Advertisement
Promo

Security management Toolkit

Preventing and removing the Nachi worm

Robert Vamosi CNET News

Published: 20 Aug 2003 10:15 BST

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

When is help not really help at all? When it's one Internet worm claiming to remove traces of another. Nachi (w32.nachi.a, also known as Welchia, worm_msblast.d, and Sachi) exploits the same Microsoft DCOM RPC Windows flaw as MSBlast, but it removes traces of that worm and even downloads the correct version-specific DCOM RPC patch to prevent further MSBlast infections on Windows 2000, NT 4.0, and XP systems. However, Nachi also scans other computers connected on a network, some that haven't been infected with MSBlast, and whether intentionally or not, it may crash those unpatched and uninfected systems while attempting to download the DCOM RPC patch. Needless to say, Nachi is not much help. In addition, in order to spread faster, Nachi takes advantage of an older Microsoft flaw, the WebDav buffer-overflow flaw, which it does not bother to patch. Because Nachi is spreading rapidly and may cause system crashes, it rates a 6/10 on the ZDNet Virus Meter.

How it works
Like MSBlast, Nachi does not arrive via email but via Internet port 135. And, like MSBlast, it attacks Windows 2000 and Windows XP machines that do not have the DCOM RPC patch from Microsoft installed. When it attacks, the unpatched machine may crash--whether or not the machine has been previously infected with MSBlast.

Nachi installs two files in Windows subdirectory WinNT\system 32:

C:\winnt\system32\wins\dllhost.exe (10,240 bytes)

(Be aware that a legitimate file system name dllhost.exe also exists. The legitimate file is typically only 5-6KB.)

C:\winnt\system32\wins\svchost.exe or tftpd.exe

This last file is the Trivial File Transfer Protocol used to download and install the DCOM RPC patches.

Additionally, Nachi uses the WebDav buffer-overflow flaw to spread to other Windows NT 4.0, 2000, and XP machines, but, ironically, it does not bother to patch this vulnerability.

Nachi is set to remove itself from infected machines on 1 January, 2004.

Prevention
If you haven't already installed the DCOM RPC patch from Microsoft, do so now. Additionally, if you do not have a desktop firewall installed, you should consider installing one to avoid infection by either MSBlast or Nachi.

Removal
Most antivirus software companies have updated their signature files to include this worm. This will stop the infection upon contact and in some cases will remove an active infection from your system. For more information, see Central Command, Computer Associates, F-Secure,McAfee, Norman, Sophos, Symantec, or Trend Micro.

  • Email
  • Trackback
  • Clip Link
  • Print friendlyPrint with EPSON

Did you find this article useful?
45 out of 89 people found this useful


Company/Topic Alerts

Create a new alert from the list below:






Video icon

Video

Sentry Posts Blog

Campaigners criticise '£10bn NHS IT ov...

The National Health Service's flagship IT project has been criticised by a tax campaign group for running billions of pounds over budget. The NHS National Programme for IT (NPfIT)... More

2 comments

Climate research centre compromised

One of the UK's leading climate change research centres has had a security breach. The Climate Research Unit at the University of East Anglia (UEA) suffered a compromise of information,... More

1 comment

Government web-monitoring plans on hol...

Government plans to compel ISPs to process and store details of all web communications have been put on hold until after the next election. The Home Office told ZDNet UK on Wednesday... More

1 comment

Featured Talkback

In association with Network Liberation Movement
It seems to me this is a burden being placed on the wrong shoulders. There is not an It system in the world that can stop an individual taking information in their heads and spewing out at the nearest undesirable third party.

By: RonaldWilkins

Read full story:
Deloitte: People are still weakest security link


Skip Sub Navigation Links to CNET Brand Links

Help

Become part of the ZDNet community.

Newsletters