Summary
Nimda is a complex virus with a mass mailing worm component which spreads itself in email attachments named README.EXE. It affects Windows 95, Windows 98, Windows Me, Windows NT 4 and Windows 2000 users.
Removal
F-Secure Anti-Virus detects the worm with updates released on September 18th, 2001 19:20 EET. Disinfection was added in the updates from September 19th, 2001 17:12 EET.
F-Secure Anti-Virus with the latest updates can detect and disinfect Nimda infections. But full disinfection of the worm will require some additional manual actions.
The F-NIMDA tool was developed to automate these actions. If you wish to do them by hand, follow the instructions below. Otherwise, download F-NIMDA from:
- ftp://ftp.f-secure.com/anti-virus/tools/fsnimda3.exe
If you're running Windows ME, you need to turn off the Autorestore functionality before starting any disinfection. Do this by clicking My Computer on desktop, then Performance- > File System - > Troubleshooting- > Disable System Restore. Turn it back on when done.
To disinfect the worm and restore security of affected workstations, please follow these instructions:
About infected sites
A web site can get infected in two ways:
- Infected htmls are copied the secure site. This can happen even if you're using a patched version of IIS or something else entirely (such as Apache or Netscape). If there are infected computers in your organization, their local html files get infected. Users might then later copy or upload such infected pages to your www server. Alternatively, if your www files are accessible via file sharing the worm might infect them directly from a workstation. To clean your site, locate all html pages which refer to "README.EML"; and remove the extra Javascript code from the end of the pages.
- Direct web worm infection. If your web site is running an unsafe version of IIS, the worm can infect your site by accessing it through http. After this it will restart spreading from your server. In this case, it is not enough to just clean the virus - your web server is unsafe and has been so for a while. It's likely there have been previous illegimate accesses to your site as well and it should be considered compromised. We recommend rebuilding the web server and applying latest patches before restoring clean copies of the html pages.
Remember, F-Secure Management Server 4.x uses IIS as a web server platform. Keep them patched. F-Secure Policy Manager Server 5.0 and higher do NOT use IIS.
A False Positive is when a file is incorrectly detected as harmful, usually because its code or behavior resembles known harmful programs. A False Positive will usually be fixed in a subsequent database update without any action needed on your part. If you wish, you may also:
- Check for the latest database updatesFirst, check if your F-Secure security program is using the latest updates, then try scanning the file again.
- Submit a sampleAfter checking, if you still believe the file is incorrectly detected, you can submit a sample of it for re-analysis.Note: If the file was moved to quarantine, you need to collect the file from quarantine before you can submit it.
- Exclude a file from further scanningIf you are certain that the file is safe and want to continue using it, you can exclude it from further scanning by the F-Secure security product.Note: You need administrative rights to change the settings.
Technical Details
- Concept Virus(CV) V.5, Copyright(C)2001 R.P.China

History
LIFECYCLE
- Infecting files
- Mass mailing
- Web worm
- LAN propagation


Execution
- SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths]
- [Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
- explorer.exe load.exe -dontrunold
Activity
- [Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced]
- [SYSTEM\CurrentControlSet\Services\lanmanserver\Shares\Security]
Propagation
Protect your devices from malware with F‑Secure Total
Protecting your devices from malicious software is essential for maintaining online security. F‑Secure Total makes this easy, helping you to secure your devices in a brilliantly simple way.
- Award‑winning antivirus and malware protection
- Online browsing, banking, and shopping protection
- 24/7 online identity and data breach monitoring
- Unlimited VPN service to safeguard your privacy
- Password manager with private data protection
Choose how many devices you want to protect to get started.
- Free customer support
- Cancel anytime
- The trial does not obligate you to buy the product
After 30 days your subscription will renew automatically for one year at €69.99.
More Support
Community
Ask questions in our Community.
User guides
Check the user guide for instructions.
Contact Support
Chat with with or call an agent.
Submit a Sample
Submit a file or URL for analysis.
)
)