Virus UpdateFebruary 7, 2005

Time: February 7, 2005
Location:
Audience:Campus
Category:
Attendancenone
Description

Please be aware that we had some virus issues last week, and the week before. These problems have been isolated and are now classified by Symantec as a variant of Randex. We currently have a number of student machines that appear to be infected. All infected ports are being shut off and listed on the Restricted Network Access page also linked off the Hitlist - on the side panel. Please check this list first for any complaints about network issues. We are trying to contact them as we turn off their ports, but this hasn't happened all the time.

If they are on the list and the reason is infection - they will need to follow the removal process or bring their machines in for NFD (this Thursday).

Randex Removal:

  1. Reboot in Safe Mode (detailed directions for booting in safe mode)
  2. Scan with defs dated at 1/31/05 or newer
  3. Remove any quarantined files
  4. Remove the following reg keys from the registry:
    1. HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionRun
      Winzip Archiver=Winzip32.exe

    2. HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionRunServices
      Winzip Archiver=Winzip32.exe

    3. HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionRunService
      Winzip Archiver=Winzip32.ex
  5. Reboot.

After they have completed the removal directions they can call and we can scan their machines and re-enable their ports. Please talk to Dan or Ethan or the dutyperson to re-enable a port.

If you have questions about this - please ask.

ContactTami Aune