Service Request Ticket - # 77060

Service Request Information

CONTACT Name Shahrokni, Seyed Abdollah   View open tasks   View tasks from last 30 days   Schedule Change Contact Date Mar 03, 2021 09:21 AM
Department Center for Academic Innovation Phone 88483
Location Email shahroknis@mail.wou.edu Request for more information Send 'Keeping in touch' email Send 'I'm thinking of you' email

SR INFO Type WOU #
Priority Equipment Type
Status Flagged
Description

Computer Edit WOU # 20130431[Edit Inv] (opens in a new window) Bldg/Room OFF PDR
Service Tag Description Apple iMac 27-inch, Intel Core i7 #Z0PG
Serial No. D25LP190F8JC Location PDR

CPU Intel Core i7(3.4GHz quad core, 6MB L3 cache)


OS MAC OS X 10.9 (Mavericks) Software MS Office 2011 Std for MAC from P0092469, Adobe CS6 Master Coll. from P0092469, ScreenFlow 4 from VISA2013003797; Gifox Pro v2.* VISA2019010246 Order11599 SR#;

TECHS Submitted by Stephanie Magee Contact smagee15@wou.edu 88925
Primary Technician Contact dcoons24@wou.edu 88925

Tracking

Entered by Date Memo
Dyllan Coons
Email

Public

Entered by Date Memo
Dyllan Coons Oct 25, 2024 02:38 PM
Task reassigned to Dyllan Coons.
Add Attachment
Dyllan Coons Oct 25, 2024 02:38 PM
Task reassigned to Dyllan Coons.
Add Attachment
Dyllan Coons Oct 25, 2024 02:38 PM
Picked up IMac (20130431) from CTL. Will get 
debanded then PDRed.
Add Attachment
David Kunz Oct 01, 2024 05:03 PM
Please PDR this device as it won't support further 
upgrades/updates
Add Attachment
Jack Martinis Sep 27, 2024 11:44 AM
Priority changed from (3) Priority to (5) Low Priority.
Add Attachment
Rowan Vasen Sep 16, 2024 08:03 AM
prob just needs pdr. given its age the OS probly 
doesn't support sentinel and then we can close this 
ticket 
Add Attachment
Rowan Vasen Sep 13, 2024 12:59 PM
escape room is ended now that seyed has left. thats 
why I said it is going to ctl 
Add Attachment
Andrew Zhen Sep 13, 2024 11:49 AM
is this iMac still used for the escape room? and 
does it need to go to pdr?
Add Attachment
Rowan Vasen Sep 11, 2024 08:23 AM
Task reassigned to UCS Tech.
Add Attachment
Rowan Vasen Sep 05, 2024 01:03 PM
Task reassigned to Rowan Vasen.
Add Attachment
Rowan Vasen Sep 05, 2024 01:03 PM
Status changed from (7) Waiting for Contact to (4) On Hold
Add Attachment
Rowan Vasen Sep 04, 2024 02:17 PM
I have heard that this iMac will be moved tmmrw to 
CTL in the library. and the contact seyed is leaving 
the university
Add Attachment
Tony Benedetti White Jun 21, 2024 01:19 PM
Task reassigned to UCS Tech.
Add Attachment
Tony Benedetti White Nov 14, 2023 01:38 PM
Contact changed from Sue Kunda to Seyed Abdollah Shahrokni.
Add Attachment
Tony Benedetti White Nov 08, 2023 08:23 AM
need to update OS to suppport sophos
Add Attachment
Tony Benedetti White Nov 03, 2023 01:46 PM
checked it out, does not have sophos and was unable 
to install sophos, was unsuccessful, might have to 
reimage? will talk to Monica and John on Tuesday.
Add Attachment
Adam Logan Nov 03, 2023 10:17 AM
**** Email from Seyed to me ****
Sounds good,  Adam! I'll see Tony, then! Thank 
you!

Have a great weekend!

Best,
Seyed
Add Attachment
Adam Logan Nov 03, 2023 09:55 AM
Task reassigned to Tony Benedetti White.
Add Attachment
Adam Logan Nov 03, 2023 09:55 AM
****This is an email****
Hi Seyed, I will be out of the office at noon, 
however I have spoken with my colleague Tony, and 
he has agreed to meet with you at the front 
enterance of Maaske at 1 pm. Does that work for 
you?
Add Attachment
Adam Logan Nov 03, 2023 09:50 AM
****Email from Seyed Shahrokni to Me ****

Hi Adam,

Thanks for reaching out!

Yes, the computer is still in the escape room in 
Maaske Hall 110 and I am happy to arrange a time 
with you today (except 11-12 and 2:30-4:30 pm) or 
any other time that works for you (if it 
makes scheduling easier, here's my Calendly link 
that you can use to book us a time). On another 
note, I have been meaning to reach out to UCS 
about this computer. Recently, UCS (David, Jenna, 
and Michael) programmed three laptops for us that 
we can now use in our escape rooms, and I was 
wondering if that iMac machine could also be set 
in the same way so that it is safe to be used in 
the escape room.

Thank you! I look forward to hearing from you!

Best,
Seyed
Add Attachment
Adam Logan Nov 03, 2023 09:49 AM
**** Email from me to Seyed Shahrokni ****

Hello Seyed,

I hope this message finds you well. We are in the 
process of reviewing open service requests and 
noticed that the case for computer 20130431[Edit Inv], last 
located in the escape room at Maaske Hall, is 
still active. It was reported that this computer 
might have bundleware and that Sophos could be 
deactivated.

We are committed to ensuring the security of our 
network and maintaining an accurate inventory. 
Therefore, we would like to investigate this issue 
and take any necessary steps to resolve it.

If the computer is still in the escape room at 
Maaske Hall, could you kindly arrange a convenient 
time for us to access it? Alternatively, you are 
welcome to bring the computer to our service desk 
at University Computing Solutions, located in ITC 
Room 009A.

Your assistance in this matter is greatly 
appreciated as we work towards a swift resolution.

Best regards,
--
Adam Logan
Add Attachment
Adam Logan Nov 02, 2023 04:38 PM
****This is an outgoing email****
Hi Laurie! 👋

We hope you’re doing well. We’re reaching out to 
kindly request your assistance in scheduling a 
suitable time for us to either come over and 
service your machine or pick it up. Unfortunately, 
we don’t have access to the first floor of Maaske.

We appreciate your cooperation and look forward to 
assisting you! 😊
Add Attachment
Public
Laurie McCoy Oct 09, 2023 02:38 PM
Task reassigned to UCS Tech.
Add Attachment
Laurie McCoy Aug 11, 2023 09:57 AM
Hello,



This machine is being used in Maaske 110 (which is an educational 
escape room). We have not been using it actively in a few months, 
but we're going to be actively using it in the Fall. 



Either way works for us! You're welcome to pick it up or just come 
in and work on it in the room. 



Thanks!
Add Attachment
Jenna Bauman Aug 11, 2023 08:51 AM
Please contact Academic Inovation and see if this 
computer is still there.  If it is, and Sue Kunda is 
still not using it and it's alright to do so, let's 
go ahead and delete her profile folder like was 
planned. 

INSTRUCTIONS:
Open Finder, click Go on the top menu bar and 
choose Go to Folder. Type /Users in the search bar, 
and delete the kundas folder (which 
stores all their data, and is where the quarantined 
malware is stored). You probably need 
to be logged into the Mac as an admin user in order 
to do this.

Let's also check and see if Sophos is installed, 
because Sopohos is NOT seeing the device anymore. 
It's possible the computer has been turned off for a 
while and maybe is not connected to Ethernet, so it 
hasn't communicated with Sophos and that's why it's 
not showing up.  Make sure the computer is connected 
to the internet and let Jenna know, and she'll try 
looking for it in Sophos again.
Add Attachment
Laurie McCoy Aug 10, 2023 01:21 PM
Status changed from (1) Pending to (7) Waiting for Contact
Add Attachment
Laurie McCoy Jun 06, 2023 09:06 AM
Task reassigned to Laurie McCoy.
Add Attachment
Lauryn Aronson Jun 01, 2023 08:15 AM
Status changed from (7) Waiting for Contact to (1) Pending
Add Attachment
Lauryn Aronson Jun 01, 2023 08:15 AM
changing status to pending so this doesn't get lost in the waiting for contact section
Add Attachment
Lauryn Aronson Feb 27, 2023 02:27 PM
Task reassigned to UCS Tech.
Add Attachment
Lauryn Aronson Jan 11, 2023 10:22 AM
Status changed from (1) Pending to (7) Waiting for Contact
Add Attachment
Lauryn Aronson Jan 11, 2023 09:58 AM
emailed to ask if there's a time we can come by
Add Attachment
Lauryn Aronson Jan 11, 2023 09:46 AM
Task reassigned to Lauryn Aronson.
Add Attachment
Jenna Bauman Jan 09, 2023 03:40 PM
We need to get hold of the w20130431. Next, open Finder, click Go on the top menu bar and 
choose Go to Folder. Type /Users in the search bar, and delete the kundas folder (which 
stores all their data, and is where the quarantined malware is stored). You probably need 
to be logged into the Mac as an admin user in order to do this.

Once the "kundas" folder is deleted, we need to run the Sophos scan again.  You can ask 
Jenna to do this if the scan ends up failing, because she can run the scan remotely. :)



Add Attachment
Jacob Limas Oct 24, 2022 02:59 PM
It didn't finish because there was so many files.
Add Attachment
Jacob Limas Oct 24, 2022 11:26 AM
I deleted the user profile and scanned it, I'll 
check it later today
Add Attachment
Jacob Limas Oct 21, 2022 03:04 PM
Since it looks like the user doesn't use it anymore. 
We can delete the user profile
Add Attachment
Lauryn Aronson Oct 13, 2022 12:19 PM
Task reassigned to UCS Tech.
Add Attachment
Lauryn Aronson Sep 29, 2022 04:13 PM
went to check this out. still has an alert but 
couldn't find where it was having issues. tried 
updating. left it scanning. john said to delete 

/Users/kundas/Downloads/Unconfirmed 
481059.crdownload

but it said we didn't have access to it. left it 
scanning. will need to go back and figure this out 
sometime.
Add Attachment
Lauryn Aronson Sep 20, 2022 12:44 PM
Status changed from (7) Waiting for Contact to (1) Pending
Add Attachment
Lauryn Aronson Sep 19, 2022 08:39 AM
****email****

Hi Lauryn,
Good morning! Yes, this iMac is in our office and 
operated by me (Seyed Shahrokni)! Is there 
anything we/I can do? Thanks! 🙂
Best,
Seyed
Add Attachment
Lauryn Aronson Sep 19, 2022 08:32 AM
emailed the center for academic innovation to ask if 
they have the imac
Add Attachment
Lauryn Aronson Sep 19, 2022 08:29 AM
****email****

Hi, Lauryn.

I'm assuming you're talking about the IMac I had 
from Academic Innovation (I no longer have it so I 
can't check on the number). I returned it to 
Academic Innovation approximately a month ago.

Best,
Sue
Add Attachment
Lauryn Aronson Sep 12, 2022 04:38 PM
****email****

I am off-contract until September 15th and will not 
be regularly checking this email until that date.
Add Attachment
Lauryn Aronson Sep 12, 2022 01:19 PM
****This is an outgoing email****
Hi Sue,

I need some additional information regarding service 
request #77060

Description:  [MEDIUM] Alert for Sophos Central 
[Western Oregon University]: We detected a 
potentially unwanted application

Do you know the location of an iMac with WOU number 
20130431[Edit Inv]?

Thank you,

Lauryn Aronson
UCS Tech.
Add Attachment
Public
Lauryn Aronson Aug 17, 2022 11:07 AM
Task reassigned to Lauryn Aronson.
Add Attachment
Lauryn Aronson Aug 17, 2022 11:07 AM
Status changed from (1) Pending to (7) Waiting for Contact
Add Attachment
Lauryn Aronson Aug 17, 2022 11:06 AM
****This is an outgoing email****
Hi Sue,

I need some additional information regarding service 
request #77060

Description:  [MEDIUM] Alert for Sophos Central 
[Western Oregon University]: We detected a 
potentially unwanted application

Do you know the location of an iMac with WOU number 
20130431[Edit Inv]?

Thank you,

Lauryn Aronson
UCS Tech.

Add Attachment
Public
Nathan Camuso Jan 12, 2022 01:37 PM
This computer is currently at the home of one of the 
Center for Academic Innovation faculty.
Add Attachment
Michael Ellis Dec 23, 2021 02:13 PM
Real time protection disabled
Add Attachment
Stephanie Magee Mar 03, 2021 09:21 AM
****This is an email****
Sophos Central Event Details for Western Oregon 
University

What happened: We detected a potentially 
unwanted application (PUA) on a computer. PUAs 
are not malicious but are often considered 
unsuitable for corporate networks.

Where it happened: w20130431

Path: /Users/kundas/Downloads/Unconfirmed 
481059.crdownload

What was detected: Bundlore

User associated with device: w20130431\kundas

How severe it is: Medium

What Sophos has done so far: We blocked access 
to the PUA.

What you need to do: In the Sophos Central 
Admin console, go to the Alerts page. Select 
the PUA alert. To remove the PUA, click Clean 
up PUA(s). If you want to let it run, click 
Authorize PUA(s). Authorize PUAs will apply to 
all your computers, not just the one in this 
alert.
Add Attachment