This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

iTunes installer being blocked on Endpoints - Windows 7 clients

The iTunes installer (iTunes_Setup.exe) is being blocked as a potential PUA on my endpoints (version 10.3). 

I've add iTunes_Setup.exe in as a file exclusion in SEC (5.2.2), but it isn't working and it is still picked up.

Is there another way I can exlude this file from being blocked?

:55325


This thread was automatically locked due to age.
Parents
  • Hello IAMU,

    first of all, please always state the name of the detection

    I've add iTunes_Setup.exe in as a file exclusion

    if you exclude the file from On-Access scanning - note that this is rather ominous, (fake) installers for popular applications make expedient hosts for malware - it should not trigger a PUA detection.  

    Is there another way I can exclude this file from being blocked?

    There is - instead of excluding it from scanning you can authorize (button Authorization, tab Adware and PUAs in the AV policy) a specific PUA (this way it will still be scanned for malware). You should do so only for named, i.e. non-Generic detections. If it's a Generic PUA it's a good idea to send a sample - if it's a false positive the detection will be amended (which also helps other users), otherwise a named detection might be added, or - there's indeed some "additional functionality" in the package which shouldn't be there.

    Christian

    :55337
Reply
  • Hello IAMU,

    first of all, please always state the name of the detection

    I've add iTunes_Setup.exe in as a file exclusion

    if you exclude the file from On-Access scanning - note that this is rather ominous, (fake) installers for popular applications make expedient hosts for malware - it should not trigger a PUA detection.  

    Is there another way I can exclude this file from being blocked?

    There is - instead of excluding it from scanning you can authorize (button Authorization, tab Adware and PUAs in the AV policy) a specific PUA (this way it will still be scanned for malware). You should do so only for named, i.e. non-Generic detections. If it's a Generic PUA it's a good idea to send a sample - if it's a false positive the detection will be amended (which also helps other users), otherwise a named detection might be added, or - there's indeed some "additional functionality" in the package which shouldn't be there.

    Christian

    :55337
Children
No Data