Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Sysmon 6 and 7 Locking Up Trend Officescan and Entire Server on Server 2008R2 #86

Closed
HanSolo71 opened this issue May 16, 2018 · 1 comment

Comments

@HanSolo71
Copy link

We have been having issues with our Server 2008R2 machines locking up for the last 2 years, after much research and working with Trend it appears that this is an issue caused by sysmon and they refuse to fix it.

Here is there responses.

Hi All,

Good day! so I did ask our Developers if they have a plan to release a hotfix and this is what they said.

"It is SysmonDrv.sys that blocks the IPC operation in Ntrtscan as previous update shows.We will not have plan to release hotfix for this issue.
Actually, customer should contact Microsoft for the further investigation as removing sysmon driver resolve the issue"

Based on the Dump files It is the SysmonDrv.sys that is blocking the IPC operationg in the Ntrtscan (Real time Scan). So it is not actually the Trend Micro OfficeScan that has the problem it is the SysmonDrv.sys that is causing the conflict.

As per the suggestion of the Developers you need to contact the Microsoft for the further investigation since we prove that removing the Sysmon actually fix the issue

@analyze-v
Copy link
Contributor

Could you try adding the following to your config file

<ImageLoad onmatch="exclude">
<Image condition="image">Ntrtscan.exe</Image>
</ImageLoad>

@lukekim lukekim closed this as completed May 15, 2019
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

3 participants