penfold Posted April 16, 2018 Posted April 16, 2018 I know someone posted a document some time ago about steps to take when a virus/ranswomware was detected on the network. I used this to create a quick step guide to pass out to members of the department so they knew the severity and steps to take to help prevent the virus from speading. I've since left my old job and need to produce this documentation again. Rather than do it from scratch (as I forgot to take a copy) has anyone got one or knows the post where this was provided please? I need to get something done today as we have had a virus over the weekend so I want to put something out to staff of what to do. From memory I thought it was for the wanacry thread but I can't see it, unless I've just skipped over it.
speckytecky Posted April 16, 2018 Posted April 16, 2018 I'm pretty sure Sophos offer a free cleanup tool.
penfold Posted April 16, 2018 Author Posted April 16, 2018 The document I am thinking about had steps such as 1) Identify Users - check the encrypted file properties to obtain user details 2) Disable User account and disconnect Computer from network. 3) perform full scan of end system (off line) 4) reimage if required. I just want staff to know what actions to take
penfold Posted April 16, 2018 Author Posted April 16, 2018 For some reason I am thining this was somehting @elsiegee40 posted but I'm not 100%?
DJ-1701 Posted April 16, 2018 Posted April 16, 2018 (edited) This thread? http://www.edugeek.net/forums/windows-server-2012/192710-protect-file-server-against-ransomware.html There is a hyperlink in it to a script in the Technet Gallery using FSRM. (https://gallery.technet.microsoft.com/scriptcenter/Protect-your-File-Server-f3722fce) Ah, sorry, misread, this is prevention... Edited April 16, 2018 by DJ-1701
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now