Home Malware Programs Worms W32.Welchia.Worm

W32.Welchia.Worm

Posted: March 28, 2006

Threat Metric

Threat Level: 9/10
Infected PCs: 9
First Seen: July 24, 2009
Last Seen: January 20, 2022
OS(es) Affected: Windows

W32.Welchia.Worm is a worm that exploits multiple vulnerabilities:

The DCOM RPC vulnerability using TCP port 135. Specifically targets Windows XP machines.
The WebDav vulnerability using TCP port 80. Specifically targets machines running Microsoft IIS 5.0 .

W32.Welchia.Worm attempts to download the DCOM RPC patch from Microsoft's Windows Update Web site, install it, and then reboot the PC. Then it checks for active machines to infect by sending an ICMP echo request, or PING, which will result in increased ICMP traffic. Also attempts to remove W32.Blaster.Worm.

Aliases

WORM_NACHI.H [TrendMicro]W32.Welchia.Worm [Symantec]Worm.Win32.Nachi.gen (v) [Sunbelt]W32/Nachi-A [Sophos]High Risk Worm [Prevx1]Worm:Win32/Nachi.A [Microsoft]Worm.Nachi.A.1 [McAfee-GW-Edition]W32/Nachi.worm.a [McAfee]Net-Worm.Win32.Welchia.a [K7AntiVirus]Net-Worm.Win32.Welchia [Ikarus]W32/Nachi.A!worm [Fortinet]Net-Worm:W32/Welchia.A [F-Secure]Win32/Nachi.A [eTrust-Vet]Win32.HLLW.LoveSan.2 [DrWeb]Worm.Win32.Nachi.A [Comodo]
More aliases (30)
Loading...