Endpoint Protection

Expand all | Collapse all

Blocks autorun.inf

  • 1.  Blocks autorun.inf

    Posted 22 days ago
    Im managing endpoint security in SEP Cloud (https://sep.securitycloud.symantec.com/) and seems autorun.inf is blocked by following message "The process explorer.exe was blocked from modifying D:\autorun.inf"
    It refers to rule "Autorun.inf_Read File" which is in Device Control policy. However, only option is to allow certain devices, not exactly modifying autorun rule.
    Any suggestions / best practices how to avoid it?



  • 2.  RE: Blocks autorun.inf

    Posted 22 days ago
    I believe this is in the Application Control rules, not Device Control. Have you checked there?

    ------------------------------
    John Owens
    Principal Product Support
    Symantec
    United States
    ------------------------------



  • 3.  RE: Blocks autorun.inf

    Posted 22 days ago
    Hi,
    There is no such policy as Application control




  • 4.  RE: Blocks autorun.inf

    Posted 22 days ago
    SES may have this as a built in rule that cannot be edited.  May want to open a support case to get confirmation on that.

    ------------------------------
    John Owens
    Principal Product Support
    Symantec
    United States
    ------------------------------



  • 5.  RE: Blocks autorun.inf

    Posted 21 days ago
    Hi!

    Thanks for advise. Can you share link where support case can be created?


  • 6.  RE: Blocks autorun.inf

    Posted 21 days ago
    https://support.broadcom.com/

    ------------------------------
    John Owens
    Principal Product Support
    Symantec
    United States
    ------------------------------