Hello and welcome to CertForums.co.uk, here we host free active certification forums with links to the best free resources for Microsoft's MCSA MCSE MCDBA Cisco's CCNA CCDA and CCNP, and CompTIA's A+ Network+ i-NET+ and Security+ certifications in the UK. If you wish to post or use other advanced features you will need to register first. Registration is absolutely free and takes only a few minutes to complete so sign up today!

If you have any problems with the registration process or your account login, please contact support

Go Back   CertForums > Computing Support Forums > Software
Home Forums Register Search Today's Posts Mark Forums Read

New Sophos update unpleasantness

Post New ThreadReply
 
Thread Tools Display Modes
  #1  
Old 02-Oct-2008, 12:09 PM
dales's Avatar
dales dales is online now
its all smoke and mirrors
Posts: 739
Points: 595 dales has over 500 pointsdales has over 500 pointsdales has over 500 pointsdales has over 500 pointsdales has over 500 pointsdales has over 500 points
Power: 16
None
Join Date: 12 Sep 2006
Certifications: A+ MCDST MCP 271,272,270,290 ITIL F
WIP: 291 MCSA,maybe MCITP hmm?
New Sophos update unpleasantness

Hi all,

Just thought I'd give you all a heads up, since monday when a new update of sophos has been rolled out over the our network we have some users that are reporting that explorer.exe will randomly crash due to DEP kicking in. I'm one of the people affected, I thought it was just me to start with but when users started trickling in calls to me with the same problem it became clear that it was not just me needing to clean up.

The problem isnt specific to a service pack as I am running xp pro sp 3 most other users are sp1 or sp2 (no auto patch management here) so it purely seems to be a problem with out AV.

Just to let you know incase any of you are scratching your head, also check out this EE thread which suggests a workaround but I'd rather wait out to find the cure.

http://www.experts-exchange.com/OS/M..._23778594.html


Regards
Dale A+ MCDST MCP, ITIL V3 Foundation, MBCS
www.dales-diary.blogspot.com
My linkedin Profile


Somewhere there's danger, somewhere there's injustice...and somewhere else the tea is getting cold.
 
Reply With Quote
  #2  
Old 02-Oct-2008, 12:16 PM
Qs's Avatar
Qs Qs is offline
Semi-Honorary Member
Posts: 1,181
Points: 1283 Qs has over 1000 pointsQs has over 1000 pointsQs has over 1000 pointsQs has over 1000 pointsQs has over 1000 pointsQs has over 1000 pointsQs has over 1000 pointsQs has over 1000 pointsQs has over 1000 points
Power: 24
None
Join Date: 13 May 2008
Location: Lichfield, West Midlands
Age: 21
Certifications: HND Applied IT, CCNA
WIP: MCDST, MCP, A+, N+
So that's what the damn thing is! We also use Sophos and have had a few users reporting problems.

Rep given matey! Saved me going hunting!

Qs


Base 8 is just like Base 10, if you are missing two fingers.
 
Reply With Quote
  #3  
Old 02-Oct-2008, 12:31 PM
UKDarkstar's Avatar
UKDarkstar UKDarkstar is online now
Premium Member
Posts: 788
Points: 1609 UKDarkstar has over 1500 pointsUKDarkstar has over 1500 pointsUKDarkstar has over 1500 pointsUKDarkstar has over 1500 pointsUKDarkstar has over 1500 pointsUKDarkstar has over 1500 pointsUKDarkstar has over 1500 pointsUKDarkstar has over 1500 pointsUKDarkstar has over 1500 pointsUKDarkstar has over 1500 pointsUKDarkstar has over 1500 points
Power: 24
None
Join Date: 14 Jun 2008
Location: UK, South Coast, Dorset
Age: 46
Certifications: BA (Hons), MBCS, CITP
WIP: ITIL Foundation, MCSA/SE
I was a SOPHOS Partner for many years but gave it up in 2007 due to continued issues like this and the fact they seemed to be going more "Enterprise" in their outlook.

We switched to ESET with NOD32 and didn't have as many problems with clients.


 
Reply With Quote
  #4  
Old 02-Oct-2008, 02:15 PM
zebulebu's Avatar
zebulebu zebulebu is offline
Premium Member
Posts: 2,039
Points: 6109 zebulebu has over 4000 pointszebulebu has over 4000 pointszebulebu has over 4000 pointszebulebu has over 4000 pointszebulebu has over 4000 pointszebulebu has over 4000 pointszebulebu has over 4000 pointszebulebu has over 4000 pointszebulebu has over 4000 pointszebulebu has over 4000 pointszebulebu has over 4000 points
Power: 86
None
Join Date: 07 Aug 2006
Location: Croydon - arsehole of the universe
Age: 35
Certifications: A few
WIP: NCDA, VCP
Sophos blows - end of.

Worst Enterprise AV vendor I've ever used.

McAfee destroys Sophos in effectiveness, ease of management, robustness and reliability. I've always used Trend at a gateway level and McAfee internally - though a lot of people I know use NOD and Kaspersky and swear by them.

 
Reply With Quote
  #5  
Old 02-Oct-2008, 02:33 PM
dales's Avatar
dales dales is online now
its all smoke and mirrors
Posts: 739
Points: 595 dales has over 500 pointsdales has over 500 pointsdales has over 500 pointsdales has over 500 pointsdales has over 500 pointsdales has over 500 points
Power: 16
None
Join Date: 12 Sep 2006
Certifications: A+ MCDST MCP 271,272,270,290 ITIL F
WIP: 291 MCSA,maybe MCITP hmm?
got an email back from sophos not really a fix but might be of help:

Hi Dale,

Part of the recent update included a web content scanner BHO.

Can you turn off the Web Content Scanner to see if this helps?

To do this, in IE go to tools-->manage add-ons-->click sophos web content scanner and disable it.

Let me know if it helps.

All the best

Donald Tibbetts


I've applied it to my machine to see if it helps so i'll let you know how I get on.


Regards
Dale A+ MCDST MCP, ITIL V3 Foundation, MBCS
www.dales-diary.blogspot.com
My linkedin Profile


Somewhere there's danger, somewhere there's injustice...and somewhere else the tea is getting cold.
 
Reply With Quote
  #6  
Old 02-Oct-2008, 02:44 PM
Qs's Avatar
Qs Qs is offline
Semi-Honorary Member
Posts: 1,181
Points: 1283 Qs has over 1000 pointsQs has over 1000 pointsQs has over 1000 pointsQs has over 1000 pointsQs has over 1000 pointsQs has over 1000 pointsQs has over 1000 pointsQs has over 1000 pointsQs has over 1000 points
Power: 24
None
Join Date: 13 May 2008
Location: Lichfield, West Midlands
Age: 21
Certifications: HND Applied IT, CCNA
WIP: MCDST, MCP, A+, N+
Quote:
Originally Posted by dales View Post
got an email back from sophos not really a fix but might be of help:

Hi Dale,

Part of the recent update included a web content scanner BHO.

Can you turn off the Web Content Scanner to see if this helps?

To do this, in IE go to tools-->manage add-ons-->click sophos web content scanner and disable it.

Let me know if it helps.

All the best

Donald Tibbetts


I've applied it to my machine to see if it helps so i'll let you know how I get on.

I'll do it also. Will update the thread if I find anything else out.

Qs


Base 8 is just like Base 10, if you are missing two fingers.
 
Reply With Quote
  #7  
Old 02-Oct-2008, 02:56 PM
Modey's Avatar
Modey Modey is offline
Lifetime Member
Posts: 1,460
Points: 2061 Modey has over 2000 pointsModey has over 2000 pointsModey has over 2000 pointsModey has over 2000 pointsModey has over 2000 pointsModey has over 2000 pointsModey has over 2000 pointsModey has over 2000 pointsModey has over 2000 pointsModey has over 2000 pointsModey has over 2000 points
Power: 41
None
Join Date: 30 Apr 2005
Location: Northants, United Kingdom
Age: 37
Certifications: A+, N+, MCP, MCDST, MCSA 2K3
Quote:
Originally Posted by zebulebu View Post
Sophos blows - end of.

Worst Enterprise AV vendor I've ever used.

McAfee destroys Sophos in effectiveness, ease of management, robustness and reliability. I've always used Trend at a gateway level and McAfee internally - though a lot of people I know use NOD and Kaspersky and swear by them.
Yup, we ditched a Sophos about 18months ago and have never looked back. We use Panda AV now and it's much much better, but that wouldn't be difficult compared to Sophos.

It was the enterprise oriented version we were using btw.


Dom aka Modey
Other quals :- HND-Computer Studies, ECDL, C&G/NCC Application Programming, C&G/RTEEB Electronic Servicing, C&G Microcomputer Technology.
 
Reply With Quote
  #8  
Old 02-Oct-2008, 08:06 PM
Sparky's Avatar
Sparky Sparky is offline
Beer monster :)
Posts: 5,773
Points: 3531 Sparky has over 3000 pointsSparky has over 3000 pointsSparky has over 3000 pointsSparky has over 3000 pointsSparky has over 3000 pointsSparky has over 3000 pointsSparky has over 3000 pointsSparky has over 3000 pointsSparky has over 3000 pointsSparky has over 3000 pointsSparky has over 3000 points
Power: 98
None
Join Date: 15 Dec 2005
Location: Scotland
Age: 29
Certifications: MSc MCSE MCSA:M MCTS:Vista N+ A+
WIP: Server 2008 upgrade
Good time to migrate over to NOD32


 
Reply With Quote
  #9  
Old 02-Oct-2008, 08:08 PM
dales's Avatar
dales dales is online now
its all smoke and mirrors
Posts: 739
Points: 595 dales has over 500 pointsdales has over 500 pointsdales has over 500 pointsdales has over 500 pointsdales has over 500 pointsdales has over 500 points
Power: 16
None
Join Date: 12 Sep 2006
Certifications: A+ MCDST MCP 271,272,270,290 ITIL F
WIP: 291 MCSA,maybe MCITP hmm?
To be fair this is the first problem sophos has given us apart from that its just worked. I do remember a couple of jobs ago that sophos used to be quite a regular thing to be called out for mind you!


Regards
Dale A+ MCDST MCP, ITIL V3 Foundation, MBCS
www.dales-diary.blogspot.com
My linkedin Profile


Somewhere there's danger, somewhere there's injustice...and somewhere else the tea is getting cold.
 
Reply With Quote
  #10  
Old 03-Oct-2008, 12:22 AM
GoodApollo GoodApollo is offline
New Member
Posts: 1
Points: 0 GoodApollo has no points
Power: 1
None
Join Date: 03 Oct 2008
Wink Sophos released a KB Article addressing this

Quote:
Originally Posted by dales View Post
got an email back from sophos not really a fix but might be of help:

Hi Dale,

Part of the recent update included a web content scanner BHO.

Can you turn off the Web Content Scanner to see if this helps?

To do this, in IE go to tools-->manage add-ons-->click sophos web content scanner and disable it.

Let me know if it helps.

All the best

Donald Tibbetts


I've applied it to my machine to see if it helps so i'll let you know how I get on.
And here is the KB Article that confirms you are correct Dales. Initially, we thought it was a MS update that was causing DEP to crash explorer.exe

 
Reply With Quote
  #11  
Old 03-Oct-2008, 10:28 AM
KK20 KK20 is offline
New Member
Posts: 2
Points: 0 KK20 has no points
Power: 1
None
Join Date: 03 Oct 2008
registered to agree

I registered to add my agreement (was googling for DEP and sophos - I had an idea it was sophos)

We developed DEP explorer problems on our network this week. I run a very tight ship (a school). All users & machines locked down, no auto updates on programs OTHER than sophos. MS updates pushed from our server, software installed by GPO so I knew it wasnt another update or piece of software since sophos was the only piece of software that has updated this week. Users have no rights to install their own software. New devices are banned so USB pens dont work.

Plus - this weeks sophos update required a restart.

Do you have a link to the sophos KB article?

edit: found it http://www.sophos.com/support/knowle...cle/46484.html


Last edited by KK20 : 03-Oct-2008 at 10:34 AM.
 
Reply With Quote
  #12  
Old 06-Oct-2008, 10:09 AM
KK20 KK20 is offline
New Member
Posts: 2
Points: 0 KK20 has no points
Power: 1
None
Join Date: 03 Oct 2008
from sophos:


Thought I'd give you an update on this.

PROBLEM:

As per:
Sophos Anti-Virus for Windows 2000+: Data Execution Prevention message displayed when closing Windows Explorer

WORKAROUNDS:

As well as the three solutions outlined in this article (1. disable the scanner locally, machine by machine, 2. disable the scanner globally using a domain group-policy, or 3. stop Explorer.exe from loading the Sophos Web Content Scanner),

- there's now a fourth option, a special 'RC2' build of Sophos Anti-Virus that comes with the web-scanner switched OFF by default. I'd recommend this one over the previous 3. You need to set EMLibrary to download it, as follows:

1) 'Select parent' in the EMLibrary Console needs to be set to 'es-central-3...' , not es-latest-3.... (choose it from the drop-down 'select parent' menu - your normal credentials should work).

2) Under the 'select packages' menu, select either :
(i) 'Windows Endpoint Security and Control 8.0 with SAV 7.6.0 RC2 VDL4.34E' , or
(ii) 'Sophos Anti-Virus for Windows 7.6.0 RC2 VDL4.34E'

- the 'RC2' in the name means it's the special build.

If you unsubscribe from your 'normal' SAV / Endpoint Security package BEFORE subscribing to the RC2 version, then you'll be able to download the RC2 into your usual Central Installation Directory, and your client PCs will update to it automatically.

Alternatively, specify a different CID, then change the client-PCs' updating policy accordingly.

Hope this helps.

Simon B.
Sophos Technical Support, Abingdon.
Contact Sophos technical support - Enterprise solutions

 
Reply With Quote
  #13  
Old 06-Oct-2008, 05:17 PM
MLP's Avatar
MLP MLP is offline
Registered Member
Posts: 61
Points: 128 MLP has over 100 pointsMLP has over 100 points
Power: 4
None
Join Date: 02 Oct 2007
Location: Northants, England
Age: 28
Certifications: HND Computing
WIP: Not Decided
Thanks for this! I got this error on a machine just before leaving work today. I was just about to spend my evening searching for a fix, so you've saved my evening. Can play Halo 3 all night instead!

Rep Given.

Maria

 
Reply With Quote
Post New ThreadReply Spread this thread: Submit this thread to digg Submit this thread to del.icio.us


Go Back   CertForums > Computing Support Forums > Software


Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump

Similar Threads
Thread Thread Starter Forum Replies Last Post
CWNP Announces Update to Industry Standard CWNA Exam wagnerk News 0 04-Aug-2008 04:56 PM
Cisco 1841 - Update ? mke Routing & Switching 4 05-Feb-2008 04:14 PM
Microsoft to Force IE7 Update on February 12th tripwire45 News 0 21-Jan-2008 04:26 PM
SOPHOS Leehaa Software 6 05-Nov-2007 12:20 PM


All times are GMT +1. The time now is 04:16 PM.

Powered by vBulletin® Version 3.6.11
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
CertForums.co.uk (C) copyright 2003-2007 All Rights Reserved. Content published on CertForums.co.uk requires permission for reprint.
Hosted by Lunarpages