ML
    • Recent
    • Categories
    • Tags
    • Popular
    • Users
    • Groups
    • Register
    • Login

    A Little Embarrassed to Even Ask This......RE: Hosts File / Windows 7

    IT Discussion
    5
    17
    2.2k
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • Bill KindleB
      Bill Kindle
      last edited by

      So right now we have:

      • list item Antivirus

      • list item UAC / Admin rights

      • list item Malware

      1 Reply Last reply Reply Quote 0
      • DashrenderD
        Dashrender
        last edited by

        Sounds like you're in a rough spot. Not sure there is anything much you can do since you can't remove local admin rights, therefore you can't lock it down. I suppose you could find and install a file monitoring softaware that sends its logs to the server.

        Do you report to these sales people? or do you report to the owner who is the sales person?

        Bill KindleB 1 Reply Last reply Reply Quote 0
        • Bill KindleB
          Bill Kindle @Dashrender
          last edited by

          @Dashrender said:

          Sounds like you're in a rough spot. Not sure there is anything much you can do since you can't remove local admin rights, therefore you can't lock it down. I suppose you could find and install a file monitoring softaware that sends its logs to the server.

          Do you report to these sales people? or do you report to the owner who is the sales person?

          Actually this is the Sr. Applications Engineer for our US Office, he's my direct report before it goes to the owner over in the UK. This is because my main job duties are support. IT for our US operations is the other half.

          1 Reply Last reply Reply Quote 0
          • scottalanmillerS
            scottalanmiller
            last edited by

            Sounds like you have a malicious, rogue user. The are local admins, they are likely making the changes and lying. I would escalate this over them. They are setting you up.

            Bill KindleB 1 Reply Last reply Reply Quote 0
            • Bill KindleB
              Bill Kindle @scottalanmiller
              last edited by

              @scottalanmiller said:

              Sounds like you have a malicious, rogue user. The are local admins, they are likely making the changes and lying. I would escalate this over them. They are setting you up.

              I would like to think that's not the case, but the last couple of 'issues' have really made my meter go off the scale........

              Bull_Shit_Detector_2.jpg

              Same user was saying my Meraki AP was garbage because their Samsung S4 constantly dropped wifi.........yeah. Only device doing that too.

              scottalanmillerS 1 Reply Last reply Reply Quote 0
              • scottalanmillerS
                scottalanmiller @Bill Kindle
                last edited by

                @Bill-Kindle said:

                @scottalanmiller said:

                Sounds like you have a malicious, rogue user. The are local admins, they are likely making the changes and lying. I would escalate this over them. They are setting you up.

                I would like to think that's not the case, but the last couple of 'issues' have really made my meter go off the scale........

                Bull_Shit_Detector_2.jpg

                Same user was saying my Meraki AP was garbage because their Samsung S4 constantly dropped wifi.........yeah. Only device doing that too.

                Sounds like either non-technical or malicious. They hosts file interaction sounds malicious. Being an idiot doesn't mean that you blame others for your failings. Being an ass does.

                Bill KindleB 1 Reply Last reply Reply Quote 0
                • Bill KindleB
                  Bill Kindle @scottalanmiller
                  last edited by

                  @scottalanmiller I'm doing some more sluething right now and Symantec may indeed be the cause. The Sonar feature apparently does monitor for alterations and protects against it (which is good IMHO) and a copy was made of the file on the 12th, of the same file...........

                  Maybe if Nick or Richard see this they can clue me in on how I can avoid this when I deploy Webroot next week, or at least make an exception to this.

                  Did I mention this user never placed a ticket either? lol

                  1 Reply Last reply Reply Quote 0
                  • Bill KindleB
                    Bill Kindle
                    last edited by

                    And there it is:
                    http://www.symantec.com/business/support/index?page=content&id=HOWTO81119#v74752971

                    1 Reply Last reply Reply Quote 0
                    • scottalanmillerS
                      scottalanmiller
                      last edited by

                      Who is responsible for having symantec in there?

                      Bill KindleB 1 Reply Last reply Reply Quote 0
                      • Bill KindleB
                        Bill Kindle @scottalanmiller
                        last edited by

                        @scottalanmiller said:

                        Who is responsible for having symantec in there?

                        hides 🙂

                        It's what our UK office has been using since before I started, so in an effort to not rock the boat too much with the other System's Admin I tried to keep everything similar so that things are uniform across the network. Since then, I've been given a little more leway with IT decisions here in the US office. I was even scoffed at by this same user this morning for saving the company a few dollars by switching to Webroot and getting an extra year compared to the costs I was looking at for renewing with Symantec.

                        1 Reply Last reply Reply Quote 0
                        • scottalanmillerS
                          scottalanmiller
                          last edited by

                          Blame the British then 😉

                          1 Reply Last reply Reply Quote 1
                          • 1 / 1
                          • First post
                            Last post