Jump to content

Recommended Posts

Posted
Is anyone else having issues with new SOLUS Installs since the upgrade to Hitman Pro - When we push SOLUS to a new machine it just sits on the 'install active' and never completes. Remove Sophos Intercept X, Reboot, try again and it works so looks like another potential intercept X issue. Anyone else getting the same?

 

Same issue on one of our clients and your fix worked for me, thanks.

  • 7 years later...
Posted

With apologies for resurrecting an old thread, this issue seems to have reappeared this summer - thought it was just a windows 11 issue as obviously we are mostly doing that this summer but did a clean build and window 10 is still affected.

 

Anyone else seeing Sophos blocking/breaking Solus 3 updates?

Seems to be very much as described upthread.

Posted

We are deploying SIMS on freshly deployed Windows 11 devices across all our Trust Schools and have this issue at all sites.

 

During installation of SIMS the process hangs on devices that have Sophos Intercept X installed, if we disable Sophos on a PC the installer runs just fine.

 

Looking in task manager you can see the installer just sitting there (a few different processes)

 

In the SIMS deployment interface the deployment eventually fails with:

'2025-08-21 13:13:20 Decompiling of the package SIMS Summer 2025 Full Release (7.224.27) (SIMS Workstation)

 

No errors / blocks reported in Sophos under detections

 

SIMS Support have sent us over the latest exclusions for Sophos and these have not helped.   We have also added several other exclusions without success, based on the processes that hang.

 

We are going to try to re-image a PC with Windows 10 to see if the issue is Windows 11 Specific and then log a call with Sophos.

 

Sophos was deploying / updatig fine to Windows 10 PCs at the end of last term

 

If you have any luck before we do please can you share any detail

Posted (edited)

You need to add the setup locations to be excluded from the Exploit Mitigation And Activity Monitoring. For Solus 3 it is: C:\ProgramData\Capita\Solus3\Deployments\ 

 

If this does not work you may need to include AMSI Protection

Edited by willtech
  • Thanks 1
Posted

I can tell you it isn't windows 11 specific - happened on a windows 10 test station too.

 

Quickest fix seems to be open up sophos central, devices, computers, find the stations in question.

Tick the tickbox on the left of the computers.

Manage software at the top.

Under 'agent mode' pick uninstall.

 

Wait a couple of minutes, then deploy SIMS to those stations.

 

Wait another few minutes, then back on sophos central pick 'manage software' again and put agent mode back to endpoint.

I imagine sophos will fix it in another month or two.

Posted
On 22/08/2025 at 12:41, willtech said:

You need to add the setup locations to be excluded from the Exploit Mitigation And Activity Monitoring. For Solus 3 it is: C:\ProgramData\Capita\Solus3\Deployments\ 

 

If this does not work you may need to include AMSI Protection

 

Thanks for the tip in relation to AMSI Protection, we added the following in addition to our existing rules and this seems to have done the trick:

 

AMSI Protection (Windows)
C:\ProgramData\Capita\Solus3\Deployments\

 

 

  • Thanks 1
Posted
1 minute ago, BobFish said:

 

Thanks for the tip in relation to AMSI Protection, we added the following in addition to our existing rules and this seems to have done the trick:

 

AMSI Protection (Windows)
C:\ProgramData\Capita\Solus3\Deployments\

 

 

Glad I could help !

  • Like 1
Posted

We have exactly the same issue. Could someone please copy and paste their Global Exclusions for Solus 3 on this thread please so I check I've covered all the bases?

Posted (edited)

From ESS:

 

SOLUS 3 - Antivirus whitelisting/exceptions

System Administrators are advised to ensure that the SOLUS 3 Agent service (and it's child/sub processes if given the option) is whitelisted in the Anti-Virus to ensure it doesn't stop the agent from finishing the installation. The deployment store for the agent should also be whitelisted.

 
it has also been found that the following whitelisting will allow the SOLUS agent to work:
 
Global Exception List
 
Trusted Windows Program List
 
S:\SIMS\Setups\SIMSAMPARKSetup.exe
S:\SIMS\Setups\SIMSApplicationSetup.exe
S:\SIMS\Setups\SIMSManualSetup.exe
D:\SIMS\Sims\Setups\SIMSManualSetup.exe
D:\SIMS\Sims\Setups\SIMSApplicationSetup.exe
D:\SIMS\Sims\Setups\SIMSAMPARKSetup.exe
C:\Program Files\Solus3\AgentService\Sims.Solus3.Agent.OfflineDeployer.exe
C:\Program Files\Solus3\AgentService\Sims.Solus3.Agent.PackageDeployer.exe
C:\Program Files\Solus3\AgentService\Sims.Solus3.Agent.UI.exe
C:\Program Files\Solus3\AgentService\Sims.Solus3.Agent.AgentService.exe
 
Local Policy Level
Real-Time Scan ONLY Exclusions

Folders

C:\Program Files\Solus3
C:\Program Files\sims\Sims .net
C:\ProgramData\Capita
C:\ProgramData\Solus 3

Files
C:\Windows\sims.ini
 
Behaviour Monitoring approved program list

C:\ProgramData\Capita\Solus3\Deployments\*
D:\Sims\Sims\Setups\SIMSManualSetup.exe
D:\Sims\Sims\Setups\SIMSApplicationSetup.exe
D:\Sims\Sims\Setups\SIMSAMPARKSetup.exe
S:\SIMS\Setups\SIMSManualSetup.exe
S:\SIMS\Setups\SIMSApplicationSetup.exe
S:\SIMS\Setups\SIMSAMPARKSetup.exe
C:\Program Files\Solus3\AgentService\Sims.Solus3.Agent.OfflineDeployer.exe
C:\Program Files\Solus3\AgentService\Sims.Solus3.Agent.PackageDeployer.exe
C:\Program Files\Solus3\AgentService\Sims.Solus3.Agent.AgentService.exe
C:\Program Files\Solus3\AgentService\Sims.Solus3.Agent.UI.exe
C:\Program Files\Solus3\*
C:\ProgramData\Capita\*

 

Edited by willtech
Posted

I have the ESS list already and I've added them all - which has made no difference to the issue. I meant more so how it appeared within Sophos on the Global Exclusions list and whether people had to add additional exclusions not covered in this list. 

Posted

The main ones to fix the issue is add the following exclusions:

 

Exploit Mitigation And Activity Monitoring

C:\ProgramData\Capita\Solus3\Deployments\ 

 

AMSI Protection (Windows)
C:\ProgramData\Capita\Solus3\Deployments\

Posted
4 hours ago, dan-bot76 said:

Yes, i have both those.

Screenshot 2025-08-28 085524.png

Screenshot 2025-08-28 085536.png


I've just tried this on my network and I think you need ** at the end for the exploit mitigation exclusion as the syntax for it is slightly different (it talks about absolute paths...)
image.png.b669ed8db697da52629b40b9f5b44b28.png

I added the AMSI exclusion yesterday, that alone didn't do the trick, I also needed this.

 

So I needed the above, and these two below, now it seems to be behaving itself and installing fine.
image.png.b0453f35714fbffb5c133a61e9c09655.png

image.png.32302a1e0232246cad78d8f4136b5bfc.png

  • Thanks 1

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...