Computing.Net > Forums > Windows XP > Nachi.B worm has got me beat! :(

Computer Problems? Computing.Net has over 1,000,000 posts about all things technology related! Over 90% answered within 24 hours! Click here to start participating now! Also, be sure to check out the New User Guide.

Nachi.B worm has got me beat! :(

Reply to Message Icon

Name: lyland
Date: February 16, 2004 at 18:38:35 Pacific
OS: XP Pro
CPU/Ram: 1 Gig
Comment:

Well just recently my virus software AVG Pro alerted my about a virus i had, it was Nachi.B. I tried to heal, delete and move to vault all to no avail. To make matters worse my system is having lots of trouble with certain programs not opening at all and I.E. is very buggy. For some reason AVG cannot fix this worm. I have tried many other virus software on line and no other program / service could even find a virus.

The worm is found under two locations:

C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\T5YBB0G9 (WksPatch1)
&
C:\WINDOWS\system32\drivers\svchost.exe (svchost.exe)

When i touch either the WksPatch1 or the svchost.exe my virus scanner immediately comes up and wants to heal it. That is only temporary as they come back after boot up. ALso if i delete them manually they come back after boot up.

I then turned off system restore and tried to find them in my registy (regedit-edit-find) but could not find either one. I tried a registry cleaner but it does not work either.

Any suggestions please???



Sponsored Link
Ads by Google

Response Number 1
Name: dssrulzz
Date: February 16, 2004 at 18:47:18 Pacific
Reply:

From what I can gather - if you have already gotten the windows updates and critical patches(fixes), you will probably have to cut your losses and reformat and reinstall. First try the reinstall(repair) option...failing that you may be saying goodbye to any information already stored unless previously backed up (then attempt to reload them)and you know those files are not infected too. Good luck.



0

Response Number 2
Name: setishock
Date: February 16, 2004 at 18:49:00 Pacific
Reply:

Try running> Stinger
http://val.nai.com/vil/stinger


0

Response Number 3
Name: AdamDavis
Date: February 16, 2004 at 18:49:26 Pacific
Reply:

from my experince AVG sucks the big one, was totally useless, i dont have any real help other then to say, get rid of that crap and get nortons or something


0

Response Number 4
Name: dssrulzz
Date: February 16, 2004 at 18:52:14 Pacific
Reply:

Give AVG a break I run both AVG and Norton and I find that AVG is quicker to respond and heal infected files Norton ever was. It was Norton that prompted me to look elsewhere to begin with.


0

Response Number 5
Name: setishock
Date: February 16, 2004 at 19:30:21 Pacific
Reply:

You have to disable(translation>delete) the restore points on your system. The little bugger is hiding out in the saved restore points. Dump them!!!!! Then run a anti-virus program. You're saying they come right back so try killing the restore points and leave them off while you run your anti-viral program. Stinger is made to zap what others have trouble getting to. Try it.


0

Related Posts

See More



Response Number 6
Name: SullyD
Date: February 16, 2004 at 19:43:51 Pacific
Reply:

Lyland,

Setishock is right about the restore points. In fact, not only should you disable system restore, but you should boot in safe mode to assure the worm is not an active process.

and your Nachi B worm is a variant of W32.Welchia.B.Worm...AKA...W32/Nachi.worm.b [McAfee], W32/Nachi-B [Sophos], Win32.Nachi.B [Computer Associates], WORM_NACHI.B [Trend], Worm.Win32.Welchia.b

Norton has a removal tool for this found here.

Best of luck to ya...

SullyD


Experience is what you get when you don't get what you want...


0

Response Number 7
Name: bigindy
Date: February 17, 2004 at 06:57:36 Pacific
Reply:

Im having the same problem. i did the whole rpc stuff to stop my comp switching off, turned off system restore. downloaded the windows updates and the patches. searched for a virus but nothings being picked up. i have 100% cpu usage on teh comp with svchost.exe (in caps letters) the culprit. i think its the nachi worm. what should i do? can i burn my vids etc before formatting my hard drive? how would i do this? this is a last resort tho. i still get the rpc error when i switch it on with the generic 32 error thing. please help!


0

Sponsored Link
Ads by Google
Reply to Message Icon

ANA-6944A/TX Quad Port 10... unable to install softwar...



Post Locked

This post is quite old and has been locked from receiving new replies. Please create a new posting instead.


Go to Windows XP Forum Home


Sponsored links

Ads by Google


Results for: Nachi.B worm has got me beat! :(

nachi.b worm www.computing.net/answers/windows-xp/nachib-worm/101951.html

This one has got be stumped... www.computing.net/answers/windows-xp/this-one-has-got-be-stumped/10984.html

Time poblems www.computing.net/answers/windows-xp/time-poblems/77273.html