mtdmitchell Posted October 12, 2010 Posted October 12, 2010 We have a server 2008 fileserver, I have enabled file resource manager to block students saving EXE files to their home directory�s.We get a notification if a student tries to save an EXE file to their home directory. � The weird thing is for some time now we have been getting these �notification�s below regard Pcclient.exe (Policy Central) � User CAMPION\WrayL07 attempted to save E:\Users\2007Intake\WrayL07\PCClient.exe to E:\Users\2007Intake on the SEC-FILESERVER server. This file is in the "Executable Files" file group, which is not permitted on the server. � � This is not happening to all users only some, I presume the PCClient.exe is trying to save to the student Home directory when they log on or log off. But WHY? Forensic software have said "Hi Martin I have heard this reported by some sites. There is nothing in PCE client that will do this so we think it is due to local a/v software or perhaps a deliberate attempt by a user to investigate the file? � This not something we have been able to replicate so any pattern to this will assist us in doing so." We get about 12-20 of these messages a day, i cannot see any pattern. Any one else experiencing this problem?
ToyHeartsFan Posted October 14, 2010 Posted October 14, 2010 Not much help but: I found the file in a small number of users home directories around the same time I introduced a software restriction policy to stop prog’s being executed that I hadn’t installed. (2003 Servers XP clients) Logged with link2ict (June) as I was concerned my software restriction policy might stop policy central working correctly, told it’s been passed on to forensic – they didn’t contact me! The answer you got from forensic is nonsense, we are a primary and the kids are not investigating the file – lol, we use Sophos but why would that cause the file to popup in users home directories? They are just grasping at straws… As far as I can tell policy central is still working but it’s hosted by link2ict so the only check I can do is that the process is running in task manager. Side note: Sophos has just started deleting the policy central file SSSTool.exe from c:\windows\system32\ (and the system restore points) it looks like the path has changed as we were originally told to add c:\windows\system32\PCENT\SSSTool.exe to the exclusion list… I don’t know what SSSTool.exe does so will log it with link2ict and ask them if I need to redeploy policy central or anything. 1
mtdmitchell Posted October 18, 2010 Author Posted October 18, 2010 glad im not the only one, i bet alot of schools are having the same problem. i think i will log a call with Link2ICT
PeteW Posted October 26, 2010 Posted October 26, 2010 Hi folks, ssstool.exe is used by Policy Central to gather information from the client server. It can be safely deleted or added to the "on-access" exclusion list within SEC. The reason it is being picked up now is that it has been installed to the C:\windows\system32 folder which is different from the original install of PC and would not be in the exclusion list from before. Link2ICT have some notes here about adding in the PC exceptions in SEC
burgemaster Posted March 31, 2011 Posted March 31, 2011 We have added SSSTool.exe to our exclusions which has worked fine... BUT Sophos looks like it is picking up the file from the "File System Volume Information" folder. As it is now named something different each time we cant exempt it? Any ideas please? File "C:\System Volume Information\_restore{42F57B0D-B53B-43AE-A32C-D08CE845AB90}\RP733\A0454838.exe" <--- SSSTool.exe
PeteW Posted March 31, 2011 Posted March 31, 2011 It sounds like before ssstools.exe was authorised, it has quarantined it and then the System Volume Copy had decided to keep a copy. (When Sophos quaretines something, it renames it) I would advise turning off System Volume Copy. Do a scan and once clean again, turn it back on.
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now