because ... my boss was an idiot? Note past tense, I believe I called it a symptom of the madness of the place, There was no COMPANY data on those boxes, at least nothing irreplacable. Various people had downloaded various.. things which is why their computers were infected.
>If data isn't an issue for you why are we having this conversation about all >the time you spent saving the data on the computer instead of wiping it and >starting over? Wasn't, Wasn't. Past tensense. And I did not save any data at all. Instructed not to. That's how stupid it all was. My mission was to remove all malware and only malware and leave everything else usable and as it was, Don't look at me that way ;) I know. I know> >You would have to define help.. I don't see how automating registry edits is >helpful when we are talking about getting rid of a virus. Well maybe we are talking at cross-purposes here, but usually if you are not going to format and reimage -- and I got the impression a couple of posts ago that you or someone else there did not want to do that because of the data ---you locate the malware files, probably with whatever virus software does detect then, delete them, and then restore the registry keys. No? If you do in fact want to format, disregard this whole fork, because that's really the way to go for the sake of the IT person's sanity in my opinion But that's what that big list of registry keys is a few posts back. Stuff that might have been changed, causing the computer to not work well? That was an example from one of the versions of the virus you mentioned. > You can lock down >a machine so registry edits cannot be done which I have and we don't have >virus software on those machines and have no issues because of the lock >downs we have done. Turned computers into basic dummy terminal's that can >surf the internet essentially. True, but these aren't the machines that are infected, right? Anyway, if you are ghosting, carry on; if you are going to remove it by hand, good luck to you and depending on the nimber of computers you might find it faster to write a script is all i am saying. If that doesn't seem faster, also fine with me. I don't have a horse in this race -----Original Message----- From: Dana [mailto:[email protected]] > Sent: Wednesday, September 02, 2009 1:51 PM > To: cf-community > Subject: Re: Fracking Hacking Spammers! > > > yeah. Data wasn't really an issue for us and I guess I made an assumption > that it wasn't for you either. I take it these are dev boxes or something > else where it really matters? > > You know -- something I did not know at the time was that you can automate > registry edits with PowerShell. Would that help? > > On Wed, Sep 2, 2009 at 11:25 AM, Scott Raley <[email protected]> wrote: > > > > > I already have Ghost and True Image servers. That only helps on rebuild, > it > > doesn't help with data on the machine unless you have a real server with > > real roaming profiles so there is nothing on the desktop to save. > > > > -----Original Message----- > > From: Dana [mailto:[email protected]] > > Sent: Wednesday, September 02, 2009 12:22 PM > > To: cf-community > > Subject: Re: Fracking Hacking Spammers! > > > > > > I don't know how many machines you are talking about and you have a newer > > version (presumably nastier tho) but > > > > the computers I worked on took a ridiculous amont of time to fix. There > was > > a manual fix and it involved really long lists of registry keys that > might > > or might now be affected. And the users thought they could not possibly > > have > > done such a thing and instantly reinfected them One guy told me I did not > > need to check his machine because he had just run virus software, Guess > > which one he ran ;) > > > > I mean, a lot depends on who you are dealing with and how important any > > data > > on those machines might be, But I would not do that again for anything > > short > > of salvaging a cure for cancer, > > > > My suggestion is that you invest in a ghost server. For whatever that > might > > be worth, > > > > On Wed, Sep 2, 2009 at 10:08 AM, Scott Raley <[email protected]> wrote: > > > > > > > > We are debating that now since the virus mutates on itself. > > > > > > > > > -----Original Message----- > > > From: Dana [mailto:[email protected]] > > > Sent: Wednesday, September 02, 2009 11:59 AM > > > To: cf-community > > > Subject: Re: Fracking Hacking Spammers! > > > > > > > > > awesome :) It would have been better to re-image the machines I am > > talking > > > about, I was told not to, well, as a sympom of the madness there, is > the > > > best way I can explain it. But based on what you just said it's pretty > > much > > > the only way to go any more? > > > > > > On Wed, Sep 2, 2009 at 9:49 AM, Scott Raley <[email protected]> > wrote: > > > > > > > > > > > It is now Antivirus 2010 and there is a new version call Braviax > which > > is > > > > programmed to embed itself in a lot of spyware tools, spybot, malware > > > > bytes, > > > > superantispyware, etc so you have to rename stuff to get it to work > > > > correctly. It infects regedit and a lot of files in windows system > so > > > when > > > > you think you fixed something you didn't. > > > > > > > > > > > > > > > > > > > > > > > > > > > > > > > > > > > > ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~| Want to reach the ColdFusion community with something they want? Let them know on the House of Fusion mailing lists Archive: http://www.houseoffusion.com/groups/cf-community/message.cfm/messageid:303327 Subscription: http://www.houseoffusion.com/groups/cf-community/subscribe.cfm Unsubscribe: http://www.houseoffusion.com/cf_lists/unsubscribe.cfm?user=89.70.5
