This is from a while ago and i think the file is to do with RAIDXpert (as it`s in the system32 folder). If not resolved could you get an md5 of said file.
Have you checked the files hash or sent it to VirusTotal?
Maybe try going to Defence+ ->Computer Security Policy-> Click on “Add” then “Select”-> Browse to the file in the System32 folder and double click it-> Check “Use a pre-defined policy” and choose “Installer or Updater” → APPLY then OK. Check to see Computer Security Policy lists the file with the correct policy.
I can confirm that this issue is not malware related, the WinMsgBalloonClient.exe is a component of the RAID monitoring console AMD RAIDXpert (a.k.a. Promise WebPAM).
The software is not linked to a particular set of mainboard drivers, and it can be used on any PC platform equipped with AMD Southbridge SB700/SB800 series chipset, regardless of PC make/model.
My system, too, is experiencing the same issue, even with suggested Defence+ authorization…
Any solution?
It seems that so far this matter is not solved. Indeed the file path is “C:\Windows\SysWOW64\WinMsgBalloonClient.exe”. Somehow CIS thinks it is “C:\Windows\System32\WinMsgBalloonClient.exe”, maybe because it is a 32 bit executable(?).
I have the same problem and get no solution to this day. Checking D+ log, I found the attached event and respective alert. Sorry, they are in Portuguese-BR…