Solved

deployment kaspersky antivirus

Posted on 2010-08-18
22
1,783 Views
Last Modified: 2013-11-22
dear all
we bought kaspersky business space edition for 20 users
i installed the administration kit on my server and i tried to
deploy the agent and anti-virus from administration kit but
we failed to do that because installer have to go to PC and
uncheck the file and printer sharing from windows firewall settings page and uncheck use simple file sharing from folder options page manually that mean if the customer has 100 workstations he has to go to each PC and enable above two features manually is that correct please advice?
please advice
0
Comment
Question by:ashraf2002
  • 8
  • 8
  • 4
  • +2
22 Comments
 
LVL 16

Expert Comment

by:Carol Chisholm
ID: 33462703
0
 
LVL 2

Expert Comment

by:aamsoh
ID: 33462729

You can change the firewall settings via Group Policy. Please go through with this article, it will help in you.
 
http://technet.microsoft.com/en-us/library/bb490626.aspx

NOTE: DON'T FORGET TO CLICK "HELPFUL COMMENTS YES"
0
 
LVL 6

Expert Comment

by:robbe
ID: 33462746
GPO is the way to go. Alternativly you can use a script to open the firewall. More info can be found here: http://www.activexperts.com/activmonitor/windowsmanagement/scripts/networking/windowsfirewall/#EFPSTWF.htm

The script can also be pushed trough GPO but i'd suggest to use GPO to open the firewall.
Set objFirewall = CreateObject("HNetCfg.FwMgr")

Set objPolicy = objFirewall.LocalPolicy.CurrentProfile



Set colServices = objPolicy.Services

Set objService = colServices.Item(0)

objService.Enabled = TRUE

Open in new window

0
 

Author Comment

by:ashraf2002
ID: 33462752
but i can use group policy in domain environment only what about work-group?
0
 

Author Comment

by:ashraf2002
ID: 33462772
dear robbe
could you please help with the steps to built script and use it?
best regards
0
 
LVL 8

Expert Comment

by:TheMak
ID: 33462773
Also enable remote administration in Computer Configuration -> Administrative Templates -> Network -> Network Connections -> Windows Firewall
By default simple file sharing is disabled when a XP Pro computer is joined to the
domain. There is a security policy/security option that
you could try to configure. It is for " network access:sharing and security
model for local accounts ". Configure it to be classic -local users. You
logon to a known secure XP Pro domain member as a domain admin and use the Group Policy edit
mmc snapin and browse to the domain level GPO you want to configure you can
do it that way and it should apply to XP Pro computers within the scope of
influence of the policy you modify. It may already be set to "classic"
Regards


0
 
LVL 6

Expert Comment

by:robbe
ID: 33462882
just copy the contents op the script in a VBS file and run it on the clients. If you are in a workgroup setup you will need to get the script running on each pc. You could create a script to copy it to the startup folder in de startmenu for the user of each pc.  There is a script here to run scripts against multiple computers: http://gallery.technet.microsoft.com/ScriptCenter/en-us/a29407e2-dd64-4311-8f7c-796733959240

Also note that if you would like to call the script from a batchfile you can have to use 'cscript <name of the file>'
0
 
LVL 8

Expert Comment

by:TheMak
ID: 33462995
but i can use group policy in domain environment only what about work-group?  I think standard profile will make your group policy working for workgroup computers.
 
Just A Thought
0
 

Author Comment

by:ashraf2002
ID: 33509074
dear all
is it possible to disable simple file sharing using GPO please advice ?
best regards
0
 
LVL 8

Expert Comment

by:TheMak
ID: 33509127
Title: Disable Simple File Sharing Question: How do I disable "Simple File Sharing" on Windows XP machines through Group Policy?  
http://www.experts-exchange.com/OS/Microsoft_Operating_Systems/Server/Q_22646619.html
0
 

Author Comment

by:ashraf2002
ID: 33509620
dear all
i need the steps to achieve disable simple file sharing using GPO in domain environment is that possible please advice?
best regards
0
Is Your Active Directory as Secure as You Think?

More than 75% of all records are compromised because of the loss or theft of a privileged credential. Experts have been exploring Active Directory infrastructure to identify key threats and establish best practices for keeping data safe. Attend this month’s webinar to learn more.

 
LVL 8

Expert Comment

by:TheMak
ID: 33509676
I think In domain environment by default simple file sharing is disabled. Check your domain users and let me know if dimple file sharing is not disabled.
Regards,
 
0
 

Author Comment

by:ashraf2002
ID: 33509878
i checked the users but it is still enabled
0
 
LVL 8

Expert Comment

by:TheMak
ID: 33510227
Follow the article link which I have given ealier, anyhow If you like you can copy this in notepad and save that notepad file with .adm extension and import that .adm extension file in Group policy on server side. After importing you will see custom Policy settings\windows explorer under computer configuration\Administrative templates..... Right click the custom policy and select view--> filters and uncheck the box "only show policy settings that can be fully managed" and press "OK".... Now you will see that "Simple File Sharing Option"..
 
CLASS MACHINE
CATEGORY !!category
CATEGORY !!WindowsExplorer
POLICY !!SimpleFileSharing
KEYNAME "SYSTEM\CurrentControlSet\Control\Lsa"
EXPLAIN !!SimpleFileSharing_Explain
VALUENAME "ForceGuest"
VALUEON NUMERIC 1
VALUEOFF NUMERIC 0
END POLICY
END CATEGORY
END CATEGORY
[strings]
category = "Custom Policy Settings"
SimpleFileSharing = "Simple File Sharing"
WindowsExplorer = "Windows Explorer"
SimpleFileSharing_Explain = "Enable to enable Use simple file sharing.
Disable to disable Use simple file sharing."
 
0
 
LVL 8

Expert Comment

by:TheMak
ID: 33510248
Sorry forgot to attach the screen shot of the policy,

Simple-File-Sharing-GPO.JPG
0
 

Author Comment

by:ashraf2002
ID: 33514372
dear all
could you please advice how can we import the *.adm file to GPO?
best regards.
0
 
LVL 8

Expert Comment

by:TheMak
ID: 33514819
Right click on Administrative Templates--> Select Add and remove Templates-->click on ADD and then browse and give the location of the .ADM template and select the .ADM file and click open...... then close the window and you will see the custom policy.
 
Regards,
 
0
 

Author Comment

by:ashraf2002
ID: 33515393
dear all

we copy the commands that you given in above solution

CLASS MACHINE
CATEGORY !!category
CATEGORY !!WindowsExplorer
POLICY !!SimpleFileSharing
KEYNAME "SYSTEM\CurrentControlSet\Control\Lsa"
EXPLAIN !!SimpleFileSharing_Explain
VALUENAME "ForceGuest"
VALUEON NUMERIC 1
VALUEOFF NUMERIC 0
END POLICY
END CATEGORY
END CATEGORY
[strings]
category = "Custom Policy Settings"
SimpleFileSharing = "Simple File Sharing"
WindowsExplorer = "Windows Explorer"
SimpleFileSharing_Explain = "Enable to enable Use simple file sharing.
Disable to disable Use simple file sharing."

and save it with .adm extension and when we add the file .adm to the gruop policy there is an error message appear.
see attached file.
please advise.

best regards.
erroe-add-policy.jpg
0
 
LVL 6

Expert Comment

by:robbe
ID: 33515489
Can you try this:

CLASS MACHINE
CATEGORY !!MyCategory
CATEGORY !!WindowsExplorer
POLICY !!SimpleFileSharing
KEYNAME "SYSTEM\CurrentControlSet\Control\Lsa"
EXPLAIN !!SimpleFileSharing_Explain
VALUENAME "ForceGuest"
VALUEON NUMERIC 1
VALUEOFF NUMERIC 0
END POLICY
END CATEGORY
END CATEGORY
[strings]
MyCategory = "Custom Policy Settings"
SimpleFileSharing = "Simple File Sharing"
WindowsExplorer = "Windows Explorer"
SimpleFileSharing_Explain = "Enable to enable Use simple file sharing.
Disable to disable Use simple file sharing."
0
 
LVL 8

Expert Comment

by:TheMak
ID: 33518397
I don't know why its giving problem, anyhow I got some thing easier then what you have above,
Disabling Simple File Sharing on Windows computers

Computer Configuration -> Windows Settings -> Security Settings -> Local Policies -> Security Options
-> "Network Access: Sharing and security model for local accounts": "Classic - local users authenticate as themselves"  
http://www.sophos.com/support/knowledgebase/article/12837.html 
Regards,
0
 
LVL 6

Accepted Solution

by:
robbe earned 500 total points
ID: 33518471
0
 

Author Comment

by:ashraf2002
ID: 33548902
dear all,

we have aproblem when we want to remove mcafee antiviruse from windows 7 using administration kit and the follwing message is appeare and after we install the network agent manually in target computer. the message is : " the computer is proably disconnected from the network cannot download the deinstallation tool using networkagent because is not installed on target computer ".

please advice.

regards.
0

Featured Post

Is Your Active Directory as Secure as You Think?

More than 75% of all records are compromised because of the loss or theft of a privileged credential. Experts have been exploring Active Directory infrastructure to identify key threats and establish best practices for keeping data safe. Attend this month’s webinar to learn more.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

As more computers now shipped with 64-bit version of Windows, more users are now using this Operating System.  So it's important to be aware how some 32-bit diagnostic tool works on these systems, so we know what to expect when analyzing the logs an…
PREFACE The purpose of this guide is to explain how to manually move a SEP client to a different client group by performing steps on the client-side. These steps may prove particularly useful because they allow the client to move after it has alrea…
This Micro Tutorial demonstrates using Microsoft Excel pivot tables, how to reverse engineer competitors' marketing strategies through backlinks.
Many functions in Excel can make decisions. The most simple of these is the IF function: it returns a value depending on whether a condition you describe is true or false. Once you get the hang of using the IF function, you will find it easier to us…

867 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

21 Experts available now in Live!

Get 1:1 Help Now