Jump to content

Recommended Posts

Posted
jmak: We have thirdline support exactly for this sort of situation i.e. when I'm away, so they're coming on-site tomorrow. The holiday's unavoidable, otherwise I would reschedule.
Posted (edited)

 

EXEs are now blocked, but I haven't blocked PDFs yet.

 

.

 

You need to block PDF access completely (not just write access) if the virus cant access a PDF it cant turn it into an infected clone. This should slow down the spread.

Edited by JJonas
  • Thanks 1
Posted

At this point i would reconsider the re-imaging solution. You can always sideline one machine and keep it off the network for testing, but in the mean time people need to know that there is a solution in progress and that it will work.

 

You can spend days weeks trying to solve it or waiting for a AV release to sort it, but if products like MB, Forefront, Sophos can't pick it up then

this virus must be rock solid and a tested solution could be a long way off.

 

This of course depends on how many machines are on your network. If we're talking thousands then ignore that re-imaging suggestion!

  • Thanks 1
Posted

JJonas: You're right. I'm doing it right now.

 

win: I think the thirdline company are going to spend a couple of days seeing whether it can be tackled with AV software, but the difficulty is knowing this for sure. We have 450 PCs, and use Ghost, so it will take around 30-60 days to reimage everything. Not impossible, but obviously not ideal either.

  • Thanks 1
Posted
JJonas: You're right. I'm doing it right now.

 

win: I think the thirdline company are going to spend a couple of days seeing whether it can be tackled with AV software, but the difficulty is knowing this for sure. We have 450 PCs, and use Ghost, so it will take around 30-60 days to reimage everything. Not impossible, but obviously not ideal either.

 

If you have any spare HDD you could do disk to disk cloning, i think ghost only allows 1:1, but if i remember correctly clonezilla will let you clone multiple disks at once which is a lot quicker than imaging over the network.

  • Thanks 1
Posted

With clonezilla you speed up exponentially. Once 1 disk is done, you can clone 2 at a time. Then 4 at a time, etc.. assuming you have enough usb-sata cables. I've used it before and it's really fast but you'll need competent people to assist.

 

Good luck with the AV hunt, others to try are superantispyware and hitman.

 

Another thing to try is to batch rename all your pdf files to e.g. pdg. This will protect them but still make them accessible to the user. They just need to right click and then open with acrobat. They can still work while you sort the problem.

  • Thanks 1
Posted

Part 1 of the conclusion to this is that Sophos have become progressively more useless to the point where we had to ditch them. Their endpoint could not clear the virus from clients. I'm off-site, as technically on holiday in Brazil, but the on-site firstline technician contacted a number of anti-virus companies for help. The *only* company that was helpful was ESET. They gave several days of consultancy (for "free"), demonstrated their endpoint cloud clear the virus, gave install assistance etc. They've given us a 30 day trial and haven't asked for any money. Clearly though they would like to win our business.

 

The school isn't completely out of the woods yet but the bulk of desktops/laptops now have the ESET client, and they are about to perform server scans (the servers aren't infected, but are hosting infected PDFs). ESET's endpoint doesn't have the capability yet to clear the PDFs, but apparently it's in the final phase of testing. It would be much easier to clean the PDFs than have to delete and reinstate, but if it comes to it that's what we'll have to do.

 

Rumour has it we're not the only organisation affected by this virus, and some other much larger places have disabled their network to try and clear it.

 

I'll update if there's anything else that people might find useful to know.

Posted

Has this sorted the slowness you mentioned at the start of the thread?

 

I forwarded it to my colleague this morning who immediately replied with highlight on the ProCurve manager line.

 

I know others use it successfully but whenever I install it, our network falls over in exactly the way you described.

  • Thanks 1
Posted

I'm being told it has sorted it, but currently 6,000 miles away :-/

 

We've used PCM for 2 years without any issue, albeit never say never. The client slowness problem seemed to be affecting launching of apps, not just network activity.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...