we've been hit with the nachi virus ... how to clean it

LuckyTaxi

Diamond Member
Dec 24, 2000
6,044
23
81
all of a sudden at 9am we get this message alerting us one of our servers had the nachi virus. so we cleaned it (CA was running so it said it cured it) and we left it at that. then we get calls from users stating they couldnt get to the internet. then my workstation decides to lock up and it's still in disarray.

anyways, we spent 7 hours trying to figure out where the source was coming from, but we still cant figure it out!
everytime we go clean a particular PC and reappears minutes later. i was able to retrieve a nachi removal tool from CA, but that didnt seem to do anything. i downloaded the welchi removal tool from symantec and it found two viruses from those PCs that were infected. i left work at 4:30pm with the issue unresolved. i figure i can do better once i'm at home with a working internet connection.

what we neglected to do was to disconnect the PCs in question from the network. then run the virus removal tool.
was this negligence the reason why i havent been able to get rid of this annoying bug?

crap...i think i forget to apply that patch. god i hate microsoft
 

Abzstrak

Platinum Member
Mar 11, 2000
2,450
0
0
easiest way I know is to put a sniffer between the network and the router and look at where the crazy ICMP traffic is coming from. You should be able to narrow it down in 2-3 minutes. Its probably multiple machines.
 

OZEE

Senior member
Feb 23, 2001
985
0
0
Also gotta remember to turn off the system restore so you don't keep reinfecting yourself
 

ozonecomputer

Member
Nov 12, 2003
28
0
0
Right click on "My Computer", there's a System Restore tab where you can turn it off. This works in XP anyway.
 

trmiv

Lifer
Oct 10, 1999
14,670
18
81
That little piece of crap wormed its way onto our network too. Believe it or not, the free online Trend Micro scanner worked great at getting rid of it. Best is to download the patches that fix the exploit. Unplug computer from the network, run virus scan to clean. Then, run the updates, then plug back in.
 

poppyq

Senior member
Oct 20, 2003
255
0
0
Make sure you patch BEFORE you use a removal tool, otherwise there's no point. You're just going to remove it and then get reinfected over and over. Also make sure your viruscan programs are using the latest definition files (if they are, they should have caught this before it even spread). My friend was running an anti-virus program but got the virus, turns out the program was running but hadn't updated the definitions on over 6 months.
 

NogginBoink

Diamond Member
Feb 17, 2002
5,322
0
0
What kind of incompetent IT staff do you have that you get Nachi MONTHS after it was the MOST PUBLICIZED computer threat ever?

What does it take for people to protect their machines? And we're not talking Joe Average Home User, we're talking about a company that presumably depends on computing resources to make money.

I'm simply flabbergasted. This is inexcusable. Your IT staff should be fired for utter and total incompetence.