Advertisement
Promo

Security management Toolkit

Networks must counter triple threat

John McCormick

Published: 21 Aug 2003 12:40 BST

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

Welchia
A worm released with the intention of fixing computers infected with Blaster is making the rounds and is causing far more damage than Blaster did. Welchia (also known as W32/Welchia.worm10240, W32/Nachi.worm, WORM_MSBLAST.D, and Lovsan.D) attempts to remove Blaster and download/install the required system patch.

The problem with Welchia, besides the fact that it's just another cyberthreat, is that it takes over the "patched" system and uses it to scan the Internet for other Blaster-infected systems -- and the bandwidth consumption is bringing individual systems and networks to their knees. Symantec has a report on Welchia, which includes a link to a removal tool and detailed manual removal instructions.

Sobig.F
The latest version of Sobig can infect a system only if a user opens a malicious email and then opens an attachment. Like other versions of Sobig, this one comes complete with an email client and attempts to spread itself to email addresses gleaned from the compromised computer.

The attachment always seems to be a filename ending in .pif, and the subject lines are intelligently designed to get people to open the attachment. Some examples are: RE: Details, RE: Approval, RE: Thank You, and RE: Your Application.

This is a very large worm (72K). Removing it from systems will be a complex undertaking, since you'll have to disconnect each compromised PC from any network before cleaning it. Details and removal instructions are available at the following security sites:

Final word
These three worms have brought down networks large and small. The information, links, and instructions provided here can help you avoid these nasty little devils or remove them if they have already infected systems on your network.

Next

Previous

1 2 3


  • Email
  • Trackback
  • Clip Link
  • Print friendlyPrint with EPSON

Did you find this article useful?
184 out of 358 people found this useful


Full Talkback thread

0 comments

Company/Topic Alerts

Create a new alert from the list below:



Video icon

Video

Sentry Posts Blog

Official Organizations Losing Data

How does this article from earlier today make you feel? How many more government, health service, or military officials are going to lose pen drives, DVDs, USB hard disks and even entire... More

2 comments

Twitter hack was DNS redirect

Twitter has said an attack on Thursday which took the site offline for many users was the result of a DNS redirect. A group calling itself the Iranian Cyber Army redirected users... More

1 comment

McKinnon lawyers seek judicial review

Lawyers seeking a judicial review for Nasa hacker Gary McKinnon lodged fresh evidence of his psychiatric state at the High Court on Thursday. Karen Todner, McKinnon's solicitor,... More

1 comment

Win a Teufel Cinebar 50 system

Win a Teufel Cinebar 50 system

What is ZDNet UK's usual tagline?

Competition closes - 14 Jan 2010


Skip Sub Navigation Links to CNET Brand Links

Help

Become part of the ZDNet community.

Newsletters