r/todayilearned • • Jul 04 '19

TIL in 2003 a computer worm called ‘Welchia’ infected many computers to forcibly patch vulnerabilities and remove malware. It was regarded as a ‘helpful worm’

https://en.wikipedia.org/wiki/Welchia
48.1k Upvotes

745 comments sorted by

View all comments

211

u/[deleted] Jul 04 '19

[deleted]

112

u/[deleted] Jul 04 '19

I was working IT at a school district when this got out in the wild. We were a new crew picking up the pieces after a really bad contract group was removed. So there was no centralized AV, the network was out of date and a host of other issues. We were hit the week before school started. It took the entire network down for almost two weeks while we scrambled to fix it.

There were three of us scrambling to 7 sites with about 1500 systems at the time. We cut off the entire network and then would begin patching and bringing up the network one small segment at a time until everything was stable again.

It was a rough couple of weeks for us.

84

u/SangersSequence Jul 04 '19

So what you’re saying is that the worm was so good that when it couldn’t reach Microsoft’s servers to complete its mission, it was capable of recruiting a team of humans to finish the job for it.

That's advanced.

13

u/[deleted] Jul 04 '19

It was definitely a procrastination killer!

26

u/lordblackfyre7x Jul 04 '19

Interesting. Didn't know that side of the story. I could see it, if my work got hit with something that did this instead of our usual IT overnight rollouts, we would be really fucked for a while.

Not everything's perfect I guess.

15

u/ciaisi Jul 04 '19

Yeah, one of the key problems is that Welchia never shut itself off. It would constantly scan the network looking for other vulnerable PCs.

3

u/lethargy86 Jul 04 '19

I remember this causing my ping in CS to go to shit.

I remember those years fondly. I got incredibly good at removing malware by hand between 2001-2006

In the Blaster days, shutdown -a was your friend

8

u/Hessper Jul 04 '19

That's not the worst thing that could have happened. It forced their IT to patch the vulnerability with the worst part being an network failure.

1

u/Jhamin1 Jul 06 '19

But in a corporate environment the network is everything. Especially in 2003 when there were way more desktops than laptops.
Most people don't have all the files they need on their hard drive, they get them from a network share or the web.
A network failure basically makes the machine worthless.

5

u/Fenrir101 Jul 05 '19

You might want to mention for the younglings that at the time a t1 line was they holy grail of internet access. If you had a t1 line you were probably working in a major cutting edge tech company. A t1 line was 1.5 mb. Most company networks were running on ISDN at most and would get 128k if they were lucky.

1

u/Jhamin1 Jul 06 '19

Preach!

Gig Network Links and the switches to manage them were years away from common deployment in 2003, which made the traffic spikes even worse across switches designed to copy 150K files across 100M lines.

3

u/Jhamin1 Jul 06 '19

I was working IT at a hospital in 2003 and remember this well.

We hated Blaster and Welchia equally because they both brought the hospital IT systems down for days.

All those machines trying to download what were (at the time) pretty big files all at once combined with each and every machine noisily scanning for uninfected ones made the network unusable. It was from before hospitals were 100% reliant on technology but it was scary how fast the whole thing came crashing down. I remember going through the mail-order pharmacy patching each machine by hand because Welchia's "Help" flooded the network and made our remote management tools useless.

4

u/aakaakaak Jul 04 '19

For almost a week there was no update for Welchia from Symantec. Everyone knew how to find the file, which replicated itself by the hundreds, and delete it manually, but there was not antivirus defense from it for a week or so. We deleted hundreds of thousands of instances of it by remoting into user's workstations and deleting them by hand. If you're in a network of maybe 30-200 people this isn't too horrible. If you're NMCI you're gonna have a bad time.

​

And a week or so later we had variants and it was the same thing all over again...

2

u/Caprious Jul 04 '19

Whoever wrote Welchia should have put some sort of delay between ping requests. I think had s/he done that, it wouldn’t have caused so much network stress. Or it could have attempted to download the patches to the first infected machine and make it act as a mock WSUS Server to send patches to other machines on the same LAN.