jsnetman Posted July 6, 2010 Posted July 6, 2010 We did this here, staff don't have a choice when a virus hits, only had to do it twice blaster and conficker. For blaster even the servers were turned off for a day or so.
jsnetman Posted July 6, 2010 Posted July 6, 2010 (edited) If you can't go to SP3 there is a download which patches the problem with conficker: http://www.microsoft.com/technet/security/Bulletin/MS08-067.mspx Seem to remember we didi deploy this patch prior to upgrading to SP3. We also deployed and ran http://www.tech-forums.net/pc/f51/conficker-information-203975/ conficker_mem_killer.exe for a good few weeks after the attack. Edited July 6, 2010 by jsnetman
synaesthesia Posted July 6, 2010 Posted July 6, 2010 No problems going to SP3 as long as you're SR1 at least. Update 75, as mentioned above provides the packages to do it. As long as your drivers are up to date (especially wireless if you have any Z91FR RM mobile one laptops or anything else with cewrtain model Intel wireless cards) you should be fine. Also make sure laptops are mains powered otherwise it wont install 1
EduMan Posted July 7, 2010 Author Posted July 7, 2010 Thank you all for your advice, ill pass them all on, beating with the shoes sounds perfect! May just try it !
synaesthesia Posted July 7, 2010 Posted July 7, 2010 Grip by the toe, aim for a square hit with the heel.
Sam_Brown Posted April 26, 2012 Posted April 26, 2012 Seriously... you need to start from having nothing on the network and then gradually working your way from there adding things back in as you get them clean. Disable all computer accounts in AD and tell them they aren't having them re-enabled until they've been cleaned and patched. That'll soon get them all coming in. Pull out all your patch cables \ disable the wifi because the last thing you want is to have 99% of everything clean only to have someone plug something in and infecting everything again. Start with the servers and making sure they are all disconnected with nothing connected to your core switch(es) and only reconnect as they are cleaned. Once you're 100% sure your core network is clean and patched then you can start with the laptops and desktops. Once you're happy the majority has been sorted out then you can start to patch desktop pc's and the like back in.
Sam_Brown Posted April 26, 2012 Posted April 26, 2012 Opps! This is what happens when I got into the "similar threads" and don't check the dates!
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now