Sophos Anti-Virus: issues on computers running Ranger software
Issue
You are experiencing one of the following issues:
'Process C:\program files\ranger remote control\client32.exe' exhibiting suspicious behavior pattern HIPS/RegMod-007.
Sophos product and version
Enterprise Console 3.0
Sophos Anti-Virus for Windows 2000+ version 7.0.6
Sophos Anti-Virus SBE 7.0.6
Ranger Products
Ranger for Networks 5.8 (5.8.1203)
Ranger Remote Control 9.0.1
Operating system
Windows 2000 SP4
Windows 2003 SP2
Windows XP Professional SP2
Windows Vista (32-bit)
Technical Information
Ranger has a number of security policies which can change mappings of drives and permission's of accounts. This can cause issues with the installation and updating of Sophos Anti-Virus.
What to do
Take the following steps under the Enterprise Console|Policies: Anti-virus and HIPS policy. This will allow Ranger for Networks and Ranger Remote Control to work normally.
1. Folder Exclusions from scanning
In Anti-virus and HIPS policy, select On-access|Windows exclusions, and add the following folders and files to the 'Excluded items' list:
C:\Program Files\Ranger\
C:\Program Files\Ranger Reporter\
C:\Program Files\Ranger Remote Control\
C:\Program Files\Sentinel Replication Tools\
C:\Windows\System32\LogFiles\Sentinel Replication\
2. Files to be authorized
In Anti-virus and HIPS policy, select Authorization|Authorization Manager, and add following files to Suspicious files, Suspicious behaviour and Buffer overflow:
Secmon.exe,
client32,
runplugin
ranger.bat
If problems persist switch off HIPS functionality in the Anti-virus and HIPS policy, by clicking HIPS runtime behavior, and deselecting 'Detect suspicious behavior'.
Further information from Sentinel Products:
Ranger for Networks - Quick Start Guide
http://www.rangersuite.com/files/qs_guide/rfn.pdf
Ranger Desktop and Start Menu are not displayed when logging on
http://www.rangersuite.com/Articles/view/0000000178
If you need more information or guidance, then please contact technical support.
- Article ID: 16088
- Created: 4 Jul 2006
- Last updated: 8 Oct 2008
