urgent help needed with inet.bat file

S

Stan

I have been trying to figure this out for some time now
and I just have not been able to do it so it is time to
turn for help. I hope someone can help me with this.

Windows 2000 advanced server with service pack 4 installed
At some point the sytem became infected with bat.trojan. I
have locked everything down and the norton virus scan is
doing the job. Here is the problem. When ever I start the
server or create a terminal connection to the server It
creates a inet.bat file in the system32 directory. Norton
identifies it as bat.trojan and since it can't delete it,
it Quarantine's it. So no harm is done. However, I would
like to get rid of the problem. I have searched the
registry to see if i could id what is creating the file
but find nothing. It has to be a dll that is corrupted but
not identified as a virus.

So does anyone know of any tools that can verify dll's or
determine what is creating the file when I start a
terminial sevices connection.

Any help at all would be very much appreciated.
Thanks,
Stan
 
S

Steven L Umbach

That may be difficult after the fact. You migh try running System File
Checker as in sfc /scannow to check system files as described in KB link. Of
course the best solution is to rebuild, but I imagine you already know that
and are trying to avoid it. One of my favorite tools is Spybot Search and
Destroy which in addition to scanning for parasites, can be used in advanced
mode/tools to check system processes and map them to application/folder if
possible and also display start up programs which you can then selectively
disable. I would aslo check the free utilities at SysInternals. You possibly
could run filemon to see what is going on when you start a TS session,
possibly comparing results to a known like configured good system. They have
other utilities that may be of use. Also check out Karl's FAQ link on
virus/trojans. --- Steve

http://support.microsoft.com/default.aspx?scid=kb;EN-US;222471
http://spybot.eon.net.au/
http://www.sysinternals.com/ntw2k/utilities.shtml
http://securityadmin.info/faq.asp#virustoc
 

Ask a Question

Want to reply to this thread or ask your own question?

You'll need to choose a username for the site, which only take a couple of moments. After that, you can post your question and our members will help you out.

Ask a Question

Top