Worm attack

Well we got hit by the Bagle.B worm today at the office. Our virus software was not updated yet before a user opened an email with an executable and ran it. No matter how often we tell our users not to open attachments, they still do. The upside to all this, is that with our software Trend’s OfficeScan and ServerProtect we were able to implement and outbreak policy that locks the machines and stops the virus from spreading. We were then able to issue a scan all to have all machine scan themselves to delete any copies of the virus. Still it shot the entire afternoon.

This incident will cause us to rethink our policy about viruses, because I had ClamAV product running on our mail gateway however I was only tagging and passing the emails. We may change that so that it discards/rejects/bounces the emails instead.

Explore posts in the same categories: Work

Comment: