yeah. Data wasn't really an issue for us and I guess I made an assumption that it wasn't for you either. I take it these are dev boxes or something else where it really matters?
You know -- something I did not know at the time was that you can automate registry edits with PowerShell. Would that help? On Wed, Sep 2, 2009 at 11:25 AM, Scott Raley <[email protected]> wrote: > > I already have Ghost and True Image servers. That only helps on rebuild, it > doesn't help with data on the machine unless you have a real server with > real roaming profiles so there is nothing on the desktop to save. > > -----Original Message----- > From: Dana [mailto:[email protected]] > Sent: Wednesday, September 02, 2009 12:22 PM > To: cf-community > Subject: Re: Fracking Hacking Spammers! > > > I don't know how many machines you are talking about and you have a newer > version (presumably nastier tho) but > > the computers I worked on took a ridiculous amont of time to fix. There was > a manual fix and it involved really long lists of registry keys that might > or might now be affected. And the users thought they could not possibly > have > done such a thing and instantly reinfected them One guy told me I did not > need to check his machine because he had just run virus software, Guess > which one he ran ;) > > I mean, a lot depends on who you are dealing with and how important any > data > on those machines might be, But I would not do that again for anything > short > of salvaging a cure for cancer, > > My suggestion is that you invest in a ghost server. For whatever that might > be worth, > > On Wed, Sep 2, 2009 at 10:08 AM, Scott Raley <[email protected]> wrote: > > > > > We are debating that now since the virus mutates on itself. > > > > > > -----Original Message----- > > From: Dana [mailto:[email protected]] > > Sent: Wednesday, September 02, 2009 11:59 AM > > To: cf-community > > Subject: Re: Fracking Hacking Spammers! > > > > > > awesome :) It would have been better to re-image the machines I am > talking > > about, I was told not to, well, as a sympom of the madness there, is the > > best way I can explain it. But based on what you just said it's pretty > much > > the only way to go any more? > > > > On Wed, Sep 2, 2009 at 9:49 AM, Scott Raley <[email protected]> wrote: > > > > > > > > It is now Antivirus 2010 and there is a new version call Braviax which > is > > > programmed to embed itself in a lot of spyware tools, spybot, malware > > > bytes, > > > superantispyware, etc so you have to rename stuff to get it to work > > > correctly. It infects regedit and a lot of files in windows system so > > when > > > you think you fixed something you didn't. > > > > > > > > > > > > > > > > > > > > > ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~| Want to reach the ColdFusion community with something they want? Let them know on the House of Fusion mailing lists Archive: http://www.houseoffusion.com/groups/cf-community/message.cfm/messageid:303320 Subscription: http://www.houseoffusion.com/groups/cf-community/subscribe.cfm Unsubscribe: http://www.houseoffusion.com/cf_lists/unsubscribe.cfm?user=89.70.5
