If it is the Morto worm you have got a lot of work ahead of you - you have to check and clean every pc in your network!
See the Symantec post on Morto:
http://www.symantec.com/security_response/writeup.jsp?docid=2011-082908-4116-99&tabid=2
Make sure all passwords on server and workstations are changed and made secure!
Do not underestimate the severity of the situation you are in. Personally, I would shut down the network now and run scans on all machines. Only reconnect a machine if you are sure it is clean.
Right now a standalone firewall would help as you could block:
.jifr.net
.jifr.co.be
.jifr.co.cc
210.3.38.82
Most important - install an up to date antivirus program, use Microsoft Security essentials on workstations if you do not have one. Buy one for the server - Symantec,Kaspersky, McAfee, Nod32...
See the Symantec post on Morto:
http://www.symantec.com/security_response/writeup.jsp?docid=2011-082908-4116-99&tabid=2
Make sure all passwords on server and workstations are changed and made secure!
Do not underestimate the severity of the situation you are in. Personally, I would shut down the network now and run scans on all machines. Only reconnect a machine if you are sure it is clean.
Right now a standalone firewall would help as you could block:
.jifr.net
.jifr.co.be
.jifr.co.cc
210.3.38.82
Most important - install an up to date antivirus program, use Microsoft Security essentials on workstations if you do not have one. Buy one for the server - Symantec,Kaspersky, McAfee, Nod32...
Last edited: