# Isn't this a GOOD computer virus?

**URL:** https://boards.straightdope.com/t/isnt-this-a-good-computer-virus/207479
**Category:** In My Humble Opinion
**Created:** [October 15, 2003, 12:21am UTC](https://boards.straightdope.com/t/isnt-this-a-good-computer-virus/207479 "2003-10-15T00:21:00Z")
**Posts on this page:** 11
**Page:** 1

<div class="post-metadata">

### Author: ![Spurious\_George](https://avatars.discourse-cdn.com/v4/letter/s/94ad74/32.png) [@Spurious\_George](https://boards.straightdope.com/u/Spurious_George)
#### Post date: [October 15, 2003, 12:21am UTC](https://boards.straightdope.com/t/isnt-this-a-good-computer-virus/207479/1 "2003-10-15T00:21:00Z")

</div>

So, our network at work was down/glitchy today, due to an infestation of the **Welchia/Nachi** worm. During a sporadic period of actual Net access, I found this page at Symantec, describing the steps the worm takes when it infects a computer:

> **[Symantec Security Center](https://www.broadcom.com/support/security-center)**
>
> Symantec security research centers around the world provide unparalleled analysis of and protection from IT security threats that include malware, security risks, vulnerabilities, and spam.

A summary, hopefully not infringing on too many Symantec copyrights – [ul]  
[li]· Copies itself to Dllhost.exe[/li][li]· Ends the process, Msblast, and deletes the msblast.exe file, which W32.Blaster.Worm drops.[/li][li]· Selects a new IP address, Sends a ping to find new valid addresses on the network.[/li][li]· Checks the computer’s operating system version, Service Pack number, and System Locale. Attempts to connect to Microsoft’s Windows Update and download the appropriate DCOM RPC vulnerability patch.[/li][li]· Checks the computer’s system date. If the year is 2004, the worm will disable and remove itself.[/li][/ul] Now, correct me if I’m wrong, but if this worm enters your system and completely delivers its payload, you are left with:  
-A computer that is now protected from the Blaster worm, where it may not have been before.  
-A computer CLEANED of the Blaster worm, if it was infected.  
-A computer updated to protect against Windows’ DCOM RPC vulnerability (_sealing the door it probably came in by to other viruses, or additional copies of itself!_)  
-If it’s 2004, a computer free of the **Welchia/Nachi** worm itself!

Now obviously, the “seek out other computers on the network and infect them” stage is an unwanted intrusion, and could cost companies valuable time and resources, and productivity loss. In fact it crippled email and Net access at my company for a large part of today. But how weird is it that all the intended effects of the worm seem to do is make vulnerable computers less vulnerable??? It’s like a big-hearted, yet radioactive 400-foot puppy, accidentally crushing downtown Tokyo while trying to protect its citizens.

Who would create and unleash a worm like this? A hacker with good intentions? A hacker feuding with the hacker who authored the Blaster worm? Someone at Microsoft, pushing their latest security updates out by force?

---

<div class="post-metadata">

### Author: ![Taran](https://avatars.discourse-cdn.com/v4/letter/t/edb3f5/32.png) [@Taran](https://boards.straightdope.com/u/Taran)
#### Post date: [October 15, 2003, 12:26am UTC](https://boards.straightdope.com/t/isnt-this-a-good-computer-virus/207479/2 "2003-10-15T00:26:17Z")

</div>

My vote is for a hacker with more good intentions than sense. Your analogy is excellent, as well as hilarious. I guess, maybe, over the long run, it’ll be a net positive if blaster is still crippling people; is it?

---

<div class="post-metadata">

### Author: ![RealityChuck](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/realitychuck/32/195_2.png) [@RealityChuck](https://boards.straightdope.com/u/RealityChuck)
#### Post date: [October 15, 2003, 12:47am UTC](https://boards.straightdope.com/t/isnt-this-a-good-computer-virus/207479/3 "2003-10-15T00:47:45Z")

</div>

Having spent hours manually checking over 2000 computers (with the rest of my department) and having to delete Welchia\* from over 250 of them, my answer is no f\*ing way is this a “good” virus.

Good intentions, possibly, but it sent so many pings out searching for infected computers that it brought our system (and the systems of colleges and businesses across the country) to a standstill.

Some half-assed hacker decided to create a good virus, but didn’t bother to think out the issues involved and tossed the damn thing out in the world to wreck computers. Intent or not, the results was just as bad (if not worse) than the disease.

There has been debate in the field whether you could create a good virus, but it boils down to: don’t screw with my computer. Even a good virus can cause harm to the computers its affecting. Computers have a myriad of settings and software and unless you test your software rigorously before releasing it, the potential for unintended problems is a big one.

You mentioned “completely delivers its payload” – how can you be sure that this will even work? Virus writers are notoriously bad programmers – Blaster, for instance, made a simple mistake that prevented it from doing a major portion of its damage. I read virus writeups all the time as part of my job, and most of them usually have a line “the virus was supposed to do X, but due to a flaw in the code, it didn’t.” Compared to virus writers, Microsoft puts out well-neigh perfect code.

I’d love to wring the neck of the moron who did this, good intentions or not. It meant we had to deal with TWO big virus outbreaks instead of one simultaneously (we actually could have gotten things under control without visiting computers if we only had to deal with Blaster, but with two, it was impossible) and it’s hard to feel the jerk who did this was doing us any favors.

\*Blaster was also present, but I’d estimate at least 85% of the infected computers had Welchia.

---

<div class="post-metadata">

### Author: ![ftg](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/ftg/32/2801_2.png) [@ftg](https://boards.straightdope.com/u/ftg)
#### Post date: [October 15, 2003, 1:59am UTC](https://boards.straightdope.com/t/isnt-this-a-good-computer-virus/207479/4 "2003-10-15T01:59:18Z")

</div>

My take: No reasonably interesting program is flawless. Such a viral anti-virus is bound to contain errors that cause problems. People need to make decisions for themselves as to how much risk they want to expose themselves to when thinking about installing software.

And, as the posts so far make clear, this particular piece of code has a serious flaw.

Good programmers know they will make mistakes. Being good at self-criticism is important. Bad programmers falsely believe they are good programmers and won’t make mistakes.

---

<div class="post-metadata">

### Author: ![davidm](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/davidm/32/225_2.png) [@davidm](https://boards.straightdope.com/u/davidm)
#### Post date: [October 15, 2003, 3:20am UTC](https://boards.straightdope.com/t/isnt-this-a-good-computer-virus/207479/5 "2003-10-15T03:20:03Z")

</div>

According to an article in this month’s Scientific American, it’s been discovered the Welchia does one more thing. It installs a surreptitious file transfer server which apparently gives the virus’ author a backdoor into the system. All the other stuff it does may be simply to remove evidence of itself and prevent having to compete with Blaster for local and network resources.

---

<div class="post-metadata">

### Author: ![rjung](https://avatars.discourse-cdn.com/v4/letter/r/45deac/32.png) [@rjung](https://boards.straightdope.com/u/rjung)
#### Post date: [October 15, 2003, 7:21pm UTC](https://boards.straightdope.com/t/isnt-this-a-good-computer-virus/207479/6 "2003-10-15T19:21:23Z")

</div>

Any program that runs on a computer without the user/owner’s authorization (and is not part of the manufacturer’s design) is bad.

I don’t care if this “benevolent virus” draws winning lottery tickets, if it runs without my say-so, it gets the boot.

---

<div class="post-metadata">

### Author: ![rjung](https://avatars.discourse-cdn.com/v4/letter/r/45deac/32.png) [@rjung](https://boards.straightdope.com/u/rjung)
#### Post date: [October 15, 2003, 7:21pm UTC](https://boards.straightdope.com/t/isnt-this-a-good-computer-virus/207479/7 "2003-10-15T19:21:23Z")

</div>

Any program that runs on a computer without the user/owner’s authorization (and is not part of the manufacturer’s design) is bad.

I don’t care if this “benevolent virus” draws winning lottery tickets, if it runs without my say-so, it gets the boot.

---

<div class="post-metadata">

### Author: ![APOC](https://avatars.discourse-cdn.com/v4/letter/a/5f8ce5/32.png) [@APOC](https://boards.straightdope.com/u/APOC)
#### Post date: [October 19, 2003, 11:15am UTC](https://boards.straightdope.com/t/isnt-this-a-good-computer-virus/207479/8 "2003-10-19T11:15:26Z")

</div>

> [@](#):
>
> \*Originally posted by davidm \*  
> \*\*According to an article in this month’s Scientific American, … \*\*

Can we get a link on that please ?

---

<div class="post-metadata">

### Author: ![Rasa](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/rasa/32/3578_2.png) [@Rasa](https://boards.straightdope.com/u/Rasa)
#### Post date: [October 19, 2003, 5:50pm UTC](https://boards.straightdope.com/t/isnt-this-a-good-computer-virus/207479/9 "2003-10-19T17:50:10Z")

</div>

Yeah, I work for a nationwide dialup ISP, and one of our providers sent us an email with a list of all of our users that are infected with Welchia/Nachi. Their infected machines were making an amazing amount of traffic, so we had to single them out, email them and let them know they had to patch their OS and clean their machine of Blaster and Welchia. It’s not so much that the virus does damage, but the way it propagates can cause huge network slowdowns.

These virus attacks of late have been hell on our tech support. Former AOL users are our largest customer base, and with AOL, their connection to the internet was behind a proxy. With most other dialup ISPs there’s no proxy. So they’d have the Blaster virus, and not be affected by it with AOL. Switch to our ISP, and the first time they connected, bam, RPC error, computer reboots. They call us and want to know why “our software” gave them a virus. Ugh. Brand damaging in the EXTREME. We have all sorts of “PLEASE READ THIS BEFORE SWITCHING FROM AOL” notices on our website and send out security alerts and all that but… no one reads them.

Virus writers can rot in hell for all I care.

---

<div class="post-metadata">

### Author: ![davidm](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/davidm/32/225_2.png) [@davidm](https://boards.straightdope.com/u/davidm)
#### Post date: [October 20, 2003, 3:46pm UTC](https://boards.straightdope.com/t/isnt-this-a-good-computer-virus/207479/10 "2003-10-20T15:46:20Z")

</div>

> [@](#):
>
> \*Originally posted by APOC \*  
> \*\*Can we get a link on that please ? \*\*

I can’t really give you a very useful link. The article was in this month’s print version. The [online version](http://www.sciam.com/article.cfm?chanID=sa006&colID=5&articleID=0007D4E3-44C7-1F7F-82D883414B7F0000) only gives the first couple of paragraphs. The part about the backdoor is later in the article. You need to either have an online subscription or read it in the print version. I imagine that some public libraries carry it.

---

<div class="post-metadata">

### Author: ![davidm](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/davidm/32/225_2.png) [@davidm](https://boards.straightdope.com/u/davidm)
#### Post date: [October 20, 2003, 4:07pm UTC](https://boards.straightdope.com/t/isnt-this-a-good-computer-virus/207479/11 "2003-10-20T16:07:48Z")

</div>

I found a similar claim elsewhere that I can link to.

From [here:](http://www.gcn.com/vol1_no1/daily-updates/23186-1.html)

> [@](#):
>
> Dunham said he has not completed a detailed analysis of the new worm, but by opening a port on a compromised machine it could leave it vulnerable to further exploits.  
> “Welchia masquerades as a ‘good worm,’ patching against the vulnerability,” he said. “In reality, it opens TCP port 707 for an attacker to remotely control the computer.”
