Jump to content

Sophos-Support-5

Members
  • Posts

    48
  • Joined

  • Last visited

Everything posted by Sophos-Support-5

  1. You are correct. You only need to swap out the SOPHOS3.mdf and SOPHOS3_log.ldf files. Regards, Sophos Technical Support
  2. Sophos Anti-Virus version 7+ works very well with Server 2008 without additional configuration. Our main Console works on it too! https://secure.sophos.com/products/enterprise/free-trials/endpoint/ Regards, Sophos Technical Support
  3. If you need a simple action plan for conficker... (1) Patch - this is your first and main priority. Patch patch patch. (2) Make sure your AV is installed, up to date and has working on-access/ real-time scanning - don't assume. Do check that all computers are running some protection. (3) Strengthen passwords for network shares. Conficker tries a large number of passwords and may guess weaker ones. Make the password long and complex - perhaps a phrase with UPPER and lowercase characters, d1g1t5 and symbols. (3) Disable file and printer sharing. OR divide your network up. If it's a small network you can pull the network cable and clean the machine. If you do: do NOT put it back on to the network unless you know every other computer connected is clean and will not potentially reinfect the machine. If you are running Sophos Anti-Virus see our "What to do" section for Conficker: Sophos Anti-Virus for Windows 2000+: removing W32/Confick and Mal/Conficker Regards, Sophos Technical Support
  4. Hotbar is detailed in the "More Information" section on our Hotbar page: Hotbar - Adware - Sophos security analysis Mywebsearch comes under the title PUA (potentially unwanted application). Sophos - Removing applications If you need further advice feel free to email direct: https://secure.sophos.com/support/query/ Regards, Sophos Technical Support
  5. Yes. If you have a problem either call us or email. Just mention that you get your software via your LEA Phone from the UK: 0844 767 4670 (0844 SOPHOS-0) Email web form: https://secure.sophos.com/support/query/ We provide a webCID so remote clients can update while they are off the main network. Our best practice to update clients (for speed, version control and bandwidth issues) suggests you use EM Library to download the required packages to a central share and then use the Enterprise Console to push out the initial install and tell clients if the updating location has changed. There are no plans to stop the webCID as it's used by a lot of our customers - we are stopping updating of Windows 95/98/Me/NT via the webCID though. However on a large network you should look at it as a backup or for laptops. Regards, Sophos Technical Support
  6. I personally don't agree. If you have any particular issues with Sophos you're better off putting them in writing and forwarding them to [email protected] for discussion. However you welcome to constantly bemoan on here. We really do welcome any feedback; though constructive feedback is always better. On another note I'm glad to see the children enjoying the snow at your school. We enjoyed the snow today too.. Graham Cluley's blog Regards, Sophos Technical Support
  7. Hi TechSupp, Possibly the schedule has become corrupt. Follow the instructions in the following article (under the What to do section) to fix the issue... http://www.sophos.com/support/knowledgebase/article/12789.html Regards, Sophos Technical Support
  8. Hi Psydii, What you are asking can be done; it's just a tad more complicated. As an overview... Reinstating the Certification Manager key means messages recieved from clients are allowed (NOTE: RMS communication is secure) to be passed to the Management service and then written to the database. If you did not back up the key and simply reinstalled the SEC on a new server the new SEC would have a different secure key and all the clients requests to send messages would be refused because the key they are using is unknown to the new SEC. The above is based on the messages actually getting to the Sophos management server to be accepted/ refused in the first place. If your new Sophos management server has a different IP address/ hostname then the clients need to be told about it before you decommission the old Sophos management server - it's all done through the Central Installation Directory (CID) that they are currently updating from. While all the clients are updating from \\oldServer\InterChk\ESXP\ you have to use that CID to re-configure them and tell them to not only look at \\newServer\InterChk\ESXP\ but also send all their status messages to the newServer from now on. If you would like more details feel free to submit a support request. http://www.sophos.com/support/query Regards, Sophos Technical Support
  9. Hi Psydii, Sophos Enterprise Manager Library (EM Library) had a version 1.2. I assume you mean Sophos Enterprise Console v1. Yes: the same registry key should be exported from the old installation and imported to the new server/ installation. Regards, Sophos Technical Support
  10. Hi Sidewinder, The Sophos Enterprise Console (SEC) and Sophos Enterprise Manager (SEM) will need to be uninstalled and reinstalled - but they are not as important as the database storing all the data regarding the installations of Sophos Anti-Virus (SAV) on each of your client machines. You can "migrate" the SOPHOS2 (or SOPHOS3 for SECv3) database from one machine to another. It is explained in appendix B of: http://www.sophos.com/sophos/docs/eng/esav_20_uen.pdf (SEC v2) http://www.sophos.com/sophos/docs/eng/esav_30_uen.pdf (SEC v3) Once the database is moved to the new machine you will also retain all of your groups and policies (SAV and Updating) inside the SEC. In order for all the client machines to talk successfully with the new server make sure you backup from the old server the registry key: HKEY_LOCAL_MACHINE\Software\sophos\Certification Manager ...and import into the registry of the new server. Reinstating this key means the security keys that allow communication between clients and the Sophos management server have been preserved. If the IP address is the same on the new server as it was on the old all the client installations will not notice a different. If however the IP address/ hostname of the Sophos management server has changed the clients will send their status messages to the wrong server. The following registry key dictates where the messages are sent: HKEY_LOCAL_MACHINE\SOFTWARE\Sophos\Messaging System\Router - ParentAddress If it is still looking to the old server initially try re-protecting a test group of clients and check in their registry again. If this continues to point to the old server please raise a support request and we can troubleshoot further: http://www.sophos.com/support/query Regards, Sophos Technical Support
  11. Hi Maniac, Disabling Anti-Virus on any machine is always a risk. Unfortunately a balance has to be stuck between security and performance. That is why it is often necessary to disable on-access on computers such as file servers. Generally there is a reduced risk as servers do not actually run the files stored on them. Also no one is doing general Internet surfing on servers or clicking on "interesting" looking programs. Regarding your problem: there might be a possible memory leak. Microsoft have issued a hotfix for a memory leak recently for Windows Storage Server 2003. The following links may prove useful... http://support.microsoft.com/kb/886805/en-us The hotfix is available from: http://support.microsoft.com/kb/913109/ I highly recommend discussing the application of the hotfix to your server with Microsoft before proceeding. Regards, Sophos Technical Support
  12. Hi Mattx, It looks like you have some old CIDs (Central Installation Directories) listed in EM Library and the package that that CID wants to download is no longer published on Sophos' databank. Check in EM Library under "Central Installations" on the left hand tree which CIDs are listed. In the column "Package" it will tell you which package each CID contains. The message shows errors for two packages: SAV 4.15 for Windows NT/2000/XP and SAV 4.15 for Windows 9x. These packages were retired on 28th February 2007. If you still have clients on SAV 4.15 for Windows NT/2000/XP they should be upgraded to SAV 6.5.x or SAV 7 (if you have recently installed Sophos Enterprise Console v3). Clients installed with SAV 4.15 for Windows 9x should be upgraded to SAV 4.7 for Windows 95/98/Me. NOTE: The different between SAV 4.1x for Windows 9x and SAV 4.7 for Windows 9x is: 4.1x has the red "lightening bolt" systray icon 4.7 has a blue Sophos shield systray icon and incorporates Sophos AutoUpdate. If you have already upgraded all you clients from 4.1x then you can safe remove the CIDs from EM Library. More information on retired products and current packages that are available please see here: http://www.sophos.com/support/timeline.html Regards, Sophos Technical Support
  13. Hi Geoff, You might find this knowledge base article useful: http://www.sophos.com/support/knowledgebase/article/12825.html Also check that all the Sophos services are started OK. If you're still unable to open the EM Library console you can submit a support request: http://www.sophos.com/support/query Regards, Sophos Technical Support
×
×
  • Create New...