Windows 2000 Welch Worm

  • Thread starter Thread starter Nick Le Lievre
  • Start date Start date
N

Nick Le Lievre

Hi

I`ve been running Windows 2000 no Service Pack since Jan 10th on a 1.2gb
hard drive. I just got a fairly cheap 6.4gb off eBay and have transfered the
data between them.

I couldn't install SP4 becuase I didn't have the hard drive space on the old
drive. I noticed that my connectoid to ISP was sending/recieving an
incredible amount of bytes during each session.

Today I downloaded a TCPViewer to see what was happening during the times
when my system was sending/recieving data with no applications running.

Well it happened and I noticed a file called DLLHOST was the culprit I
searched google and discovered I may be infected with the Welch worm so I
download Symantec's Welch fixtool and sure enough it detected two files
infected.

I`m downloading SP4 now but apparently the MS fix for this problem is not
included in the Service Pack is this true ? (I downloaded the MS fix as well
just in case).
 
Nick said:
Hi

I`ve been running Windows 2000 no Service Pack since Jan 10th on a
1.2gb hard drive. I just got a fairly cheap 6.4gb off eBay and have
transfered the data between them.

I couldn't install SP4 becuase I didn't have the hard drive space on
the old drive. I noticed that my connectoid to ISP was
sending/recieving an incredible amount of bytes during each session.

Today I downloaded a TCPViewer to see what was happening during the
times when my system was sending/recieving data with no applications
running.

Well it happened and I noticed a file called DLLHOST was the culprit I
searched google and discovered I may be infected with the Welch worm
so I download Symantec's Welch fixtool and sure enough it detected
two files infected.

I`m downloading SP4 now but apparently the MS fix for this problem is
not included in the Service Pack is this true ? (I downloaded the MS
fix as well just in case).

Installed SP4 and I see there's a load of post SP4 security fixes which I`ve
also installed including MRT.exe the software removal tool which removes
nachi aka welch. Now getting the remaining Outlook Express updates...
 
Back
Top