本帖最后由 senlinlu 于 2017-05-14 18:05 编辑
关于“勒索病毒”病毒应急处理方案 作者:senlinlu 2017.5.14 1、通过短信群发通知:明天上班第一件事,拔掉网线; 2、科信或信息中心立刻组织专业人员在核心网络设备二、三、四级交换机和出入口防火墙、路由器上阻断445端口的通讯,防止病毒扩散; 3、在一机两用平台或病毒监控中心平台查看已监测到的因未关机而已感染的主机,确认是否断网; 4、制作补丁集、免疫工具、关闭服务脚本U盘,并写保护防止感染; 5、依据部门轻重依次打补丁、运行关闭服务脚本和免疫工具。 6、最后才是处理中毒终端,运行蠕虫病毒恢复工具RansomRecovery.exe并备份相关资料。
网络设备阻断TCP 135、139、445和UDP 137、138端口 Cisco交换机 ip access-list deny-wannacry deny tcp any any eq 135 deny tcp any any eq 139 deny tcp any any eq 445 deny udp any any eq 137 deny udp any any eq 138 permit ip any any interface [需要挂载的三层端口名称] ip access-group deny-wannacry in ip access-group deny-wannacry out 华为交换机
acl number 3050 rule deny tcp destination-port eq 135 rule deny tcp destination-port eq 139 rule deny tcp destination-port eq 445 rule deny udp destination-port eq 137 rule deny udp destination-port eq 138 rule permit ip traffic classifier deny-wannacry type and if-match acl 3050 traffic behavior deny-wannacry traffic policy deny-wannacry classifier deny-wannacry behavior deny-wannacry precedence 5 interface [需要挂载的三层端口名称] traffic-policy deny-wannacry inbound traffic-policy deny-wannacry outbound
免疫工具下载地址:nsatool.exe 补丁下载地址: l Security Update for Windows XP SP3 (KB401259 p-kb4012598-x86-custom-chs_dca9b5adddad778cfd4b7349ff54b51677f36775.exe l Security Update for Windows Server 2003 (KB401259 erver2003-kb4012598-x86-custom-chs_b45d2d8c83583053d37b20edf5f041ecede54b80.exe l Security Update for Windows Server 2003 for x64 Systems(KB401259 erver2003-kb4012598-x64-custom-chs_68a2895db36e911af59c2ee133baee8de11316b9.exe l Security Update for Windows 7 (KB4012212) cu/2017/02/windows6.1-kb4012212-x86_6bb04d3971bb58ae4bac44219e7169812914df3f.msu l Security Update for Windows 7 x64 (KB4012212) cu/2017/02/windows6.1-kb4012212-x64_2decefaa02e2058dcd965702509a992d8c4e92b3.msu l Security Update for Windows Server 2008 R2 x64 (KB4012212) cu/2017/02/windows6.1-kb4012212-x64_2decefaa02e2058dcd965702509a992d8c4e92b3.msu l Security Update for Windows10 () cu/2017/03/windows10.0-kb4012606-x86_8c19e23de2ff92919d3fac069619e4a8e8d3492e.msu l Security Update for Windows10 x64 () cu/2017/03/windows10.0-kb4012606-x64_e805b81ee08c3bb0a8ab2c5ce6be5b35127f8773.msu
关闭服务脚本: 新建一个关闭服务脚本.bat脚本文件 net stop rdr net stop srv net stop netbt 勒索蠕虫病毒文件恢复工具下载链接:
https://dl.360safe.com/recovery/RansomRecovery.exe
|