Yenra : Anti Virus : Nimda Worm Virus Protection : Symantec Provides Comprehensive Protection Against W32.NIMDA.A@MM


Symantec today announced that new analysis of W32.Nimda.A@mm reveals that the worm contains an additional destructive payload that will not only require detection, but removal. The new analysis indicates that the worm is a file infector, infects .exe files resides in memory.

W32.Nimda.A@mm is a mass-mailing worm that utilizes multiple methods to spread itself. The worm sends itself out by e-mail, infects machines over the network, and infects unpatched or already vulnerable Microsoft IIS Web servers. The worm also has various side effects, such as increasing network traffic while searching for machines to infect, which may cause network bandwidth problems. W32.Nimda.A@mm will also attempt to create security holes by creating a guest account with administrator privileges and create open shares on the infected system.

Symantec currently provides an integrated detection and repair solution against W32.Nimda.A@mm. In one step, users can download a solution that will simultaneously detect the worm and repair damaged files. Symantec is developing a separate removal tool to eradicate the worm from the PC memory.

"Using blended Internet security threats the combination of viruses, exploits, or vulnerabilities to attack businesses and destroy assets, continue to rise," said Vincent Weafer, senior director of Symantec Security Response. "To combat such a fast spreading threat, Symantec integrated its solution for W32.Nimda.A@mm to detect and repair, allowing for quick clean up with little downtime."

Symantec Security Response recommends that IT administrators implement the following to stop the propagation of W32.Nimda.A@mm:

Additionally, consumers can immediately protect themselves against the new worm by implementing the following:

Both consumers and enterprises can be infected through a variety of methods.

Shared Drives PC users with shared drives enabled are also at risk. The worm searches for open network shares and will attempt to copy itself to these systems and then execute. IT administrators should close all network shared drives.

Web sites When users visit a compromised Web site, the server will run a script attempting to download an Outlook file, which contains the W32.Nimda.A@mm worm. The worm will create an open network share on the infected machine allowing access to the system. W32.Nimda.A@mm specifically targets versions of IIS servers, taking advantage of the known Universal Web Traversal exploit (MS Security Bulletin MS00-078), which is similar to the exploit used in the Code Red attack. Compromised servers will display a Web page and attempt to download an Outlook file that contains the worm as an attachment.

