Jump to content

Recommended Posts

Posted

Just looking at our options this year as Sophos has been a right pain and from reading around it's down to Sophos, Symantec or Kaskersky.

 

Reading these on AV-Comparitives.org to help make an informed choice...

 

http://www.av-comparatives.org/seiten/ergebnisse/report19.pdf

 

http://www.av-comparatives.org/seiten/ergebnisse/summary2008.pdf

 

...which should give some detection rate \ scanning speed etc figures. The other issue is system resources but there doesn't seem to be any official figures around for this so guess it's experience and recommendations on that front.

 

If anyone wants to put their current product and their views on here as well it would be much appreciated.. particularly if it's one of the 3 above ;)

Posted

I'm also looking at dropping Sophos as soon as the license expires. Then I'm off to ESET most likely. Used the home product for years and only heard good things about the business / enterprise version plus they give (i think) 50% discount on Education purchases.

 

http://www.eset.co.uk/

Posted

I recommend, er, let me think, Sofos, no: Sophos :D

 

Sophos has been a right pain

 

I love feedback. Can you define "pain" so I can hit Product Management over the head? For instance what top three features would make you happily stay with Sophos?

 

NOTE: All my own views. I don't respresent the company's views, et cetera.

Posted

One thing Sophos annoys me is the amount of memory it uses. one suggestion i could say it make an uninstall utility in the enterprise console.

 

Other than that i haven't had any problems with Sophos myself.

 

But today i still don't know of any enterprise AV package i can recommend.

Posted
One thing Sophos annoys me is the amount of memory it uses. one suggestion i could say it make an uninstall utility in the enterprise console.

 

Interesting. Why would you want to uninstall it (I'm being serious - no jokes please :p)? OK you might be moving to another supplier but they have their own tools to help you. We've integrated an AV removal tool into our product to help all our customers displace other AV vendors and make it simple to switch over to us...

 

Endpoint Security and Control 8: removal tool

 

I wouldn't think too many people happily running Sophos would want a mass uninstall option in the console. If you're removing a number of machines from the network then you have to remove all software including the OS. I'd be interested in daily situations where you would find it vital. Where are these machines going and why don't you want to protect them any more? If they're staying on the network then they should have AV on them (as the Conficker virus has helped to highlight).

 

If you really need a en masse central uninstall then...

 

osql command from the database for hostnames (spat into a text file) + psexec @hostnameList.txt .... + vb script to call uninstall strings from registry = the feature you're after. 10 minutes work. No big secret.

 

Any other requests?

Posted (edited)
I wouldn't think too many people happily running Sophos would want a mass uninstall option in the console.

 

Oh dear, what about the people who want to go with another product ?

 

If you really need a en masse central uninstall then...

 

osql command from the database for hostnames (spat into a text file) + psexec @hostnameList.txt .... + vb script to call uninstall strings from registry = the feature you're after.

 

All that just to do a mass uninstall ?

Trend - Click on the group in the console, click on uninstall, click on ok. DONE.

 

No commands from the database to get names into a text file, no psexec, no vb script. Some people would have problems with all that as they are teachers and not IT Techies.

Keep It Simple

Edited by mattx
Posted

Sophos really hammers the machine, got a DLL fix to try but not sure if that'll be the solution though...

 

Lots of votes for NOD here, what's the management console like? One of the things that annoys me with Sophos is that there's no way to view the log history of a client machine without either being at the client or browsing through the C: drive to find it :rolleyes:

 

Can you get full history with NOD, e.g. infections, action taken, updates etc etc?

Posted
what about the people who want to go with another product ?

 

You didn't read my posting - I covered that scenario. The new supplier should help - we do with new customers, or if an existing customer takes over another company and wants to roll out Sophos.

 

Trend - Click on the group in the console, click on uninstall, click on ok. DONE.

 

Why? Would someone tell me why!!! I don't do your job. I don't know what tasks you have to perform. I sit in a box minding my own business until you raise a case and then I kick into action :cool:. I then start to understand how you're using the software and the issues you're having. I honestly can't see why you would need to remove it. Do you come in every morning and need to zap the product from 10 machines? Or is this a weekly thing!

 

OK Trend do it and we don't. But we don't because we don't get enough requests for the feature.

 

Scenario: 100 people say they want role-based tools for the Console. 2 people want central removal control. Guess who wins...

 

Sophos Endpoint Security and Control: administration consoles > Helpdesk Console OR Enterprise Read-Only Console

 

We want to please as many people as possible and it all starts with justifying the feature and prioritising it. Tell me why it's a cool feature or describe the pain you have because it's not there and I'll raise it internally for you.

Posted

NOD32 Review Review of the Eset NOD32 Antivirus and Security - PC World

 

NOD32's overall malware detection rate wasn't stellar, however. When pitted against AV-Test.org's nearly 900,000-strong "zoo" of Trojans, viruses, and other malware, NOD32 caught only 90 percent, compared to the 96 percent rate of top performers Kaspersky Anti-Virus 6, Symantec Norton AntiVirus 2007, and BitDefender Antivirus 10. It fared surprisingly poorly with 32-bit Windows viruses (approximately 1 in 11 samples in the zoo), catching only 73 percent.

 

In disinfection tests, NOD32 cleaned up all malware files but missed resulting changes to the Hosts network settings file and most of the less-important Registry changes, for a disappointing 55 percent success rate.

 

Posted

We want to please as many people as possible and it all starts with justifying the feature and prioritising it. Tell me why it's a cool feature or describe the pain you have because it's not there and I'll raise it internally for you.

 

I mentioned this to a Sophos tech I spoke to the other day (may even have been you :p ) but might as well put it down again...

 

- access log of all client activity from console, in the same way you can access the log file of another PC from Event Viewer in Windows

- view progress of scan in real time on management console would be quite handy as well

- more info about what has happened in a cleanup rather than just an alert and no detail as it is at the moment

- lower CPU \ memory usage when starting up, updating & scanning

Posted
Why? Would someone tell me why!!! I don't do your job. I don't know what tasks you have to perform. I sit in a box minding my own business until you raise a case and then I kick into action . I then start to understand how you're using the software and the issues you're having. I honestly can't see why you would need to remove it. Do you come in every morning and need to zap the product from 10 machines? Or is this a weekly thing!

 

OK Trend do it and we don't. But we don't because we don't get enough requests for the feature.

 

Scenario: 100 people say they want role-based tools for the Console. 2 people want central removal control. Guess who wins...

 

Sophos Endpoint Security and Control: administration consoles > Helpdesk Console OR Enterprise Read-Only Console

 

We want to please as many people as possible and it all starts with justifying the feature and prioritising it. Tell me why it's a cool feature or describe the pain you have because it's not there and I'll raise it internally for you.

 

Well you wanted feedback, now you have it along with all the other posts from people who have mentioned other factors........

Posted
Well you wanted feedback, now you have it along with all the other posts from people who have mentioned other factors........

 

I told you in a previous post (different thread) that I could only find mentioned memory footprint size.

 

I do welcome all feedback. However if you are not currently using our latest software then you may be stating features that have already been incorporated into the product set and therefore not best placed to comment.

 

AND you still haven't told me why you need to uninstall remotely all the time??? If it's so easy to uninstall Trend then do it on ten computers and install the latest version of Sophos (or use our removal tool that wipes Trend out of the way automatically on install). Then let me know what you think.

Posted
If it's so easy to uninstall Trend then do it on ten computers and install the latest version of Sophos

 

I would rather stick pins in my eyes thanks !! :D

Posted

I'd want to remove Sophos centrally as sometimes it borkes on updates and jams so to go out and manually un-install it all is a PITA, especially on teacher laptops which often are oh i'm using it or its in room X not my classroom etc so being able to put on the console un-install Sophos would be good. Also in the past, we've had the issue of it deciding all of a sudden Program X is dodgy, so an option to mass un-install it in that room to get round a problem urgently would be very handy!

 

I too want a much smaller footprint client, its far too big and numb so reduce the size, anti-virus software should need no more 512kb of ram to live! (ok maybe a bit too small but 60 or 70mb which I often see is too great!) same with CPU thrashing which is a common trait of it.

 

I hold no faith in this request as I made it 3 years ago when it was just getting bigger and bigger and bigger and more PC hungry and to the point where I needed a £1000 server to run the thing, but at the time I said I want a simple Anti-Virus program, clear off with all this firewall client, application control, NAC etc that is bundled in with it, I just want an option of a clean and clear Anti-Virus program that scans drives for viruses that's it! All I want.

 

I'm not bothered about PUA, NAC, Firewall etc, if I want them I want them as separate programs I can install (I know some are but get my picture here!) thats my choice, fine I know that you can leave the NAC and firewall client off if your not licences etc but it will still be clinging in there I'm sure, so go back and revisit Sophos V3 please and V4 with the good old days of the SAVAdmin console before the Enterprise Console as that is the product I want really, the simple basic one that was with the N logo! Fine the update popup was a really annoyance which the new one doesn't have which is better, but I'd sooner go back in time than it get any worse.

Posted

Unless all of your machines have Cray logos on them I would steer clear of CA Integrated Threat Managment. Talk about heavy, it cruches even some of our newest machines, infact I think that I can demonstraite some of their code in faux python:

 

Import NeutronStar
Import StellarCoreFragment
Import RudimentryAV
Import RudimentryAnitiMalware
Import FlashyResourceHoggingWebInterface

While I=1:I=1

 

:(

Posted

Swapped off the resource heavy Symantec Corporate (which was bundled on our old RM system) to AVG Network Edition 7.5 - which at the time was light weight, network managable and cheap! It was doing great, until they made it resource heavy with version 8. :( Been on a trial with Avast - which has native MSI installation (so we can push it with GPO - one less to have to remember to install), and network management utils. Cost - about £4k.

 

We also trialed Sophos... found it a bit heavy on the client, and a bit too expensive for us - as we also want to protect a local Sharepoint and Exchange install.

 

After the work been doing with MS with Sharepoint recently, had my head turned a bit by Forefront - Microsofts corporate AV and AntiMalware product. Same pluses as Avast - except cheaper per machine and it also keeps all my licencing in one place. Bonuses - the Sharepoint and Exchange versions have profanity filters!! :bowl:

 

Food for thought.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...