Category: Malware

Type: -

Aliases: Nimda.e, W32/Nimda@mm, I-Worm.Nimda


Nimda.E is a recompiled variant of Nimda.A virus-worm. It is not compressed. It uses the same techniques as Nimda.A, except it spreads itself with SAMPLE.EXE file name.

Other minor differences are as follows:

1. The worm uses COOL.DLL name to upload itself to webservers

2. The worm uses HTTPODBC.DLL name to start from on servers

3. The worm uses CSRSS.EXE name to copy itself to servers

This version of Nimda has few serious bugs that allow it to infect files several times and to jam NT systems considerably.

Apparently the author of Nimda was offended because his virus wasn't named "Concept Virus" like he wanted. The virus code contains a copyright text string which is never displayed, saying "Concept Virus(CV) V.6, Copyright(C)2001, (This's CV, No Nimda.)"


Automatic action

Based on the settings of your F-Secure security product, it will either automatically delete, quarantine or rename the detected program or file, or ask you for a desired action.

Knowledge Base

Find the latest advice in our Community Knowledge Base.

About the product

See the manual for your F-Secure product on the Help Center.

Contact Support

Chat with or call an expert for help.

Submit a sample

Submit a file or URL for further analysis.

Technical Details

The actual lifecycle of Nimda can be split to four parts:

1) Infecting files, 2) Mass mailing, 3) Web worm and 4) LAN propagation.

F-Secure Anti-Virus detects this variant with updates released on October 29, 2001 / 18:32:39 (GMT+2).

A tool to disinfect all Nimda variants including Nimda.E is available here:



On October 30th, F-Secure received reports of live infections in Germany and Sweden. On October 31st, we received further reports from USA, China, France, Norway, Finland and Spain.

For more information on Nimda.A please read the description:



[F-Secure Corp.; October 30th, 2001]

Date Created: -

Date Last Modified: -