Disinfecting multiple PCs at school infected with unknown malware

ttomovcik

Level 1
Thread author
Verified
Oct 30, 2016
17
Clean install everything on 115 PC, rest 5 PCs you need to collect samples or run a scan via LiveCD and get to know what type of virus it was. Yeah follow @SHvFl advice.
If you want to continue with trying to remove the malware, rather than reformatting, I recommend doing scans with Zemana AntiMalware and Malwarebytes, as they are both very good at finding infections.
Well, every PC is infected so that sucks. And what the worst thing, some PCs are infected with Jigsaw, WannaCrypt0r and Petya. And the server too which has every students project files from AutoCAD (mechanical and inventor) and system images. I´m plannig to create new Linux file server for this kind of stuff but looks like I´m gonna need some time to decrypt the files on server. :( I might create at some point (if I´ll have time) snapshot of the system partition from one of the infected machines and do collect some malware files from that.

Off-topic question:
Do you guys think that AutoCAD will run from Linux distro when the license file is shared on school server? (Talking about running Wine on Linux and getting license from another linux server)
 
  • Like
Reactions: AtlBo and SHvFl

brambedkar59

Level 29
Verified
Top Poster
Well-known
Apr 16, 2017
1,875
Off-topic question:
Do you guys think that AutoCAD will run from Linux distro when the license file is shared on school server? (Talking about running Wine on Linux and getting license from another linux server)
AutoCAD is not supported on linux. Also Wine support for AutoCAD is not that great since v2008. See here.
There are some free applications like AutoCAD (eg. Draftsight, librecad, medusa, pycad) but they are not that great (in terms compatibility & features), also there is the issue of compatibility with newer versions of AutoCAD.
You could try running windows inside VM on linux, and install AutoCAD on Guest OS.
PS all I did was a Google search.
 
  • Like
Reactions: AtlBo

Game Of Thrones

Level 5
Verified
Well-known
Jun 5, 2014
220
we have many malwares like this in our country, since usb flash drives are widely use here, eset is really weak in usb infections, kaspersky bitdefender and norton are way better, bitdefender knows this infection as trojan.symmi i think, bitdefender is detecting this threat at first sight unlike eset and cuts the infection chain, but for having the hidden files back you have to run a cmd command.kaspersky is way better at repairing the flash drive and most of the time you do not need to run the cmd command. norton behaves like bitdefender.
Type the following command in Command prompt: attrib -h -r -s /s /d X:\*.* , (Where, X is the USB drive letter) and press Enter. (For example: If your drive letter is D, then the command is attrib -h -r -s /s /d D:\*.*) Copy all data from USB flash drive to your computer. Format the USB drive.
 
  • Like
Reactions: AtlBo and Vasudev

ttomovcik

Level 1
Thread author
Verified
Oct 30, 2016
17
depending on your school's financial situation, I would switch to an other Endpoint solution after this chaos. Preferably one from Kaspersky, Bitdefender or Symantec.
I´m going to make one GNU/Linux file server and will see what can I doo with other PCs. Maybe install Windows 7/10 or any GNU/Linux distro and switch to open-source. Will see. School starts 2nd September, so I´m gonna update this thread if something changes.
 
  • Like
Reactions: AtlBo

WinXPert

Level 25
Verified
Honorary Member
Top Poster
Malware Hunter
Well-known
Jan 9, 2013
1,457
Since you got script worms, try temporarily block wscript.exe ans cscript.exe.


If you want to continue with trying to remove the malware, rather than reformatting, I recommend doing scans with Zemana AntiMalware and Malwarebytes, as they are both very good at finding infections.

Really? for vbs?

Try an updated Avast! and do a boot scan
 

mekelek

Level 28
Verified
Well-known
Feb 24, 2017
1,661
I´m going to make one GNU/Linux file server and will see what can I doo with other PCs. Maybe install Windows 7/10 or any GNU/Linux distro and switch to open-source. Will see. School starts 2nd September, so I´m gonna update this thread if something changes.
setting them up with a deep freezing software forced to restore to clean state every reboot might be also a good solution (Shadow Defender, Deep Freeze, Rollback RX)
 

Maxwell Sien

Level 2
Verified
Nov 15, 2016
97
I´m both student and technician ;) And yup I´m allowed to clean them, basically do whatever I want to.

I don't mean to be arrogant, but my side job is Malware Removal Service. I Feel that i Can Remove all of this (except Ransomware, it need a Dectyptor), absolutely free for your School..

Maybe we cant contact with phone or something else?
 
Last edited:
F

ForgottenSeer 58943

First, what are you protecting the gateway with? It is absolutely, 100% crucial you have a high quality UTM/NGFW on the gateway. Not only will this prevent many/most infections, it will prevent re-infections and outbound dropper grabs. I'm not talking PfSense or Untangle, I mean a real gateway, Fortinet, ZyXEL USG, whatever. If you put a Fortinet on the gateway immediately with all of the botnet, malware and web filtration enabled it would stop the outbound communication immediately. Grab a Fortigate 60E w/UTM bundle from Amazon for $300. (that's my advice)

Also, this sounds a bit like a file-less malware I ran into a few weeks ago. Try Trend Micro House-Call, it captures strange stuff. HitmanPro also finds some crazy stuff.. Also don't neglect Super Anti-Spyware, I've had that actually pick up and remove a couple really odd programs. But do run Adlice Rogue Killer and see what is happening, often you'll find malware re-loading tasks.
 

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top