I have a Windows 2003 server patched to the hilt and with the latest McAfee DAT and it still somehow managed to get infected with WinNT/Hackdef.AW. I cannot seem to be able to remove this. I've tried:
-Microsoft's malicious software removal tool - identified WinNT/Hackdef.AW, said it was remove, but reappeared after reboot.
-NAI's Enterprise VirusScan with latest DAT didn't detect.
-NAI's Stinger didn't detect.
-AdAware didn't detect.
-Tried a couple of other's, but didn't detect.
Symptom:
After reboot, shortly after login, blank windows popup, system will be shutdown window appears with countdown (shutdown -a = workaround), left alone would result in reboot.
Thanks for any assistance you can offer.
Bill