-
Posts
2,568 -
Joined
-
Last visited
Content Type
Forums
News
20th
EduGeek EDIT Conference
Blogs
Everything posted by Gongalong
-
Gongalong => SSR
-
It would be great to block the list that you get for executables in FSRM, and even better to block SWFs as well, or just generally to have lots of control. I've just spotted this thread http://www.edugeek.net/forums/windows/7041-stopping-exe-files-being-run-usb-stick-3.html
-
Hi All, Can anyone recommend any software for locking down USB drives? For the moment we're trying not to prohibit their usage, but we want to be able to lockdown what's run from them, a little like File Server Resource Manager. Does such a thing exist? TIA
-
Hi folks, Although I have done the SCCM configuration training, and have it installed, for the moment I simply don't have the time to wrestle with packaging up apps in the ideal way etc. My main concern for the moment is keeping applications up-to-date e.g. Java, Adobe Reader, Flash. Is there an alternative, a bit like an anti-virus client, that I can stick on a PC and administrate centrally to make sure PCs are updated? I'm ideally after recommended-because-have-used things, hence the post here. TIA
-
I'm being told it has sorted it, but currently 6,000 miles away :-/ We've used PCM for 2 years without any issue, albeit never say never. The client slowness problem seemed to be affecting launching of apps, not just network activity.
-
Are they still any good, or taken a quality nosedive?
-
I was under the impression that Linksys had died for some reason. Never seem to see their hardware any more. This 9-year old router still fab though.
-
Part 1 of the conclusion to this is that Sophos have become progressively more useless to the point where we had to ditch them. Their endpoint could not clear the virus from clients. I'm off-site, as technically on holiday in Brazil, but the on-site firstline technician contacted a number of anti-virus companies for help. The *only* company that was helpful was ESET. They gave several days of consultancy (for "free"), demonstrated their endpoint cloud clear the virus, gave install assistance etc. They've given us a 30 day trial and haven't asked for any money. Clearly though they would like to win our business. The school isn't completely out of the woods yet but the bulk of desktops/laptops now have the ESET client, and they are about to perform server scans (the servers aren't infected, but are hosting infected PDFs). ESET's endpoint doesn't have the capability yet to clear the PDFs, but apparently it's in the final phase of testing. It would be much easier to clean the PDFs than have to delete and reinstate, but if it comes to it that's what we'll have to do. Rumour has it we're not the only organisation affected by this virus, and some other much larger places have disabled their network to try and clear it. I'll update if there's anything else that people might find useful to know.
-
9-year old Linksys is working fine :-)
-
Love FTL. Played it quite a bit last Christmas. Not sure what it was about Shadowrun. A bit slow paced perhaps. I played the RPG back when it was launched and loved it. I suspect I'll only have time for Alien: Isolation now, but will see. Thanks all for the recommendations.
-
I'm not sure I can because it's ISP provided. I can't log in to it yet, so will need to call the ISP.
-
I've turned it off-and-on-again. No change.
-
Hi folks, Not a school issue, a "home" issue. I'm currently abroad at my in-laws. They're using an ISP (Vivo) provided wireless router, which is a rebadged D-Link DMG-6661. The wireless to my laptop drops fairly regularly, but all I have to do is reconnect and off it goes again. Annoying! Laptop is using an Intel Centrino N-1000 wireless chipset with 8.1. I've updated to the latest driver from the Intel site, no change. I do have an old Linksys WRT54G stashed here somewhere. Is there anything I can do to stabilise the D-Link, or am I better to just connect the Linksys to it and use that? TIA
-
Thanks both. I went for Shadowrun: Dragonfall, but was a little bored by it. Have switched to Alien: Isolation as I'm a huge fan of the film series. I've heard it's slow, so have been prewarned at least.
-
The staff member says they caught the power cable on the top left corner of the laptop, which lifted the casing away. Having looked in more detail, the base of the chassis is secured to the top by a screw. The hinge requires that this part of the case is solid for something to push against. With no solid chassis the hinge is free to move, so it's just a mess.
-
Hi folks, It's a time of year when I have to spend 3 weeks abroad with my in-laws. They spend a lot of time with the kids though, so it's my one chance in the year to play computer games. So I have 3 weeks to play one or more Steam games (on my rather old gaming laptop, so it might not be up to super duper demanding shtuff). (Steam because it's easy, but if it's easily available via digital download elsewhere then I can try and get it.) What's your recommendation for the best game this year on Steam based on the limits above? I like RPG, FPS, retro stuff. Less so beat 'em ups, puzzles, and arcade things, but probably still worth mentioning. TIA
-
Hi folks, As per my recent posts, we've had a virus outbreak that has potentially wrecked a lot of PCs, and could cause a lot of downtime on our network. With zero day attacks being common, and other forms of security almost being more important than anti-virus, what do other schools do in terms of best practice? For example, I have increased the number of file screens on our servers to prevent executable files from being in places where they are not needed. This would have probably helped a lot with our current outbreak, which was in part converting PDFs to EXEs (40,000 files were affected). Albeit we have to balance this with students who are programming – they are allowed EXE files, but only with a specific prefix. Do other schools prevent use of USB memory sticks? We don’t currently. What else do you do? Any suggestions/ideas welcomed! TIA
-
JJonas: You're right. I'm doing it right now. win: I think the thirdline company are going to spend a couple of days seeing whether it can be tackled with AV software, but the difficulty is knowing this for sure. We have 450 PCs, and use Ghost, so it will take around 30-60 days to reimage everything. Not impossible, but obviously not ideal either.
-
jmak: We have thirdline support exactly for this sort of situation i.e. when I'm away, so they're coming on-site tomorrow. The holiday's unavoidable, otherwise I would reschedule.
-
We use DPM, so it's based on retention periods, but I've recovered from two dates to a temporary location away from the network just in case. I've checked the restores and they appear clean. I've run a search on the network shares and there are around 40,000 EXEs. A large number are virus'd PDFs, but there's also a lot of other things that teachers are using.
-
Yes, been liaising with Sophos support since it was first found. I had hope initially, but they say they can only help if we use their Source of Infection tool to find it, and that's not working. EXEs are now blocked, but I haven't blocked PDFs yet. I agree re. the individual machine clean, I think that's the only way at this point.
-
ProCurve Manager isn't showing any high bandwidth usage across the switches. In terms of connection latency... Ping tests, or something more? They did to create on network shares. Today I added file screens across all shares to block the creation of any form of executable file. Not sure how I block them from running EXEs? Yep, we'll need to find something that works ahead of reimaging, otherwise my worry is the clients will just get reinfected. I did wonder about this. We could unplug all the fibres from our core switch and work around the school, although it still means finding working AV.
-
Unfortunately I'm now effectively on holiday, and not at the school. Are you referring to looking for them in Task Manager?
-
Some of the scanners here found a virus in the infected file, although I wonder if this is the root virus or just a side effect. Yes, very much so.
-
Thanks all for the replies. File Server Resource Manager, right? We use this to lock down EXEs for students, but I was thinking about widening it out for everything. Student create EXEs when programming, but we've added in an exclusion so that files starting with a certain prefix are allowed. We've killed a couple of tasks that were running on the server that may have caused a disk queue. Today the clients actually seem to be working again, so far. Will do. OK, not sure how to do that, but I'll research. My best guess is these infected PDFs. The virus is annoying enough to even change the executable file's icon to a PDF, so unwitting staff can easily mistake them, even though they've been told not to open PDFs. (Also for abillybob) This is the virus that Sophos picks up: Detailed Analysis - W32/Agent-AKJF - Viruses and Spyware - Erkennen und Entfernen von Web-Bedrohungen, Viren und Spyware | Sophos - Threat Center - Sicherer Schutz von Mobile, Cloud, Endpoint, Encryption, Email, Web, UTM Firewall, Wi-Fi, VPN und Serv Both I suspect. Infected PDFs are in the data shares of the servers. I don't think the servers are infected, but they're hosting the files. Clearly some clients are infected, and I'm sure of those are staff PCs because of where the infection is occurring. How is it running? Surely standard Users can't run files and thus would be blocking the spreading!? See the link above for the forms it takes, but because it's on client PCs it's basically an epic job. I'm hoping that Sophos can sort out their endpoint to properly destroy it. Thanks, will do that. The fact their on-access scanner cleans it, but their manual scanner doesn't worries me.
