TER General Board

Nimda worm - to whom it may interest...red_smile
Felicia FoXX See my TER Reviews 8663 reads
posted

FYI - If you don't already know about it....


http://dailynews.yahoo.com/h/nm/20010918/tc/tech_worm_dc_5.html

be safe..

ff

More updated info (interoffice memo, name of firm withheld)

Subject:  Virus Alert -- THIS COULD BECOME UGLY

The new virus (trojan) released today looks like it will infect thousands of computers.  At first it was thought that the attachment would only have one name, that is not the case.  This is a serious situation and we must ask that you do not open any email ATTACHMENT you were not expecting, even if it is from
someone you know.

There is also a slim possibility that you may infect your workstation by accessing an infected Web site.  If you are prompted to download any files from any web site please decline this download.  This is an alternative avenue the virus (trojan) can take to infect workstations.








-- Modified on 9/18/2001 5:32:59 PM

Check SYSTEM.INI file for SHELL=EXPLORER.EXE statement.  If anything else, you've got the virus.
Unless you absolutely need it, turn off file sharing.
Update Internet Explorer to the latest version - see URL provided.
Don't click on any email attachment you are not sure of; especially an attachment named README.EXE or with a .EML file extension.
Be very suspicious of an email attachment that arrives with nothing in the email subject line.
This includes emails from people you know as this virus propogates by sending itself to everyone in your address book under your name.
IMPORTANT - You can get this virus by simply visiting a website.

DDcutie6795 reads

I looked and can't find where to do that.  

Thanks,
Kelli
[email protected]

John.Galt6066 reads


You have to go into the settings for your network interface. (which if you have DSL would ne your network card, or a modem if you connect by phone).

You get here under control panel, then network. You click on the item called File Sharing and either make an adjustment or remove it. Probably remove it. I am doing this from memory as I am now on Windows XP and not windows 98 and dont know if they have changed.

Assuming you are using Windows 9x, right click on Network Neighborhood then click on Properties and Click on File Sharing then uncheck "Share My Files".

If you do not have a Network Neighborhood Icon, then you won't have File Sharing enabled and you don't need to worry.

Please pay attention to this one! I've been fighting this all day, it's a nasty one!!! Removal tools are hopefully on their way.

BD

Staff7507 reads

TER has been fully patched against this virus but many of it members have not.  Please follow the links above to patch yourself.  Both mcafee and Norton have come out with updates to their virus protection.

-- Staff

The Nimda worm like its predecessors, infect computers running IIS 4 or IIS 5.  Windows 9X are not in any way threathened with infection.  As somebody pointed out earlier, the IE version 5.5 patch 2, will protect against the little bugger as well.  There is no need to worry, unless you are running windows 2000, or XP.  In that case, just go into control panel, add/remove programs, add/remove windows components, and uncheck the Internet Information Services (IIS).  Unless you are running a web server or have multiple computers connected together, you do not need to have it installed.  Just uncheck it and you will be safe from this virus infecting your computer.  

If need be, just go pick up McAfee or Norton Anti-Virus 2002, or 2001.  It will protect your system from the virus.  

Neutrogena

See the following link:

http://www.microsoft.com/technet/treeview/default.asp?url=/technet/security/topics/Nimda.asp

NIMDA CAN AFFECT ANY MACHINE running Internet Explorer 5.0 that has not been patched to the latest service pack or upgraded to IE 6.0.  This includes a Windows 9x system.  Worse, the system can be infected by merely accessing an infected website!  This one is nasty.

DDcutie9525 reads

In the last two days I have received a couple dozen blank emails.  Completely blank, no header, nothing.  Some are from email addys that I recognize.  Does this have anything to do with the virus?  I am using IE 5.0.  They did not seem to have a patch for me.  Only 5.1 and beyond.  

Thanks,
Kelli

Kelli,

Could be.  Strongly urge you to upgrade.  It's free at the Microsoft website.

Check your SYSTEM.INI file as follows:
Click on Start, then Run and enter SYSEDIT in the "Open" field.
Then click OK.  
Several dialogue windows will open and one will be named SYSTEM.INI.  
Click anywhere on that windowto make it active and bring it on top.  
Look for a line that begins with SHELL=.  
It should read shell=Eplorer.exe.  
If it says anything other than exactly that, you have the virus.  If not, you are just fine.

Best

Register Now!