Results 1 to 12 of 12

Thread: W32.Welchia.Worm

  1. #1
    O\/\/N3D
    Join Date
    Jul 2003
    Location
    Glasgow
    Posts
    372
    Thanks
    0
    Thanked
    0 times in 0 posts

    W32.Welchia.Worm

    Beware , brand new worm, only discovered tonight ..... dont seem too malitious (sp?) but its like only a few hours old so they may not know everything about it yet.
    Was just removing the Blaster worm from my mum's machine and this popped up in norton.

    more info here http://securityresponse.symantec.com...chia.worm.html

    thought I would let you know

  2. #2
    herbalist
    Join Date
    Jul 2003
    Location
    on a nice fluffy cloud in my head
    Posts
    1,335
    Thanks
    0
    Thanked
    0 times in 0 posts
    cheers mate

    if war is the answer, then we are asking the wrong question
    2 things i hate the most - xenophobia and the french
    "chuffing"

  3. #3
    DR
    DR is offline
    on ye old ship HEXUS DR's Avatar
    Join Date
    Jul 2003
    Location
    HEXUS HQ, Elstree
    Posts
    13,412
    Thanks
    1,060
    Thanked
    841 times in 373 posts
    thanks for the headsup

  4. #4
    | 4|\/| 31337!!!!!!1
    Join Date
    Jul 2003
    Location
    Stourbridge, West midlands, England
    Posts
    445
    Thanks
    0
    Thanked
    0 times in 0 posts
    Cheers. man. I think i might write a lil script for dealing with it. I just know Im gonna get mates that dunno wot to do when they get it. Microsoft patches are to big to download quickly on dial up so a nice lil script will did the job last time. Poor german mate on dial up couldnt stay online long enuff to download the patch.

    Arguing with an administrator is like kicking God in the nuts

  5. #5
    HEXUS.social member Agent's Avatar
    Join Date
    Jul 2003
    Location
    Internet
    Posts
    19,185
    Thanks
    739
    Thanked
    1,614 times in 1,050 posts
    You dont need the patch to stop it shuting down.
    Quote Originally Posted by Saracen View Post
    And by trying to force me to like small pants, they've alienated me.

  6. #6
    | 4|\/| 31337!!!!!!1
    Join Date
    Jul 2003
    Location
    Stourbridge, West midlands, England
    Posts
    445
    Thanks
    0
    Thanked
    0 times in 0 posts
    I havnt really looked at the virus and I havnt had it because Im on 98 and my mate lives in germany and there is no way she would have understood instructions so I just read its paths and wrote a lil script.

    Arguing with an administrator is like kicking God in the nuts

  7. #7
    Member
    Join Date
    Jul 2003
    Posts
    163
    Thanks
    4
    Thanked
    1 time in 1 post
    • Chan's system
      • Motherboard:
      • Asus M4A88TD-M EVO
      • CPU:
      • AMD Phenom II X4 955 BlackEdition
      • Memory:
      • 4GB Corsair XMS3, DDR3
      • Graphics card(s):
      • 1GB GTX460
      • PSU:
      • 520W Corsair HX Series Modular
      • Case:
      • Antec 300
      • Operating System:
      • Win 7 Pro
      • Monitor(s):
      • 2x Samsung SyncMaster P2450H 1920x1080
    lol i wondered why the TCP port 135 died done and suddenly today i've had +80 ICMP "ping" attempts.

    all safely blocked so no problemo

    thanks for just clearing that up

  8. #8
    One skin, two skin......
    Join Date
    Jul 2003
    Location
    Durham
    Posts
    1,705
    Thanks
    0
    Thanked
    1 time in 1 post
    That's a very strange virus! Why stop another virus then disable yourself when it gets to 2004?

  9. #9
    Member
    Join Date
    Jul 2003
    Posts
    61
    Thanks
    0
    Thanked
    0 times in 0 posts
    just read this on anuffer forum looks like anuffer 1 is doing its rounds


    Virus Warning: W32/Nachi.worm
    Anyone else been hit by this Virus yet?

    Causing a bit of mayhem in the office this morning....

    most systems have been affected by it..

    Quick Description:

    This is another virus that exploits the MS03-026 vulnerability. In addition to exploiting this RPC DCOM vulnerability, the virus also attempts to exploit an NTDLL.DLL vulnerability (MS03-007) via WebDav

  10. #10
    Senior Member joshwa's Avatar
    Join Date
    Jul 2003
    Location
    Sheffield, UK
    Posts
    4,847
    Thanks
    126
    Thanked
    67 times in 62 posts
    • joshwa's system
      • Motherboard:
      • PC Chips M577 AT/ATX
      • CPU:
      • AMD K6-2 500Mhz
      • Memory:
      • 128mb PC100 SDRAM
      • Storage:
      • 8GB Fujitsu
      • Graphics card(s):
      • 3dfx Voodoo 3 3000 AGP (16mb)
      • PSU:
      • ATX 500watt
      • Case:
      • Midi Tower AT
      • Operating System:
      • Windows 98 SE
      • Monitor(s):
      • 22" TFT Widescreen
    it's a friendly virus ! but apparently it doesn't work very well :

    "The worm attempts to download the DCOM RPC patch from Microsoft's Windows Update Web site, install it, and then reboot the computer.

    The worm checks for active machines to infect by sending an ICMP echo request, or PING, which will result in increased ICMP traffic.

    The worm will also attempt to remove W32.Blaster.Worm."

  11. #11
    You are feeling sleepy... acidrainy's Avatar
    Join Date
    Jul 2003
    Location
    Glasgow
    Posts
    1,518
    Thanks
    4
    Thanked
    2 times in 2 posts
    Originally posted by www.josh.org.uk
    it's a friendly virus ! but apparently it doesn't work very well
    Still nice idea though
    I hereby name it Capser " The friendly worm "

  12. #12
    Ive got 10/40w for blood... THCi's Avatar
    Join Date
    Jul 2003
    Location
    Somewhere, sometime, dunno why though.
    Posts
    512
    Thanks
    0
    Thanked
    0 times in 0 posts
    Oh, for those of us on Blueyonder, they have kindly blocked all port 135's on thier routers.

    Read more on status.blueyonder.co.uk cant remember what ticket it was, something about slowspeeds IIRC.

Thread Information

Users Browsing this Thread

There are currently 1 users browsing this thread. (0 members and 1 guests)

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •