Sophos

HIPS/RegMod-002

Category
Type
What's been detected
  • Runtime behavior alerts of this type inform the user that an attempt has been made to install a file into the registry of the computer in order for it to run on system startup. Any attempt at this behavior by an unauthorized program could indicate a malware infection.

    Please note that some software applications perform actions that can sometimes resemble malware behavior in the way that they modify the system registry. For this reason, configuring software so that some features are run on system startup carries an increased likelihood of unwanted detections for HIPS/RegMod-002.

What to do

Summary

 
Affected operating systems Windows
Detected by Sophos Anti-Virus for Windows, version 7

Action

Your options

If you've received an alert, then you have 2 options:

  • authorize the file
  • send the file to the lab for analysis

Authorize the file if it's from a trusted source.

Send it to the lab for analysis if:

  • you trust the file, but it generates alerts.
  • you don't trust the file

To reduce the chance of unwanted detections, Sophos HIPS should be set to 'Alert only' mode for the duration of any software installations.

Sending a file to the lab?

When you complete the sample submission form, please give a reason for your submission and mention this "HIPS/" detection.

More Information

Runtime behavior alerts of this type inform the user that an attempt has been made to install a file into the registry of the computer in order for it to run on system startup. Any attempt at this behavior by an unauthorized program could indicate a malware infection.

Please note that some software applications perform actions that can sometimes resemble malware behavior in the way that they modify the system registry. For this reason, configuring software so that some features are run on system startup carries an increased likelihood of unwanted detections for HIPS/RegMod-002.

RSS|Atom
Get reports about the latest suspicious behavior and file detections delivered to your computer