I was downloading from a friends server and when the file was copying to my folder a virus warning popped up. you can see it there. When I clicked OK it said something about access denied. Then I clicked OK again and it said it had been deleted. The thing is my computer has been acting screwy since. AND that keeps popping up. So Norton obviously didn't delete it! I've got a hijackthis list thingy if it helps if not..*shrug*
Anyone recognize the virus? Know what to do? I downloaded some program called..fixwelch but it says: W32.Welchia.Worm has not been found on your computer.
I don't know what to do from here. Can anyone help? Thanks in advance!


Logfile of HijackThis v1.97.3
Scan saved at 12:27:06 AM, on 2/14/2004
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\Program Files\Norton SystemWorks\Norton AntiVirus\navapsvc.exe
C:\Program Files\Norton SystemWorks\Norton Utilities\NPROTECT.EXE
C:\WINDOWS\System32\nvsvc32.exe
C:\PROGRA~1\NORTON~1\SPEEDD~1\nopdb.exe
C:\WINDOWS\System32\svchost.exe
C:\windows\system\hpsysdrv.exe
C:\HP\KBD\KBD.EXE
C:\hp\drivers\video\HKCMD.EXE
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\AIM+\AIM+.exe
C:\Program Files\AIM95\aim.exe
C:\PROGRA~1\WINZIP\winzip32.exe
C:\Documents and Settings\Owner\Local Settings\Temp\HijackThis.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Messenger\msmsgs.exe R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar =
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page =
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar =
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton SystemWorks\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton SystemWorks\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [hpsysdrv] c:\windows\system\hpsysdrv.exe
O4 - HKLM\..\Run: [KBD] C:\HP\KBD\KBD.EXE
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE NvQTwk,NvCplDaemon initialize
O4 - HKLM\..\Run: [S3TRAY2] S3tray2.exe
O4 - HKLM\..\Run: [IgfxTray] C:\hp\drivers\video\IGFXTRAY.EXE
O4 - HKLM\..\Run: [HotKeysCmds] C:\hp\drivers\video\HKCMD.EXE
O4 - HKLM\..\Run: [PS2] C:\hp\drivers\keyboard\PS2.EXE
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [ccRegVfy] "C:\Program Files\Common Files\Symantec Shared\ccRegVfy.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKCU\..\Run: [AIM] "C:\Program Files\AIM+\AIM+.exe" -cnetwait.odl
O4 - HKCU\..\Run: [Acme.PCHButton] C:\PROGRA~1\HPINST~1\plugin\bin\PCHButton.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: AIM (HKLM)
O9 - Extra button: Real.com (HKLM)
O9 - Extra button: Yahoo! Messenger (HKLM)
O9 - Extra 'Tools' menuitem: Yahoo! Messenger (HKLM)
O9 - Extra button: Messenger (HKLM)
O9 - Extra 'Tools' menuitem: Messenger (HKLM)
O12 - Plugin for .pdf: C:\Program Files\Internet Explorer\PLUGINS\nppdf32.dll
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: JT's Blocks -
O16 - DPF: Yahoo! Bingo -
O16 - DPF: Yahoo! Blackjack -
O16 - DPF: Yahoo! Checkers -
O16 - DPF: Yahoo! Chess -
O16 - DPF: Yahoo! Chinese Checkers -
O16 - DPF: Yahoo! Dice -
O16 - DPF: Yahoo! Dominoes -
O16 - DPF: Yahoo! Dots -
O16 - DPF: Yahoo! Fleet -
O16 - DPF: Yahoo! Gin -
O16 - DPF: Yahoo! Go Fish -
O16 - DPF: Yahoo! Literati -
O16 - DPF: Yahoo! Pool 2 -
O16 - DPF: Yahoo! Spades -
O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) -
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} (Shockwave ActiveX Control) -
O16 - DPF: {28F00B0F-DC4E-11D3-ABEC-005004A44EEB} (Register Class) -
O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) -
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) -
O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (YInstStarter Class) - http://download.yahoo.com/dl/installs/yinst.cab
O16 - DPF: {41F17733-B041-4099-A042-B518BB6A408C} - http://a1540.g.
O16 - DPF: {4A3CF76B-EC7A-405D-A67D-8DC6B52AB35B} (QDiagAOLCCUpdateObj Class) -
O16 - DPF: {6211AC26-A1B4-422A-AC52-1E70B7D24465} (FileSharingCtrl Class) -
O16 - DPF: {6A060448-60F9-11D5-A6CD-0002B31F7455} (ExentInf Class) -
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) -
O16 - DPF: {90C9629E-CD32-11D3-BBFB-00105A1F0D68} (InstallShield International Setup Player) -
O16 - DPF: {917623D1-D8E5-11D2-BE8B-00104B06BDE3} (CamImage Class) -
O16 - DPF: {97438FE9-D361-4279-BA82-98CC0877A717} (Cubis Control) - http://mirror.worldwinner.com/games/v54/cubis/cubis.cab
O16 - DPF: {9F1C11AA-197B-4942-BA54-47A8489BB47F} (Update Class) -
O16 - DPF: {A031D222-B496-11D2-9CC8-00105A10AAF6} (WONWebLauncher Class) -
O16 - DPF: {AD7FAFB0-16D6-40C3-AF27-585D6E6453FD} -
O16 - DPF: {C2FCEF52-ACE9-11D3-BEBD-00105AA9B6AE} (Symantec RuFSI Registry Information Class) -
O16 - DPF: {C62DFDC7-2EEC-4C2C-827A-BC0BFB4260B3} (IMViewerControl Class) -
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
O16 - DPF: {F6BF0D00-0B2A-4A75-BF7B-F385591623AF} (Solitaire Showdown Class) -

Dani AI

Generated

Brief expert summary and next steps for 's report and the replies below.

W32.Welchia (aka Nachi) is a 2003 network worm that exploited the RPC/DCOM buffer-overflow (MS03-026) and a WebDAV/ntdll flaw (MS03-007). It behaved “helpfully” by trying to delete the Blaster/msblast executable and fetch Microsoft patches, but its behavior (TFTP installs, scanning and ICMP floods) caused system instability and major network disruption. (learn.microsoft.com)

Key indicators to look for (these are more relevant than browser hijack items): unexpectedly high ICMP/ping traffic, random reboots, a new %windir%\system32\wins (or C:\winnt\system32\wins) folder containing suspicious copies of dllhost.exe or svchost.exe, a running TFTP executable/service, or a TCP listener on port 707. Welchia’s presence isn’t guaranteed to show in HijackThis logs, so treat ’s HijackThis advice as complementary rather than definitive. (iet.ucdavis.edu)

Practical workflow (safe order):

  1. Isolate the PC immediately (unplug NIC / disable wireless).
  2. From a known-clean machine, download updated AV signatures or vendor removal tools to removable media.
  3. Boot the suspect machine offline (Safe Mode without networking recommended) and run full scans and the vendor remover. Manual hunts can use the following commands to locate/rid an active payload:
netstat -ano | findstr ":707"
tasklist /FI "PID eq <pid>"
taskkill /PID <pid> /F

If a removal tool returns “not found” (as happened with the OP’s FixWelch run) it may be a false negative or an updated variant — try multiple reputable scanners. If system files or services were altered (renamed svchost/dllhost in odd folders, unknown services), the safest route after backing up data is a rebuild/reinstall. (f-secure.com)

Context for the thread: / were correct to point to vendor removal tools (obtain them from the vendor site, not random mirrors); ’s caution about unknown ZIPs is valid. Use the symptoms above to decide whether scans/removal are sufficient or a rebuild is necessary.

Recommended Answers

All 6 Replies

Don't shpw no virus ,
First thing is to put hijackthis in its own folder on you c:\ drive ,like C:\HJack,because it save a backup of what it does and they can get lost in a temp folder .
Uou should also run ad-aware and spybot ,update them first , links in my signature .

Log looks good actually. you could run it and fix these .

This one is optional ,but reccomended ,but is known to be big resource hog

O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE

O16 - DPF: {28F00B0F-DC4E-11D3-ABEC-005004A44EEB} (Register Class) -

O16 - DPF: {AD7FAFB0-16D6-40C3-AF27-585D6E6453FD} -

Welchia is an evil demon from the pits of hell that caused me much grief and loss of internet.Attached to this message is Symantic's removal tool.

Welchia is an evil demon from the pits of hell that caused me much grief and loss of internet.Attached to this message is Symantic's removal tool.

How do we know? That zip file might have the worm in it! Like tequila. :cheesy:

If it did have a virus and someone got it then I'd probably get banned, which I'm trying to avoid :P. If you're dubious of it, search symantic's website instead.

Maybe you should just download it from Symantec's website. It's safer to get there than from anywhere else.

Be a part of the DaniWeb community

We're a friendly, industry-focused community of developers, IT pros, digital marketers, and technology enthusiasts meeting, networking, learning, and sharing knowledge.