CSA prevents Sophos V7 from installing

Hi,
We run CSA v4.5.1 on all our servers and desktops. We also run Sophos Anti-virus agent. Recently we upgraded to the latest version of Sophos (7.0.4) but noticed that it wasn't installing correctly. Further investigation confirmed that CSA was preventing Sophos from accessing a registry key called appinit_dlls. Sophos technical support confirmed this was necessary for the application to install correctly.
The CSA logs report nothing (even with the Log Deny overrride option), so we can't step through a wizard as we normally do when CSA prevents a legitimate application from behaving correctly. Also, putting the agent group into test mode has no effect either. What does work is manually disabling the CSA service while in Windows Safe Mode, restarting the PC, applying the Sophos application update, and then turning the CSA service back on again. Sophos is then able to carry out its ide file updates ok. Its just the initial update of the actual application that it runs into trouble with.
I have nearly 700 PC's I would have to apply this workaround to, so I'd appreciate if anyone had come across a more easily applied fix than this one.

TAC finally got back to me with something more concrete, here it is as an FYI.
Hopefully they will work with Sophos to resolve this issue permanently going forward.
Thanks for all of the thoughts and ideas!
This AppInit_DLLs entry is an important piece of CSA as it provides a hook into all applications as they load. The csauser.dll is loaded when an application runs, and provides, in our dll, buffer overflow protection and COM+ Component checks. What is happening is that Sophos apparently wants to hook the same way, however, we will not allow changes to the AppInit_DLLs string. And this protection is done by the agent w/o any true rules on the MC, which is why there is not a log.
Based upon the information I have there are two options. And only two options, both of which require specific coordination between the Sophos Rollout and CSA. I am checking with development for another option, but the two options are.
1) Testmode.
2) Stop the agent or turn the security level to Off then install.
Major bummer since it affects all point releases as well!! :(

Similar Messages

  • How can I prevent staff members from installing find my iPhone on their company iPhones?

    Hello,
    Staff members that are issued with company iPhones are syncing their personal Apple IDs to the phone and installing the find my phone app. When they then leave and the phone is wiped so that it can be set up for the next user, after the set up the phone is showing as locked to their Apple ID.
    Obviously if we get the phone handed to us personally we can unlock it and disable the app before wiping the phone but that's not always possible.
    Is there an app or a way of preventing users from installing the find my iPhone app?
    Cheers,
    Harri

    Did you already ask this question in the iPhone in Business and Education forum? As far as I remember there is an Apple app (Apple Configurator) that let you set up company devices and prevent other users from installing other apps after that.
    Another option would be letting them remove the device from Find my iPhone in order to deactivate the Activation lock feature again:
    Find My iPhone Activation Lock: Removing a device from a previous owner’s account

  • What can prevent NI-DAQ from installing on a computer?

    What can prevent NI-DAQ from installing on a computer? I have been using Labview/NI-DAQ for 7 years and have never had this problem before. The s/w does not appear to be installed on machine but when I run the installation cd it does not install anything.Windows NT is the OS. Labview 6.1 and ni-daq 6.9.2 are the versions.

    duane wrote:
    What can prevent NI-DAQ from installing on a computer? I have been using Labview/NI-DAQ for 7 years and have never had this problem before. The s/w does not appear to be installed on machine but when I run the installation cd it does not install anything.Windows NT is the OS. Labview 6.1 and ni-daq 6.9.2 are the versions.
    I was able to remedy problem by using windows explorer to view ni-daq cd and run the nidaq.msi in the nidaq dir. Going this route caused a user window to appear that allows you to remove all / repair etc. I selected the remove all option which then removed whatever had been installed on previous installation. I then went the usual route of control panel\settings\remove s/w to remove the MAX. I then went back and ran setup.exe in the nidaq cd root dir and everything installed properly. The key was the first step mentioned above. The control panel\settings\remove s/w display did not show ni-daq evidently due to prior improper installation which prevented uninstalling this way. The autorun feature of the ni-daq cd did not deal with the improper installation because it would simply say it successfully installed when it did not install any thing. The original installation that improperly installed the ni-daq was when I installed the labview full development system. Everything else installed correctly at that time except for ni-daq. Who Knows?

  • How can I prevent rogue software from installing itself via Firefox on my system?

    I don't know if this malware is exploiting a hole in Win7 or Firefox or both.
    So bear with me in my description. I am trying to ascertain if there are Win 7 security settings or configuration changes I can make to eliminate this. Or are there Firefox configuration settings I can change to prevent this or both. Did not find any help articles that seemed to address this from the search arguments I thought to use.
    In the last two weeks I have had two different "security product" windows activate on my Win7 Pro system. Somehow they prevented my starting anything else such as task manager. My AV application detected attempt to create outgoing internet connection in both instances. In either case I ceased using my system as soon as the malware Window activated. I was burned by a third party cookie exploit last year. If you clicked anything, you were toast, such as a "do you really want to navigate away from this page?" warnings. Didn't get one of these messages this time with either of these. But in both instances, registry entries were created for this malware and it installed itself in the following directory path, C:\users\{myID}\appdata\local\temp\ as dtjupjnml\lcuatursjmo.exe s well as registry entries under dtjupjnml and lcuatursjmo after searching with the regedit FIND feature. I didn't recall the names from the first instance, but it installed exactly the same way.
    This did not come from an e-mail attachment or link. I don't do those.

    Do a malware check with some malware scan programs.<br />
    You need to scan with all programs because each program detects different malware.<br />
    Make sure that you update each program to get the latest version of the database before doing a scan.<br />
    * http://www.malwarebytes.org/mbam.php - Malwarebytes' Anti-Malware
    * http://www.superantispyware.com/ - SuperAntispyware
    * http://www.microsoft.com/windows/products/winfamily/defender/default.mspx - Windows Defender: Home Page
    * http://www.safer-networking.org/en/index.html - Spybot Search & Destroy
    * http://www.lavasoft.com/products/ad_aware_free.php - Ad-Aware Free
    See also "Spyware on Windows": http://kb.mozillazine.org/Popups_not_blocked and [[Searches are redirected to another site]]

  • CSA prevents remote application from accessing the registry

    Hi all,
    I have recently install CSA 6.01.106 and I am getting the following notification in the event log.
    Audit: The process '<remote application>' (as user PROD01\S60MP6I$) attempted to access the registry key '\REGISTRY\MACHINE' and value ''. The attempted access was an open (operation = OPEN/KEY). The operation would have been denied.
    does anyone know how to create an execption without creating a blanket rule to permit everything?
    Or are you able to provide me with some more tips to assist me with what is going on here?
    many thanks

    You can create a user state that will allow remote connections if it is legitimate.
    It may be trying to read permissions to connect or run an application.
    Tom

  • How do I prevent creative cloud from installing a desktop shortcut?

    I have absolutely no need for a desktop shortcut to cc, since I have it running in the taskbar whenever I start my computer. What's worse is that I have to type in admin username and password to be able to delete these icons from my work computer. It's a pain that this thing that I don't want keeps popping up with every update. My desktop is already cluttered, it doesn't need Adobe's help making it worse.
    Any way to stop Adobe from adding a desktop shortcut to CC?
    Thanks!!

    There is no option to uncheck "Create Desktop Shortcut" as in other installers as far as I know.

  • Is There Any Way Under Heaven to Prevent Kit-Kat from Installing?

    I've already had my phone screwed up enough.  Tonight the stupid Kit-Kat downloaded to my Galaxy S3, and I'm getting those annoying pop-up dialogues asking me when I want to start the install.
    I don't WANT to start the install.  After reading so many problems here, especially the battery charging issues, I don't understand why this update continues to be pushed on those that have not already been stuck with it.
    Please!  ANYONE!  Tell me how to get this out of my phone.  I am looking for new phone, though I shouldn't have to, but it's going to be a couple of months before I can do it.  I'm only one year into a 2-year contract so I'm having to pay out of pocket for the new one.  I've already spent a ton of money on portable power packs, extra batteries, extra chargers.
    These things are money-pits, plain and simple.  And making people tear their hair out.  For Pete's sake, leave us alone!

    bubblemaker  Elector
    Try this...
    Application Manager-All-Google Services Framework-Uncheck Show Notifications
    That at least stopped the annoying popups that just WAIT for you to get through your lock-screen, then jump in before you can hit another app, forcing the install.
    I don't know if this will hold it off forever, but my daughter has been able to avoid the 4.3 update since last December.
    The Android icon will appear in your notification bar, but it will remain quiet.
    EDITED TO UPDATE:  Well, no, it isn't working after all.  All is lost and our phones are doomed.

  • Prevent software update from installing safari

    Am I really going to have to uncheck that box every time there is an itunes update on my windows box? Seriously?

    Thanks very much for your pointer. I somehow missed that menu option.

  • How to lockdown and prevent add-ons from being installed?

    Hi. I'd like to lockdown an installation of Firefox on a Win XP computer, to prevent add-ons from being installed by limited account users. How do I accomplish this please?

    Use a mozilla.cfg file in the Firefox program folder to lock prefs or specify default values.
    Place a file local-settings.js in the defaults\pref folder where you also find the file channel-prefs.js to specify using mozilla.cfg.
    pref("general.config.filename", "mozilla.cfg");
    pref("general.config.obscure_value", 0); // use this to disable the byte-shift
    See:
    * http://kb.mozillazine.org/Locking_preferences
    You can use these functions in mozilla.cfg:
    defaultPref(); // set new default value
    pref(); // set pref, but allow changes in current session
    lockPref(); // lock pref, disallow changes
    lockPref("xpinstall.enabled", false);

  • I am prevented from installing Kodak HERO printer driver?

    I've upgraded to Mountain LION and I am prevented from installing the Kodak HERO software as it is not via the App store! AAAAAAAAARGH!
    Has anyone seen this and, if they have, how did they get this resolved?

    If you have Gatekeeper set to max security (Mac App Store only) only updates through the Mac App Store can be installed.
    If you open System Prefs > Security & Privacy > click the padlock to unlock the pref screen, you can then change the Gatekeeper Prefs on the lower half of the window.

  • Prevent Air from Installing

    Team,
    I have to install various products from Adobe, but I would like to disable or prevent Air from installing during the process. What are some steps to achieve this task? I use SCCM to update my Adobe products.

    Password protect access to your AIR file. :)
    More seriously, there's no AIR specific way to prevent
    someone from stealing and serving your AIR files.
    You'd have to resort to traditional methods like asking for a
    serial before downloading or some form of content
    management.

  • Firefox prevented this site from asking you to install software on this computer? ....... i want to install the software!!!

    i am trying to install a garmin plug in, and this is the message i get as i am redirected, no chance to react to the message, i had to take a screen shot of it .......

    Hello post.crane, put the site URL in Exceptions, at Security panel, see for more information :[https://support.mozilla.org/en-US/kb/unable-install-add-ons-or-extensions#w_firefox-prevented-the-site-from-asking-you-to-install-software Firefox prevented the site from asking you to install software]
    thank you

  • OneNote prevents my computer from going to sleep when I have a shared notebook open. Suggestions?

    Hello,
    The issue is that my computer will not go to sleep if I have OneNote opened with my shared notebook loaded.
    Background: I'm currently running Windows 8 Pro on a desktop machine with Office 2010 Home and Student installed. I log into the OS under my outlook.com internet account.  OneNote, which I always keep open, has my main
    notebook shared on my SkyDrive.
    Scenarios: The computer will go to sleep if I reboot the machine and do not open OneNote. The computer will go to sleep if I close my shared notebook, reboot the machine and open OneNote (with no notebooks open). The computer will go to sleep if I open
    OneNote with my shared notebook, close it, AND exit OneNote from the icon in the system tray.
    The scenarios I ran lead me to believe that OneNote is continuously polling my shared online notebook, thus preventing my computer from going to sleep. The is a regression from the behavior in Windows 7. Are there any configuration changes I can make to
    fix this?
    Thanks.

    Try modify the settings under:
    Control Panel --> Power Options --> Multimedia settings --> When sharing media to Allow the computer to sleep
    Max Meng
    TechNet Community Support
    A new Office has arrived, try it now.
    A beautiful Start. It begins here. Windows 8 and Windows RT.
    Please remember to mark the replies as answers if they help and unmark them if they provide no help.

  • How can I DISABLE the pop up 'Would you like to copy it to Library', preventing this message from bothering for each and every book, again and again, time after time? (Windows 7 64bit US).

    How can I DISABLE the pop up 'Would you like to copy it to Library', preventing this message from bothering for each and every book, again and again , time after time? (Windows 7 64bit US).
    I guess this may be a feature request. Adobe may think this is a good message for every new eBook.
    I sure would like to decide about that myself.
    Thanks in advance if this will be changed.

    singmk wrote:
    Decided to setup the mail for exchange on my N8 so I could see my work emails. Worked like a charm but after a couple of hours decided I didn't like being that contactable so deleted the mailbox.
    Now to the problem, during setup I was forced to enable the phone lock and had to pick a 7 digit alphanumeric code. Fair enough I thought and went ahead. When I removed the mailbox however the lock remained in place with the default auto time of 30 minutes. When I checked in Phone management there is no option to disable this lock so I thought I could at least change the default time to something bigger but when you try, it remains at 30 mins. You also can't disable the auto time as it pops up an error message saying can't unlock phone.
    Does anyone know if I'm missing something obvious here or is this something which can't be disabled once it's switched on? I've done a soft reset back to factory settings with no luck and the only other thing I can think of is re installing the firmware which seems a bit extreme.
    Would like to hope there is some way to have control over this. Can someone help?
    Which firmware your N8 having now? You can check firmware by choosing Call, then type *#0000#.
    My N8 works fine on security setting and able to define Phone auto lock period, by choosing Menu>Settings>Phone>Phone management>Security settings>Phone and SIM card>Phone auto lock period>User defined>Lock after(minutes)
    You will prompt to enter Lock code each time u define auto lock priod or enable/disable auto lock.
    Hope this can help you.
    If you find this post helpful, please show your appreciation by clicking the Kudos star at the left. If it provides you the solution, please click on the GREEN Accept as Solution button at below

  • Is there a way to prevent ibooks author from shutting down after just one or two uses of the alpha tool?

    Is there a way to prevent ibooks author from shutting down after just one or two uses of the alpha tool?

    Hello One Job at a time,
    Deleting the application will not delete your projects.
    Normally I keep all my work files on a separate drive.
    If you command click on the title name of your project you will get a drop down path to show you the location of your book project.
    or you can click on the drop down triangle beside its name to duplicate.
    Just remember where you saved the file too.
    In your applications folder on your computer select the iBA icon and press delete and also erase / empty the trash can.
    You can then go back to the APP STORE and install iBA from new again.
    I hope this helps.
    Regards,
    Nigel

Maybe you are looking for