This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Sophos WMI at logon

I posted this at the other sophos forum but they directed me here. Maybe some1 here can enlighten me.

Hi,

Could someone help me with the following problem.

We have a large network of computers that we like to keep as up to date as possible. For that we have created a logonscript that runs when the user logs in. This scripts checks multiple parameters and variables giving us an idea of the state of the computer.

One of the things we record is our sophos antivirus.
We connect via WMI to the correct namespace (securitycenter/securitycenter2) and read the basic information.
Running the script when the computer is booted results in a correct scan (sophos up to date and enabled) but when the script runs at logon, WMI keeps telling us sophos is disabled but up to date.
Both 32 as 64 bit systems and on different os.

Now i'm wondering, is this a problem with wmi giving us a false positive or is it sophos that doesn't start/write to WMI until after the user is logged on.

Any help on this matter is greatly appreciated.
Thanks

All our reports based on the data we get from the logon script are no longer compliant since it displays false positives.

This leads me to belive there are 2 possible answers.

- Sophos is enabled, but it doesn't tell WMI (that would suck)

- Sophos isn't enabled at all untill somtime after booting (sucks even more)

Tests with other AV products has not given any false positives yet so atm it leads me to belive this problem only occurs with sophos and could be potentially fixed.

Again, any info/help/insight would be appreciated

thx

:54433


This thread was automatically locked due to age.
  • Hi,

    Could the script query the state of the SAVService and SAVAdminService service before it makes the query to the Action Center to help troubleshoot timing?

    I assume that once logged on fully and it returns the correct state that is as the same user?

    Does the query return an error when querying the Action Center when run as a  login script?  It's not that it can't query.

    Regards,

    Jak

    :54447
  • results of sophos when booting:

    Sophos Anti-Virus Statusreporter    Running
    Sophos Anti-Virus    Running
    Sophos Agent    Running
    Sophos AutoUpdate Service    Running
    Sophos Device Control Service    Running
    Sophos Message Router    Running
    Sophos Web Control Service    Running
    Sophos Web Intelligence Service    Running
    Sophos Web Intelligence Update    Stopped

    SavService.exe    20141031112418.421875+060
    SAVAdminService.exe    20141031112435.218750+060

    this should normally also contain wmi information since i scripted it to do so but it does not.

    This is an example of what the log should also contain:

    (Sophos Anti-Virus {6BABF8F7-3EB6-BD1D-9167-8C5ECA060A29} 331776)

    :54453