ZDNet UK


Skip to Main Content

ZDNet.co.uk - Winner of Best Business Website 2007
  1. Home
  2. News
  3. Blogs
  4. Reviews
  5. Prices
  6. Resources
  7. Community
  8. My ZDNet

 

ZDNet UK RSS Feeds


IT Jobs

Security management Toolkit

Preventing and removing the Nachi worm

Robert Vamosi CNET News.com

Published: 20 Aug 2003 10:15 BST

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

When is help not really help at all? When it's one Internet worm claiming to remove traces of another. Nachi (w32.nachi.a, also known as Welchia, worm_msblast.d, and Sachi) exploits the same Microsoft DCOM RPC Windows flaw as MSBlast, but it removes traces of that worm and even downloads the correct version-specific DCOM RPC patch to prevent further MSBlast infections on Windows 2000, NT 4.0, and XP systems. However, Nachi also scans other computers connected on a network, some that haven't been infected with MSBlast, and whether intentionally or not, it may crash those unpatched and uninfected systems while attempting to download the DCOM RPC patch. Needless to say, Nachi is not much help. In addition, in order to spread faster, Nachi takes advantage of an older Microsoft flaw, the WebDav buffer-overflow flaw, which it does not bother to patch. Because Nachi is spreading rapidly and may cause system crashes, it rates a 6/10 on the ZDNet Virus Meter.

How it works
Like MSBlast, Nachi does not arrive via email but via Internet port 135. And, like MSBlast, it attacks Windows 2000 and Windows XP machines that do not have the DCOM RPC patch from Microsoft installed. When it attacks, the unpatched machine may crash--whether or not the machine has been previously infected with MSBlast.

Nachi installs two files in Windows subdirectory WinNT\system 32:

C:\winnt\system32\wins\dllhost.exe (10,240 bytes)

(Be aware that a legitimate file system name dllhost.exe also exists. The legitimate file is typically only 5-6KB.)

C:\winnt\system32\wins\svchost.exe or tftpd.exe

This last file is the Trivial File Transfer Protocol used to download and install the DCOM RPC patches.

Additionally, Nachi uses the WebDav buffer-overflow flaw to spread to other Windows NT 4.0, 2000, and XP machines, but, ironically, it does not bother to patch this vulnerability.

Nachi is set to remove itself from infected machines on 1 January, 2004.

Prevention
If you haven't already installed the DCOM RPC patch from Microsoft, do so now. Additionally, if you do not have a desktop firewall installed, you should consider installing one to avoid infection by either MSBlast or Nachi.

Removal
Most antivirus software companies have updated their signature files to include this worm. This will stop the infection upon contact and in some cases will remove an active infection from your system. For more information, see Central Command, Computer Associates, F-Secure,McAfee, Norman, Sophos, Symantec, or Trend Micro.

  • Email
  • Trackback
  • Clip Link
  • Print friendly Print with HP

Did you find this article useful?
45 out of 89 people found this useful


Company/Topic Alerts

Create a new alert from the list below:






Related Jobs

Principal Applications Specialists

Ensures that new versions of system software are properly installed and thoroughly tested. Ensures that new versions of system software are ...

Java Developer - High Performance/Real-time/Multithreaded Development

My client, a leading Financial Spread Betting firm is now looking for a strong real-time Java technologist to develop the company's new pricing ...

Design Engineer -Machine Design -access Manchester/Yorkshire -Good

My client designs and manufactures machines to be used in hospitals, laboratories and schools. To design the machines they are looking for people ...

Sentry Posts Blog

Mobile Linux Better For Mobile Busines...

Mobile Linux Better For Mobile Business Apps? Author: Eric Everson, MyMobiSafe.com As mobile Linux is carving it’s footprint on the future of mobile application development, the... More

Post a comment

DWP downplays security breach

The Department for Work and Pensions (DWP) has admitted that some of its staff have been forwarding passwords with password protected material. An email that was leaked on the 'Dizzy... More

Post a comment

How many headshots does one chairperso...

We got a strange request last week from the head of PR from Russian security experts Kaspersky. It seems although the company was very happy with the interview we recently carried with... More

Post a comment

Featured Talkback

It seems to me this is a burden being placed on the wrong shoulders. There is not an It system in the world that can stop an individual taking information in their heads and spewing out at the nearest undesirable third party.

By: RonaldWilkins

Read full story:
Deloitte: People are still weakest security link

DOWNLOAD

Security Essentials

Security Downloads

There are masses of security suites out there for small businesses. Here's a selection to get you started

Editor’s Rating
1 Norton 360™
2 AVG Anti-Virus Free Edition Rating: 10
3 PC Tools AntiVirus Free Edition
4 Kaspersky Internet Security

See All Software

In association with Symantec