Remove W32.Welchia.Worm. Removal instructions
Severity scale: (60 / 100)
W32.Welchia.Worm is a worm that exploits multiple vulnerabilities:
The DCOM RPC vulnerability using TCP port 135. Specifically targets Windows XP machines.
The WebDav vulnerability using TCP port 80. Specifically targets machines running Microsoft IIS 5.0 (most likely be found on Windows 2000 systems).
W32.Welchia.Worm attempts to download the DCOM RPC patch from Microsoft's Windows Update Web site, install it, and then reboot the computer. Then it checks for active machines to infect by sending an ICMP echo request, or PING, which will result in increased ICMP traffic. Also attempts to remove W32.Blaster.Worm.
W32.Welchia.Worm properties: • Allows remote user connection • Hides from the user • Stays resident in background
Automatic W32.Welchia.Worm removal:
We are testing STOPzilla's efficiency at removing W32.Welchia.Worm
(2008-04-24 12:42:04)
Malwarebytes Anti Malware
We are testing Malwarebytes Anti Malware's efficiency at removing W32.Welchia.Worm
(2008-04-24 12:42:04)
We are testing Spyware Doctor's efficiency at removing W32.Welchia.Worm
(2008-04-24 12:42:04)
Information added: 2004-03-19 10:00:00
Information updated: 2008-04-24 10:04:49
Additional resources related to W32.Welchia.Worm:
Attention: If you
know or you have a website or page about W32.Welchia.Worm removal, feel free
to add a link to this list: add
url
more resources
|
Latest spyware news:
Subscribe to news
Similar parasites:
|
Post Comment: