-
Posts
2,568 -
Joined
-
Last visited
Content Type
Forums
News
20th
EduGeek EDIT Conference
Blogs
Everything posted by Gongalong
-
Hi folks, Our virus problems continue, and it’s getting a bit desperate. As background, we saw the first signs of the infection via Sophos “threat detection” last Tuesday/Wednesday. Our backups suggest the virus hit predominantly the Friday before that (28th Nov). At least one thing the virus is doing is converting PDFs into EXE files. The EXE files presumably host the virus, but they also display the PDF if clicked on. Certainly if you browse to a directory on a PC using Sophos it triggers a “threat detection”, as does scanning any files/folders with these files in. Sophos are struggling. Because this is a zero day attack their software isn’t doing a great job of cleaning the virus. Bizarrely their on-access scanner does clean it, but not their scheduled or right-click/forced scan. We are using their Source of Infection tool (Sophos Source of Infection Tool) to try and spot the problem, but needless to say are having no luck getting trapped locations to infect. Last week we were running scans continually, because it takes so long on the file servers, so inevitably things were slow but usable. The bigger problem is this week. Particularly from Tuesday onwards the “network” has almost ground to a halt, specifically classroom PCs are so slow they’re unusable e.g. logging on/off, opening files from the network. I did ramp up the virus checking, so that both clients and servers are performing on-access scanning, so I have disabled the latter to see if that helps but it doesn’t seem to be. I can’t spot anything obviously wrong from a server load perspective – low CPU and RAM usage. Also we use ProCurve Manager, so I know the switches aren’t under load. It’s a bit less clear if the SAN is under load (we run a two host Hyper-V cluster, joined to a single SAN) although I’m doing some more monitoring of that. It’s possible there’s an issue there. The catastrophe situation is basically if the students can’t use PCs, and that’s where we’re at. Clutching at straws I’m debating whether to try a small roll out of MS Endpoint from SCCM, to see if that is better at spotting the infection. Other than that I’m stuck for ideas. Sophos should be continuing their research, but need their so called “Source of Infection”. To add to the problem I’m away on holiday (unavoidably) from tomorrow until the start of the Spring term, so we have a thirdline consultant providing cover. Other than the above I’m stuck for ideas. Anyone have any suggestions? TIA
-
The LA sent the installs through from Capita. I've yet to try and deploy them and it will have to wait until Spring Term as I'm off on leave now. The client's still working for the moment though.
-
We paid a lot for Sophos (£5k over 3 years IIRC), but the renewal was due just when I started here and I didn't feel I was in a position to make huge change at that time. Their support has been good though.
-
How good is the administrative side of ESET, clear and straight-forward?
-
difinity: I'm not sure. Sophos are putting significant effort into identifying it, and are "narrowing down the source".
-
Because tens of thousands of PDFs are infected, and the Sophos on-access scanner is stopping people from executing them, I'm leaving them there for the moment. I'm monitoring the generation of EXE files and there's no growth, in fact they are slowly reducing as some are getting cleaned up. I'm creating a belt and braces backup, because we use DPM with retention periods, so just in case those retention periods expire I have what should be a clean set of files to hand. Certainly a lesson in dealing with a virus and disaster recovery...
-
Just to update, turns out the virus we have is a zero day attack as far as Sophos are concerned, so particularly nasty. Resolution continues...
-
Annoyingly we have to go through the LA for SIMS support. Still using Sophos? My worry with a data restore is that the clock is ticking. We use DPM, and it keeps between 30-60 days of backup, depending on the exact server. In fact that's just for our file servers. For SIMS I naively keep only 7 days of the SIMS share folder, and the infection had already taken hold before that time.
-
Does anyone use Sophos? Good or bad experiences with it?
-
(Just to clarify, in this case only the data shares on the servers were infected. The servers themselves weren't running the virus.)
-
Hi All, Following on from my other post, what would others do if suffering a mass virus infection on their servers? It's a difficult balance between keeping the system in production, but not allowing more infection to spread. In our case it looks like the anti-virus (Sophos) is at least identifying the virus now, and cleaning or quarantining (oddly it seems to vary). I've also taken some steps to ensure every endpoint is working correctly. Based on the above I've left the servers in production, because of the huge issues it would cause to take them offline. The worst of this is the SIMS share on the SIMS server appears to have been partly corrupted, but that was using some other LA provided anti-virus (McAfee). Is/was this a good approach, or would you have approached differently? TIA
-
Yes, I've had several discussions with Sophos. Support has been variable - clearly some of it is outsourced, and they troubleshoot from a script. It transpires some bits on the server weren't working properly, but it isn't clear enough there are problems. Email reporting doesn't seem to be working, so something still to resolve. Oddly it's not able to clean all the files, so I've sent some samples off.
-
Heh, so much for the expert trainer! This seems like a reasonable guide for setup, although it's more involved than I'd like. I guess this is why it's cheaper using System Center 2012 Configuration Manager - Part 6. Adding the Endpoint Protection role, configure Alerts and custom Antimalware Policies. - Configuration Manager 2012 - www.windows-noob.com
-
Ah, after this it asks for the location of the CONNECT.INI. I give it, and then SIMS starts. On a second run I get the same upgrade error, no request for the CONNECT.INI, and SIMS starts. It's something I guess, but the error isn't ideal and I can probably workaround it with a cloned PC.
-
I get as far as deploying the client, but when I run it I get "Digital Signature Failure. The SIMS setup file SIMSApplicationSetup has failed its digital signature check. Your SIMS workstation has not been fully upgraded. Please contact your technical support provider."
-
In the SCCM training I just remember an option for deploying it and no other choice :-/ In related news http://www.edugeek.net/forums/mis-systems/146410-virus-corruption.html
-
Hi All, Mid-week we spotted a nasty virus infection on our network (Agent-AKJF). It was bad enough that Sophos wasn't addressing it correctly, but the LA had put McAfee on our SIMS server and it doesn't seem to have spotted it all. It has targeted EXEs and PDFs on the shared drive, but the server itself and SIMS database appear fine. I have removed McAfee and installed Sophos, which has at least found and cleaned up the virus, but I suspect some of the EXE files have been corrupted and/or quarantined. I've tried copying the SIMS\Setups folder from a backup from a week ago (as far as our principal backup goes) but that also appears to be affected by the virus. The other backup I have is from June and that appears problematic also, perhaps because it's too old. In short, the problem is I can no longer deploy the SIMS client, although it makes some of the right noises it doesn't complete properly and I cannot launch SIMS on the client. Coincidentally we're due to upgrade both the server's Windows version and SQL version in the Spring half term (unless we can bring this forward), so the question is whether there's some easy way to repair the SIMS install but without involving the LA? I'm assuming that migrating to the new server with the new SIMS install will resolve these issues. We might be able to limp along until Christmas or half term because I can image new PCs with an image from a PC that has the SIMS client. Advice appreciated! TIA
-
From what I remember of my SCCM training it just gets deployed to everything with a CM client, no choice? Do you know if it plays well with Hyper-V? I'm hoping so, because it's MS software.
-
Hi folks, We've just had a major virus issue (Agent-AKJF) on our Windows network, while using Sophos. There was some problem with Sophos vs. the server console, but even so the console isn't particularly great, it's expensive, and with this and the virus incident I'm not that impressed. (There was also the infamous time where it quarantined its own software in 2012.) I hear polar opposite opinions about MS Endpoint, which I can deploy with SCCM. It's very cheap but difficult to control with SCCM. Some people say it's great, others awful. I would like something straightforward to control, clear on reporting, and of course effective. What are others using and can recommend, or not? TIA
-
We're in north-east Hampshire. I've seen some stories of laptops sent off to Internet companies advertising a repair service, and the laptops don't come back, hence I'd prefer to use a recommended site.
-
Sadly this is accidental damage, as the laptop has a 3-year warranty.
-
Hi All, Can anyone recommend a 3rd party company for laptop repair, specifically Lenovo? Lenovo themselves are stupidly expensive, to the point where it’s cheaper to buy a replacement. I’ve used Topaz before for Toshiba, and they’re excellent, but sadly only repair Toshiba Toshiba laptop repairs :: Topaz Support Ltd - Toshiba laptop repair and service specialist TIA
-
Hi folks, This is perhaps more a question of etiquette, but when adding applications are there any "must do's"? To add a bit more detail, is it just a case of following the "wizard" and is that sufficient where no additional changes are required, or should other property fields be filled out after the application is added, or as part of the wizard process? To emphasise, this is on the assumption it's a straightforward MSI with no transforms or other changes. TIA
-
What type of subscription, and are they listed as a separate item in the O365 header?
-
Hi folks, Anyone seeing groups yet? This article suggests they should be active, and we have an E1 subscription, yet I don't see them: Exploring Office 365 Groups | Office 365 content from Windows IT Pro TIA
