Jump to content


  • 0
slice16

Sophos AV blocking Network Applications after install

Question

Afternoon All,

 

I thought I would post this question on here, as after 2 hours on the Phone to Sophos, they don't have an idea as to the issue. I was hoping someone had deployed the SCCM client to machines that are running the Sophos endpoint AV and firewall locally.

 

Here is the issue:

 

After installing the SCCM 2007 R3 client to a small number of XP and Windows 7 machines, all network based programs get blocked by the Sophos firewall. If we turn off all rules, everything starts working again.

 

The applications being blocked are:

 

nslookup.exe

rundll32.exe

wmiprvse.ece

werfault.exe

iexplore.exe

grpwise.exe

almon.exe

justched.exe

 

All are marked with an event type of 'Modified Memory' and show the launching application as wmrprvse.exe.

 

We have tried added these alerts to the firewall rules as trusted to no avail. Once we remove the client, all is fine.

 

Any ideas?

 

Thanks,

 

Paul

Share this post


Link to post
Share on other sites

1 answer to this question

Recommended Posts

  • 0

After some research, it looks like Sophos doesn't give an option to add exclusions for the relevant applications. There appears to be 2 solutions:

 

1) Turn of the memory security option for all (not the most secure of solutions :( )

2) Recreate the Firewall policy by running the Install in interactive mode on another machine. Once everything has been captured, export the policy and import into the Control Panel.

Share this post


Link to post
Share on other sites

Join the conversation

You can post now and register later. If you have an account, sign in now to post with your account.

Guest
Answer this question...

×   Pasted as rich text.   Paste as plain text instead

  Only 75 emoji are allowed.

×   Your link has been automatically embedded.   Display as a link instead

×   Your previous content has been restored.   Clear editor

×   You cannot paste images directly. Upload or insert images from URL.

Loading...


×
×
  • Create New...

Important Information

We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue.