Hehe, happened to RP twice.Originally posted by Shotgun:Sometimes the problem is not with having uninvited guests on the network. Its having invited guests with insecure/infected/ laptops. Entire networks can kena for no reason.
Well I was thinking that most companies that use managed switches that are VLAN capable would probably have a windows domain controller. You can turn on the RADIUS service and auth against that.Originally posted by Shotgun:EAP with WPA will require servers for authentication. If its a big enough network, I guess its worth it?
The cheaper way is as mentioned, leave the WEP guys on a seperate VLAN and route them to the network with extremely strict port restrictions.
Sometimes the problem is not with having uninvited guests on the network. Its having invited guests with insecure/infected/ laptops. Entire networks can kena for no reason.
they should ask the students to do it themselves... tsk tsk tsk... what sort of education are they giving?Originally posted by ndmmxiaomayi:LOL
For some reason I also never tio.
Twice it infected RP, twice I wasn't affected.
When see the queue for reformatting... you can prepare to camp your laptop.
NYP aso kena a thumbdrive virus call auto.exe. Best part is the whole level is infected and the helpdesk doesnt seem to know about itOriginally posted by ndmmxiaomayi:Hehe, happened to RP twice.
They did that previously... and figured it was a bad move. We lose lots of MS licenses this way and MS is not happy about it. So they do it instead.Originally posted by AndrewPKYap:they should ask the students to do it themselves... tsk tsk tsk... what sort of education are they giving?
Running XP.Originally posted by Shotgun:You were running vista or just a very well secured XP?
The reformat queue at SP moves a lil faster. Those school approved laptops had ghost images stored in the network.
Aha. Send it to the helpdesk and the helpdesk will kena.Originally posted by abao:NYP aso kena a thumbdrive virus call auto.exe. Best part is the whole level is infected and the helpdesk doesnt seem to know about it
Lucky thing is the virus doesnt seem to do much and the AVG on my own laptop detects and clears it rather quickly.
I also found a bat script written by dunnoe who that seems to clear and delete the virus on one of the pc's. Later I post the bat file for you to verify.
Wrong !!! on paper .... in real wireless have more interference and you can never fully use utilitise it - thus no matter what cable is still faster !!!Originally posted by ndmmxiaomayi:802.11N is faster than most Cat 5 cables. But Cat 6 cables will still win over wireless...
Eh? You guys didn't get corporate licenses or something? Over here, all the students use one XP Pro license.Originally posted by ndmmxiaomayi:They did that previously... and figured it was a bad move. We lose lots of MS licenses this way and MS is not happy about it. So they do it instead.
Even for network install... it's freaking slow. Around 10,000 staff and students, we don't have so many switches to plug in to.
And the network at one go can only handle this much.
20-port switch, 10 switches, 200 laptops can be formatted at one go.
Each session takes about 4 to 5 hours... you can imagine how bad it is.
Even with CDs going around, the time is reduced to about 3 hours per laptop. Not fast enough.
queue at helpdesk will be longer...not that many people know linux as well as windows.Originally posted by Phaze:Migrate all to linux.
It's corporate license... that's why MS not happy. One license key can install on a lot of PCs. No need validation also.Originally posted by Shotgun:Eh? You guys didn't get corporate licenses or something? Over here, all the students use one XP Pro license.
Our tech center here runs from 9-5, with booking required for students who want to reformat. That way, we control the number of students reformatting at one time.
Last I checked, there were at least 3-4 switches wiring up the entire notebook tech support center. Whether theres a Gigabit ethernet connected to the image server, i'm not sure. It would make sense if there was.
Easier said than done. RP is totally wireless... using Linux will totally break that... add on to the fact that getting wireless to work in Linux is hell. 3rd party programs like ndiswrapper is not compatible with all drivers... manufacturers that produce Linux wireless drivers don't produce a simple enough instructions to install the drivers... either that, the drivers don't work at all...Originally posted by Phaze:Migrate all to linux.
Yupz. I noticed it with .pf extensions when doing a search on some of the school computers.Originally posted by ndmmxiaomayi:Aha. Send it to the helpdesk and the helpdesk will kena.
You can delete the file... but it's stuck in the registry... that's how it can be very persistent...
Reference thread - http://forums.spybot.info/showthread.php?t=18625&page=2
From unknown person:tink these deletes the malwares right?
delete_auto.bat
@echo off
cls
if exist c:\autorun.inf attrib -h -a -s -r c:\autorun.inf
if exist d:\autorun.inf attrib -h -a -s -r d:\autorun.inf
if exist e:\autorun.inf attrib -h -a -s -r e:\autorun.inf
if exist f:\autorun.inf attrib -h -a -s -r f:\autorun.inf
REM Replace with harmless autorun.inf
REM ==================================
if exist c:\autorun.inf echo "[autorun]" > c:\autorun.inf
if exist d:\autorun.inf echo "[autorun]" > d:\autorun.inf
if exist e:\autorun.inf echo "[autorun]" > e:\autorun.inf
if exist f:\autorun.inf echo "[autorun]" > f:\autorun.inf
REM Make it read-only to prevent trojan from replacing its own copy.
REM ================================================================
if exist c:\autorun.inf attrib +r c:\autorun.inf
if exist d:\autorun.inf attrib +r d:\autorun.inf
if exist e:\autorun.inf attrib +r e:\autorun.inf
if exist f:\autorun.inf attrib +r f:\autorun.inf
if exist c:\auto.exe attrib -h -a -s -r c:\auto.exe
if exist d:\auto.exe attrib -h -a -s -r d:\auto.exe
if exist e:\auto.exe attrib -h -a -s -r e:\auto.exe
if exist f:\auto.exe attrib -h -a -s -r f:\auto.exe
if exist c:\auto.exe echo "0"> c:\auto.exe
if exist d:\auto.exe echo "0"> d:\auto.exe
if exist e:\auto.exe echo "0"> e:\auto.exe
if exist f:\auto.exe echo "0"> f:\auto.exe
if exist c:\auto.exe attrib +r c:\auto.exe
if exist d:\auto.exe attrib +r d:\auto.exe
if exist e:\auto.exe attrib +r e:\auto.exe
if exist f:\auto.exe attrib +r f:\auto.exe
another bat file found on the same computer
c:
cd %windir%
if exist DiskMan32.exe attrib -h -a -s -r DiskMan32.exe
if exist Kvsc3.exe attrib -h -a -s -r Kvsc3.exe
if exist AVPSrv.exe attrib -h -a -s -r AVPSrv.exe
if exist mppds.exe attrib -h -a -s -r mppds.exe
if exist MsIMMs32.exe attrib -h -a -s -r MsIMMs32.exe
if exist NVDispDrv.exe attrib -h -a -s -r NVDispDrv.exe
if exist cmdbcs.exe attrib -h -a -s -r cmdbcs.exe
if exist upxdnd.exe attrib -h -a -s -r upxdnd.exe
if exist DbgHlp32.exe attrib -h -a -s -r DbgHlp32.exe
if exist msccrt.exe attrib -h -a -s -r msccrt.exe
if exist DiskMan32.exe del DiskMan32.exe
if exist Kvsc3.exe del Kvsc3.exe
if exist AVPSrv.exe del AVPSrv.exe
if exist mppds.exe del mppds.exe
if exist MsIMMs32.exe del MsIMMs32.exe
if exist NVDispDrv.exe del NVDispDrv.exe
if exist cmdbcs.exe del cmdbcs.exe
if exist upxdnd.exe del upxdnd.exe
if exist DbgHlp32.exe del DbgHlp32.exe
if exist msccrt.exe del msccrt.exe
c:
cd %windir%
cd system32
if exist mppds.dll attrib -h -a -s -r mppds.dll
if exist upxdnd.dll attrib -h -a -s -r upxdnd.dll
if exist DiskMan32.dll attrib -h -a -s -r DiskMan32.dll
if exist cmdbcs.dll attrib -h -a -s -r cmdbcs.dll
if exist Kvsc3.dll attrib -h -a -s -r Kvsc3.dll
if exist DbgHlp32.dll attrib -h -a -s -r DbgHlp32.dll
if exist AVPSrv.dll attrib -h -a -s -r AVPSrv.dll
if exist MsIMMs32.dll attrib -h -a -s -r MsIMMs32.dll
if exist NVDispDrv.dll attrib -h -a -s -r NVDispDrv.dll
if exist msccrt.dll attrib -h -a -s -r msccrt.dll
if exist mppds.dll del mppds.dll
if exist upxdnd.dll del upxdnd.dll
if exist DiskMan32.dll del DiskMan32.dll
if exist cmdbcs.dll del cmdbcs.dll
if exist Kvsc3.dll del Kvsc3.dll
if exist DbgHlp32.dll del DbgHlp32.dll
if exist AVPSrv.dll del AVPSrv.dll
if exist MsIMMs32.dll del MsIMMs32.dll
if exist NVDispDrv.dll del NVDispDrv.dll
if exist msccrt.dll del msccrt.dll
Yupz. I noticed it with .pf extensions when doing a search on some of the school computers..PF files = Prefetch files = no harm
Anyways, I'm glad that whoever did it, it cleared the virus on the computer i used for 1 of my practicalsOriginally posted by ndmmxiaomayi:.PF files = Prefetch files = no harm
But I always delete them... don't like lurkers.
[/quote]
i seecoz in my school, C:\ is main drive. D, E, F are usually for CD or thumbdrives. the middle letters are network mapped drives, some which we dont have read/ write access.
Why is the batch file only restricted to C, D, E and F drives? What if the user has more?
[quote]
The batch file only remove certain variants... perhaps only those around your school?
It doesn't remove the reference registry entry... if somebody plugs a thumbdrive in, he will be infected... just that files may not be found.
Anyway, although the replacement of autorun.inf files is a good idea... our dear bad guys is always ahead of us.
The batch file is a bit cute in its own way... first assume that C is where Windows is installed, then it uses a variable file path (%windir%) ... LOL
of course cable... provided u get the correct one...Originally posted by davidche:Is cable modemor wireless modem faster??
Wireless seems to be more convinient horr, but is it true that other ppl may be able to tap into your connection?
And as a general qn, is transmission between cable faster,.. or without cable ??
Applies for mouse too