I am, alarmingly, pretty close to being a system administrator for a 24 hour news network, especially at 5 AM when no-one else (from IT) is here. On the recommendation/insistence of our parent companies IT department (who are the actual system administators) we have been doing virus checks / repairs with sophos, even going so far as to use a command line program in safe mode.
So, first off, I cannot post specs because this is dozens of computers. Many are win 7 64 bit, some 32 and 64 bit XP, some server 2003, all pro versions where applicable. Secondly, many of these machines are completely seperate from the internet, and are only networked internally to the building (not to say they aren't still at risk of course). Thirdly, we have doen these scans and sophos installs not because we have seen any (like none) problems ourselves, but rather because the IT department that lives 500 Km away wanted us to.
Upon thurough scans most machines are clean. Yesterday I found 1 instance of MAL/VBcheMan-A, one MAL/BH-136, and a co worker found a couple too. For the most part we have been able to clean these machines and they have passed several tests since.
However, one of the tools we are using, the comand line app from sophos, is supposed to be run in command line safe mode. What I am finding is that on most machines (like I said, a wide veriety of machines and OSes), all of which are working perfectly well, I run into a crash and restart when trying to access safe mode. Sometimes this happens before the log-in screen, sometimes after i have enter my password and it has been accepted, and today 2 machines restarted as I was entering my password.
Now, these are broadcast machines, so they more or less have been built by bloody idiots, despite thier enourmous cost. But that it happens on such a diversity of machines concerns me. Google searches bring up nothing about this problem, although it is actually something I have seen before. I'm not look for a recipe to fix this, really I more or less have been able to work around it.
What I am hoping to get some feedback on is if anyone else has noticed this sort of thing before, and has any vauge guesses about what might cause it. My 2 guesses myself are:
1-This is indeed a virus / malware. Despite the scans etc that say this machine is clean, and the lack of symptoms, something is preventing safe mode to protect itself. US / Chinese government censorship applications maybe, we are a news orginization...
2- This is hardware "manufacturers" who have intentionally disabled safe mode in a typically wrong headed attempt to prevent piracy of their remarkably poorly designed broadcast systems. These are the kind of people who sell you a computer for $100,000 and then make its functionality depend on a 2$ usb dongle. Can you disable safe mode when building an OS?
Both ideas are kind of ridiculous, but then again in our society the two most likely personality types to "rise to the top" are psycopaths and sociopaths, so I am ready to accept ridiculous. Likewise, i am very open to any other suggestions. Thank you for your input, and feel free to direct me to useful threads or tell me this thread is in the wrong spot, I am new to this forum.
Ben