Jump to content

Recommended Posts

Posted
I just received a quote too and it is 4 1/2 times what we are currently paying for McAfee!!:eek:

 

When I got a price for Nod32 turned out to be roughly 30-40% more then we're paying for McAfee (that would be for a three year contract). It's a real shame as I much prefer NOD32 to McAfee :(

Posted
Symantec is fine if you have at least 1GB of RAM on the PC (Windows XP), otherwise it will grind to a halt. Not that great at preventing infection though but then all AV programs have the problem of exploits being made faster than they can keep up the definitions.
Posted

Sophos Support 5 - all very well in being but my point is these options should be part of the console, not reg hacking to speed up the program! Turning off HIPS now (put it on to protect against Conficker) but instead it just screams at the top of its voice about... NetSupport School, one of the most common classroom management programs out there :rolleyes:

 

Also putting "do nothing" in an antivirus program doesn't instill much confidence, if the behaviour is to block why not just say that?

 

Checking our scan options ours are near enough exactly as you've mentioned - the autoupdate needs a scheduler to update at a fixed time of day, that way we can be sure it won't start going mental during an exam. Again we could kill the update service, work out the timing etc so it's outside an update window but we shouldn't need to do this.

 

This was the suggested fix for the DLL, I'm guessing it's the same one by looks of the file name...

1. Click Start > Run > type regedit > click OK.

 

2. Browse to:

 

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\Current Version\Windows\AppInit_Dlls

 

Modify the AppInit_Dlls key and delete the following from the value data string:

 

C:\PROGRA~1\Sophos\SOPHOS~1\SOPHOS~1.DLL

 

If it's causing that many problems why is it running?

 

We had the IDE only package, was fine until it expired and someone made a boo boo with the certificates which meant redploying the SAV client to all machines (or the workaround we learnt about later setting the clock back in time). Again it's silly things but it causes so much aggro that doesn't need doing.

 

Tbh I think the detection rates are fine and probably does a good job there but someone needs to sit down and fix the client and management console as there seems to be some features that are just crying out to be sorted imo.

Posted
Well after trying our current Symatec Corporate 8 on on the little netbook today i promptly put NOD32 back on, the performance hit was noticable with symantec.

 

SAVCE8 must be at least 2 to 3 years old. Your licensing should have allowed you to upgrade. We were on 10.2 at least 18 months ago.

 

10.2 supports Vista, but runs like a dog... a lame one...

 

Now using Sophos which doesn't make things grind to a halt

Posted
Turning off HIPS now (put it on to protect against Conficker) but instead it just screams at the top of its voice about... NetSupport School, one of the most common classroom management programs out there :rolleyes:

 

The way HIPs works is to look at how the program is behaving. If the vendor decided to program it in such and way that it uses malware-like API calls then they should get the slapped knuckles. However you can always forward a sample and ask if we can remove detection. It's not always possible but sometimes we can. 50/50 chance.

 

https://secure.sophos.com/support/samples/

 

putting "do nothing" in an antivirus program doesn't instill much confidence, if the behaviour is to block why not just say that?

 

True. Not going to defend it. It's crap wording and I've said that to anyone that would listen to me from the day I first saw it.

 

the autoupdate needs a scheduler to update at a fixed time of day, that way we can be sure it won't start going mental during an exam. Again we could kill the update service, work out the timing etc so it's outside an update window but we shouldn't need to do this.

 

I take you point. However a fixed time would probably kill your network when all the clients kick in en masse and lock all the files in the CID. It's been raised before and I can see why it would be very useful in some instances but for the majority this would hurt more than heal.

 

This was the suggested fix for the DLL, I'm guessing it's the same one by looks of the file name...

1. Click Start > Run > type regedit > click OK.

 

2. Browse to:

 

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\Current Version\Windows\AppInit_Dlls

 

Modify the AppInit_Dlls key and delete the following from the value data string:

 

C:\PROGRA~1\Sophos\SOPHOS~1\SOPHOS~1.DLL

 

If it's causing that many problems why is it running?

 

It's not causing any problems for 99.9% of customers and is yet another tier of protection you get with SAV to stop malware. However it is an extra feature that puts load on the computer and IF you find in YOUR network it's causing a problem you can remove it. But remember we are effectively breaking our product to help you.

 

We had the IDE only package, was fine until it expired and someone made a boo boo with the certificates which meant redploying the SAV client to all machines (or the workaround we learnt about later setting the clock back in time). Again it's silly things but it causes so much aggro that doesn't need doing.

 

You know, I think Sophos gets a bad reputation for things like this because we design the software to be secure: internal certificates that must be correct and the registry with the correct permissions set. Install one of our competitors and it'll install fine. Install SAV and you get error upon error right? I see tons of support cases and they're all down to things not set right on the client. If you really think HKLM\Software\Classes needs nothing but EVERYONE, FULL CONTROL then I'll have to disagree. And if anyone remembers the wonderful 3057 error blame a certain major graphic drivers manufacturer for redoing the permissions on certain registry keys. What gets me is that they made a clean getaway and we had to change our product for either their honest mistake or stupid short-sighted programming. Only today I had a customer that installed a patch from Microsoft and it broke SAV. Who's fault is that? Doesn't matter - our product isn't working so we get the call.

 

The point of SAV's pedanticness is this: The new wave of malware targets AV programs and we've got to defend ourselves first so we can protect the rest of the computer.

 

Tbh I think the detection rates are fine and probably does a good job there

 

Me too. It's a very fine balance between quick turn around of samples and not getting something wrong. We're quite proud of the current levels but again are working to improve all the time.

 

someone needs to sit down and fix the client and management console as there seems to be some features that are just crying out to be sorted imo.

 

We have a feature request process and all of them get reviewed. However you don't tend to get feedback on them but people do listen. Even better come along to one of our open days and chat to us and put your point across.

Posted

We're using Sophos on our servers (I refuse point blank to use McAfee on the servers)

The workstations all have the LEA supplied Mcafee, which is awful - we have no access to any central management system, so can't set exclusions and can't find out whether PCs have had infections or are even up to date (without physically checking them).

If we had the money I'd invest in something else (Sophos or NOD32) but as we don't we're stuck with it.

I do like the Sophos Enterprise Console - so easy to deploy, manage, update and review all computers (shame it's just the servers we have it on). As another poster said: install it and it just works. I get emails about infections, etc and I have a nice console for management

Posted

Sophos-Support-5, fair play for replying on each point - can't fault the tech support at Sophos from the times I've called up as well, just renewed our package for 6 months until Summer which gives time for the next Enterprise Console release and other updates to kick in.

 

The certificate problem we had was a Manifest error meaning no client could update from 7.3.5 (our stable package that seemed to have expired) to the 7.6.5 new package. Turned out the internal certificate had expired and was known to Sophos, hence the date rewind or redeploy.

 

Just make the client less resource hungry and then it'll be sorted :cool:

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...