Video Screencast Help
Search Video Help Close Back
to help

Prevent registration of new Browser Helper Objects (HIPS) [AC15]

Created: 07 Jan 2013 | 5 comments
Elements_Media's picture
0 0 Votes
Login to vote

Hi @ All

 

We are using a AC rule in SEP to Prevent registration of new Browser Helper Objects. Now it is blocking us some windows updates... (f.e. for Internet Explorer)

How do I have to design the Application Control exclusion?

 

Thanks for you help

Comments 5 CommentsJump to latest comment

Brian81's picture

in the application policy, add msiexec under "Do not apply this rule to the following processes:"

0
Login to vote
Elements_Media's picture

This would widen the attack surface to much.

0
Login to vote
Elements_Media's picture

Am I right or is that not allmost the same as disabling the policy? Because allmost anything uses msiexec to install itself, not?

Is there not a possibility to say, msiexec will just be excluded when it is used by the windows update?

Thanks for your help, Brian.

0
Login to vote
Mithun Sanghavi's picture

Hello,

What version of SEP 12.1 are you running?

{B4F3A835-0E21-4959-BA22-42B3008E02FF} is a BHO itself with File name URLREDIR.DLL.

However, in your case, msiexec.exe is trying to register itself with the above BHO and is being blocked by SEP.

Could you let me know if the msiexec.exe application is legitimate??

If yes, please diable the ADC rule and run the Application again.

Hope that helps!!

 

Mithun Sanghavi
Symantec Technical Support Engineer, SEP
MIM | MCSA | MCTS | STS | ITIL v3

Twitter: @mithun_sanghavi

Don't forget to mark your thread as 'SOLVED' with the answer that best helps you.<&a

0
Login to vote