question about nimda...

MajesticMoose

Diamond Member
Nov 14, 2000
3,030
0
0
Is it possible for me to get infected without opening any attachments? I got home from work today and McAfee had a bunch of infected files detected. I had morpheus running and i had my firewall down for some reason that i forget now. I thought this was a mail thing, though....

Ideas?
 

aphex

Moderator<br>All Things Apple
Moderator
Jul 19, 2001
38,572
2
91
Haha... I was thinking 'nambla' from south park :D
 

m2kewl

Diamond Member
Oct 7, 2001
8,263
0
0
Yes, there are many variants of the Nimda virus now...check out Trend Micro's website. Make sure you have a backup and run the nimda fix tool.
 

Heisenberg

Lifer
Dec 21, 2001
10,621
1
0
Can't nimda spread over network resources also? I don't really know a lot about it. Try reading about it on Mcafee's or Norton's site.
 

AnthraX101

Senior member
Oct 7, 2001
771
0
0
There are 3 main ways nimda spreads. Attachments (Not an automatic infection, unless you use an older version of Outlook), ISS (Automatic infection if it is able to come in via this channel, but if you have a recent version/no version at all, then it cant get in this way), and via a network (MAY be an autmatic infection, it does some realy funky things).

One guy was distributing nimda all thorughout the campus network. After tracking him down several times and attempting to get him to fix it (only being told to f*** off), I "fixed" it for him. You see, nimda shares your HD under the guise of "c$". It was a simple matter to add a deltree *.* /y to his autoexec.bat, and crash his computer so he had to reboot.

Armani
 

Mookow

Lifer
Apr 24, 2001
10,162
0
0
my roommate got it just b/c he forgot to unshare his shared folders when he got back to the dorm.
 

MajesticMoose

Diamond Member
Nov 14, 2000
3,030
0
0
I'm guessing it came through the network since it wasn't an attachment and i have no clue what ISS is (therefore i assume i don't have it). Checked out sharing and nothing out of order, i did how ever take away sharing on the two folders that were previously shared. They were actually the parent dirs for where most of the infected files were.

Thanks everybody,
m00se
 

Russ

Lifer
Oct 9, 1999
21,093
3
0


<< i have no clue what ISS is (therefore i assume i don't have it). >>



I'm guessing he meant IIS; in other words, Microsoft's web server. You can also get Nimda just by visiting an infected web site.

Russ, NCNE