Jump to content

Recommended Posts

Posted

Hi there,

 

we are experiencing a strange drive mapping issue that a) random and b) happens to existing and new users.

 

Basically from the image you can see that the mappings are made but appeaqr to be losing there association to 'Explore'. You can do start / run and unc to the destinations no problem.

 

This issue is effecting random users and happens all the time to them.

 

Any ideas?

 

ThanksDrive_Mapping_Issue.jpg

Posted

Hi there,

 

right we have run Malwarebytes and Kaspersky Virus Removal Tool across the 2 DCs and NAS and despite both products detecting and removing items, we're still getting the issue.

 

My account was new as of last week and I get the weird issue. After the scans the servers were restarted and my profile was reset and the local profile was removed from the workstation.?

 

Any other avenues we should be looking at

 

Thanks

Posted

Have you tried the command prompt on the workstation?

 

How are the drives mapped? Login script, group policy, local mapping, rm software?

 

I'd try clearing the mappings "net use /del *" and re-mapping manually.

Posted (edited)
Is there a rouge Autorun.inf in the root of these drives?

 

There were and Kaspersky picked them up and removed them. Also it picked up something called downloadme.vbs which contained some dodgy stuff!

Edited by bodminman
Posted

AutoRun.inf eh? :)

Often, modifications are made to the entries in the registry:

HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2

Particularly if your drives start losing their standard icons, actions etc.

 

Have you tried resetting the profile of the affected user?

Posted
AutoRun.inf eh? :)

Often, modifications are made to the entries in the registry:

HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2

Particularly if your drives start losing their standard icons, actions etc.

 

Have you tried resetting the profile of the affected user?

 

My user profile was reset immediately after the servers were restarted after the Kaspersky scans but the problem still appeared.

  • 1 month later...
Posted

Im having the exact same problem, were you able to get this working?

 

I suspect the autorun.inf virus but scanned the server and there is nothing detected

Posted
As i suspected its the autorun.inf virus, however RMVP4 does not pick the virus up (what crap!), I am having to clean the server using Sophos, but now have issues with local profiles. Hard work but its gotta be done
Posted

This is a typical example why on every network I support, I enable:

 

User Config > Admin Templates > System - Turn off Autoplay (All drives)

 

It makes it impossible for the virus to spread anymore and only requires a user to open up My Computer manually.

 

One school I support had the Conflicker virus (autorun virus) before I started and although the virus was removed, it still created a lot of damage. I ended up re-installing the one server from new and the problems then disappeared.

Posted
What happens when autorun is disabled but the users double click the drive in My Computer - does it not do the same thing, the virus will still get onto the computer etc?
Posted
What happens when autorun is disabled but the users double click the drive in My Computer - does it not do the same thing, the virus will still get onto the computer etc?

 

The virus is exploiting the autorun or autoplay pop-up menu function, so by disabling it, users are forced to manually browse a memory stick via My Computer (even if the memory stick has the autorun virus, it cannot run).

 

I've also heard the argument that because a memory stick is encrypted it can't be infected, which is untrue. You insert a memory stick, enter the password and then the autorun function would start as normal.

 

Put it this way, the sites I support haven't had a single conflicker infection and it's because the autorun function is disabled. Most users don't notice, as typically they navigate to My Computer for mapped network drives anyway.

  • Thanks 1
Posted

Im having this issue and the problem seems to be with roaming profiles, the server has been cleaned but as soon as someone logs in using a cached profile the network is infected again. I have combatted this by disabling the users and deleting all the local profiles using delprof. At the same time i am cleaning all the profiles.

 

I have read the virus also spreads by using the RECYCLER folder so i am deleting everything in those folders too

 

RMVP4 and Sophos have not picked it up, I have seen this before and am using the cmd to delete the infection.

 

Has there been a new strain of the virus as it seems to have infected 3 people here...

Posted
We have not been successful here and unfortunately have had another school which has been infected, the problem is with the local cached profiles reinfecting the server. Shame that I cant go in during the summer as the head refuses to pay for the extra service, maybe on the last day of term or when we get back from the summer holidays
Posted
I'd be getting something in writing to the head to say that there is an issue that needs sorting urgently. If he still doesn't want to know then on his head be it. Just a case of making sure he's aware of the possible consequences and that you are prepared to sort it out.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...