w32.Nimda Virus

Jay

Golden Member
Oct 9, 1999
1,728
7
81
I just installed Windows last night and installed Norton AV right after that. I then went to be and woke up this morning to have the AV tell me I have this virus, but that it cannot fix the problem. WTF???
 

Didou

Member
Sep 28, 2001
114
0
0
I've had that virus. The only way to get rid of it is to delete the infected files.Sorry. :(
 

RaySun2Be

Lifer
Oct 10, 1999
16,565
6
71
That sucks Jay. Go to the Symantec site and it should have instructions on how to clean out the virus. It is a nasty one to get rid of. McAfee has good information on how to clean it out too.

Good Luck.
 

RaySun2Be

Lifer
Oct 10, 1999
16,565
6
71
Here's the Symantec links:

Nimda Info

Removal Instructions

The also have a Nimda removal tool that you can try: Removal Tool

Do you know how you got infected? Email, Web Page, or IIS?

Microsoft Web Server Patch Bulletin

Also, more cleaning tools and instructions can be found at a thread on Russ' BBS: HERE!


I would try the cleaning tools before taking drastic measures such as wiping the hard drive.

Good luck!

(I spent a straight 28 hours at work because of that &#*^$*&#($^ virus.
 

JonB

Platinum Member
Oct 10, 1999
2,126
13
81
www.granburychristmaslights.com
Jay, it is a pain. Our work network, including one of mine, got hit though open files shares. My computer never got infected (it never began actively e-mailing and infecting others) but at one time, I had over 1000 eml, nws and riched20.dll files spread across an 80GB hard drive used for our department.

Norton AV helped, but the biggest help was running Windows Update and getting all the security patches installed.

All clean now, as of Friday anyway. Good Luck, and don't forget to run Windows Update.
 

Corsairpro

Platinum Member
Feb 12, 2001
2,543
0
0
i use yahoo mail and someone just sent me an email with an attachment..... i clicked the scan with norton antivirus link..... it was indeed the worm.... not sure... i didnt download anything so i didnt get it right?
 

Jay

Golden Member
Oct 9, 1999
1,728
7
81
It must have come through IIS. I haven't installed my e-mail yet and the share that I do have on there is read-only, no write access. I went to download the IIS 5.0 fix and it won't work with WindowsWO (hmm, letters don't look right. Well, you get the idea.)
 

RaySun2Be

Lifer
Oct 10, 1999
16,565
6
71
JonB,
That's exactly how my division's network got infected, through open network shares with corporate, who had all servers and some PCs infected. We just got the .eml and riched20.dll files.

Corsair, yes, you should be fine, be sure to delete that email, and let the person that sent you the email know that they have been infected with the Nimda virus.

Jay, you can also be infected by surfing the Internet and happening upon a website that has been infected. Nimda infects IIS, then also mods the html files to infect others going to that website.