Hi Friends

Im Elango from India,

I have new problem, we have 6 computers connected with network switch. one system win2K other five is win98. resently a virus affect all our systems (virus name w32.sality) still we unable to clean it. if i scan with norten virus not found. but we get virus found message very offen with each and evry exe files. The virus message is follwoing:

"" Scan type: Realtime Protection Scan
Event: Virus Found!
Virus name: W32.Sality.U
File: C:\DRIVER\WIN98II\SUCATREG.EXE
Location: C:\DRIVER\WIN98II
Computer: CHEMICAL2
User: sevak
Action taken: Clean succeeded : Access allowed
Date found: Tuesday, December 19, 2006 3:16:57 PM ""

Secondly, due to this problem one of our systems win2K when i switch on it immediately all the five systems internet sharing is gone out. after some time we are get the internet sharing after remove the dns numbers from win2k computer.

Even i tryed DHCP setting also. when the system browse the internet the adsl router light and ethernet switch light for router and the problem facing win2k system light are blinking very fast. If i remove the dns numbers or from win2k computer then all other is work fine.

We configured each system ip like this to x.x.x.7 the router ip is 192.168.1.1.

I have changed the router setting as DHCP and checked with ipconfig all other computors working fine, they automatically asigned by router ip as and 192.168.2.105.

But this particular computors show ip as , and gateway 0.0.0.0.

Is there any solution for this two problem without reinstall the OS.

Please guide me.

Regards
Elango:sad:

Dani AI

Generated

Immediate priorities: isolate infected machines and stop further spread. As reported by , multiple LAN computers are showing realtime infection alerts and a single Win2000 host appears to trigger network disruption when it joins. Physically disconnect the suspected host(s) from the network and disable all shared folders and mapped drives before any cleanup is attempted.

Suggested cleanup workflow (ordered, on a clean machine when creating tools): image the infected drive to preserve evidence; build a bootable rescue USB/CD on a known‑clean computer; boot the infected system from that rescue media and run full scans with a rescue engine (examples: Kaspersky Rescue Disk, Microsoft Defender Offline, ESET SysRescue). After offline remediation, boot into Safe Mode and run updated on‑disk scanners (Malwarebytes or a current AV). If many executables remain altered or corrupt, restore those applications from trusted backups or reinstall them — in-place fixes can work but are not guaranteed.

To locate the network problem (builds on ’s packet-capture suggestion): collect basic network info and identify any rogue DHCP/proxy responders. Useful commands to run on a connected Windows machine:

ipconfig /all
arp -a
netstat -ano
route print

If Wireshark is available, capture and filter for DHCP/BOOTP (filter bootp or udp.port==67 || udp.port==68) to see which MAC/IP is issuing offers. When a rogue responder is found, disconnect it, disable services like ICS/Routing or any third‑party proxy on that box, and factory‑reset the router; then reconfigure DHCP with a known range and a new admin password.

Final points: unsupported OSes (Win98/Win2K) are high risk — consider replacement. After cleaning, update AV signatures, rotate all passwords, monitor the network for reinfection, and prefer image restores or clean reinstalls for critical systems. As noted, removing shared access and scanning from an offline environment are essential first steps.

dear Elango !

you have virus in your network so do some step as

fst think unshared all sheared folder and map drive or remove the full control of all (sheared folder). on server or system.

2nd remove server from the network and scan you server in dos mode with a good anti virus, same as with system.

3rd check the Bad sector in H.disk.

it can be solution

vipin dev

Hi, as your network is a small network, it's not hard for you to find out the source of the virus. why not capture the packets in your network and try to analyze the source of it. If you monitor your network all the time, it will be quicker for you to find out the problems and solutions.

hi
i want a new virus collection
please help me

Be a part of the DaniWeb community

We're a friendly, industry-focused community of developers, IT pros, digital marketers, and technology enthusiasts meeting, networking, learning, and sharing knowledge.