Service Request Ticket - # 77106

Service Request Information

CONTACT Name Caires-Hurley, Jaclyn   View open tasks   View tasks from last 30 days   Schedule Change Contact Date Mar 16, 2021 01:58 PM
Department Education & Leadership Phone 89322
Location Email hernandezj@wou.edu Request for more information Send 'Keeping in touch' email Send 'I'm thinking of you' email

SR INFO Type WOU #
Priority Equipment Type
Status Flagged
Description

Computer Edit WOU # 20190242[Edit Inv] (opens in a new window) Bldg/Room RWEC 115
Service Tag DQP8PY2 Description Dell OptiPlex 7060 SFF desktop, i5-8500 3Ghz 6core
Serial No. DQP8PY2 Location Jaclyn (Hernandez) Caires-Hurley, 2nd workstation

CPU intel i5-8500(6-Core/Thread,9MB Cache, up to 4GHz)


OS Windows 10 Enterprise 64bit Software MS office Pro Plus 201* from XXXX2019009325

Wired NIC E4:54:E8:59:11:E0


TECHS Submitted by Katherine Reynoso Contact kreynoso15@wou.edu 88925
Primary Technician Contact ppuett16@wou.edu 88925

Tracking

Entered by Date Memo
Peter Puettmann
Email

Public

Entered by Date Memo
Peter Puettmann Apr 22, 2021 11:20 AM
Status changed from (7) Waiting for Contact to (5) Completed
Add Attachment
Stephanie Magee Mar 25, 2021 03:57 PM
came to pick it up, did hardwire and made an admin
Add Attachment
Peter Puettmann Mar 24, 2021 10:23 AM
Task reassigned to Peter Puettmann.
Add Attachment
Peter Puettmann Mar 24, 2021 10:22 AM
bringing in for an image. 
Add Attachment
Katherine Reynoso Mar 23, 2021 01:53 PM
Status changed from (1) Pending to (7) Waiting for Contact
Add Attachment
Katherine Reynoso Mar 23, 2021 10:37 AM
Apprently, it's at her house. Her son has been 
using it occasionally for school. I gave her how to 
access this and delete the application. She said 
she would give us a call if it's been deleted.
Add Attachment
Katherine Reynoso Mar 22, 2021 03:06 PM
****This is an email****
Hi Katherine,
I am available on Tuesday, all day. Please let me 
know what time works best for you. 

Have a great weekend,
Add Attachment
Katherine Reynoso Mar 19, 2021 02:11 PM
****This is an email****
Hello,

I'll be in the office Monday and Tuesday if you 
are available. If not, let's get in touch next 
week and schedule a meeting during the first week 
of classes.

Thank You,
Katherine
Add Attachment
Katherine Reynoso Mar 18, 2021 08:34 AM
****This is an outgoing email****
Hi Jaclyn,

I need some additional information regarding 
service request #77106

Description: *Sophos issue

I'm Katherine with UCS. We've received a 
notification from our anti-virus that there is a 
potentially unwanted application on your computer. 
We want to make sure the application is no 
malicious or unwanted. Do you mind if I stop by 
your office to look at this computer? It is 
20190242[Edit Inv], the desktop computer. Let me know what 
times work for you. If you have any questions feel 
free to email me or call our front office at 503-
838-8925

Thank You,
Katherine
Add Attachment
Public
Katherine Reynoso Mar 18, 2021 08:10 AM
Sophos Central Event Details for Western Oregon 
University

What happened: We detected a potentially unwanted 
application (PUA) on a computer. PUAs are not 
malicious but are often considered unsuitable for 
corporate networks.

Where it happened: W20190242

Path: C:\Users\hernandezj\AppData\Roaming\Browser 
Assistant\S.dll

What was detected: Browser Assistant

User associated with device: MASH\hernandezj

How severe it is: Medium

What Sophos has done so far: We blocked access to 
the PUA.

What you need to do: In the Sophos Central Admin 
console, go to the Alerts page. Select the PUA 
alert. To remove the PUA, click Clean up PUA(s). 
If you want to let it run, click Authorize 
PUA(s). Authorize PUAs will apply to all your 
computers, not just the one in this alert.
Add Attachment
Katherine Reynoso Mar 18, 2021 08:09 AM
Contact changed from Student Student to Jaclyn Caires-Hurley.
Add Attachment
Katherine Reynoso Mar 16, 2021 02:00 PM
Contact Info: d
Add Attachment
Public
Katherine Reynoso Mar 16, 2021 01:58 PM
Sophos Central Event Details for Western Oregon 
University

What happened: We attempted to restore a cleaned 
up application but failed.

Where it happened: W20160534

Path: 
C:\Users\kelleym\AppData\Local\Microsoft\Windows\
INetCache\IE\4XNKY921\kamino-webcam-ui_x32[1].exe

What was detected: ML/PE-A

User associated with device: MASH\kelleym

How severe it is: Medium

What Sophos has done so far: Sophos detected an 
application and cleaned it up along with any 
associated items. Later someone tried to restore 
it. An admin on your account may have done this 
(by clicking the "Allow" button next to a 
detection event) , or Sophos may have done it 
automatically. The restore was not fully 
successful; some items may have been restored, 
but not all.

What you need to do: To check whether the 
application is working, review the Sophos Clean 
log on the endpoint computer. This shows which 
items were restored and which ones weren’t. By 
default the log is at 
C:\ProgramData\Sophos\Clean\Logs\clean.log.
Add Attachment