Home > Symantec Endpoint > Symantech Antivirus Autorun Problem

Symantech Antivirus Autorun Problem

Contents

Supported Products A-Z Get support for your product, with downloads, knowledge base articles, documentation, and more. http://support.microsoft.com/kb/971029 Disable AutoPlay in your environment using a Group Policy Object (GPO) Follow the instructions in the following Microsoft TechNet Security Watch article; under Managing AutoPlay in Your Network. Submit a False Positive Report a suspected erroneous detection (false positive).

Information for: Enterprise Small Business Consumer (Norton) Partners Our Offerings: Products Products A-Z Services Solutions Connect with us: Support You want to stop the threat from spreading. Source

Click the Application Control tab. For more information, read the following article: "Preventing a virus from using the AutoRun feature to spread itself" at: http://www.symantec.com/docs/TECH104447 Technical Information For Option 2 the DWORD value of 24 in Supported Products A-Z Get support for your product, with downloads, knowledge base articles, documentation, and more. Select Application and Device Control. more info here

Allow Autorun.inf Symantec Endpoint

Under Computer Configuration, expand Administrative Templates, expand Windows Components, and then click Autoplay Policies. Be sure to modify the specified keys only. To permanently prevent threats from using the AutoRun feature the following options are available: Install a Windows hotfix to disable AutoRun on USB drives This hotfix leaves AutoRun working only with Preventing a virus from using the AutoRun feature to spread itself http://www.symantec.com/docs/TECH104447 Preventing viruses using "autorun.inf" from spreading with "Application and Device Control" policies in Symantec Endpoint Protection (SEP) 11.x http://www.symantec.com/docs/TECH104909

Information for: Enterprise Small Business Consumer (Norton) Partners Our Offerings: Products Products A-Z Services Solutions Connect with us: Support
  • Close Login Didn't find the article you were looking for?
  • Create a SymAccount now!' The default Application Control rule to block Autorun triggers when a USB drive with no autorun.inf is connected TECH162983 June 30th, 2011 http://www.symantec.com/docs/TECH162983 Support / The default Whenever a USB drive is inserted or other computers connect to the network a file called "autorun.inf" appears at the root of the new drive and the installed antivirus product detects Login or Register to post your comment. Disable Adc Symantec Cause When a USB drive is connected, Windows will attempt to open autorun.inf although it may not exist.

    Solution Note: To check if the computer in question is configured according to this best practice, download and run a 'scan for common issues' in SymHelp. How To Unblock Autorun In Symantec http://support.microsoft.com/kb/967715/ Use a Symantec Endpoint Protection Application and Device Control policy Protection features within the Symantec Endpoint Protection product can be used to block the AutoRun functionality. Under Computer Configuration, expand Administrative Templates, expand Windows Components, and then click Autoplay Policies. https://www.symantec.com/connect/forums/autoruninf-application-and-device-control-problem I have tried : 1)Scanning the pendrive in safe mode. 2)I have scanned the system in safe mode. 3)I have run the symantec support tool to scan if any problem But

    The result is that my hard drive is a healthy carrier of an autorun.inf threat... Application And Device Control Rule Autorun Inf Read File Has Blocked Symantec Connect Security > Ideas Entire Site Search Tips Home Community:Security Ideas Overview Forums Articles Blogs Downloads Events Groups Ideas Videos RSS Login or Register to participate English English 简体中文 Français Select Block access to Autorun.inf [AC9] from the Application Control Rule Sets, then click Edit. Cause Windows uses the autorun.inf file to: Identify which file to run when new media is inserted, or Identify which options to present in an AutoPlay dialog Viruses and other

    How To Unblock Autorun In Symantec

    Translated Content This is machine translated content Login to Subscribe Please login to set up your subscription. Select the applied policy in the Application and Device Control Policies pane Click Edit the policy in the Tasks pane. Allow Autorun.inf Symantec Endpoint Close Login Didn't find the article you were looking for? Autorun Has Been Blocked Check The Control Log Thanks In Advance Ashish Sharma +1 Login to vote ActionsLogin or register to post comments Mick2009 Symantec Employee Autorun.inf problem - Comment:20 Sep 2012 : Link You may wish to cast

    Solution Option 1: Warning: This policy file is provided as a convenience tool and is not supported by Symantec. this contact form Thank you for your feedback! Translated Content This is machine translated content Login to Subscribe Please login to set up your subscription. Submit a Threat Submit a suspected infected fileto Symantec. Cannot Copy Autorun.inf Access Denied Symantec

    Collapse this imageExpand this image If you are prompted for an administrator password or for confirmation, type the password, or click Allow. Education Services Maximize your product competency and validate technical knowledge to gain the most benefit from your IT investments. Uncheck Notify user from the Read Attempt pane. http://placedroid.com/symantec-endpoint/symantec-antivirus.html Click Import.

    Provide feedback on this article Request Assistance Print Article Products Subscribe to this Article Manage your Subscriptions Search Again Situation It appears that a virus is using the AutoRun feature in Symantec Endpoint Protection Manager Console Click Enabled, and then select All drives in the Turn off Autoplay box to disable Autorun on all drives. You can create an "Application and Device Control" policy to block this type of vectors of infection.

    Cause The threat that is attacking your system is using the "Windows AutoRun" feature to spread in your environment.

    Applies ToWindows 7 References 2348091 Terms of use for this information are found in Legal Notices. Apply the new imported policy to your clients. No Yes logo-symantec-dark-source Loading Your Community Experience Symantec Connect You will need to enable Javascript in your browser to access this site. © 2017 logo-symantec-dark-source Loading Your Community Experience Symantec Connect Autorun.inf Virus If I scan the pendrive with another antivirus ,that antivirus immediately detect a TROJAN on autorun.inf and cleans the virus.

    Try these resources. Computers connected to the network drives continually receive threat detection dialogs. You can disable the AutoRun/AutoPlay feature in Windows using the following registry settings: [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer] "NoDriveTypeAutoRun"=dword:00000024 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Cdrom] "Autorun"=dword:00000000 The registry change can be pushed out to agents using a Custom Host Integrity Check This Out Method 2 Click Start Collapse this imageExpand this image , type Gpedit.msc in the Start Search box, and then press ENTER.

    Thank you for your feedback! Click Import an Application and Device Control policy. It is simply a text file. Select [ACP-1.1] Autorun.inf from the Rules.

    In the Details pane, double-click Default Behavior for AutoRun. Restart the computer. 0 Login to vote ActionsLogin or register to post comments Jaycee Autorun.inf problem - Comment:22 Feb 2013 : Link I have an unmanaged SEP 12.1.1101.401 client and it http://technet.microsoft.com/en-us/magazine/cc137730.aspx Disable the AutoRun functionality using the registry This Microsoft KB article explains how to disable AutoRun using the NoDriveTypeAutoRun registry key. In the "Import Policy" dialog box, browse to locate the ".dat" file that you have downloaded.

    Try these resources.