Check all app shares are readonly
lock down any shared use executables on the network
Try an trace back any workstation infections to the network source executable and then lock it down and clean it
ban the use of USB drives
limited cpu morning and afternoon scans for all workstations for dl_,dll,exe,scr,tmp
Full overnight workstation scans on all files at high CPU (get them to leave them on)
Evening scans on all servers servers for dl_,dll,exe,scr
Monitor the network for machines which are online but have had their AV disabled by sality, isolate and reimage.
stuff like that worked for us when we got zero day hit by it.
oh yeah and make sure your service desk and engineers are checking and cleaning their data as some of ours spread more than they cleaned
McAfee Maniac (Volunteer Moderator)
x2 4.00 ePolicy Orchestrator (Patch 5/Build 1298)
x1 4.5 ePolicy Orchestrator ( Test server)
x1 3.6.1.255 ePolicy Orchestrator 3.6.1 Patch 4
Mcafee Agent 3.6.0.608 & 4.0.0.1494
Groupshield 6.02
VSE 8.5.0.781 Patch 4/8 5400 10000 units
VSE 8.7.0.570 Patch 2 5400
x1 Sophos EC 3 SAV 10 x 70