w32.welchia.worm (Symantec def.)

From: Jay Nichols (jaynichols99_at_hotmail.com)
Date: 08/31/03


Date: Sun, 31 Aug 2003 07:54:34 -0700


After writing binary zeroes over my entire disk array and
reformatting the disks I loaded W2K server. Following
that I went to the MS update site and let them decide what
updates were necessary and applied them. Then I loaded
the NAV virus from my NAV server with the 8/27 virus
updates. the scan reported 5 instances of the virus.

I have reported this to MS by phone. I also sent an email
to Symantec. MS indicates that I might have had the virus
attack my server between the time I had W2K raw loaded and
the time I had completed loading the updates from
them. ??? I suppose that would be possible, but no
other computers, servers or workstations, in my site have
the infection. My conclusion is the MS download site is
infected. My consultant is setting one of his servers to
binary zeroes and trying the same method I used to see if
he comes up with the same problem.



Relevant Pages

  • Re: SOPHOS Antivirus
    ... > This one feature can eliminate 99% of the virus infected inbound email ... By definition a firewall has no mail filtering function. ... > updates for every 4 hours on the server and have the server push the ... > updates to the desktops. ...
    (alt.computer.security)
  • SBS2003 Anti Virus
    ... Yes - Use the AVD (Active Virus Defence) from Network ... Does hourly updates, has scanners for SMTP, Exchange, ... Server and will start at a 5 cal count for ...
    (microsoft.public.windows.server.sbs)
  • Re: Strange Server Behaviour
    ... Thanks for updates. ... I am Charles the backup of Brandy, as the Brandy is currently sick at home. ... Microsoft CSS Online Newsgroup Support ... | Subject: Re: Strange Server Behaviour ...
    (microsoft.public.windows.server.sbs)
  • Re: WSUS Client not yet reported
    ... The client still fails to report. ... Check your server status ... Suggestion 2: Check the IIS settings: ... any updates in your thread. ...
    (microsoft.public.windows.server.sbs)
  • Re: SUS
    ... > I have setup a SUS Server on win2k. ... 0-2.reg will not configure your machine to automatically download updates from ... critical updates or service packs that your machine needs. ... It will also ask you if you want to install them, ...
    (microsoft.public.windows.server.general)