5/20/2013 1:37:55 PM Would be blocked by Access Protection rule (rule is currently not enforced) user-pc C:\Program Files (x86)\Skype\Phone\Skype.exe \REGISTRY\USER\S-1-5-21-448539723-746137067-1343024091-24813\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\AutoDetect Anti-spyware Standard Protection:Protect Internet Explorer favorites and settings Action blocked : Create
The .exe path varies across several applications, but very often it points to "C:\Windows\CCM\UpdateTrustedSites.exe"
And the register entrie are always the ones under "Internet Settings\Zones" or "Internet Settings\ZoneMap".
Re: Anti-spyware Standard Protection:Protect Internet Explorer favorites and settings
you may have a particular Virusscan Access Protection rule (the one whose name you see in the log excerpt) configured to notify only when the rule condition triggers.
In my opinion this is an important rule to be enabled fully (i.e. add blocking, too), here is why:
Protect Internet Explorer favorites and settings”
Intention: This rule is designed to prevent modification of Microsoft Internet Explorer configurations and files by any process not listed in the rule’s exclusion list. A common tactic of malware is to change the browser’s start page, and install favorites. This rule protects against certain start page Trojans, adware, and spyware that modify browser settings.
Risks: There really aren’t any drawbacks to enabling this rule, as it simply blocks processes from making changes to favorites and settings in Microsoft Internet Explorer.
In addition I recommend reviewing other Access Protection rules and jot down which does have only one action enabled and consider that rule to have both action enabled or turn off all actions of that rule altogether.
Don't forget, when your helpful posts earn a kudos or get accepted as a solution you can unlock perks and badges. Those aren't the only badges, either. How many can you collect? Click here to learn more.
Community Help Hub
New to the forums or need help finding your way around the forums? There's a whole hub of community resources to help you.