AppleShare Network: WDEF Infection and Remedy



Our office has an AppleShare network with about 12 Macintosh nodes of
varying configuration. The workstations are constantly going catatonic for
about a minute at a time. They seem to be looking out onto the network for
something (there's a network activity indicator under the Apple when this
occurs), but all work is being done locally.

Almost any action can bring on the behavior. We're using a combination of
LocalTalk and PhoneNet. Does this possibly sound like a problem with
termination in the network cabling? I've used Inter*Poll to test
performance, but can't locate any particular black hole on the net.

It sounds more like you're dealing with the WDEF virus. The virus tries to
infect a mounted AppleShare volume but, because AppleShare doesn't use the
Desktop file, everything comes to a halt while WDEF figures out what to do.

We suggest running a good anti-virus utility on all your Macintosh systems
except the file server. Symantec's SAM version 1.5 or higher will catch
WDEF. You will want to eradicate the virus from your server (you'll have to
start up with a floppy), but you don't want to install an anti-virus INIT
on it, so that it runs all the time. You really wouldn't be keeping the
server clean, just slowing it down.

You can remove WDEF without an anti-virus utility by simply rebuilding the
Desktops on every Macintosh on the network. But be aware that you probably
have several infected floppy disks around, just waiting to reinfect your
hard drives. Also, if you work at home, you should check those computers
for infection.


Published Date: Feb 18, 2012