Advertisement
Promo

Security management Toolkit in association with http://ad.doubleclick.net/clk;214682528;14505427;f?http://uk.blackberry.com/ataglance/security/

Preventing and removing the Nachi worm

Robert Vamosi CNET News.com

Published: 20 Aug 2003 10:15 BST

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

When is help not really help at all? When it's one Internet worm claiming to remove traces of another. Nachi (w32.nachi.a, also known as Welchia, worm_msblast.d, and Sachi) exploits the same Microsoft DCOM RPC Windows flaw as MSBlast, but it removes traces of that worm and even downloads the correct version-specific DCOM RPC patch to prevent further MSBlast infections on Windows 2000, NT 4.0, and XP systems. However, Nachi also scans other computers connected on a network, some that haven't been infected with MSBlast, and whether intentionally or not, it may crash those unpatched and uninfected systems while attempting to download the DCOM RPC patch. Needless to say, Nachi is not much help. In addition, in order to spread faster, Nachi takes advantage of an older Microsoft flaw, the WebDav buffer-overflow flaw, which it does not bother to patch. Because Nachi is spreading rapidly and may cause system crashes, it rates a 6/10 on the ZDNet Virus Meter.

How it works
Like MSBlast, Nachi does not arrive via email but via Internet port 135. And, like MSBlast, it attacks Windows 2000 and Windows XP machines that do not have the DCOM RPC patch from Microsoft installed. When it attacks, the unpatched machine may crash--whether or not the machine has been previously infected with MSBlast.

Nachi installs two files in Windows subdirectory WinNT\system 32:

C:\winnt\system32\wins\dllhost.exe (10,240 bytes)

(Be aware that a legitimate file system name dllhost.exe also exists. The legitimate file is typically only 5-6KB.)

C:\winnt\system32\wins\svchost.exe or tftpd.exe

This last file is the Trivial File Transfer Protocol used to download and install the DCOM RPC patches.

Additionally, Nachi uses the WebDav buffer-overflow flaw to spread to other Windows NT 4.0, 2000, and XP machines, but, ironically, it does not bother to patch this vulnerability.

Nachi is set to remove itself from infected machines on 1 January, 2004.

Prevention
If you haven't already installed the DCOM RPC patch from Microsoft, do so now. Additionally, if you do not have a desktop firewall installed, you should consider installing one to avoid infection by either MSBlast or Nachi.

Removal
Most antivirus software companies have updated their signature files to include this worm. This will stop the infection upon contact and in some cases will remove an active infection from your system. For more information, see Central Command, Computer Associates, F-Secure,McAfee, Norman, Sophos, Symantec, or Trend Micro.

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

Did you find this article useful?
45 out of 89 people found this useful



Company/Topic Alerts

Create a new alert from the list below:






Video icon

Video

Sentry Posts Blog

Nasa hacker petition presented to Numb...

Sting's wife Trudie Styler and Janis Sharp have presented a petition to Number 10 calling for Nasa hacker Gary McKinnon not to be extradited to the US. Styler, and Sharp, who is... More

Post a comment

UK to appoint cyber-sec tsar?

The UK is to appoint a cyber security tsar along the lines of the US, according to a story in the Telegraph this morning. The story is similar to one that appeared in the Guardian... More

Post a comment

Nokia Siemens denies Iran web snoop

Nokia Siemens has denied providing deep packet inspection capabilities to the Iranian authorities, following an article in the Wall Street Journal on Monday. The WSJ published the... More

Post a comment

Featured Talkback

It seems to me this is a burden being placed on the wrong shoulders. There is not an It system in the world that can stop an individual taking information in their heads and spewing out at the nearest undesirable third party.

By: RonaldWilkins

Read full story:
Deloitte: People are still weakest security link


Skip Sub Navigation Links to CNET Brand Links

Help

Become part of the ZDNet community.

Newsletters