Jump to content

Recommended Posts

Posted

We have a server 2008 fileserver, I have enabled file resource manager to block students saving EXE files to their home directory�s.We get a notification if a student tries to save an EXE file to their home directory.

The weird thing is for some time now we have been getting these �notification�s below regard Pcclient.exe (Policy Central)

User CAMPION\WrayL07 attempted to save E:\Users\2007Intake\WrayL07\PCClient.exe to E:\Users\2007Intake on the SEC-FILESERVER server. This file is in the "Executable Files" file group, which is not permitted on the server.

This is not happening to all users only some, I presume the PCClient.exe is trying to save to the student Home directory when they log on or log off. But WHY?

 

Forensic software have said

 

"Hi Martin

 

I have heard this reported by some sites. There is nothing in PCE client that will do this so we think it is due to local a/v software or perhaps a deliberate attempt by a user to investigate the file?

This not something we have been able to replicate so any pattern to this will assist us in doing so."

 

 

We get about 12-20 of these messages a day, i cannot see any pattern.

 

Any one else experiencing this problem?

Posted

Not much help but:

 

I found the file in a small number of users home directories around the same time I introduced a software restriction policy to stop prog’s being executed that I hadn’t installed. (2003 Servers XP clients)

 

Logged with link2ict (June) as I was concerned my software restriction policy might stop policy central working correctly, told it’s been passed on to forensic – they didn’t contact me!

 

The answer you got from forensic is nonsense, we are a primary and the kids are not investigating the file – lol, we use Sophos but why would that cause the file to popup in users home directories? They are just grasping at straws…

 

As far as I can tell policy central is still working but it’s hosted by link2ict so the only check I can do is that the process is running in task manager.

 

Side note:

Sophos has just started deleting the policy central file SSSTool.exe from c:\windows\system32\ (and the system restore points) it looks like the path has changed as we were originally told to add c:\windows\system32\PCENT\SSSTool.exe to the exclusion list…

 

I don’t know what SSSTool.exe does so will log it with link2ict and ask them if I need to redeploy policy central or anything.

  • Thanks 1
  • 2 weeks later...
Posted

Hi folks,

 

ssstool.exe is used by Policy Central to gather information from the client server. It can be safely deleted or added to the "on-access" exclusion list within SEC.

 

The reason it is being picked up now is that it has been installed to the C:\windows\system32 folder which is different from the original install of PC and would not be in the exclusion list from before. Link2ICT have some notes here about adding in the PC exceptions in SEC

  • 5 months later...
Posted

We have added SSSTool.exe to our exclusions which has worked fine... BUT

 

Sophos looks like it is picking up the file from the "File System Volume Information" folder. As it is now named something different each time we cant exempt it?

 

Any ideas please?

 

File "C:\System Volume Information\_restore{42F57B0D-B53B-43AE-A32C-D08CE845AB90}\RP733\A0454838.exe" <--- SSSTool.exe

Posted

It sounds like before ssstools.exe was authorised, it has quarantined it and then the System Volume Copy had decided to keep a copy. (When Sophos quaretines something, it renames it)

 

I would advise turning off System Volume Copy. Do a scan and once clean again, turn it back on.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...