHook.dll
C:\Program Files\Quest\ChangeAuditor\Agent\Plug-in for ADAM\CAADAMMain.exe
C:\Program Files\Quest\ChangeAuditor\Agent\Plug-in for ADAM\CAADADAMPerfCount.dll
C:\Program Files\Quest\ChangeAuditor\Agent\Plug-in for ADAM\CAADAMService.exe
C:\Program Files\Quest\ChangeAuditor\Agent\Plug-in for ADAM\dbghelp.dll
C:\Program Files\Quest\ChangeAuditor\Agent\dbghelp.dll