You can use App Rules to prevent risky or forbidden file types (for example, exe, vbs, scr, dll, avi, mov) from being uploaded or downloaded.
To prevent risky or forbidden file types from being uploaded or downloaded
Create an object like this one:
Navigate to OBJECT | Action Objects > App Rule Actions.
Click +Add.
Create an action like this one.
To create a policy that uses this object and action
Create a policy like this one:
To test this policy, you can open a Web browser and try to download any of the file types specified in the match object (exe, vbs, scr). Here are a few URLs that you can try:
http://download.skype.com/SkypeSetup.exe
http://us.dl1.yimg.com/download.yahoo.com/dl/msgr8/us/msgr8us.exe
http://g.msn.com/8reen_us/EN/INSTALL_MSN_MESSENGER_DL.EXE
You will see an alert similar to this one: