bodminman Posted May 13, 2011 Posted May 13, 2011 Hi there, we are experiencing a strange drive mapping issue that a) random and b) happens to existing and new users. Basically from the image you can see that the mappings are made but appeaqr to be losing there association to 'Explore'. You can do start / run and unc to the destinations no problem. This issue is effecting random users and happens all the time to them. Any ideas? Thanks
bodminman Posted May 17, 2011 Author Posted May 17, 2011 Hi there, right we have run Malwarebytes and Kaspersky Virus Removal Tool across the 2 DCs and NAS and despite both products detecting and removing items, we're still getting the issue. My account was new as of last week and I get the weird issue. After the scans the servers were restarted and my profile was reset and the local profile was removed from the workstation.? Any other avenues we should be looking at Thanks
bodminman Posted May 17, 2011 Author Posted May 17, 2011 Cheers, I take it I can't replace the bugger either!?!
steve Posted May 17, 2011 Posted May 17, 2011 Have you tried the command prompt on the workstation? How are the drives mapped? Login script, group policy, local mapping, rm software? I'd try clearing the mappings "net use /del *" and re-mapping manually.
bodminman Posted May 17, 2011 Author Posted May 17, 2011 It's an RM CC3 job. Logged into the same OC as SystemAdmin the drive mappings all work fine.
Gatt Posted May 17, 2011 Posted May 17, 2011 Is there a rouge Autorun.inf in the root of these drives?
bodminman Posted May 17, 2011 Author Posted May 17, 2011 (edited) Is there a rouge Autorun.inf in the root of these drives? There were and Kaspersky picked them up and removed them. Also it picked up something called downloadme.vbs which contained some dodgy stuff! Edited May 17, 2011 by bodminman
AXE Posted May 17, 2011 Posted May 17, 2011 AutoRun.inf eh? Often, modifications are made to the entries in the registry: HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2 Particularly if your drives start losing their standard icons, actions etc. Have you tried resetting the profile of the affected user?
bodminman Posted May 17, 2011 Author Posted May 17, 2011 AutoRun.inf eh? Often, modifications are made to the entries in the registry: HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2 Particularly if your drives start losing their standard icons, actions etc. Have you tried resetting the profile of the affected user? My user profile was reset immediately after the servers were restarted after the Kaspersky scans but the problem still appeared.
po_jo_45 Posted July 8, 2011 Posted July 8, 2011 Im having the exact same problem, were you able to get this working? I suspect the autorun.inf virus but scanned the server and there is nothing detected
po_jo_45 Posted July 11, 2011 Posted July 11, 2011 As i suspected its the autorun.inf virus, however RMVP4 does not pick the virus up (what crap!), I am having to clean the server using Sophos, but now have issues with local profiles. Hard work but its gotta be done
chazzy2501 Posted July 11, 2011 Posted July 11, 2011 why not add a software restriction policy on the mapped drive.
Michael Posted July 11, 2011 Posted July 11, 2011 This is a typical example why on every network I support, I enable: User Config > Admin Templates > System - Turn off Autoplay (All drives) It makes it impossible for the virus to spread anymore and only requires a user to open up My Computer manually. One school I support had the Conflicker virus (autorun virus) before I started and although the virus was removed, it still created a lot of damage. I ended up re-installing the one server from new and the problems then disappeared.
po_jo_45 Posted July 11, 2011 Posted July 11, 2011 What happens when autorun is disabled but the users double click the drive in My Computer - does it not do the same thing, the virus will still get onto the computer etc?
Michael Posted July 12, 2011 Posted July 12, 2011 What happens when autorun is disabled but the users double click the drive in My Computer - does it not do the same thing, the virus will still get onto the computer etc? The virus is exploiting the autorun or autoplay pop-up menu function, so by disabling it, users are forced to manually browse a memory stick via My Computer (even if the memory stick has the autorun virus, it cannot run). I've also heard the argument that because a memory stick is encrypted it can't be infected, which is untrue. You insert a memory stick, enter the password and then the autorun function would start as normal. Put it this way, the sites I support haven't had a single conflicker infection and it's because the autorun function is disabled. Most users don't notice, as typically they navigate to My Computer for mapped network drives anyway. 1
po_jo_45 Posted July 12, 2011 Posted July 12, 2011 Awesome! thanks for clearing that up, i will get that done asap
mhussain Posted July 15, 2011 Posted July 15, 2011 hoW do you manually remove this virus as SOPHOS is not picking it up!
bodminman Posted July 15, 2011 Author Posted July 15, 2011 Initially we used Trend Micro Housecall to scan everything! After we managed to get things clean, we ripped out RMVP4 and installed VIPRE AV.
hfnistelrooy Posted July 15, 2011 Posted July 15, 2011 Im having this issue and the problem seems to be with roaming profiles, the server has been cleaned but as soon as someone logs in using a cached profile the network is infected again. I have combatted this by disabling the users and deleting all the local profiles using delprof. At the same time i am cleaning all the profiles. I have read the virus also spreads by using the RECYCLER folder so i am deleting everything in those folders too RMVP4 and Sophos have not picked it up, I have seen this before and am using the cmd to delete the infection. Has there been a new strain of the virus as it seems to have infected 3 people here...
po_jo_45 Posted July 18, 2011 Posted July 18, 2011 We have not been successful here and unfortunately have had another school which has been infected, the problem is with the local cached profiles reinfecting the server. Shame that I cant go in during the summer as the head refuses to pay for the extra service, maybe on the last day of term or when we get back from the summer holidays
bodminman Posted July 18, 2011 Author Posted July 18, 2011 I'd be getting something in writing to the head to say that there is an issue that needs sorting urgently. If he still doesn't want to know then on his head be it. Just a case of making sure he's aware of the possible consequences and that you are prepared to sort it out.
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now