To register for an Internet.com membership to receive newsletters and white papers, use the Register button ABOVE.
To participate in the message forums BELOW, click here

WinDrivers Computer Tech Support Forums  

Go Back   WinDrivers Computer Tech Support Forums > For Techs Only > Spyware & Antivirus - Security

Spyware & Antivirus - Security Discuss all system security, spyware, adware and malware issues here.

Reply
 
Thread Tools Search this Thread Display Modes
Old February 6th, 2001, 01:44 PM   #1
cerebralcortex
Guest
 
Posts: n/a
Angry Tracking the person who keeps infecting with VBS.LOVELETTER

Here at my work we keep getting infected every month or two with the columbia variation of the VBS.LOVELETTER virus. We are almost positive that we are being infected internally by someone that has archived the virus onto a floppy or CD-R since it is always the same virus. We run NT4.0 and Win2k only. We find the files and delete all the infected ones but someone keeps infecting us. How can I track where the virus is being introduced, can I track one of the VBS files through sever logs? Any help would be greatly appreciated.
  Reply With Quote
Old February 6th, 2001, 03:52 PM   #2
MacGyver
Guest
 
Posts: n/a
Lightbulb

You should have antivirus clients with updated signatures installed on all network workstations to pick up the virus before it can do anything. I use CA InoculateIT at work and if somebody shuts down their antivirus client, the server terminates their network connection automatically! I also have virus scanner running on the server for maximum protection. We have never been infected since using this setup.

The other option is to remove the file association for VBS so the script can't run anymore. Most people never need Visual Basic Scripting anyway. You can also download this free tool http://www.cerberus-infosec.co.uk/vf.exe that will go through the registry and remove any VBS related extensions so the VBS related viruses can't do anything.

Don't try to track the virus manually, you are wasting your time.

Good luck in your hunt.

------------------
sHIFT hAPPENS11
  Reply With Quote
Old February 6th, 2001, 09:27 PM   #3
thirdfey
Registered User
 
thirdfey's Avatar
 
Join Date: Jun 2000
Location: Pinehurst, NC USA
Posts: 1,887
Post

are you auditing your network? if so, the vbs virus goes out and looks for every drive either local or mapped to rename the picture files and such, so setup auditing to track down when files are changed. to make this easier on your security log setup a dummy folder with a bunch of file types that the virus attacks and audit up the but. So the next time you get hit with the virus and gets to the folder in a network drive, you can see in the security log the username that did it, setup a dummy folder in each of your shares if need be. That should do it for you I would think.

------------------
we are number one, all others are number two......or lower
__________________
I'd rather be riding my motorcycle
"I gotta have more cowbell, baby" Bruce Dickinson(Christopher Walken)
thirdfey is offline   Reply With Quote
Reply

Bookmarks

Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump


All times are GMT -5. The time now is 02:30 PM.



Acceptable Use Policy

internet.comMediabistrojusttechjobs.comGraphics.com

WebMediaBrands Corporate Info


Advertise | Newsletters | Feedback | Submit News

Legal Notices | Licensing | Permissions | Privacy Policy

Powered by vBulletin® Version 3.7.3
Copyright ©2000 - 2009, Jelsoft Enterprises Ltd.