Our Windows 2000 SBS AD server has been terminally infected with a 
variant of the Virut virus.  It will die soon, as will single sign-on,  
DNS, DHCP, and WINS.

DNS will be easy to migrate.  There are numberous writeups on DHCP/WINS 
(I seem to recall), but I'm going into uncharted territory with the user 
migration.  I'm not even certain exactly what type of implementation I 
really need.  Here are some possibilities:

http://www.samba.org/samba/docs/man/Samba-HOWTO-Collection/samba-pdc.html 
(Just samba)

http://www.howtoforge.com/openldap-samba-domain-controller-ubuntu7.10 
(with OpenLDAP)

It also seems possible to do Samba/Kerberos (I lost the reference for 
now ... I know, lmgtfy)

I'm not certain where to go, and our company is looking to hire someone 
who has either experience in this, or has some Windows Domain 
Authentication/active directory/LDAP background, which is the greatest 
gaping hole in our understanding.

The timescale is as soon as possible (I'm not sure how long it will be 
until one of the borked services writes to null again).  Please drop me 
a line.

Best,

Josh