The Nimda virus

November 2016

Introduction to the Nimda virus

Le Nimda virus (code name W32/Nimda) is a worm which spreads by email. It also has four other ways to spread:

  • The web
  • Shared folders
  • Microsoft IIS security holes
  • File transfer

At particular risk are users of Microsoft Outlook in Windows 95, 98, Millenium, NT4, and 2000.

What the virus does

The Nimda worm retrieves the list of addresses found in the address books of Microsoft Outlook and Eudora, as well as email addresses contained in HTML files found on the infected machine's hard drive.

Next, the Nimda virus sends all of these recipients an email with an empty body and a subject chosen at random (and often very long). It adds to the message an attachment named Readme.exe or Readme.eml (file containing an executable). The viruses use an .eml extension to exploit a security flaw in Microsoft Internet Explorer 5.

What's more, in Microsoft Windows the Nimda virus can spread over shared network folders, infecting executable files found there.

Viewing Web pages on servers infected by the Nimda virus may lead to infection when a user views pages with the vulnerable Microsoft Internet Explorer 5 browser.

The Nimda virus is also capable of taking control of a Microsoft IIS (Internet Information Server) Web server, by exploiting certain security holes.

Finally, the virus infects executable files found on the contaminated machine, meaning that it can also spread by file transfers.

Symptoms of infection

Workstations infected by the BadTrans worm will have the following file on their hard drive:

  • README.EXE
  • README.EML
  • files with the extension .NWS
  • files with a name like mep*.tmp, mep*.tmp.exe (for example mepE002.tmp.exe)

To check if you are infected, do a search for the files named above on all of your hard drives (Start / Search / For Files or Folders...).

Eradicating the virus

To eradicate the Nimda virus, the best method involves first disconnecting the infected machine from the network, then using up-to-date antivirus software or the Symantec virus removal tool (preferrably restarting the computer in safe mode):
Download the virus removal tool

What's more, the virus can spread using a security hole in Microsoft Internet Explorer, which means that you may catch the virus by visiting an infected site. To fix it, you must download the patch for Microsoft Internet Explorer 5.01 and 5.5. Please check the version of your browser, and download the patch if need be:
http://www.microsoft.com/windows/ie/download/critical/Q290108/default.asp

More information about the virus


Related :


El virus Nimda
El virus Nimda
Der  virus Nimda
Der virus Nimda
Le ver Nimda
Le ver Nimda
Il virus Nimda
Il virus Nimda
O vírus Nimda
O vírus Nimda
This document entitled « The Nimda virus » from CCM (ccm.net) is made available under the Creative Commons license. You can copy, modify copies of this page, under the conditions stipulated by the license, as this note appears clearly.