Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations SkipVought on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

Finding Natchi/Blaster

Status
Not open for further replies.

bazcurtis

Technical User
Jul 11, 2001
134
0
0
GB
Hi,

We seem to have one machine on our network with natchi. We can't find it. Does anyone know if you can find it via the network traffic it produces and if so what tools would be good for this?

Any help most welcome.

Best wishes

Michael
 
The best way to resolve the problem would be to shut down all servers (if possible) and workstations, disconect the network cables then run the fixes available from the net ie (will need to download this type of NACHISFX.EXE tool before you disconect from the network and save burn to a cdrom)
Have you patched all the 2000/XP/nt machines with the Microsoft patches
Although this is a long and widen process, at least you can totally disinfect the virus from the system. (just completed the task myself!)
 
we used angryip (try a google search to locate and download this) run angryip or a network sniffer that shows port activity and pay attention to ports 4444, 707, and 69 if a machine is running traffic from these ports check the machine for the nachi
 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top