I have been battling a virus on my network for since last Friday. My virus software (Trend) finds the virus, but is misdiagnosing it. It says it is Dos_Agobot.GEN which affects the hosts file. It is fixing that problem, but at each re-occurrence also drops lsas.exe in the system32 folder (and sometimes others) sets it to run in the registry in
We are booting into safe mode and deleting the files and the registry entries. It eventually comes back.
This is affecting Windows 2000 and some or ouor XP machines. None of our NT workstations have been affected.
We thought we were done with it as it had been gone since late yesterday, but reappeared with a vengeance this afternoon.