When a Threat Defense for Active Directory policy is applied in a Symantec Endpoint Security (SES) environment, certain applications may fail to launch. A few examples of errors are below:
When a Symantec Endpoint Detection and Response (EDR) policy is also applied:
Unhandled exception has occurred in <application name>. If you click Continue, the application will ignore this error and attempt to continue. If you click abort, the application will close immediately.
Could not load file or assembly 'DotNetHookDllCs, Version=1.0.0.1, Culture=neutral, PublicKeyToken=xxxxxxxxxxxxxxxx' or one of its dependencies. Could not find or load a specific file. (Exception from HRESULT:0x80131621)
Without an EDR policy applied you may still notice error messages that reference:
SETDAD DotNetHookDllCs.dll
This is caused by a know limitation prior to 14.3 RU9 in how we handled certain applications.
Possible solutions to this issue are as follows:
Upgrade any the SES agent on any device where this error is present to 14.3 RU9 or later. If that does not resolve the issue, follow one or both of the next items below.
Screenshot showing the Process Exception and Enable Legacy .NET Obfuscation sections of a TDAD policy.