This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Windows 8 server beta msiexec.exe suspicious?

Hello,

I tried to be very safe with my Server  beta installation, clean drive, installing SumatraPDF and  immediately Sophos Endpoint Security and Control 9.5 (sadly my Sophos credentials where in a PDF), and then proceeding to a few reputable standards like Chrome, AMD's driver. Little after starting the Visual Studio 11 beta "online" installation, I got repeated suspicious behaviour HIPS/FileWriteMod-003 from C:\Windows\SYSWOW64\msiexec.exe , which apparently even ended up in my quarantine, even though my VS installation proceeded normally but failed at the very end. A file msiexec.exe with md5 84996dc545774c3703de5c97ddae2a24 is there anyway, so maybe the Visual Studio installer replaced itself?

Thanks!

:25335


This thread was automatically locked due to age.
Parents
  • Right, thanks, I just saw that Sophos can be ignored during installations! It is my first day using Sophos and cant remember any other product I ever used being triggered my MS installers. Now, it would be wonderful reporting to the labs straight from the quarantine, with a right click let's say, any other "upload" logically will have to take place outside the quarantine or even with Sophos disabled, with the obvious security risks, right? Though it does look like the Sophos quarantine is different, in other products files are repackaged in the quarantine, here it just means access denied?

    '

    :25341
Reply
  • Right, thanks, I just saw that Sophos can be ignored during installations! It is my first day using Sophos and cant remember any other product I ever used being triggered my MS installers. Now, it would be wonderful reporting to the labs straight from the quarantine, with a right click let's say, any other "upload" logically will have to take place outside the quarantine or even with Sophos disabled, with the obvious security risks, right? Though it does look like the Sophos quarantine is different, in other products files are repackaged in the quarantine, here it just means access denied?

    '

    :25341
Children
No Data