При входе в систему и в процесе применения Group Policy я получаю в логах VirusScan записи подобные этим:
Would be blocked by Access Protection rule (rule is currently not enforced) NT AUTHORITY\SYSTEM C:\WINDOWS\System32\svchost.exe \REGISTRY\MACHINE\SYSTEM\ControlSet001\Services\NWCWorkstation\Parameters\ServiceLogon\000000000009b349 Common Maximum Protection:Prevent programs registering as a service Action blocked : Create
Would be blocked by Access Protection rule (rule is currently not enforced) MyDomain\MyUserName C:\WINDOWS\system32\svchost.exe \REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ProxyServer Common Standard Protection:Protect Internet Explorer settings Action blocked : Write
Правильно ли будет добавить svchost.exe в Processes to exclude в правилах
Common Standard Protection:Protect Internet Explorer settings и
Common Maximum Protection:Prevent programs registering as a service
или нужно действовать по другому?
Можно ли разрешить svchost.exe изменять только определенные ключи в реестре?
Would be blocked by Access Protection rule (rule is currently not enforced) NT AUTHORITY\SYSTEM C:\WINDOWS\System32\svchost.exe \REGISTRY\MACHINE\SYSTEM\ControlSet001\Services\NWCWorkstation\Parameters\ServiceLogon\000000000009b349 Common Maximum Protection:Prevent programs registering as a service Action blocked : Create
Would be blocked by Access Protection rule (rule is currently not enforced) MyDomain\MyUserName C:\WINDOWS\system32\svchost.exe \REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ProxyServer Common Standard Protection:Protect Internet Explorer settings Action blocked : Write
Правильно ли будет добавить svchost.exe в Processes to exclude в правилах
Common Standard Protection:Protect Internet Explorer settings и
Common Maximum Protection:Prevent programs registering as a service
или нужно действовать по другому?
Можно ли разрешить svchost.exe изменять только определенные ключи в реестре?