22 Oct
2003
22 Oct
'03
8:24 a.m.
It sounds to me like the Nachi/Welchia virus, it could be a new variant.
Have you tried doing a "netstat -ano" on a infected machine and seeing
if
there are any port open that should not be, like 4444 or 707.
And then look for the PID in task manager.
You could also use something like Tcpview.
http://www.sysinternals.com/ntw2k/source/tcpview.shtml
jfp.
------------------------------------------------------------------------
Jean-Francois Pirus