welchia worm

Discussion in 'Software' started by poconomike, Feb 26, 2004.

  1. poconomike

    poconomike Private E-2

    My NAV auto protect is popinng up saying i have welchia on my pc. One file it was able to remove, the other says access to file was denied. Full scans and the welchia fix tool do not find it. The file log says its in a temp file. How do i delete all my temp files (both internet and windows temp)? Would disk cleanup do it?
     
  2. Kodo

    Kodo SNATCHSQUATCH

    What OS are you using please?
     
  3. General_Lee_Stoned

    General_Lee_Stoned BuZZed Lightyear

    do you know the name of the file its trying to delete

    edit:sorry kodo didnt see you there
     
  4. poconomike

    poconomike Private E-2

    Im using Windows XP..Im sorry i do not have the file right here (im at work), but its something like../temp internet file/wks ptch
     
  5. General_Lee_Stoned

    General_Lee_Stoned BuZZed Lightyear

    easy enough to clean internet files
    yes disk clean up would do the job
    or click tools in top toolbar-select internet options and you will see a tab to delete temporary internet files

    strange how access is denied though unless you have a running process using that file at the time
     
  6. Kodo

    Kodo SNATCHSQUATCH

    in your browser select TOOLS--> INTERNET OPTIONS

    In the center hit the button that says DELETE FILES, then check the box off in the next prompt to delete all offline files too and hit ok.

    That will delete your internet cache.
     
  7. General_Lee_Stoned

    General_Lee_Stoned BuZZed Lightyear

    yeah just like that lol :)
     
  8. alanc

    alanc MajorGeek

  9. poconomike

    poconomike Private E-2

    ok guys..im really confused..i got the message again tonight...
    here is the file NAv could not access
    Source: C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\WFK4CFNO\WksPatch[1].exe
    Click for more information about this threat : W32.Welchia.B.Worm

    Here is the one it fixed

    Source: C:\WINDOWS\SYSTEM32\drivers\svchost.exe

    what can i do to stop getting this? Remember my auto protect will get it, but full scans or fix wont see it
     
  10. Kodo

    Kodo SNATCHSQUATCH

    make sure you have the latest XP updates.. there's a patch in it that prevents this virus from reinfecting
     
  11. poconomike

    poconomike Private E-2

    ok...right now i cane get to update site..do you know which patch it is? am i deleting the worm by emptying my temp internet folders?
     
  12. Kodo

    Kodo SNATCHSQUATCH

  13. poconomike

    poconomike Private E-2

    confused again..i installed that patch last week, the first time i igot the welchia.b...it does say there is a more recent patch, but it directs me to windows update which i cant get too...frustrating...can anyone tell me what is happening? my auto protect is getting one of them, but not the internet temp file one? is it a site im going to?
     
  14. Kodo

    Kodo SNATCHSQUATCH

  15. poconomike

    poconomike Private E-2

    i have this patch, but to see if i need more recent updates, it refers me to windows update link, which isnt working for me at the moment
     
  16. Kodo

    Kodo SNATCHSQUATCH

    Install the patch again. then use the second tool. Disconnect from your network, Turn off system restore and run the tool in the second link I provided.
     
  17. poconomike

    poconomike Private E-2

    ok...i downloaded the patch again...ran the removal tool withh system restore off..it says welchia not found on your computer..this is what happened last week..the tool doesnt find it, full scan doesnt find it, but every few days my auto protect will delete the one, but not the temp internet folder one...am i getting reinfected or never getting rid of it in the first place? is it harmfull? or is it ok if i delete it from temp everytime?
     
  18. Kodo

    Kodo SNATCHSQUATCH

  19. alanc

    alanc MajorGeek

    From Kodo's last link:
     
  20. poconomike

    poconomike Private E-2

    virus help please

    If anyone can be of assistance, I'd really appreciate it. My NAV aoto protect will periodically give me the following messages: "Welchia.32.B" was found and automatically deleted from /windows/system32/drivers/svchost.exe...i then get two more messages, the first saying welchia.b found and access to the file was denied, the second saying the repair failed...the file for both of those messages is /windows/system32/config/localsettings/temp internet files/ie5/GD3456/wkspatch(1)... well, this file is hidden, so i unhide it and scan that file with norton..no threats found..In fact if i do full scan or run the welchia fix, no threats are found..Any input as to what is happening. Am i infected? It seems like NAV is catching the worm and deleting it from the one file, but can from the second cause its hidden. Does this make sense? My pc seeems to be running ok.. The only thing is that if i get this auto protect message and then try to go to NAV reports,,NAV doesnt respond. I must reboot..everything else seems to work ok..My auto protect bloodhound heuristics is set to the recommened level (the middle one)..What should I do?

    Thanks gang
     
  21. Kodo

    Kodo SNATCHSQUATCH

  22. poconomike

    poconomike Private E-2

    sorry..stinger found nothing
     
  23. Kodo

    Kodo SNATCHSQUATCH

    Mike, you say the file is located here
    windows/system32/config/localsettings/temp internet files/ie5/GD3456/

    Find the directory GD3456 and see if you can delete it. make sure your browser is closed.
     
  24. poconomike

    poconomike Private E-2

    yes, i can delete it and i have..but sure enough within a few days, ill get the auto protect warning again..ive applied all windowspatches listed on the NAV welchia virus page, but have been ubable to do a total update as i cant get the windows update patch to cooperate..it will run and i go through the 0% complete, 33, 66, then 100..it will sometiumes show the critical updates, but when i click on that..it fails...time of day?...i do have XP service pack 1
     
  25. General_Lee_Stoned

    General_Lee_Stoned BuZZed Lightyear

    ok looking through this thread and at the link provided by alanc
    this worm creates a running service with a whole variety of possible names so maybe its something to do with that :confused:
    anyway norton reccomends running the scan in safe mode have you tried that

    somehow you must be getting reinfected have you cleaned out all your old e-mail folders just a thought

    looking on the bright side according to symantec this worm is due to self terminate on the 1st of june 2004 so i suppose you could just wait till then or reset your date on your machine :D
     
  26. poconomike

    poconomike Private E-2

    thanks..i tried switching my date to june 1..i started my machine...left windows run for a couple hours..turned it off..the next time i logged on, i switched it back to the current date..this did not help...do i have to leave it at june 1?
     
  27. General_Lee_Stoned

    General_Lee_Stoned BuZZed Lightyear

    dont know man i was just throwing ideas up in the air :D ;)

    but if it works.......LOL
     
  28. alanc

    alanc MajorGeek

    Have you tried deleting the windows\system32\drivers\svchost.exe file in safe mode?

    There is a valid svchost.exe in the system32 directory, but the one in system32\drivers is bogus and safe to delete.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds