English
Deutsch
Francais
Español
Italian
Home
Vireninfos
W32/Nimda
Suche
Home
Support
Lösungen
Produkte
Downloads
Vireninfos
Statistiken
VDF Historie
Virenkunde
Datei-Upload
Sicherheits-News
In-the-Wild-Viren
Unternehmen
Presse
Partner
Newsletter
W32/Nimda - Malware
Siehe auch
Kurzfassung
Vollständig
Statistik
Wie würden Sie diese Information bewerten?
Wertlos
Hervorragend
Alias:
W32/Nimda.gen@MM
Type:
Worm
Size:
57,344 bytes
Origin:
unknown
Date:
09-18-2001
Damage:
VDF Version:
Danger:
Medium
Distribution:
Medium
Technical Details
W32/Nimda is an Internet virus that can send itself by email, as a mass mailer. It can be activated on all Microsoft Windows 9x/Me and NT/2000 Platforms. Nimda sends itself as email attachment. These attachments are named README.EXE, the extension being usually unlisted.
The email looks differently: the subject is a random text and the body is usually empty. In Outlook or Outlook Express, the attachment is not in preview mode.In some cases the attachment can have the extension .COM or .WAV.
If the file README.EXE is opened automatically or by double-click, the worm copies itself in Windows Temp folder. It creates a file with the name FormMExxxx.TMP.EXE, where xxxx are random characters. This file is run and then
deleted by the next system start in Windows 9x/Me. Then the worm copies itself in Windows system as:
* WINDOWS\LOAD.EXE
* WINDOWS\RICHED20.DLL
* WINDOWS\SYSTEM\RICHED20.DLL
* WINDOWS\SHELLNEW\RICHED20.DLL
The files with the same name will be overwritten. The file LOAD.EXE will be inserted in SISTEM.INI. Thus, the worm will be activated by the next system start:
SHELL=exploerer.exe load.exe -dontrunold
After a few minutes, the worm creates various .EML or .NWS files in Windows subfolders. These too contain the worm. If there are any shared folders with writing rights, the worm copies itself in the subfolders of the network drives, as .EML or .NWS files.
Finally, the worm resets all the Windows properties back to the standard values. After this, there are no "hidden" or "system" files declared. The extensions of the known program files are suppressed.
If there is an Internet connection, Nimda tries to download by FTP a file named ADMIN.DLL. In NT the worm tries to log as a guest and to give this account administrator rights. From this moment on, the drive C:\ is shared with read and write properties. The worm deletes then all the keys in the registry:
\System\CurrentControlSet\Services\
Ianmanserver\Shares\Security
If the worm is activated on IIS Web-server, it creates the file README.EML. When this file is opened (by accessing a web-site) it installs in Java-Script the following files:
* Index.html
* Index.htm
* Index.asp
* Readme.html
* Readme.htm
* Readme.asp
* Main.html
* Main.htm
* Main.asp
* Default.html
* Default.htm
* Default.asp
When one of the above sites is accessed, Java-Script is opened. The browser loads the README.EML file on the local computer. Some browsers are set to open and immediately run the attachment file README.EXE.
Kurzfassung
hier
.
Beschreibung erstellt von Crony Walker am Tue, 15 Jun 2004 14:00 (GMT+1)
»
Über Malware
»
Über Phishing
»
In-the-Wild-Viren
« zurück
Diese Seite drucken
Worm/Bagle.FJ
W32/Elkern.C
TR/Crypt.CFI.Gen
Worm/Mytob.U
Worm/Mytob.CR
TR/Dldr.Java.OpenConnection.AQ
DR/Buzus.qvy
DR/Mirar.AJ
EXP/Flash.1275
CC/00233
Einfach aktuelle Nachrichten von Avira bekommen, als
Erkennt und entfernt folgende Malware und ihre Varianten:
Worm/Sober.J
Worm/Sober.P
Worm/Sober.Y
W32/Stanit.A
Worm/NetSky.AA
Worm/NetSky.B.1
Worm/NetSky.C
Worm/Netsky.D.Dam
Worm/NetSky.P
Worm/NetSky.X
Worm/Mytob.IN.2
Worm/Mytob.KS
TR/Spy.Banker.AATZ
TR/Spy.Banker.AATZ.1
TR/Spy.Banker.AATZ.2
TR/Spy.Banker.AATZ.3
Hier downloaden
Virenwarnung
auf Ihre Webseite einbinden
© 2008 Avira GmbH
Copyright
Datenschutz
Sitemap
Feedback
Impressum
FAQ
Kontakt