Strange problem at one site with AVG CloudCare v3.6.4. Only one of 3 particular PCs would ever appear in the console at once. Lets call them PC26 (Maint), PC29 (Chef) and PC31 (Accts). This week PC29 was listed, status ok, updates ok. It even had the correct label name against it showing that is was Chef's computer. I tried reinstalling PC31 which succeeded, but it appeared on the list with the name Chef rather than Accts - and PC29 dropped off the list. I relabelled it to Accts, then PC29 came back on the list instead but with the new label.
Took me a while initially to realise that all three were essentially sharing one database entry and the last change/install took precedence as far as the console list was concerned.
Also tried removing AVG CloudCare off all three PCs at once and using the AVG Remover tool, rebooting, then reinstalling each one. And the same again but with the brand new 4.0.2 release of Avast Business Cloudcare. No chance.
In the end, after 25 mins online with tech support, we used the 'setup.exe -b' command to re-register the clients to the CloudCare database and reset registry keys. This cleared the problem and all clients came up normally.
To use setup -b, start a command prompt with Admin rights. Then change to the appropriate directory, depending upon client and 32 or 64 bit, eg
C:\Program Files(x86)\AVG\CloudCare or
C:\Program Files(x86)\AVAST Software\Business Agent\
Showing posts with label antivirus. Show all posts
Showing posts with label antivirus. Show all posts
Friday, 17 November 2017
Wednesday, 2 March 2016
Backup, Backup, Backup ! Or what happens when you click on a Locky / Cryptolocker infected email attachment
I run an IT Services company providing IT Support in Preston, Lancashire. We recently had an incident where someone opened a fake invoice attachment in Word, then managed to enable macros and run some very suspicious code that triggered the Locky cryptovirus.
You might take the view that it'll never happen to you. But these emails are looking more authentic every week. Its only a matter of time until someone in your business triggers one. Read the story of How to fix a cryptovirus like Locky, Cryptolocker, Torrentlocker for more details of what happened and just how quickly it took hold.
The bottom line is you need layers of security
- so scan the incoming email for junk and viruses
- then scan on the computer or laptop for viruses with a different antivirus package
- keep a separate Malware manual scanner handy for a second opinion
- train your staff
- make multiple backups
The key to multiple backups is a full easy to access onsite backup, as well as an online backup stored in a datacentre. That needs to be offsite to protect from fire, flood and theft - and in some cases cryptovirus too.Use a backup that offers a history or file versioning.
Be aware that a file sync service such as Dropbox or Onedrive isn't necessarily a useful backup - whatever damage or deletion or amendment or encryption happens to your file, will by synced immediately to the datacentre and then to your other devices. This will happen before you've had time to react.
You might take the view that it'll never happen to you. But these emails are looking more authentic every week. Its only a matter of time until someone in your business triggers one. Read the story of How to fix a cryptovirus like Locky, Cryptolocker, Torrentlocker for more details of what happened and just how quickly it took hold.
The bottom line is you need layers of security
- so scan the incoming email for junk and viruses
- then scan on the computer or laptop for viruses with a different antivirus package
- keep a separate Malware manual scanner handy for a second opinion
- train your staff
- make multiple backups
The key to multiple backups is a full easy to access onsite backup, as well as an online backup stored in a datacentre. That needs to be offsite to protect from fire, flood and theft - and in some cases cryptovirus too.Use a backup that offers a history or file versioning.
Be aware that a file sync service such as Dropbox or Onedrive isn't necessarily a useful backup - whatever damage or deletion or amendment or encryption happens to your file, will by synced immediately to the datacentre and then to your other devices. This will happen before you've had time to react.
Tuesday, 2 December 2008
Antivirus XP 2008 and tdssserv.sys trojan / rootkit
Just had another encounter with this fiend - except this time it was too late to try and load Malwarebytes or AVG updates or Ad-Aware. They were all blocked, although internet access appeared ok for most sites. Trying to access AVG for example just bounced you back to a Google looking results page every time.
There's some good info over here and I was interested to see that the old Microsoft/Sysinternals Rootkit Revealer showed up the hidden components (the F-Secure Backlight rootkit eliminator showed up nothing). I booted off CD and manually removed them - the TDSSserv components were key. Was then able to start Windows and install Malwarebytes to clear up any loose ends.
It's getting rough out there.
There's some good info over here and I was interested to see that the old Microsoft/Sysinternals Rootkit Revealer showed up the hidden components (the F-Secure Backlight rootkit eliminator showed up nothing). I booted off CD and manually removed them - the TDSSserv components were key. Was then able to start Windows and install Malwarebytes to clear up any loose ends.
It's getting rough out there.
Saturday, 6 September 2008
Antivirus XP 2008 or 2009 virus/spyware removal
I've come across a few PCs in the past month with the Antivirus XP 2008 problem. Basically its some spyware that fakes your Security Centre to look like there's a problem and needs fixing. It looks very authentic. There's a very thorough write-up at The Register, Anatomy of a Hack.
Two of the infections I saw had got in past AVG. One had 7.5 Free and the other had v8 but slightly dated definitions - unlucky timing, I wouldn't hold it against the folks at AVG. My AVG 8 Pro spotted the .exe as soon as I copied it over to the PC.
I've heard of a couple of cases where people have had to put hours into extracting the bad and getting their PC back up and running - should have called Redleg tech support first ;-) Best fix I've come across has been the AntiMalware product from Malwarebytes. You can find it over here.
Two of the infections I saw had got in past AVG. One had 7.5 Free and the other had v8 but slightly dated definitions - unlucky timing, I wouldn't hold it against the folks at AVG. My AVG 8 Pro spotted the .exe as soon as I copied it over to the PC.
I've heard of a couple of cases where people have had to put hours into extracting the bad and getting their PC back up and running - should have called Redleg tech support first ;-) Best fix I've come across has been the AntiMalware product from Malwarebytes. You can find it over here.
Subscribe to:
Posts (Atom)

