Re: Help with virus on 2000 machine



From: "WiZEGUY" <WiZEGUY@xxxxxxxxxxxxxxxxxxxxxxxxx>

| Is there an application that i can run on a 2000 machine that shows me what
| patches are needed? Mind you, these servers have no access to the internet.
| I'm having an issue with a virus that i can't get rid of and i think it's
| because these systems haven't been patched in a long time.
|
| FYI about virus - Risk: "Downloader" in File: C:\WINNT\system32\i

That line is incomplete...

What comes after; C:\WINNT\system32\i ?

|
| My antivirus is successfully catching and deleting it but it reoccurs
| everytime a scan is performed. Also, it's now starting to shutdown by itself
| with that system shutdown window that states:
|
| This system is shutting down. Please save all work in progress and log off.
| Any unsaved changes will be lost. This shutdown was initiated by NT
| AUTHORITY/SYSTEM. The system process 'C:\WINNT\system32\services.exe'
| terminated unexpectedly with status code 128. The system will now shut down
| and restart.
|
| Any help how to resolve this is very much appreciated!

Complete information is needed for the next step.
This includes what anti virus software is indicating "Downloader" which, by the way, is a
Trojan and NOT a virus.

--
Dave
http://www.claymania.com/removal-trojan-adware.html
http://www.ik-cs.com/got-a-virus.htm


.



Relevant Pages

  • Re: Microsoft Security Bulletin MS03-026, latest windows 2000 patch
    ... virus that exploits vulnerability described in MS03-026. ... workstation that is not patched and it just happens to be a Domain Admin ... > latest patches on my servers and on most workstations on ... I know that my Servers ...
    (microsoft.public.win2000.security)
  • SP1, Services, Reboots
    ... I have a 2 Windows 2003 Servers in different domains. ... This shutdown was initiated by NT Authority\System. ... The system will now shutdown and restart... ... this has only started since SP1 and the other patches were ...
    (microsoft.public.windows.server.general)
  • Re: system shut down
    ... You might have the sasser virus or the blaster virus ... To stop shutdown, click Start, click Run and type: ... It doesn’t remove the worm. ... You can then connect to the Internet and download the Microsoft relevant patch. ...
    (microsoft.public.windowsupdate)
  • Re: IIS Hack : Anyone explain cause...
    ... But as noted it was an NIMDA virus on the machine which caused the ... protected rant as we all know that IIS and indeed lots of software has ... bugs...this is why a whole host of patches have recently been released ... the virus was non-destructive and our global ...
    (microsoft.public.inetserver.iis)
  • Re: strange notepad on desktop
    ... Running a firewall is only part of a complete security plan. ... Download and run HFNETCHK from www.microsoft.com/security to see what ... critical patches if any you are missing, ... Windows and IIS from the same location, and download and run a virus scan to ...
    (microsoft.public.security)