Tuesday, November 3, 2009

Re: [Avid-L2] Worms on Thumb drives

Disable Autorun in local policies.
Disable front USB ports on your editing CPUs.
Local Windows User Accounts are NOT Administrators.

We set up an internal FTP server that is scanned actively. All files
(graphics, etc...) are copied to that server first. It's a two step
process but we managed to avoid getting hit by Conficker or Downadup.

We enforce a strict "No USB Thumb Drive" policy. Any editor that
bypasses this policy will have his edit system re-imaged with no
opportunity to back up his or her "personal" files.

---
Rob Lawson
System Administrator, ACSR ISIS, Windows & Unity
CBS News
Sent from New York, NY, United States


On Tue, Nov 3, 2009 at 4:48 PM, RT <huipro@hawaii.rr.com> wrote:
> We saw a major infestation of the Autostart/doubleclick worm recently,
> on machines that are shielded from the internet and problem free for years..
>
> With USB - there is no safe place to hide.  Dipshit editor downloads a
> graphic from the web onto his flash drive and before you know it,
> nasties are on every machine in the workgroup.
>
> This one had made hundreds of copies before being found out.  There was
> no backup disk image so it required rebuilding the OS and drivers from
> scratch.  A worthless and thankless job.
>
> Norton is no longer off by default.  Retraining the editors takes more time.
>
>
> Quinatwork@aol.com wrote:
>
>> Earlier in the week there was a thread on systems getting infected.
>> Apparently this is the bugger:
>>
>> _http://www.technewsworld.com/story/Kido-Worm-Keeps-On-Truckin-via-USB-Thumb-D
>> <http://www.technewsworld.com/story/Kido-Worm-Keeps-On-Truckin-via-USB-Thumb-D>
>> rives-65869.html_
>> (http://www.technewsworld.com/story/Kido-Worm-Keeps-On-Truckin-via-USB-Thumb-Drives-65869.html
>> <http://www.technewsworld.com/story/Kido-Worm-Keeps-On-Truckin-via-USB-Thumb-Drives-65869.html>)
>>
>>
>> Quinton Lee, MIS
>> Q.A. Lee Consulting
>> Helping People and Technology Work Together
>> **************A Good Credit Score is 700 or Above. See yours in just 2
>> easy
>> steps!
>> (http://pr.atwola.com/promoclk/100000075x1215855013x1201028747/aol?redir=http://www.freecreditreport.com/pm/default.aspx?sc=668072%26hmpgID=62%26bcd=De
>> <http://pr.atwola.com/promoclk/100000075x1215855013x1201028747/aol?redir=http://www.freecreditreport.com/pm/default.aspx?sc=668072%26hmpgID=62%26bcd=De>
>> cemailfooterNO62)
>>
>> [Non-text portions of this message have been removed]
>>
>>
>
>
>
> [Non-text portions of this message have been removed]
>
>
>
> ------------------------------------
>
> Search the offical complete Avid-L archives at:   http://archives.bengrosser.com/avid/
>
> Everything you MUST know about Color Correction in one book:   http://tinyurl.com/ColorCorectionforvideo   Get your copy todayYahoo! Groups Links
>
>
>
>


------------------------------------

Search the offical complete Avid-L archives at: http://archives.bengrosser.com/avid/

Everything you MUST know about Color Correction in one book: http://tinyurl.com/ColorCorectionforvideo Get your copy todayYahoo! Groups Links

<*> To visit your group on the web, go to:
http://groups.yahoo.com/group/Avid-L2/

<*> Your email settings:
Individual Email | Traditional

<*> To change settings online go to:
http://groups.yahoo.com/group/Avid-L2/join
(Yahoo! ID required)

<*> To change settings via email:
mailto:Avid-L2-digest@yahoogroups.com
mailto:Avid-L2-fullfeatured@yahoogroups.com

<*> To unsubscribe from this group, send an email to:
Avid-L2-unsubscribe@yahoogroups.com

<*> Your use of Yahoo! Groups is subject to:
http://docs.yahoo.com/info/terms/

No comments:

Post a Comment