Hello PaulCab,
Yes, You can block the .DLL's that are used for BHO's in browsers using the Application and Device Control in SEP 12.x
Here are the steps:
How to block BHO’s using Application and Device Control
- Log into Symantec Endpoint Protection Manager console
- Navigate to your Application and Device control policy. (Log only as a test)( Production will test for block)
- In application control, add a rule set. "Block BHOs"
- Make it apply to all processes using the * in the upper dialog
- Under Rules click to Add and choose Add Condition
- Choose Registry Access Attempts
- Under Apply to the following registry keys click Add
- In Registry key add HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\*
- Click OK
- In the Actions tab
- Set Read Attempt to "Continue processing other rules"
- Set Create, Delete, or Write Attempt to "Block access"
- Click the boxes for Enable Logging
- Click OK
Check these Articles:
How to create a rule that will block or log Browser Helper Objects in Symantec Endpoint Protection
https://support.symantec.com/en_US/article.TECH94965.html
Hardening Symantec Endpoint Protection (SEP) with an Application and Device Control Policy to increase security
https://support.symantec.com/en_US/article.TECH132337.html
How the Application and Device Control Hardening policy works
https://support.symantec.com/en_US/article.TECH132307.html
Regards,