Would you mind copy and pasting the code in an email. Some of us have .vbs ,.exe ...etc restrictions Thanks -----Original Message----- From: thin-bounce@xxxxxxxxxxxxx [mailto:thin-bounce@xxxxxxxxxxxxx] On Behalf Of Paul DeHaan Sent: Tuesday, August 19, 2003 2:25 PM To: thin@xxxxxxxxxxxxx Subject: [THIN] MSBLAST remove - AD Group Policy startup script. Here is a script that we have implemented as a Group Policy startup script. It will run each time a computer in our Active Directory domain turns on or restarts their computer, then write to a log file if it finds and removes one or move of the worms. This has caught and removed a number of unknown instances of the worm for us. The program follows the basic steps to remove the MSBlast worm and some of it's variants (posted by Symantec, NAI, etc.). Feel free to use or edit this to fit your environment. Regards, ******************************************************** This Week's Sponsor: RES PowerFuse, The Management Framework for Windows Eliminate Multiple Tools, Multiple Support Channels and Multiple Costs Manage, Control, and Secure an Entire Windows environment with Ease, including Real-time Reporting and Documenting Components Validate a Meaningful ROI on All of your IT Investments with RES PowerFuse. http://www.respowerfuse.com/ ********************************************************** Useful Thin Client Computing Links are available at: http://thethin.net/links.cfm For Archives, to Unsubscribe, Subscribe or set Digest or Vacation mode use the below link: http://thethin.net/citrixlist.cfm