Erik:

Yes I am implementing the kix removal of wsh/vbs by using the logon script (I should have done this long ago!!) We were hit by veryfunny.vbs it is just a loveletter variant.

I am also going to be reevaluating the latest security update for outlook. And will try to implement it before the end of the week....

I still haven't been able to find out how the attachment got through, but it look's like my virus scanner failed (Mcafee GroupShield). The initial user received the attachment at 6:45am. Several other people also received the same email, but the server caught and cleaned those, but not her's.

At 9:11am she ran the attachment, her local virusscan was disabled waiting on a reboot to bring it up the latest version.

At 9:12 the second user ran the attachment, and then the next user..... until a total of 7 people had ran the virus, resulting in a complete and total overload for the server based virusscan to catch them all.

I was out of the building and I wasn't informed until almost an hour after the initial infection. That is when one of my help desk tech's shutdown both mail servers, while scrambling to get in touch with me (At this time I was on my back upstairs to my office).

It took me another 20 min to get up to speed and get the servers running on a separate network, also hooked my self up to this separate network. Started a Scan On demand at 10:02am and at 4:12pm it just finished

For those who are interested...

Total number of infected email's was..... 4095!!
Total downtime 6.5 hours,

...... yea.


Bryce