W32.Welchia.Worm (if you think Blaster worm is gone)


Status
Not open for further replies.

ransoma22

Senior Member
W32.Welchia.Worm is a worm that exploits multiple vulnerabilities:

exploits the DCOM RPC vulnerability (described in Microsoft Security Bulletin MS03-026) using TCP port 135. The worm specifically targets Windows XP machines using this exploit.

exploits the WebDav vulnerability (described in Microsoft Security Bulletin MS03-007) using TCP port 80. The worm specifically targets machines running Microsoft IIS 5.0 using this exploit.

The worm attempts to download the DCOM RPC patch from Microsoft's Windows Update Web site, install it, and then reboot the computer.

The worm checks for active machines to infect by sending an ICMP echo, or PING, which will results in increased ICMP traffic.

The worm will also attempt to remove W32.Blaster.Worm.

Extracted from:
http://www.symantec.com/avcenter/venc/data/w32.welchia.worm.html
 

eeps, not another one...
 

Sounds like a helpful worm
 

West_ray said:
haha ... so should we hope tat we kena it ?? :D

Nah, you don't want to kenna this one.

Causing slow network to many WAN link and internet link right now as we speak.

Many networks in Japan and Singapore are being slow down since yesterday.....
 

Hello,go to where har to get patch??
 

andylee said:
Hello,go to where har to get patch??

huh? u kena this worm liao ar ???? wahhh ... u very into fashion and trends hor ... wanan be the 1st to get it ar ...
 

Ai yah, my company's IT expert has been telling me to be careful mah, if got how to go to clubsnap?? :D
 

andylee said:
Ai yah, my company's IT expert has been telling me to be careful mah, if got how to go to clubsnap?? :D

Best is to practise "safe computing", but for this virus you
have to make sure your windows is properly patched.

NAV live update 18/8 already protected against this one.
 

sianz with virus..... formated my com several times this wk liao.....
 

hey man, today my company email account start getting stupid mails,something like "your violent wallpaper" stuff!!! wa liao, almost 20 odd mail of sorts.but they have one things in common!!all very big file size with funny names!!muz be those people who forward without knowing they have fungus!!! :angry: really slow down my work!! :angry:
 

andylee said:
hey man, today my company email account start getting stupid mails,something like "your violent wallpaper" stuff!!! wa liao, almost 20 odd mail of sorts.but they have one things in common!!all very big file size with funny names!!muz be those people who forward without knowing they have fungus!!! :angry: really slow down my work?? :angry:


It could be this virus
http://us.mcafee.com/virusInfo/default.asp?id=description&virus_k=100561
 

Status
Not open for further replies.
Back
Top