17 lines
889 B
Markdown
17 lines
889 B
Markdown
---
|
||
tags:
|
||
- policy
|
||
---
|
||
1. Tell users to notify IT immediately if S1 notifies of detected malware.
|
||
|
||
2. Disconnect the infected PC from the network immediately and run a full scan. If you don’t know whose is infected, proceed to #3.
|
||
|
||
3. Look in the root of all network shares for the most recently modified files. There should be a file called PLEASE_READ.txt or something similar. The owner of that/those files is the infected PC.
|
||
|
||
4. In vSpere web client, edit settings of API-DC11. Find ‘Network adapter 1’ uncheck Connected and click OK. This is the equivalent of pulling the plug to that server’s network connection. This can be done for other vms as well.
|
||
|
||
5. If it seems appropriate shut down api-nas01 and api-nas02.
|
||
|
||
6. Go to the S1 console and run a full computer scan on all computers to verify nobody else is infected.
|
||
|
||
7. Assess the damage and restore encrypted files. |