disconnect/disallow the offending systems asap
this will reduce load and buy time for research & fixing.
www.symantec.com is reporting some new worms.. you might wanna hit the site..
there are free manual fixes that you can download for individual threats
talk to your network guys to see where it all comes from.
later talk about beefing security. no dhcp & allow access by MAC only.
allowed machines are subject to search, monitoring & confiscation.
access control, policy and enforcement. ban or control wifi systems.
allow nothing personally owned. inspect provided equipment regularly.
laptops that go home and surf the net then come in and ride on yours are
some of the worst offenders im sure. users dont update virus definitions
frequently eneough or dont run firewalls at home then they hand carry
nasties into your network. seperate your infrastructure. multiple domains..
campus.east.. campus.west.. campus.north.. campus north2 this minimizes
viral spread. its like getting VD. then giving it to half of the campus then
saying "im sorry" sorry doesnt cut it.
and i leave you with a question:
what good is a self defending network when you can rely on users to break it
from the inside?