Jump to content

GrahamWibbly

Members
  • Posts

    5
  • Joined

  • Last visited

Everything posted by GrahamWibbly

  1. Again thanks to all who replied. I couldn't do this tonight as there was something very important on that needed to use the network. I'm going to tackle it tomorrow. The servers are detecting the virus (even though they were right up to date with Windows updates and anti virus). When I removed it with Sophos, the server service was stopped, I ran another virus scan straight away and nothing was detected, I rebooted in safe mode and ran another scan and nothing was detected again but as soon as I rebooted normally and was connected to the network it reappeared. There's no way I'm flattening them, so need to remove. Going to turn everything off tomorrow, go round each workstation and run the hotfix and a virus scan. Once I've done that I'll do the same on the servers and then re-connect everything. I'll turn autorun off so USB sticks don't spread it and then will insist any sticks get brought to myself for a scan before use. Is this Malwarebytes Anti Malware free? I've never heard of it, but I am willing to try anything that will make life easier. Thanks again for everyones help.
  2. Thanks for all the replies, I think Sophos does actually remove it, it's just as soon as it reconnects to the network it picks it back up again. I did try what Trekmad said above but when I got to step 5 there wasn't actually a DLL named there. Looks like it could be a late night for me.
  3. I get that. I was thinking more along the lines of doing it room by room, disconnecting each as I go. Then reconnecting them all at the end. What's pissing me off is where it's come from and why Sophos didn't pick it up. So my plan should basically be: 1) Disconnect the servers from the network. 2) Go round every PC and run the removal tool from above and also run Windows Update.
  4. Hi, Thanks for the prompt reply. Is it possible to get rid of this without shutting the network down (this isn't really an option at this moment in time)?
  5. Hi, I appear to have picked up the W32/Confick-E virus. Not entirely sure where from as the servers were all bang up to date with Windows Updates and Sophos Anti-Virus. The Sophos website says to install the MS08-067 hotfix from Microsoft (which when I've checked was actually installed on my machines last year.) It then says to use Sophos to clean the virus. Now I've tried doing this, I do a full Sophos scan, it picks the virus up, I perform a clean and it says clean successful. At this point a few services (such as the server service) are turned off (presumably to allow a proper clean) so I have to reboot. Upon reboot I run another scan and the virus is still there. Is it possible that some of my desktop machines have the virus and are transmitting it back to the server when the server reboots and reconnects to the network? If this is the case it looks like I may have to go round every PC and ensure they're all up to date with Updates and do a virus scan on them all. Has anyone any experiences with this virus or have any suggestions? Many thanks.
×
×
  • Create New...