W32.Welchia.B.Worm

For system help, all hardware / software topics NOTE: use Coders Corner for all coders topics.

Moderators: Krom, Grendel

Post Reply
User avatar
AceCombat
Owned by Timex
Owned by Timex
Posts: 6516
Joined: Sat Apr 12, 2003 2:01 am
Location: Oakwood, GA

W32.Welchia.B.Worm

Post by AceCombat »

i somehow picked this up, norton caught it the instant it attempted its payload delivery.....i woke up this morning to find that Automatic Scheduled Virus Scan Alert.....with a "Deleted" status next to it.

im checking all sources that i have, to see if i can find the source.



Just a heads up to those who i do contact by other means outside of DBB.
User avatar
Wolf on Air
DBB Admiral
DBB Admiral
Posts: 1872
Joined: Mon Dec 13, 1999 3:01 am
Location: Stockholm, Sweden
Contact:

Post by Wolf on Air »

IIRC, Welchia is the Blaster antivirus, and infects you the same way - email is totally unrelated. You had your firewall down, n00b ;)

Anyway, if memory serves it's payload isn't even active since X months ago, so if your system clock is correct it would run, and then delete itself.

You got it from some loser with an unpatched and unfirewalled windows machine with the system clock wrong (you have no idea how common this combination is).
User avatar
Flatlander
DBB Fleet Admiral
DBB Fleet Admiral
Posts: 2419
Joined: Thu Apr 15, 1999 2:01 am
Location: Pennsylvania
Contact:

Post by Flatlander »

Haven't run Windows Update in a while, eh?
User avatar
AceCombat
Owned by Timex
Owned by Timex
Posts: 6516
Joined: Sat Apr 12, 2003 2:01 am
Location: Oakwood, GA

Post by AceCombat »

actually my firewall was up....
i run WinUpdate every week......

glad to hear it would have deleted itself. but NAV 04' Pro caught it before it even had the chance to delete itself and deleted it for its own good.
User avatar
Avder
DBB Material Defender
DBB Material Defender
Posts: 4926
Joined: Sat Oct 09, 1999 2:01 am
Location: Moorhead, MN

Post by Avder »

Your security must be looser than a two dollar..*cough*

:P
User avatar
Testiculese
DBB Material Defender
DBB Material Defender
Posts: 4689
Joined: Sun Nov 11, 2001 3:01 am

Post by Testiculese »

edit: confused AV with firewall.
User avatar
fliptw
DBB DemiGod
DBB DemiGod
Posts: 6459
Joined: Sat Oct 24, 1998 2:01 am
Location: Calgary Alberta Canada

Post by fliptw »

AceCombat wrote:actually my firewall was up....
i run WinUpdate every week......

glad to hear it would have deleted itself. but NAV 04' Pro caught it before it even had the chance to delete itself and deleted it for its own good.
which firewall are you using?

besides the fact if the firewall was working, NAV would not have the oppurtunity to stop this worm.
User avatar
AceCombat
Owned by Timex
Owned by Timex
Posts: 6516
Joined: Sat Apr 12, 2003 2:01 am
Location: Oakwood, GA

Post by AceCombat »

fliptw wrote:
which firewall are you using?

besides the fact if the firewall was working, NAV would not have the oppurtunity to stop this worm.
Zone Alarm Pro

How so would NAV not beable to stop the worm?!?!

*EDIT* it was Quarantined not Deleted, but it was still stopped
User avatar
Testiculese
DBB Material Defender
DBB Material Defender
Posts: 4689
Joined: Sun Nov 11, 2001 3:01 am

Post by Testiculese »

Lemme translate this to AceSpeak:

besides the fact if the firewall was working, NAV would not have the oppurtunity to stop this worm.

equals

If you firewall is set up correctly, the virus would not have gotten past it, hence the the Antivirus would have never even seen it.

/me sets mode -MastersDegree AceCombat ;)
User avatar
Flatlander
DBB Fleet Admiral
DBB Fleet Admiral
Posts: 2419
Joined: Thu Apr 15, 1999 2:01 am
Location: Pennsylvania
Contact:

Post by Flatlander »

Not to mention, if you had been keeping up with Windows Update, the security hole/exploit this worm uses would have been patched and thus unavailable.
User avatar
AceCombat
Owned by Timex
Owned by Timex
Posts: 6516
Joined: Sat Apr 12, 2003 2:01 am
Location: Oakwood, GA

Post by AceCombat »

Flatlander wrote:Not to mention, if you had been keeping up with Windows Update, the security hole/exploit this worm uses would have been patched and thus unavailable.

hey flat, is Welchia associated with Nachi?

this is the title of the article you sent me to:

Virus Alert About the Nachi Worm
User avatar
fliptw
DBB DemiGod
DBB DemiGod
Posts: 6459
Joined: Sat Oct 24, 1998 2:01 am
Location: Calgary Alberta Canada

Post by fliptw »

it uses the same exploit in the RPC service Ace.

oh, wow, look what the link Flat posted says
Microsoft Knowledge Base Article - 826234 wrote:This article contains information for network administrators and IT professionals about how to prevent and how to recover from an infection from the Nachi worm. The Nachi worm is also known as W32/Nachi.worm (Network Associates), Lovsan.D (F-Secure), WORM_MSBLAST.D (Trend Micro), and W32.Welchia.Worm (Symantec).
User avatar
WarAdvocat
DBB Defender
DBB Defender
Posts: 3035
Joined: Sun Jun 23, 2002 2:01 am
Location: Fort Lauderdale, FL USA

Post by WarAdvocat »

This is why we make fun of this guy :)
User avatar
AceCombat
Owned by Timex
Owned by Timex
Posts: 6516
Joined: Sat Apr 12, 2003 2:01 am
Location: Oakwood, GA

Post by AceCombat »

i stand corrected. i never knew Welchia was associated with Nachi
User avatar
BUBBALOU
DBB Benefactor
DBB Benefactor
Posts: 4198
Joined: Tue Aug 24, 1999 2:01 am
Location: Dallas Texas USA
Contact:

Post by BUBBALOU »

WarAdvocat wrote:This is why we make fun of this guy :)
FootCombat© is the posterchild for vas deferens removal!
Post Reply