Hi,
It's possible that this is a much bigger problem than being presented.
I have now seen this problem with Sophos and MS AV programs and Steve Schwartz has observed the problem with Mcafee as well.
(FYI - Tuesday is commonly known as Microsoft Security update day)
In my attempt to copy the SSIQBACK.DLL file on my own Server to replace it for one of our clients who needed the file replaced after trying to run their Backup this morning. MS System Center Endpoint Protection intervened and removed the file as well as modified the Windows Registry entries. Please see below for details:
Category: Trojan Downloader
Description: This program is dangerous and downloads other programs.
Recommended action: Remove this software immediately.
System Center Endpoint Protection detected programs that may compromise your privacy or damage your computer. You can still access the files that these programs use without removing them (not recommended). To access these files, select the Allow action and click Apply actions. If this option is not available, log on as administrator or ask the security administrator for help.
Items:
file:F:\Softrak\system\SSIQBACK.DLL
regkey:HKLM\SOFTWARE\Wow6432Node\MICROSOFT\WINDOWS\CURRENTVERSION\SHAREDDLLS\\F:\Softrak\system\SSIQBACK.DLL
shareddll:HKLM\SOFTWARE\Wow6432Node\MICROSOFT\WINDOWS\CURRENTVERSION\SHAREDDLLS\\F:\Softrak\system\SSIQBACK.DLL
To correct the above I have done the following:
Before recovering the SSIQBACK.DLL file from last night's Image Backup of the Guest Machine, the SSIQBACK.DLL file was excluded from the AV program on the Host Machine & Guest Servers. This allowed the replacement of the deleted file on the Guest Machine successfully.
The question I have is how best to deal with the Adagio Windows Registry entries that the AV reported as changed? Softrak, please advise action required.
Unfortunately, after replacing the file on our Server, when I try to open any Adagio module, it now requests a WKSETUP. Softrak, please advise action required
One last thing,
in response to Andrew's suggestion to exclude the \Softrak\System folder,
I have been advised by our System Support technical people that the exclusion of any Folder from AV checking potentially creates an unacceptable opportunity for Hackers to save an Virus program to that Folder and as it is an AV excluded Folder their Virus programs can run without AV intervention. Softrak, please advise action required.
I suggest everyone immediately add an exclusion to their AV programs on all Workstation & Servers that run Adagio for SSIQBACK.DLL file. Ideally prior to an Adagio Backup being run.
Warmest regards,
Kerry Gullins
IOS Consulting Group.inc.
ps.s It might be advisable to move this to the private Forum until a complete resolution is available and then later add an edited version to the Technical Forum.
_________________________
Kerry Gullins
IOS Consulting Group Inc.
Phone. 778.819-1467
kerryg@iosgroup.com
www.iosgroup.com