This article details MyWorkDrive Server and Client Antivirus settings for versions 5.2 and above. When you run Windows antivirus programs on MyWorkDrive, you can help enhance the security of your organization. However, if they aren't configured correctly, Windows antivirus programs can cause problems in MyWorkDrive server and clients. MyWorkDrive support has attempted to detail basic exclusion requirements however each Antivirus vendor operates differently and may require additional exclusions and settings to ensure 100% functionality.
For information regarding Firewall settings for communication, see Firewall Settings for the MyWorkDrive Server
Server Antivirus Exclusions
Folder Exclusions
C:\wanpath*.*
C:\Program Files (x86)\Wanpath*.*
C:\ProgramData\WANPATH*.*
C:\Windows\Microsoft.NET\Framework64\v4.0.30319\Temporary ASP.NET Files*.*
Process exclusions
Many antivirus programs support the scanning of processes, which can adversely affect MyWorkDrive if the incorrect processes are scanned. Therefore, you should exclude the following MyWorkDrive or related processes from process scanning.
"C:\Program Files (x86)\Wanpath\MyWorkDrive\ActiveDirectoryService\MyWorkDrive.ActiveDirectoryService.exe"
"C:\Program Files (x86)\Wanpath\MyWorkDrive\Service\MyWorkDrive.Service.exe"
"C:\Wanpath\WanPath.Utilities\Exe\cloudflared.exe"
w3wp (IIS Worker Processes)
This may be particularly impactful in high volume environments. We have seen environments where there are a large number of files opened/closed/saved or file transfers where CPU utilization can be cut by 30% by removing scanning on these four services/processes. Assuming you have appropriate border and file system security, redundantly scanning MyWorkDrive processes is a bottleneck you may seek to avoid.
Server Installation and Upgrades
Antivirus and EDR products can also interfere with installing or upgrading MyWorkDrive Server. Typical symptoms include the security product blocking the installer from accessing its components, blocking extraction of the installer package, quarantining or locking files after they are extracted, and blocking installation of required dependencies such as .NET (formerly .NET Core) and the ASP.NET Core Module (ANCM) for IIS. ANCM has been a frequent problem. In some cases it fails to install entirely. In others, the files are copied to disk but the security product prevents ANCM from being registered and enabled in IIS, and the MyWorkDrive Server site cannot start. See .NET Requirements for MyWorkDrive Server for steps to verify and manually reinstall these components.
Products where customers have recently needed to add exclusions or allowlist the .NET and ANCM installers include SentinelOne, Carbon Black, CrowdStrike Falcon, and FortiClient. This is not a complete list, and any endpoint protection product can cause the same behavior depending on its policy settings.
ThreatLocker and other application allowlisting products work differently. Rather than detecting suspicious behavior, they block any executable that has not been explicitly approved. This affects the MyWorkDrive installer itself and the Microsoft dependencies it downloads and runs, including the .NET Hosting Bundle, the Visual C++ Redistributable, and Edge WebView2. If these are not approved, installation will fail on initial install, and again on future upgrades whenever a new version of any of these components is required. Approving them by publisher certificate rather than by file hash avoids having to re-approve each new version as it is released.
There are three options for avoiding these problems:
- Apply the server exclusions described earlier in this article before running the install or upgrade. Installer extraction runs from temporary locations that the installed-path exclusions may not cover. If exclusions alone don't resolve the problem, use option 2.
- Temporarily stop or disable the antivirus/EDR agent for the duration of the install or upgrade. Re-enable it after installation completes and the server has been verified working.
- Ask your antivirus/EDR vendor to adjust their detection heuristics so they don't block the MyWorkDrive installer, extraction, or dependency installs. In our experience, vendors are often slow or unwilling to make these changes, so options 1 and 2 are usually the more practical path.
Local Web Application Firewall
In addition to corporate firewall settings if your antivirus product enables a local web application firewall add the following exclusions.
Allow any to localhost 127.0.0.1 for Administration Console management.
TCP/UDP Ports
If your antivirus application adjusts or limits TCP or UDP ports, we advise disabling that feature. MyWorkDrive makes real time calls via LDAP to the AD to authenticate users on login and again on file access/save, resulting on a high volume server in a large number of calls. If you are limiting tcp/udp ports this can result in the domain controller reporting unavailable and the operating system "timing out" AD calls for 15 minutes when ports are exhausted. When the OS times out those AD calls your MyWorkDrive server will report offline to users and deny logins/file access/save.
McAfee Antivirus Example Exclusions
As an example, for McAfee Endpoint Security add the following MyWorkDrive exclusions. In addition to these exclusions review firewall ports required for various MyWorkDrive services.
Threat Prevention
Exclude c:wanpath*.*

Firewall
Add Local Host (127.0.0.1) and Local Subnets Exclusion


LAN Example: 10.0.0.0/24 LocalHost: 127.0.0.1
Web Control
Add exclusion for 127.0.0.1

Clustering
It is imperative that, when running in Cluster mode with shared configuration files stored on an SMB path, that AV and Security Products are configured with path, folder or type exclusions to ensure they are not operating on the files or scanning the path as a network share.
Antivirus will alter and place locks on files in ways that can cause file contention and result in corruption or incomplete information being replicated to secondary servers.
Please be sure to disable network scanning for all installed instances of your endpoint security and include the path, file types and computer accounts for your MyWorkDrive servers in your exclusions.
Windows Client Antivirus Exclusions
For virus applications other than Windows Defender, we recommend setting exclusions in your security products on client machines running MyWorkDrive.
-
C:\Users\%username%\AppData\Local\MyWorkDrive*.* - user configuration data. Users need to be able to read, write and modify this path, including subfolders.
-
C:\Program Files (x86)\Wanpath\MyWorkDrive-Client-Windows*.* - the application. Users need to be able to read from this path, including subfolders. Install requires being able to write to this path (logs)
-
C:\ProgramData\Wanpath*.* - log files - users need to be able to read/write/modify this path.
-
%temp%\CBFS* - file system driver temp files (the folder name is randomized on each login) - users need to be able to read/write/modify files and folders in this path.
-
C:\Users\%username%\AppData\Roaming\WanPath\ MountingPointsInfo.json - users need to be able to read/write/delete this file – file is created on login and deleted on logout.
-
regasm.exe utility, a default component of windows installations, used to register DLLs. Users need to be able to run this utility.
Note that our application will both do DLL registration and registry updates from the application and call regasm.exe. Both methods should be permitted for installation.
Failure to set client exclusions may result in:
- Errors on application launch including client hanging, client failing to login or unusual warning messages.
- Inability to open files - error messages or hanging/no response
- Saving resulting in corrupt files
- Files being locked or warning about being locked inappropriately
Network Scanning
For optimal performance, we also strongly recommend Excluding Network Drive Letter Scanning from AV/Endpoint security applications to avoid unnecessary load on the server, file systems, internet connection and security devices, generated by redundant scans by all connected users.
Browser Technologies
Should you have policies that restrict functions like CSS or JavaScript in browsers, please permit them for local host and published URLs for users to avoid impact in Web Clients / Web Administration
Here is partial list of the most common technologies used in MyWorkDrive web applications
Admin Panel Browser Components - Angular.js - FontAwesome - Microsoft ASP.NET - Chart.js - Spin.js - Moment.js - Underscore.js - Clipboard.js - Modernizr - jQuery UI - jQuery - Kendo - Bootstrap
Webclient Browser Components - HSTS - Font Awesome - Microsoft ASP.NET - Google Code Prettify - Moment.js - Dojo - jQuery UI - jQuery