
22 Oct
2003
22 Oct
'03
1:24 p.m.
It sounds to me like the Nachi/Welchia virus, it could be a new variant. Have you tried doing a "netstat -ano" on a infected machine and seeing if there are any port open that should not be, like 4444 or 707. And then look for the PID in task manager. You could also use something like Tcpview. http://www.sysinternals.com/ntw2k/source/tcpview.shtml jfp. ------------------------------------------------------------------------ Jean-Francois Pirus <jfp(a)clearfield.com> Clearfield Software Ltd Phone (+64-9) 358 2081 4th Floor 8-10 Whitaker Place Fax (+64-9) 358 2083 P O Box 2348 Auckland, New Zealand ------------------------------------------------------------------------