Endpoint Protection

 View Only
Expand all | Collapse all

Browser Intrusion Prevention is malfunctioning

Migration User

Migration UserOct 24, 2014 06:41 AM

ℬrίαη

ℬrίαηOct 24, 2014 06:45 AM

Migration User

Migration UserOct 24, 2014 07:25 AM

Chetan Savade

Chetan SavadeOct 24, 2014 11:33 AM

Chetan Savade

Chetan SavadeOct 24, 2014 12:04 PM

  • 1.  Browser Intrusion Prevention is malfunctioning

    Posted Oct 24, 2014 04:34 AM

    Hi,

     

    Following error appears on a lot of clients today when the users start Internet Explorer.

     

    Browser Intrusion Prevention is malfunctioning. Browser type: Internet Explorer. Try to update the signatures Browser path: C:\Program Files (x86)\Internet Explorer\iexplore.exe        

    Do anyone know what the error can be??



  • 2.  RE: Browser Intrusion Prevention is malfunctioning

    Posted Oct 24, 2014 05:29 AM

    I'm having similar problems but I can trigger it by simply downloading CSV and TXT files from a few specific websites on Windows 7 w/ Internet Explorer 8 & SEP 12.1.5 (locked into this thanks to 3rd parties that won't support anything greater, is ridiculous) - have confirmed that the lockups are happening in IE11 too tho.

    Symptoms I experience are you click on the download link for the CSV or TXT file, it asks whether you want to open/save. Click on open and it hangs on 'Verifying / download to: Temporary Folder', you can close that window but the rest become unresponsive. It practically locks the computer up you can't end the iexplore.exe process and the computer then fails to shutdown, have to cold reboot. Only started this morning, was fine yesterday so I'm guessing it's a definition issue. 

    If I run "iexplore -extoff" I can download the file fine.

    If I run iexplore as normal and disable the Symantec Vulnerability Protection BHO and Browser Intrusion / Network Threat Protection, it still crashes when downloading these TXT files (and randomly doing other things)

    If I uninstall SEP12.1.5 everything works fine again. As I said earlier, I think this is a definition issue as SEP12.1.5 was installed 14 days ago and they do this process several times a day, only started this morning.



  • 3.  RE: Browser Intrusion Prevention is malfunctioning

    Posted Oct 24, 2014 06:26 AM

    we are too having this issue after the last definition update its driving our clients mad!



  • 4.  RE: Browser Intrusion Prevention is malfunctioning

    Posted Oct 24, 2014 06:39 AM

    We are also having this issue on many of our machines when trying to launch IE, since a definition update thismorning.  It is affecting Windows 7 and Windows 8 machines running IE9 and IE11 (and presumably others too)

    Is this being looked at?



  • 5.  RE: Browser Intrusion Prevention is malfunctioning

    Posted Oct 24, 2014 06:39 AM

    Anyone opened a case with support? This needs to be looked at ASAP.



  • 6.  RE: Browser Intrusion Prevention is malfunctioning

    Posted Oct 24, 2014 06:41 AM

    I haven't, anyone else?



  • 7.  RE: Browser Intrusion Prevention is malfunctioning
    Best Answer

    Posted Oct 24, 2014 06:41 AM

    ive opened a case and had this back it looks like a fix they recomended previously now breaks stuff and needes reversing!

     

    Was a GPO has previously been created to suppress the message "The Symantec Intrusion Prevention add-on from Symantec Corporation is ready for use" in your environment.

    Due to changes in the way CIDS works, it's no longer recommended to implement such GPO.

     

    http://www.symantec.com/business/support/index?page=content&id=TECH224237

     

     



  • 8.  RE: Browser Intrusion Prevention is malfunctioning

    Posted Oct 24, 2014 06:42 AM

    I think I found the problem.

    http://www.symantec.com/business/support/index?page=content&id=TECH164924

    "

    Due to a change in how this protection works in CIDS version 14.0 and above, it is no longer recommended to implement a GPO as described below. Leaving such a GPO in place will result in pop-up messages indicating "Browser Intrusion Prevention is malfunctioning. Check the System logs for details."

    Symantec Technical Support recommends removing such a GPO if one has been created.

    "



  • 9.  RE: Browser Intrusion Prevention is malfunctioning

    Posted Oct 24, 2014 06:45 AM

    Anyone opening a case to confirm?



  • 10.  RE: Browser Intrusion Prevention is malfunctioning

    Posted Oct 24, 2014 07:03 AM

    We're not using any GPO for IE Add-on Management so it's not the issue in our environments.



  • 11.  RE: Browser Intrusion Prevention is malfunctioning

    Posted Oct 24, 2014 07:06 AM

    Can confirm that the removal of the previous fix in the above URL worked for us:

    Remove CLSID {6D53EC84-6AAE-4787-AEEE-F4628F01010C}=1 from User Configuration/Policies/Administrative Templates/Windows Components/Internet Explorer/Security Features/Add-on Management



  • 12.  RE: Browser Intrusion Prevention is malfunctioning

    Posted Oct 24, 2014 07:25 AM

    PaulHod above



  • 13.  RE: Browser Intrusion Prevention is malfunctioning

    Posted Oct 24, 2014 09:53 AM

    I can confirm that we do NOT have this GPO policy set Remove CLSID {6D53EC84-6AAE-4787-AEEE-F4628F01010C}=1 from User Configuration/Policies/Administrative Templates/Windows Components/Internet Explorer/Security Features/Add-on Management

    Received this message on Windows 7 using the CIDS definitions - 10/23/2014 R12. 

    So I'm thinking Symantec might have had an Oops. 



  • 14.  RE: Browser Intrusion Prevention is malfunctioning

    Posted Oct 24, 2014 10:33 AM

    I got this message also on many clients. Window 7 SP1 IE9

     



  • 15.  RE: Browser Intrusion Prevention is malfunctioning

    Posted Oct 24, 2014 10:38 AM

    I opened a case with Symantec and they confirmed their definitions for Oct 24th 2014 caused this issue with a flash player. They are working on releasing a definition update and that should resolve the issue. Your only options are disabling it on the endpoint or dealing with it until they get the definitions updated.



  • 16.  RE: Browser Intrusion Prevention is malfunctioning

    Posted Oct 24, 2014 10:54 AM

    The solution on this thread suggests it's GPO related.

    So...which is it...defs or GPO?



  • 17.  RE: Browser Intrusion Prevention is malfunctioning

    Posted Oct 24, 2014 11:13 AM

    I'm hoping that it's the definitions because we don't have that GPO enabled in our environment at all.

    I've also got a case opened but, have yet to hear from support.



  • 18.  RE: Browser Intrusion Prevention is malfunctioning

    Posted Oct 24, 2014 11:20 AM

    The GPO update mentioned previously resolved the issue for us.



  • 19.  RE: Browser Intrusion Prevention is malfunctioning

    Posted Oct 24, 2014 11:27 AM

    Disabling this GPO is wrong. The GPO force the enabling of the Symantec Vulnerability Protection in IE.



  • 20.  RE: Browser Intrusion Prevention is malfunctioning

    Broadcom Employee
    Posted Oct 24, 2014 11:32 AM

    Hi,

    Similar issues have been reported to the Symantec support & team is working on it.

    Please create a support case.

    Please gather a full memory dump along with the Symhelp report prior to call support.

    Time being follow this workaround:

    How to Backdate Virus Definitions in Symantec Endpoint Protection Manager

    http://www.symantec.com/docs/TECH102935



  • 21.  RE: Browser Intrusion Prevention is malfunctioning

    Broadcom Employee
    Posted Oct 24, 2014 11:33 AM

    Could you share the support case number?



  • 22.  RE: Browser Intrusion Prevention is malfunctioning

    Posted Oct 24, 2014 12:02 PM

    Hi Chetan my case number was

    Case Number 07536951

     

    removing the gpo settings fixed it for all of my clients



  • 23.  RE: Browser Intrusion Prevention is malfunctioning

    Broadcom Employee
    Posted Oct 24, 2014 12:04 PM

    Thanks for the udpate.



  • 24.  RE: Browser Intrusion Prevention is malfunctioning

    Posted Oct 24, 2014 12:06 PM

    Ray07 the GPO is no longer needed as the addon is no longer used please read the following

    Issue

     
     

    An updated Client Intrusion Detection System engine is being released in October 2014. This engine is available to users of Symantec Endpoint Protection 12.1 (SEP 12.1) and above.

    http://www.symantec.com/business/support/index?page=content&id=TECH224237

    Cause

     
     

    You would like additional information on this release.

     

     

    Solution

     
     
    Client Intrusion Detection System (CIDS) v14.1 will be released as a staged release for Enterprise customers.  SEP clients will upgrade this feature via LiveUpdate.
     
    For more information about Staged Releases please see the following document: About Endpoint Protection staged content rollouts
     
    This release provides a new generation Browser Protection engine. Please be aware that this engine removes the need for Browser Helper Objects (BHO), browser plugins or add ons.  No functionality will be lost due to this change.  It simply gives customers browser independent protection and allows Symantec Endpoint Protection to tackle even more complex threats.
     
    It is normal for Internet Explorer users to no longer see the BHO and similarly, Firefox users will not see the add-on installed in their browsers.  
     
    If a GPO has previously been created to suppress the message "The Symantec Intrusion Prevention add-on from Symantec Corporation is ready for use," the policy setting must be removed now to avoid cosmetic error messages reading "Browser Intrusion Prevention is malfunctioning. Check the System logs for details." See the article Internet Explorer 9 displays a pop-up stating "The Symantec Intrusion Prevention add-on from Symantec Corporation is ready for use" for more details.
     
    Because this is a staged rollout, customers may see the change at different times.  This is a positive change, no functionality is being removed; this change improves Symantec Endpoint Protection’s protection capabilities.


  • 25.  RE: Browser Intrusion Prevention is malfunctioning

    Posted Oct 24, 2014 12:44 PM

    GPO is also not the cause here.  No message with virus definitions 10/24 rev 17, experience issue with virus definitions 10/24 rev 25.



  • 26.  RE: Browser Intrusion Prevention is malfunctioning

    Posted Oct 24, 2014 01:16 PM

    I followed the post that discussed the CIDS changes, New Features in Client Intrusion Detection System (CIDS) 14.1 (http://www.symantec.com/docs/TECH224237), very closely since it was posted on 8/29/14. It concerned me because of the nature of its release (via LiveUpdate opposed to in a SEP client upgrade) and the possibility users would receive prompts from IE or IE simply would not work. I noticed its release was postponed several times as it originally was due to be released in September.

    That being said, we never set a GPO to control the browser prompts to begin with. I know Symantec recommended this if you received prompts with how the now older BHO worked. We have over 13K total SEP clients and many are not receiving the error (yet). I am using the monitor in SEPM -> Client Activity -> with Advanced settings of event source: Network Intrusion Protection Sys   and   severity: Warning and above. Out of our 13K clients, I have 145 currently reporting the error. I have only fixed two at this point, but I have fixed them with a simple reboot. Has anyone else tried this?

    Here is something I noticed...

    On a working machine, in IE, the Symantec Vulnerability Protection add-on is DISABLED (I expected it to be removed based on CIDS post above, but disabled will work for now.)

    On a machine reporting the error, in IE, the Symantec Vulnerability Protection add-on is ENABLED. After I reboot the machine, it disables this add-on and resolves the error.



  • 27.  RE: Browser Intrusion Prevention is malfunctioning

    Posted Oct 24, 2014 03:24 PM

    If this helps, I have over 4500 clients and only 178 reporting issue.  Rebooting and upgrading to v12.1.4100 did not resolve issue here.  Client running virus definitions October 23, 2014 rev17 no error, but virus definitions October 23, 2014 rev 25 do have the issue.



  • 28.  RE: Browser Intrusion Prevention is malfunctioning

    Posted Oct 24, 2014 03:33 PM

    Wattsdown!  Thanks!

    It's the add-on, it was ENABLED.  We DISABLED it and no error!  Will await additional information from Symantec, but this workaround will help ease our users.

     

    Thanks again for providing the information to the post!

     



  • 29.  RE: Browser Intrusion Prevention is malfunctioning

    Posted Oct 24, 2014 03:43 PM

    Excellent EIG-AV!

    I was suprised when the add-on was still available/installed in IE. The CIDS tech article mentioned it would be removed, so I'm confused why it is still there. Yes, we will wait for further info from Symantec on this one, but it seems we are onto something.
     



  • 30.  RE: Browser Intrusion Prevention is malfunctioning

    Posted Oct 24, 2014 04:21 PM

    They are rolling it back. Symantec just released this...

    Internet Explorer hang or machine freeze after CIDS update 10/23/2014 r12

    http://www.symantec.com/business/support/index?page=content&id=TECH225736&actp=SUBSCRIPTION



  • 31.  RE: Browser Intrusion Prevention is malfunctioning

    Posted Oct 24, 2014 05:38 PM

    CASE#07540125 - no GPOs for us, just stopped browsing this morning.  Symantec has no answers yet, but my company is lovin' it!  All we do is browser-based and over 1000 people spent a non productive day.

     

    J