Edu-IT Posted July 28, 2015 Posted July 28, 2015 @pete Yes they do, it has something to do with remote accessing the Postgres SQL database and the AD at the same time utilising the Usermanager UI, it seemed fine for the last couple of months and then wham! [ATTACH=CONFIG]31543[/ATTACH] It seems the last updates refined the file scanning, been running deepscan so will probably lighten this on the template before I re-install Avast, only affected the DC though as this is where the executable is run from, We will keep trying! God loves a trier Did this get whitelisted?
pete Posted July 28, 2015 Posted July 28, 2015 It's worth noting that DeepScan *really* doesn't like pulsar.exe (part of SIMS) either. Set an exclusion for it and NT6.exe and...well, most of c:\Program files (x86)\SIMS if you're using DeepScan on clients. The failure mode for pulsar.exe when DeepScan is triggered is the 15-second scan notification and then it kills pulsar.exe, requiring the end-user (who's probably got started working) to have to re-open SIMS. Excluding the SIMS Document Server from URL scanning also helps, especially if you're tidying orphaned documents.
Tall_Paul Posted July 29, 2015 Posted July 29, 2015 I was considering purchasing NOD32 for all my workstations but I'm going to give Avast a go and see how we get on. Many thanks to all of you for your feedback whilst you've been trying it.
Edu-IT Posted August 3, 2015 Posted August 3, 2015 It's worth noting that DeepScan *really* doesn't like pulsar.exe (part of SIMS) either. Set an exclusion for it and NT6.exe and...well, most of c:\Program files (x86)\SIMS if you're using DeepScan on clients. The failure mode for pulsar.exe when DeepScan is triggered is the 15-second scan notification and then it kills pulsar.exe, requiring the end-user (who's probably got started working) to have to re-open SIMS. Excluding the SIMS Document Server from URL scanning also helps, especially if you're tidying orphaned documents. For the DocStorage, what have you entered in to exclude?
pete Posted August 3, 2015 Posted August 3, 2015 (edited) For the DocStorage, what have you entered in to exclude? http://simsservername:8080/ http://simsservername:8080/* http://simsservername.domain.whatever:8080/ http://simsservername.domain.whatever:8080/* If your document server is running on another port, look in Tools > Setups > Document Management Server to check the settings. Edited August 3, 2015 by pete 1
LeMarchand Posted August 4, 2015 Posted August 4, 2015 Has anyone sysprepped a machine with this installed? I'm getting a "Windows could not finish configuring the system" error which various people seem to think was related to their AV install. Also (assuming that's the problem) has anyone got an install script for the exe?
pete Posted August 4, 2015 Posted August 4, 2015 ^ No, I was in two minds when building the recent slim image but didn't bother. I did do the McAfee client on images for years without issue. Have you tried setting on-access scanning to disabled before you sysprep and then let the Avast portal turn it back on after client activation? I'm using WPP (SCCM-lite) to push out Avast and IIRC someone in this thread is using PDQ Deploy.
LeMarchand Posted August 4, 2015 Posted August 4, 2015 I never had a problem with McAfee either, but our contract expires soon. As it happens, it was Avast. Once it was removed from the image all was good (apart from my unattend file needing tweaking as it's not doing the initial Admin log in or letting me specify a machine name - not that the old one ever did). Contacted Avast and they were very helpful and knocked up an MSI PDQ. Just got to tweak a few things in GPO now and script deletion of the Avast icon.
pete Posted August 5, 2015 Posted August 5, 2015 I never had a problem with McAfee either, but our contract expires soon. As it happens, it was Avast. Once it was removed from the image all was good (apart from my unattend file needing tweaking as it's not doing the initial Admin log in or letting me specify a machine name - not that the old one ever did). Contacted Avast and they were very helpful and knocked up an MSI PDQ. Just got to tweak a few things in GPO now and script deletion of the Avast icon. Wait, Avast support do MSIs to order? They kept that quiet and it would be a little more elegant than my current deployment (uses the .exe with file version checks).
LeMarchand Posted August 5, 2015 Posted August 5, 2015 Wait, Avast support do MSIs to order? They kept that quiet and it would be a little more elegant than my current deployment (uses the .exe with file version checks). https://support.business.avast.com/hc/en-us/articles/205540655-Do-You-Need-a-GPO-MSI- looks like it's only recently, so I suspect it's because the "Spring" launch is delayed. They did it pretty quickly, too. 1
pete Posted August 5, 2015 Posted August 5, 2015 (edited) Cool, I assume you can specify proxy support in the request? (or munge the property table to set it) Edited August 5, 2015 by pete
LeMarchand Posted August 5, 2015 Posted August 5, 2015 Cool, I assume you can specify proxy support in the request? (or munge the property table to set it) Possibly. I only noticed that part in the console after they'd done it! Hoping that the clients replicate the console settings now. It did look like they logged in to the console, so I suspect that they'll base the MSI on whatever you have set there. Not on site until Friday (possibly) or the 17th if I don't make it in on Friday to confirm.
Edu-IT Posted August 5, 2015 Posted August 5, 2015 https://support.business.avast.com/hc/en-us/articles/205540655-Do-You-Need-a-GPO-MSI- looks like it's only recently, so I suspect it's because the "Spring" launch is delayed. They did it pretty quickly, too. Where did you get the info about the delay? Does it fix the bcc event log issue?
pete Posted August 6, 2015 Posted August 6, 2015 Possibly. I only noticed that part in the console after they'd done it! Hoping that the clients replicate the console settings now. It did look like they logged in to the console, so I suspect that they'll base the MSI on whatever you have set there. Not on site until Friday (possibly) or the 17th if I don't make it in on Friday to confirm. You can specify proxy support - IP, Port and Auth/NoAuth (and credentials, if appropriate) is necessary info on the ticket. Poking around with the MSI it looks like it's been built with WiX.
LeMarchand Posted August 6, 2015 Posted August 6, 2015 Where did you get the info about the delay? It's Summer, so...
MattDLEA Posted August 25, 2015 Posted August 25, 2015 Just installing this now on both my host and hyper-v server is there any exclusions I need to add its just a vanilla network and no Sims on there yet. Am I Ok just using the default template but turning off deepscan
Edu-IT Posted August 25, 2015 Posted August 25, 2015 I added in all the recommend Microsoft exceptions. Microsoft Anti-Virus Exclusion List - TechNet Articles - United States (English) - TechNet Wiki
pete Posted August 26, 2015 Posted August 26, 2015 (edited) Is anyone else having end-users moaning that http://www.tes.com is being blocked by Avast at the moment if they're using Chrome? (26-08-15, midday). I've got a remote user with the problem, but I can't replicate it here using the same workstation build and config and other sites are fine for them. edit: Virustotal.com is reporting that TES is clean. Quttera is saying there's a couple of iffy things, but their heuristics have been a bit trigger-happy in the past. Edited August 26, 2015 by pete
Edu-IT Posted August 26, 2015 Posted August 26, 2015 I assume it's OK now? Just tried and seems alright for me.
pete Posted August 26, 2015 Posted August 26, 2015 No idea - I can't replicate it here as either me or a normal end-user. If it's not a false positive, I suspect that they're being served a dodgy advert. Since we block adverts at the gateway, I wouldn't see it and (depending on my browser cache/cookies) I'll get different adverts served so it's hard to check.
pete Posted September 1, 2015 Posted September 1, 2015 No idea - I can't replicate it here as either me or a normal end-user. If it's not a false positive, I suspect that they're being served a dodgy advert. Since we block adverts at the gateway, I wouldn't see it and (depending on my browser cache/cookies) I'll get different adverts served so it's hard to check. And in school today http://www.tes.com works fine for that user (sans adverts blocked at the gateway).
pete Posted September 3, 2015 Posted September 3, 2015 And in school today http://www.tes.com works fine for that user (sans adverts blocked at the gateway). But it's getting blocked for another person today. I still think it's a site element doing it (based on randomness). It would be nice if Avast listed whether it was "this site is on a list of dodgy sites" or "I'm blocking this site because of element X". I have a ticket open, so we'll see how it goes.
klop Posted September 7, 2015 Posted September 7, 2015 This looks great, have signed up and now downloading to a couple of laptops to try it. Has there been any developments with the proxy though? I'd like to install to all our staff laptops but want them to be covered whilst offsite too. thoughts of the 6 week holidays with no updates, etc worry me. Or is there a way now for the client to look at ie or similar for proxy settings? Thanks
Edu-IT Posted September 7, 2015 Posted September 7, 2015 This looks great, have signed up and now downloading to a couple of laptops to try it. Has there been any developments with the proxy though? I'd like to install to all our staff laptops but want them to be covered whilst offsite too. thoughts of the 6 week holidays with no updates, etc worry me. Or is there a way now for the client to look at ie or similar for proxy settings? Thanks What are you trying to do? You can specify the proxy through the console?
klop Posted September 7, 2015 Posted September 7, 2015 @Edu-IT Hi, I would like to use this on all our clients, both desktops and laptops. Problem with laptops that I see is in school the proxy is necessary but outside of school the laptop will not connect. I use a wpad file on the laptops to apply / not apply the proxy for explorer, chrome, etc. and it works well. This wont as far as I can see help with Avast? I'd be a little worried over holiday periods that laptops taken offsite would not connect to the cloud management dashboard console thingy.
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now