To work around this problem, Create an Application and Device Control policy that blocks the specific DLLs that write to CD or DVD drives.
- Log into the Symantec Endpoint Protection Manager (SEPM).
- Click on Policies.
- Select Application and Device Control.
- Click Add an Application and Device Control policy.
- Type in a context-relevant Policy name, e.g. "Block CD-DVD burning on Windows 7".
- Click on Application Control in left-hand pane. In the right-hand pane under "Application Control Rule Sets" click Add.
- Click on the Add button at bottom of Rules and from popup menu select Add Condition and File and Folder Access Attempts.
- Click Properties.
- Type a context-relevant Name for this condition, e.g. "Block accesses to IMAPIv2 DLLs".
- To right of Apply to the following files and folders click Add.
- Add the following filepaths for File or Folder Name to Match, clicking OK after each and repeating Add in previous step.
%SystemRoot%\SysWOW64\imapi2.dll
%SystemRoot%\SysWOW64\imapi.dll
%SystemRoot%\SysWOW64\imapi2fs.dll
%SystemRoot%\System32\imapi2.dll
%SystemRoot%\System32\imapi.dll
%SystemRoot%\System32\imapi2fs.dll
- Click on the Actions tab and select Block Access in both of the "Read Attempt" and "Create, Delete, or Write Attempt" sections.
- Click on the Add button at bottom of Rules and from popup menu select Add Condition and File and Folder Access Attempts.
- Click Properties.
- Type a context-relevant Name for this condition, e.g. "Block all but read attempts on CD-DVD drive".
- To right of Apply to the following files and folders click Add.
- Add a single asterisk ( * ) for File or Folder Name to Match.
- Check Only match files on the following drive types.
- Check only the CD/DVD drive checkbox.
- Click on OK.
- Click on the Actions tab, select Continue processing other rules for "Read Attempt" section, and select Block Access and check Enable logging in the "Create, Delete, or Write Attempt"section.
- Click on OK.
- Click on the Add button at bottom of Rules and from popup menu select Add Condition and Launch process Attempts.
- Click Properties.
- Type a context-relevant Name for this condition, e.g. "Block ISO burning"
- Check Enable this condition.
- To right of Apply to the following processes click Add.
- Add the following Process name to match:
isoburn.exe
- Click OK.
- Click on the Actions tab and select Block Access.
- Check Enable logging.
- Click on OK.
- Save the policy and assign it to any desired groups.
If you check Enable logging, processing that is blocked or permitted is recorded in the control log of the SEP client.
When you burn a disk from a disk image (including burning by using Mastered format of Windows OS), the drive name is recorded as the file name written in the control log.