Отправлено 06 Февраль 2011 - 10:36
Dr.Web® Enterprise Server version 6.00.0.201009100
Отправлено 06 Февраль 2011 - 11:38
Some backgroud. As you might already know, the virus uses two way to infect machines in the network
how to eradicate this virus permanently Win32.HLLW.Autoruner.5555 making havoc in the network and yet we use
- vulnerability in the windows service
- weak passwords on the administrator accounts
So the first step is to apply all patches from the Windows Update. If this is not possible for now, then I'd suggest to disable Task Scheduler service. It might help too (virus will be injected to computer but won't be able to start).
Then you have to set strong password on all local computer administrator accounts as well as to all domain administrator accounts.
Normally SpiderGuard prevents infection of the computer. But if you have at least one unprotected machine in the network, it will try to infect other computers again and again.
Run GUI scanner (Drweb32W, fast scan option) one some suspicious computers to see if they are really infected. If they are infected, then you will have to cure the whole network, otherwise only a few machines that are unprotected for now.
If the machine will be infected again, then use security audit events to see the source of the infection. It will help you to find unprotected/infected computers in the network.
BTW, a bit more details about what you observes and what you already did would be very helpful
Читают тему: 1
0 пользователей, 1 гостей, 0 скрытых