|
|||||
| Support: Security: PC Sentry: Welchia | |||||
|
name: Welchia aka: Nachi, WORM_MSBLAST.D type: Worm host platform: Windows first Incidence: 08/20/03 last incidence: 08/20/03 level of incidence: High damage capacity: Medium links: McAfee, Norton look for: the file Dllhost.exe in C:\Windows\System\Wins or C:\Windows\System32\Wins Welchia is a variant of the worm MSBlast. It affects Windows 2000 and XP machines that have not patched the Buffer Overrun In Windows RPC Interface. Once the worm has infected a machine it attempts to download and install Microsoft's RPC Buffer Overrun patch, stops and removes MSBlast (if on machine), and, ultimately, turns itself off in 2004. Green Apple has disabled ingress/egress on ports used by Welchia which
greatly lessen the capability for the worm to enter or leave our network and
affect our users. However, every Windows user is urged to visit Microsoft's
Windows Update and install the patch to close the RPC Buffer Overrun flaw.
Windows Update is found at If you are infected, besides installing the patch, you will need to remove
the worm. Symantec (Norton) has developed a tool for this: |
|||||
|
|