Hello, I have a firewalled network with 5 10.10.x subnets. I am getting Welchia infections on random machines, but am unable to trace the source. I have NAV Corp 8.1 on all machines and servers (or so I believe). However, once a machine is hit, the AV is disabled and the firewall log eventually fills up with ping attempts. It's easy to fix the machines infected by shutting down DLLHOST.EXE, but I am still concerned about the source of the virus. It has hit three subnets already .