I am getting an annoying virus and I'm trying to know where its comming from? The fallowing is from the sonicwall2040 log. The ips starting from 192 are computers within house and the mac addresses I left it at zero's, because I dont want to disclose that info. Note: I am running an exchange server 2k aswell. The virus name is the netsky. How do I stop it? Should I close port 137? if yes How do I do that? and would it affect anything on the network? I have deleted the virus before from all pcs and exchange server using all tricks from all antiviral websites and using tek-tips, but to no avail, it still comes back. That virus is very annoying. Please Help!!!!!!!!!!!!!!!!!!
06/01/2005 11:01:17.768 IP spoof dropped 192.168.1.29, 137, LAN 192.168.1.33, 137, DMZ MAC address:00.00.00.00.00.00
06/01/2005 10:59:56.128 IP spoof dropped 192.168.1.25, 137, LAN 192.168.1.38, 137, DMZ MAC address:00.00.00.00.00.00
Most Appreciative,

06/01/2005 11:01:17.768 IP spoof dropped 192.168.1.29, 137, LAN 192.168.1.33, 137, DMZ MAC address:00.00.00.00.00.00
06/01/2005 10:59:56.128 IP spoof dropped 192.168.1.25, 137, LAN 192.168.1.38, 137, DMZ MAC address:00.00.00.00.00.00
Most Appreciative,