This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Sophos Central Server changing file attributes remotely causes explorer to freeze for 20 to 30 seconds

Hi, 

 

I have been having a weird issue, for awhile I thought it was a Windows issues and made a case with Microsoft, after going back and forth with them for about a week or two we realized it was Sophos.

 

Basically if I have a share folder or unc patch to a server and attempt to change a files attributes i.e. read only or hidden the window will essentially lock up for 20 to 30 seconds when I click apply.  This happens regardless of the user, I even tried domain admin same thing.  It is also regardless of which server I try to connect and make the changes to (we have 7 or 8).  It does not happen from workstation to workstation or server to workstation only workstation to server or server to server, basically only when the target OS the file is on is a Windows Server, I can confirm it happens on Server 2008R2, Server 2012 and Server 2016.  What is more odd is I originally dismissed Sophos due to disabling Sophos via the console login with the tamper protection password and still seeing the issue, basically I can completely disable Sophos and the issue is still there.

However up Microsofts request I uninstalled Sophos, magically the issue disappeared, I then reinstalled and there is was again.  

 

Any Ideas?



This thread was automatically locked due to age.
Parents
  • What does "completely disable Sophos" mean?  Disable all the user mode services from services.msc and reboot?

    What OS is the client?  Are Win 7 and Win 10 equally impacted?

    Does the client have HMPA installed?  If so, the first thing I would do is rename hmpalert.sys in \windows\system32\drivers and reboot.
    With the HMPA driver not loaded it will not inject the HMPA dll into processes which would include Explorer.
    Rulling out HMPA would be the first thing I would try.

    Regards,

    Jak


  • The workstations are Windows 10, by disabling I mean going into Admin Login on the server itself, entering in the tamper protection password and turning off every aspect of Sophos, I did this one at a time as well to see if I could narrow it down further.

    Respectfully, 

     

    Badrobot

     

Reply
  • The workstations are Windows 10, by disabling I mean going into Admin Login on the server itself, entering in the tamper protection password and turning off every aspect of Sophos, I did this one at a time as well to see if I could narrow it down further.

    Respectfully, 

     

    Badrobot

     

Children
No Data