|
Virus Alert: Nimda WormNovember 1, 2001: Nimda.E is a new variant of this worm with changed file names and other modifications to make it harder to detect. Detailed information is available from Symantec. NAV can detect infected files, even when using the definitions for the original Nimda.A variant, but there is also a new removal tool specfic for Nimda.E. September 27, 2001 - Nimda reactivation warning from CERT: The W32/Nimda worm contains code that will cause an infected host to send infected mail messages every 10 days. Host that were initially infected on Tuesday, September 18th and not recovered could start sending another round of messages tomorrow, September 28th. September 18, 2001: Some hosts at Cornell have been infected with a new, and quickly spreading worm named "W32.Nimda" or "Concept Virus Worm (CV) v.5." A CIT News Flash describes three ways this worm can be transmitted. All Windows users are urged to apply patches from Microsoft that protect against this worm. How to Protect Against Nimda
The specific patch (Q290108) fixes similar flaws in both Internet Explorer and Outlook.
Notification of Possible InfectionsWhen web requests are detected originating from hosts at Cornell and indicating that these hosts might be infected, network administrators are notified by e-mail of the IP addresses of the possibly infected hosts. If you receive such a notification and the host is running Windows NT or 2000, it is most likely that the host is indeed infected. Please repair the machine as soon as possible or disconnect it from the network to prevent the spread of this worm and the possible infection of other vulnerable machines. How to Remove the Worm from Infected Systems
Last modified: November 5, 2001 |