Jump to content

Sophos-Support-5

Members
  • Posts

    48
  • Joined

  • Last visited

Everything posted by Sophos-Support-5

  1. Uninstall and reinstall? Rubbish. Use the console like everyone says! And why is every SAV problem on here followed a few posted down with "I have a removal script". It's not broke, just not configured. All you need to do is change the updating policy in the Enterprise Console and the client will pick it up. *IF* you're really stuck the credentials are stored locally in... %programfiles%\Sophos\AutoUpdate\Config\iconn.cfg ...and YOU could script something to swap out the current file for a new one on boot/logon/shutdown etc. If you need to obfuscate the password then look at: Enterprise Console: obfuscating the username and password FYI: sweepupd is not an automatically created account. It's just that it's been on peoples systems since SAV4 that everyone thinks we put it there . However a "quick install" of EM Library creates a "SophosEndpoint" account. Otherwise it's up to you what account you use for updating. We don't recommend using anything as powerful as an admin unless troubleshooting an updating problem etc.
  2. Full requirements at: Sophos PureMessage for Microsoft Exchange - system requirements If you need any further help please feel free to submit a support query: Sophos - Contact technical support
  3. The way HIPs works is to look at how the program is behaving. If the vendor decided to program it in such and way that it uses malware-like API calls then they should get the slapped knuckles. However you can always forward a sample and ask if we can remove detection. It's not always possible but sometimes we can. 50/50 chance. https://secure.sophos.com/support/samples/ True. Not going to defend it. It's crap wording and I've said that to anyone that would listen to me from the day I first saw it. I take you point. However a fixed time would probably kill your network when all the clients kick in en masse and lock all the files in the CID. It's been raised before and I can see why it would be very useful in some instances but for the majority this would hurt more than heal. It's not causing any problems for 99.9% of customers and is yet another tier of protection you get with SAV to stop malware. However it is an extra feature that puts load on the computer and IF you find in YOUR network it's causing a problem you can remove it. But remember we are effectively breaking our product to help you. You know, I think Sophos gets a bad reputation for things like this because we design the software to be secure: internal certificates that must be correct and the registry with the correct permissions set. Install one of our competitors and it'll install fine. Install SAV and you get error upon error right? I see tons of support cases and they're all down to things not set right on the client. If you really think HKLM\Software\Classes needs nothing but EVERYONE, FULL CONTROL then I'll have to disagree. And if anyone remembers the wonderful 3057 error blame a certain major graphic drivers manufacturer for redoing the permissions on certain registry keys. What gets me is that they made a clean getaway and we had to change our product for either their honest mistake or stupid short-sighted programming. Only today I had a customer that installed a patch from Microsoft and it broke SAV. Who's fault is that? Doesn't matter - our product isn't working so we get the call. The point of SAV's pedanticness is this: The new wave of malware targets AV programs and we've got to defend ourselves first so we can protect the rest of the computer. Me too. It's a very fine balance between quick turn around of samples and not getting something wrong. We're quite proud of the current levels but again are working to improve all the time. We have a feature request process and all of them get reviewed. However you don't tend to get feedback on them but people do listen. Even better come along to one of our open days and chat to us and put your point across.
  4. We've added a lot of features into version 7 and heads up on version 9 (~September 09) as we're adding even more in. You can strip SAV right down and see if things improve but modern virus attacks are becoming even more complex. Conficker has highlighted the usefulness of HIPs to prevent registry modifications and stop that particular virus adding its service key - we've even seen a new strain of Conficker targeting our cleanup tool because it's been so successful but we're combating that too! I do remember the golden age of SAV "classic" (the lightening bolt). The product was simple because AV could be. Now we're all living in a world of master crackers and vast sums of money being poured into malware writing by international organised crime - not geeks in garages. If you want the lightest SAV... - disable HIPs - disable buffer overflow (BOPs) - on-access scanner settings... -- just read -- scanning level = normal -- scanning options = all unchecked -- extensions "allow me to control exactly what is scanned" -- exclusions = remote files -- cleanup = do nothing (i.e. just block) - disable application control - strip out the Sophos_detoured.dll (the registry hack you mentioned?) - disable the SophosBHO that actively scans website for malware (it's still running to protect you if SAV isn't) ...that should mean SAV doesn't have to do too much checking on a file before releasing it. - run a full scan on the computer regularly to include new files and modified files in SAVs decision caching technology ...that should mean SAV is only comparing checksums and not scanning the whole file before releasing it. - set AutoUpdate to stop running as the user logs on and allow a quicker boot(Sophos Anti-Virus for Windows 2000+: disabling updates on power-up) - set AutoUpdate schedule to a longer delay (one hour, two hours?) not great if you've just done the above point! There's no best practice and you can adjust it as required to suit your network. - set EM Library to a fixed package (not "latest SAV+IDEs" in EM Library) so you don't get engine updates each month. Rather you keep using the current engine and "top-up" with identity files which are lighter to download. - setup a simple webCID on a local IIS server and allow clients to update from there with tons more file locking tolerance that UNC "file and print sharing". ...that should shorten the time taken for clients to update. - defrag the hard drive - switch off system restore (if you're not using it). Or exclude C:\System Volume Information\ - run scandisk to identify bad areas - purge the temp locations and recycle bin (exclude C:\Recycler?) regularly It's a big list and I could go on. You obviously don't have to do all of these things. You can see which ones might help you and just implement those. SAV + EM Library + Enterprise Console are very flexible products. From reading the threads on this site I get the impression from the feedback of users that NOD32 is initially complex to learn compared to SAV. Perhaps it is not. Perhaps SAV looks easier than it is because of its interface and layout? Perhaps the learning curve is steeper for Sophos than you first think and maybe some people are making light of the effort they have put into configuring it? I don't honestly know. However the evidence I have suggested the vast majority of users really like it and those open to suggestions can get help from Support to tweak it for their needs. Regards, Sophos Technical Support
  5. Hi All, Can the users of NOD, Kaspersky, McAfee, Symantec, Trend, Avast, AVG, etc. post the memory footprint of an average client (main scanner process name, peak memory, etc)? The main headache for SAV users seems to be memory usage and I would like to gather a bit of intelligence from users of other products. From reading the different threads on here it seems as though Symantec is quite heavy too but all the rest seem OK or there are other nagging problems that override the footprint issue. Regards, Sophos Technical Support
  6. utterly: completely, entirely, to the fullest extent en.wiktionary.org/wiki/utterly useless: Without use or possibility to be used; : (of a person) unable to do well at a particular task or thing. Useless is mildly insulting source: en.wiktionary.org/wiki/useless Therefore: SAV is completely unable to remove this infection? What is failing to be cleanup? We don't want you to. It is necessary based on our analysis of the worm. However the scan time sounds a bit long to me. What were your scan settings? Extensive? That shouldn't be required. It all really depends what's on the drive. You could try disk cleanup to remove as much unnecessary junk from the computer as possible. Also switch off system restore if you think the backups are potentially infected - it'll increase the scan time too. Then look at: W32/Brontok-N Win32 executable file virus - Sophos security analysis > 'more information' Sophos: Disinfecting PE executables Regards, Sophos Technical Support
  7. Worked for me just now. We've not had any reported problems with downloading the file. If you want another link (that doesn't require registration) then try (754kB): http://www.sophos.com/support/cleaners/scct_10_sfx.exe Regards, Sophos Technical Support
  8. Removing the scheduled tasks created by Conficker can be tricky as it's not easy to tell if the task is legitimate or not. Microsoft's KB does suggest removing all AT jobs... Virus alert about the Win32/Conficker.B worm You can call us: Sophos - Contact technical support Regards, Sophos Technical Support
  9. Go to a machine. Unplug the network cable. Run a FULL scan (scan all files checked). When the scan has finished cleanup items in quarantine. Run another FULL scan. If it comes back clean we're cleaning it up. If you put the computer back on the network and it gets "infected" then there is an unpatched or unprotected machine on the network - or someone plugged in a USB pen into the computer. Regards, Sophos
  10. The people in support know what they’re talking about! Version 3.0.2 (currently the latest) is far better than either 3.0.0 or 3.0.1. If you're not using 3.0.2 then you should definitely upgrade ASAP. I've seen a number of problems with 3.0.0 and 3.0.1 - hence the 3.0.2 release. I know some people will say 3.0.0 or 3.0.1 is working happily but there are problems out there that are fixed in 3.0.2. It’s definitely worth reading the release notes to see what’s fixed (and what's not )… PureMessage for Microsoft Exchange version 3.0.2 release notes Some people find PureMessage works really well out-of-the-box. However it is normal to have to fine-tune the settings for your precise network. The following articles might help you understand how PureMessage can work even better for you... PureMessage for Microsoft Exchange: how to configure for the best spam capture rates Sophos Extensible List: SXL Spam campaigns can last only a matter of minutes; therefore it's important to keep up to date. If you are seeing a particular type of spam that is getting a low score then maybe we've not seen many samples. You can submit samples of spam email in the same way as viruses... How to submit spam, and false-positive spam samples to SophosLabs If you do decide to upgrade I want it to be as easy as possible. So a heads-up that we have tightened up on the requirements. Namely service pack levels for OS, Exchange and the MSDE/SQL that houses the databases... Sophos PureMessage for Microsoft Exchange - system requirements If you hit any problems or need further advice please call us free 24/7/365... Sophos - Contact technical support Regards, Sophos Technical Support P.S. Regarding your moving from SAV: I know we’ve been weak on virus removal and that’s going to change soon!
  11. Hi PRicho, Please call us (24/7/365) if you require assistance. If you submitted a file sample (and included an email address) you should have received a email reply with a case reference in the subject line. Please quote this when calling. From UK: 0844 767 4670 (0844 SOPHOS-0) International: +44 (0)1235 465818 Regards, Sophos Technical Support
  12. It just so happens we're working on Sharepoint protection right now... Sophos for Microsoft SharePoint (beta) provides proactive, real-time protection of your collaborative workspace. Sophos for Microsoft SharePoint > Sophos beta program While it's in beta we really REALLY like feedback!! Regards, Sophos Technical Support
  13. I told you in a previous post (different thread) that I could only find mentioned memory footprint size. I do welcome all feedback. However if you are not currently using our latest software then you may be stating features that have already been incorporated into the product set and therefore not best placed to comment. AND you still haven't told me why you need to uninstall remotely all the time??? If it's so easy to uninstall Trend then do it on ten computers and install the latest version of Sophos (or use our removal tool that wipes Trend out of the way automatically on install). Then let me know what you think.
  14. You didn't read my posting - I covered that scenario. The new supplier should help - we do with new customers, or if an existing customer takes over another company and wants to roll out Sophos. Why? Would someone tell me why!!! I don't do your job. I don't know what tasks you have to perform. I sit in a box minding my own business until you raise a case and then I kick into action . I then start to understand how you're using the software and the issues you're having. I honestly can't see why you would need to remove it. Do you come in every morning and need to zap the product from 10 machines? Or is this a weekly thing! OK Trend do it and we don't. But we don't because we don't get enough requests for the feature. Scenario: 100 people say they want role-based tools for the Console. 2 people want central removal control. Guess who wins... Sophos Endpoint Security and Control: administration consoles > Helpdesk Console OR Enterprise Read-Only Console We want to please as many people as possible and it all starts with justifying the feature and prioritising it. Tell me why it's a cool feature or describe the pain you have because it's not there and I'll raise it internally for you.
  15. Wow. That's old. Really old. I doubt it would work. REM -===- VERSION 1.01 -===- @ECHO OFF ECHO ================================================== ================== ECHO Sophos Anti-Virus 5.x / Sophos Anti-Virus 6.x -- Removal Script ...so no removal of SAV7.x then. And I can see obvious formatting problems with the text. Namely rogue spaces... ECHO [-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\[b]Servic es\[/b]SAVAdminService] >> %TEMP%\SOTMP.REG ECHO [-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\[b]Servic es\SAVOnAccess Control[/b]] >> %TEMP%\SOTMP.REG ECHO [-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\[b]Servic es\SAVOnAccess Filter[/b]] >> %TEMP%\SOTMP.REG ECHO [-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\[b]Servic es[/b]\SAVService] >> %TEMP%\SOTMP.REG ECHO [-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\[b]Servic es[/b]\Sophos Agent] >> %TEMP%\SOTMP.REG ECHO [-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\[b]Servic es[/b]\Sophos AutoUpdate Agent] >> %TEMP%\SOTMP.REG ECHO [-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\[b]Servic es[/b]\Sophos AutoUpdate Service] >> %TEMP%\SOTMP.REG ECHO [-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\[b]Servic es[/b]\Sophos Message Router] >> %TEMP%\SOTMP.REG The newer versions now include the line asking not to pass the script around so we can control this kind of thing... ECHO Sophos Anti-Virus [b]4/5/6/7.x[/b] -- Removal Script ECHO Copyright (c) 2007-2009, Sophos Plc, http://www.sophos.com ECHO. ECHO DO NOT DISTRIBUTE WITHOUT THE PRIOR CONSENT OF ECHO SOPHOS TECHNICAL SUPPORT. I would not recommend running that script purely because it could cause far more problems that the ones you're trying to fix. Regards, Sophos Technical Support
  16. Interesting. Why would you want to uninstall it (I'm being serious - no jokes please )? OK you might be moving to another supplier but they have their own tools to help you. We've integrated an AV removal tool into our product to help all our customers displace other AV vendors and make it simple to switch over to us... Endpoint Security and Control 8: removal tool I wouldn't think too many people happily running Sophos would want a mass uninstall option in the console. If you're removing a number of machines from the network then you have to remove all software including the OS. I'd be interested in daily situations where you would find it vital. Where are these machines going and why don't you want to protect them any more? If they're staying on the network then they should have AV on them (as the Conficker virus has helped to highlight). If you really need a en masse central uninstall then... osql command from the database for hostnames (spat into a text file) + psexec @hostnameList.txt .... + vb script to call uninstall strings from registry = the feature you're after. 10 minutes work. No big secret. Any other requests?
  17. FYI: Sophos Bootable Anti-Virus: download and CD creation instructions
  18. I recommend, er, let me think, Sofos, no: Sophos I love feedback. Can you define "pain" so I can hit Product Management over the head? For instance what top three features would make you happily stay with Sophos? NOTE: All my own views. I don't respresent the company's views, et cetera.
  19. Things you can (perhaps) visually spot... Extract from the "more information" tab on Mal/Conficker-A Malicious behavior (WORM_DOWNAD.AD, W32/Conficker.worm, Worm:Win32/Conficker.gen!A, Worm:W32/Downadup, Net-Worm.Win32.Kido) - Sophos security analysis (1) \ (e.g. C:\windows\system32\zdtnx.g) (2) The registry entries added by Mal/Confiker-A are under: HKLM\SYSTEM\CurrentControlSet\Services\ (3) The random service name will also be added to the list of services referenced by: HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost\netsvcs (4) When spreading to removable media Mal/Conficker-A attempts to create the following hidden files: \autorun.inf \RECYCLER\S-x-x-x-xxx-xxx-xxx-x\.dll (where x represents a random digit) Please read the above page in full for more information and also Sophos Anti-Virus for Windows 2000+: removing W32/Confick and Mal/Conficker Regards, Sophos Technical Support
  20. You shouldn't let it. Conficker isn't that bad if you're protected. This virus is causing a certain amount of panic because, in all honesty, it's exposing how poorly protected some networks are. Microsoft released the patch back in October and loads of networks still don't have it installed. If you're patched on ALL machines and you have up-to-date AV on ALL machines then you won't suffer. Asked "are you 100% patched?" the usual answer is "yes, certainly, yes, yes, yes. Ah, well probably." If you have no central management of either (1) patch control or (2) minimum AV requirement on every machine allowed to communicate on the network then how can you be sure you're protected? Answer: Sophos Endpoint Security 8 (which includes SophosNAC) or Sophos NAC Advanced (that doesn't require SAV to be installed): Endpoint control - How much control do you want? Our vulnerabilities list shows three vulnerabilities in February, one in January and nine back in December. Hands up who is 100% patched on 100% of their machines and can prove it. Latest vulnerabilities analysis Regards, Sophos Technical Support
  21. An excellent suggestion!! I would love mattx to come - actually anyone who can make it should! Sophos: Events in EMEA (Europe, Middle East and Africa)
  22. As the fffffffd article suggests (even though it's describing the Sophos Control Center and not the Enterprise Console it's the same version of RMS)... Sophos small business solutions: 'Error fffffffd' is reported in the Sophos Control Center ...the Console pushed out the scheduled task; the task was known to have run; however nothing has been heard from the client since. Common issues are either the IP address the client has been told to send messages is wrong, the server or client has multiple IP addresses the they're getting in the way of each other, or something is blocking the communication. The best thing to do is check... (1) All the Sophos services are started (you can do this remotely with a snapin) (2) Restart the Sophos Message Router and Sophos Agent services (again remotely). (3) Can you telnet from the client to the server and server to client? Open a cmd prompt. enter: telnet 8192 This tests if something is listening on 8192 (the standard message router port). You should get IOR:48405439543058504309559450345983450349584305234783473204 Connection to host lost. If you get nothing then something is blocking the communication. The IOR:... string (as one long string starting with "IOR:" can be decoded to make sure it contains the right IP address: ILU IOR Parser The client polls the server every 15 minutes so as long as the client can telnet the server the Windows firewall shouldn't cause too many problems. (4) Check the logs under C:\Documents and Settings\All Users\Application Data\Sophos\Remote Management System\3\Router\Logs (you can do this remotely via the C$ share of the computer). In the logs you'll have vertical column of I 's if you scroll down look for W 's (warnings) or E 's (errors). Post up the latest router log and agent log (...\Remote Management System\3\Agent\Logs) if you need further advice. They're the ultimate source of what's going wrong. Three out of the above four can all be done from the server without ever visiting the client machine. If you prefer feel free to run the SDU (Sophos Diagnostic Utility)... Sophos Diagnostic Utility (SDU): how to download and install ...on the client and the Sophos Management Server (so we can see what's being received on the server-side) and email the logs into us: https://secure.sophos.com/support/query/ Regards, Sophos Technical Support
  23. Mr Support was my father. Only to you. Sophos is growing very faster. I couldn't find it. I have seen the usual "memory hog" issues. Sophos isn't an AV any more. It's a full Endpoint protection agent. Maybe we should say you need 1Gb of RAM minimum. However I would hope that either (1) in your pre-purchase testing you spot the memory footprint and decide it's not for you as "my PIII 700 Mhz, 128 MB RAM, 4.2Gb hard drive DAN computers from the back page of Computer Shopper ain't gonna be happy" or (2) realise that the MS suite, web browsers and general Windows XP machines need at least 1Gb of RAM to work well ("work well" is debatable I know). Sophos cover the latest OSes and stretch back to, what seems like, the dawn of time and offers 98/Me/NT too. We may attract customers with really old hardware because of this. I genuinely apologise for the lapse. That's not how it's meant to work. Can you PM me (or post if you prefer) the email? I would really like to see a copy. It's my job to give you no reason to complain. Issues can occur with any piece of software. It's the nature of the beast that software designed to intercept every single file request on a computer can cause issues. However it's how these issues are dealt with that matters. You test the product; notice a problem; call support; provide as much information as we need to re-create and understand the issue; we tell you how to either (a) fix the issue or (b) workaround it for now and fold into our roadmap the permanent fix in a later release. No. I was working too hard P.S. If the legal department is reading this then: Any views or opinions presented here are solely those of the author and do not necessarily represent those of the company. The company will not accept any liability in respect of such communication, and the employee responsible will be personally liable for any damages or other liability arising.
  24. For those that do not have SAV installed or are finding cleanup difficult please check out: Sophos Conficker Cleanup Tool
×
×
  • Create New...