mg-t
[Top] [All Lists]

Nimda Worm Virus

To: <mg-t@autox.team.net>
Subject: Nimda Worm Virus
From: "Ben Prince" <blprince2@home.com>
Date: Sun, 7 Oct 2001 18:36:51 -0700
List Participants,

I recently was burned with the Nima worm virus.  I believe I was infected from
a message on the list.

We have all been cautioned on numerous occasions to not open any executable
attachments to email messages, unless you know the source.  This includes
attachments with "exe", "bat", "com" and a number of other extensions.
Extensions like "txt" and "jpg" should be all right.

I am using MS Internet Explorer (IE) and MS Outlook Express.  I was of the
impression that as long as I didn't click on an attachment, I would not be
opening it.  I was wrong.  With the particular Internet Explorer version, IE
5.5, that I was using, opening a message also opens any attachments, making
infections a risky possibility.

Later versions of IE don't have this problem.  With a newer IE release, you
don't open an attachment unless you directly click the attachment.  Go to
www.microsoft.com for detailed information.   You will find that there are a
number of options.to correct the problem:

      Patch provided in MS Security Bulletins MS01-020 or MS01-027
      IE 5.01 Service Pack 2
      IE 5.5 Service Pack 2
      IE 6

I highly recommend that you upgrade with one of the appropriate above
selections if you have an older IE version.  I selected IE 5.5 Service Pack 2.
To download it, go to www.msn.com.

To get rid of the Nimda worm , Symantec (Norton) offers a removal tool at no
cost.  To download this tool, Fixnimda, go to www.symantec.com.

I also recommend that you purchase anti-virus software.  I have had good luck
with Norton, although I must confess that I didn't have it turned on when my
computer was infected.  If it had been turned on, it probably would have
caught the problem right off.  In the future, I'm going to run the Norton
software in the background all the time.  Also, email scanning will be turned
on all the time.  Furthermore, I'll run a full system scan at least once a
week, as well as downloading any new virus definitions.

When the Norton anti-virus software scans, it quarantines any infected files.
With my machine, I had about 180 infected files in quarantine.  It is my
understanding that it is a good idea to delete quarantined files right away,
because if you temporarily turn anti-virus software off, then files can
"escape" from quarantine.

The things I suggest, then, include:

    Make frequent backups
    Download an upgrade IE fix from Microsoft
    Run anti-virus software all the time in the background.  Have email
scanning turned on.
    Frequently update with new virus definitions
    Frequently run full system scans.
    Down Fixnimda from Symantec to have it ready to go
    If the anti-virus program detects the Nimda, run Fixnimida and follow any
other instructions from Symantec regarding file extraction and restoration
    Delete the quarantined files.

If you still have problems, you may have to reload and/or reinstall from
scratch.

Ben
54 TF 1500

///
///  mg-t@autox.team.net mailing list
///


<Prev in Thread] Current Thread [Next in Thread>
  • Nimda Worm Virus, Ben Prince <=