This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Windows 8 server beta msiexec.exe suspicious?

Hello,

I tried to be very safe with my Server  beta installation, clean drive, installing SumatraPDF and  immediately Sophos Endpoint Security and Control 9.5 (sadly my Sophos credentials where in a PDF), and then proceeding to a few reputable standards like Chrome, AMD's driver. Little after starting the Visual Studio 11 beta "online" installation, I got repeated suspicious behaviour HIPS/FileWriteMod-003 from C:\Windows\SYSWOW64\msiexec.exe , which apparently even ended up in my quarantine, even though my VS installation proceeded normally but failed at the very end. A file msiexec.exe with md5 84996dc545774c3703de5c97ddae2a24 is there anyway, so maybe the Visual Studio installer replaced itself?

Thanks!

:25335


This thread was automatically locked due to age.
Parents
  • Hello sokratis,

    you are more or less correct, quarantine is "just" a list of threats/files which need to be dealt with (but you might also simply ignore them).
    The "send as sample" suggestion has already been raised in the early days of this forum :-) - guess it's a trade-off: convenient vs. indiscriminate submission. Apart from that - who should be authorized to send the sample? There are also some technical challenges. But it might come.

    Christian
    :25345
Reply
  • Hello sokratis,

    you are more or less correct, quarantine is "just" a list of threats/files which need to be dealt with (but you might also simply ignore them).
    The "send as sample" suggestion has already been raised in the early days of this forum :-) - guess it's a trade-off: convenient vs. indiscriminate submission. Apart from that - who should be authorized to send the sample? There are also some technical challenges. But it might come.

    Christian
    :25345
Children
No Data