I switched my computer on this morning and a warning window appeared immediately telling me that I should run AVG for Windows to get rid of a worm called NACHI, which is in some way, that I don't fully understand, associated with the recent RPC worm.
I looked at AVG for details of this worm, but I'm not sure what my next step should be, however I also wondered if anyone had heard of this, its been around since Aug 18 apparently, yet my computer has only recently alerted me about it.
Thank you for your help on this Dwight. It is actually very peculiar how this has shown itself. It began on the day I posted the question, first time I'd ever seen it, despite its having been released on Aug 18. However, I ran AVG twice and each time 2 files were found to contain a virus and this was healed. Then later in the day the same warning window appeared again, I ran AVG once more and it appeared again to correct the problem.
Later I ran AVG once more and no virus were found.
Things have been running smoothly and efficiently ever since - but it seems odd to me in the first instance - no worries though it appears now to be gone. Thanks a lot for this help and these websites
If your computer is being infected with this worm, I'd guess you're using Windows XP. If so, log on as an administrator and enable the Internet Connection Firewall (ICF) for your Internet connection. See http://www.microsoft.com/security/protect/windowsxp/firewall.asp for details.
Ok Tom now here's the thing, at last I thought I'd lost the nachi however, I left my computer alone for an hour and when I returned low and behold the warning window was there once more.
Yes I do run XP Professional, I did have Nortons and Zone Alarm Pro, but had to uninstal both for other reasons, the only firewall I currently use is the Microsoft one stored on my computer and AVG virus scanning.
What bothers me about this worm is that so far it does not affect the way my system performs. and the warning window only comes up now and then - its the first time I've seen this actually.
I am now going to link to that which you gave me, thanks I hope it works.
Note:
Since writing this I still have time to edit and add that my ICF was in fact enabled in the box 'Protect my computer and network......' However, I do recall doing this but I did so on August 23rd and I believe Nachi may already have been there as it was activated I believe August 18 - now I do have aproblem it seems.
[This message was edited by Mrs. Micawber on 09-14-03 at 03:27 AM.]
I ran the virus test again this morning. No virus was found in System32\Win also when I checked the virus log. It showed that yesterday and today 2 virus were successfully removed Trojan Horse and Worm Nachi - therefore I am mystified.
Since Nachi was IE based as opposed to email based I wondered therefore if I keep getting reinfected each time I open Internet Explorer? Just a thought from this otherwise ignorant lady.
I find it odd that it was released on Aug 18 and that I have only detected it this week, despite being constantly on the computer ??????
I think the little devil has departed from whence it came.
I have selected a new restore point from today, as I downloaded and installed the patch again. So far, all seems well in love and war - keeping my fingers crossed.