News  
   Documentation  
   Help  
 Training 
 Labs
 Contacts 
 Connecting
 About   
 Purchases
 Policies
 TTU Home  
 ITS Home


Welchia Worm (from Symantec's Security Response site)

Welchia attempts to patch the Blaster worm using the same vulnerability (RPC), but then creates unnecessary traffic (pings) to slow the network while seeking other machines to infect.  It can infect Windows XP and Windows 2000 machines.

 

| ResNet Instructions | RemovalHow to Disable System Restore |Resources |


 

If you are in ResNet: 

  1. Be sure you have patched for the Blaster worm.  (For more info see:  Blaser Removal)

  • Open the file for your operating system below.

Windows XP   (Turn off system restore first - see below.)

Windows 2000

  • Follow the wizard.
  • Reboot.
  1. Be sure you have patched the DCOM process.
     
  2. Fix Welchia as instructed below.

Please note if you are running Windows 2000 and are not up-to-date on all your Critical Updates, you may continue to have problems.

Removal

  • Download the FixWelch.exe file (courtesy of  Symantic's web site).
  • Save to your desktop or other location.
  • Close all programs and DISCONNECT from the internet.
  • Disable System Restore if you are running Windows XP (Instructions below.)
  • Double click on the FixWelch.exe file on your desktop to open the program.
  • Click Start to run the removal tool.

  • When completed, restart your computer.
  • Run the removal tool again to ensure that the system is clean.
  • Re-enable System Restore.
     
  • If this is a personally owned computer, check your virus provider site for the most recent virus definition updates.
  • Check Microsoft for critical updates (http://windowsupdate.microsoft.com)  and apply all that are indicated.

Disabling System Restore in Windows XP
  • Click Start.
  • Right-click My Computer
  • Select  Properties from the floating menu.
  • Click the System Restore tab.
  • Select Turn off System Restore check box.
  • Click Apply.
  • Click Yes in message box.
  • Click OK.

After the worm is removed, restart your computer and follow the steps above to deselect "Turn off System Restore".


Resources

For more information on this worm, consult the Norton Antivirus Center.

 

Maintained by:  Academic Computing Support Last updated: April 30, 2004
TTU Home     ITS Home     Contacts     News
Copyright © Tennessee Technological University. All rights reserved.
Information Technology Services, Box 5071— Clement Hall 220, Cookeville, Tennessee 38505   Phone: 931.372.3387