View Full Version : Network Controlled remover
openbsd-flipp
11-23-2004, 09:19 AM
I am a network administrator in a mid sized company. At least once an hour I get a call about spyware problems. Since I am not the person who built the network I am stuck cleaning other peoples messes. What I am looking for is a network controlled spyware removal tool. What would bennifit us the most is one that can integrate it self with active directory and/or be controlled by a central server. This would effectively quarter the ammount of work that I need to do during the day and allow me to work in the development aspect of my job more then a few hours a day. Does any one have any ideas about software like this?
How do they gain access to the net?
Independant of server, or THRU the server...
If its independant of the server, you will want to install an independant program to clean each client.
If its thru the server, there should be a SERVER side solution, including firewalls, AV, and Bot protection...
I think Spybot SD, and Spyblaster would be good Client side(LEARN to use them, advanced mode) VERY nice programs, and run them 1 time aweek to keep things clean.
openbsd-flipp
11-23-2004, 12:07 PM
What I would like to use is a similar setup that symantec has for the corporate customers. You install the server control software on the server and ermotely install the client software. All the updates get downloaded to the server and propagated through out the network. You can then schedule scans and removal accross the netwrok that are run hidden from the clients. The main problem that I have is the number of computers on the network makes it almost impossable to make sure everything is updated and running at our multiple locations.
Spybot has a Scheduler, that could be set for 12am(midnite) when no one is useing it...
Run and auto fix... Not sure about updating tho..
But you didnt tell me if they are client side access, or Server access to the web.
openbsd-flipp
11-23-2004, 12:55 PM
i would prefer server side access only but client side would work as well
If the client has DIRECT access to the net, you MUST install protection on the CLIENT.
If it is run thru the SERVER, the server can controll access, and protection it self.
Is IE run/loaded from the server or the client... SAME idea..
openbsd-flipp
11-23-2004, 01:42 PM
The network is all connecting through privoxy to help knock down the ammount of crap brought into it but there is still some str8 access to the web. I am not filtering out some sites because they require direct access to load the admin data.
Then i would load it on the client side, to cut the load...
Its that, or the server must load and run the software accross ALL the clients itself, and that could take ALOT of time.
You could set up a configuration on the server, that see's each client as a HD, and is read as such. I wouldn't leave this config up, as Virus and bots can run thru it.
But most Botware, only checks the config of the system it is on...The reg, and config of the system it is on, ONLY.
llbbl
11-24-2004, 05:44 AM
sounds like the new job is going well. :D
llbbl
11-24-2004, 05:55 AM
Here u go bro this is what u are looking for.
http://www.mcafeesecurity.com/us/products/mcafee/antivirus/desktop/vs_spyware.htm
* Corporate/Business Application -
Industry’s first and only commercial/industrial grade "Anti-Spyware" protection with best-in-class management software.
* Extended potentially unwanted programs (PUPS) support -
Ensures greater system stability by scanning for PUPS attempting to modify the registry
* Single Agent Solution -
Seamlessly integrates with McAfee VirusScan Enterprise 7.1 and 8.0i enhancing VirusScan Enterprise with registry/file scanning and cleaning
* Centralized management and reporting -
Integration with McAfee ePolicy Orchestrator and ProtectionPilot provides a complete security management solution, including detailed graphical reporting, from a single console
llbbl
12-15-2004, 08:37 AM
Hey I found this also. More Enterprise level Spyware remover programs.
http://www.webroot.com/products/spysweeper/enterprise/
Webroot Spy Sweeper Enterprise provides comprehensive spyware and adware protection for corporations. Using a client / server architecture, Spy Sweeper Enterprise proactively detects and removes all forms of spyware, adware and other unwanted programs within the organization. Spy Sweeper Enterprise effectively manages the corporate spyware threat by reducing security risks, minimizing support requests and reestablishing computing and network performance.
Webroot Spy Sweeper Enterprise provides
* Centralized management via the admin console
* Manual or automated deployment of definition updates and product upgrades
* Customizable protection and security policies
* Reporting capabilities for malicious threats by date and type of spyware detected
* Comprehensive detection and elimination of spyware, adware and other unwanted programs
vBulletin® v3.7.0, Copyright ©2000-2008, Jelsoft Enterprises Ltd.