The Nachi variants were coded to delete themselves when the system clock reached 1 Jan 2004,
yep tru forgot that.. I will do a bit of research.. have had it on boxes at work in the last week..

Ali.. While it is possable for some one to have the virus on their machine.. What folder was it in? The question is what was the delivery method..

While I am seriously watching for you information, I feel it is some code that spreads via email/Sneakernet, not one that is spread via the RPC/DCOM Vulnerability.. If the Admin service shutdown window comes up on a Win9x machine.. Well the code for that came With the Virus.. Because as you Know Ali.. the Shutdown problem was as a result of the RPC Service failing As a result of the attack through the various ports.. The Message comes from the NT Kernal..
I feel your "Clients" had two Virii, one was the lovely one that shutdown their machine, the other Was the Blaster but it was dorment ie not active..

Now that the subject has been brought up.. I will Find a Win9x box and put a copy of blaser on it and set it running and see what it does..

cheers