Computing.Net > Forums > Security and Virus > w32.nimba - more trouble

Computing.Net: Over 1,000,000 posts about all things technology related! Over 90% answered within 24 hours! Click here to sign up now, it's free!

w32.nimba - more trouble

Reply to Message Icon

Original Message
Name: Gordon
Date: September 4, 2002 at 17:23:03 Pacific
Subject: w32.nimba - more trouble
OS: XP home
CPU/Ram: AMD 1.6G, 256ddr
Comment:

Norton Detected the w32.nimba.enc virus on my computer. It could not repair the file, but rather quarantined it. I deleted the files to remove the virus from my machine. A few minutes later, norton detected more files that were infected with the w32.nimba.enc virus and could not repair, but rather quarantined them. I asked some people what I should do, and it was
suggested that I disable the system-restore on my computer and then delete the files.
This I did. Later, norton detected 54 more files on my computer that had contracted the w32.nimba.enc virus. I scanned my computer for viruses with norton, and it told me that there were no viruses on my machine, although it had 54 files quarantined. I downloaded panda scan from

http://www.pandasoftware.com/activescan/activescan.asp?language=2&Country=63&Partner=1&Ref=EN-PR-AS-107

and ran it on my computer. While it was running, norton detected more files that contained the w32.nimba.enc virus. Norton detected these WHILE the panda scan was operating, and by the time panda scan finished, and had detected no virus, norton had quarantined 101 files, and was not able to repair them.

I've heard that norton had falsely-recognized w32.nimba viruses before, and
added the .enc to the end of the virus when it showed it. I am wondering if that is the case in my situation. I dont know whether I have a big mean virus that can't be deleted, or if I have a stupid norton that made me delete a bunch of perfectly good files. Either way, I have a problem that needs solving. My macine works fine and appears not to be affected by the
virus. My os is windows XP.

All of the infected files appear to be comming from Microsoft Outlook. It
appears as though outlook is downloading the files, as they all end in
.eml,.nws, or .dll.

I also downloaded

http://www.bitdefender.com/download/download.php?file=AntiNimda.exe

which targeted nimba a,c, and e specifically. they found nothing.

Ideas other than formatting?


Report Offensive Message For Removal


Response Number 1
Name: Norm
Date: September 5, 2002 at 00:12:31 Pacific
Reply: (edit)

Norton detected these WHILE the panda scan was operating, and by the time panda scan finished, and had detected no virus, norton had quarantined 101 files, and was not able to repair them.

Not a good thing, conflicts running more
than one AV at a time causes problems.

Good luck


Report Offensive Follow Up For Removal

Response Number 2
Name: Norm
Date: September 5, 2002 at 01:25:20 Pacific
Reply: (edit)

More info and another tool >

http://www.pandasoftware.es/library/NimdaMoreinf4_en.htm


Report Offensive Follow Up For Removal

Response Number 3
Name: Gordon
Date: September 5, 2002 at 11:18:50 Pacific
Reply: (edit)

I didn't run norton at the same time I was running panda...norton just popped up and told me it was finding viruses.

I went to

http://www.pandasoftware.es/library/NimdaMoreinf4_en.htm

and downlaoded the file and ran it, but it didn't detect the nimba virus. When it was done, I went looking for its extension (riched.dll), and found it still there, unscathed. Everytime I delete its extension, it reappears, even when I deactivate system resore. This implies to me that the virus has integrated itself into my system and these virus scanners I'm using don't dig deep enough to find it...I'll try to look for some of its specific coding and remove it manually, but I dun kno if thats gunna be bery effective or not. Anything more sensitive than these virus scanners?


Report Offensive Follow Up For Removal

Response Number 4
Name: Norm
Date: September 5, 2002 at 15:20:17 Pacific
Reply: (edit)

I thought you allready had this link >

http://securityresponse.symantec.com/avcenter/venc/data/w32.nimda.e@mm.html

Not an expert, but I did stay at a
HolidayInn Express last night.

Sorry, all I can offer.


Report Offensive Follow Up For Removal

Response Number 5
Name: Gordon
Date: September 6, 2002 at 09:15:26 Pacific
Reply: (edit)

I've downloaded both nimba A and E removers, and they didn't find anything. Is there somewhere where I can download a nimba C tool?


Report Offensive Follow Up For Removal


Response Number 6
Name: ryan
Date: September 10, 2002 at 19:27:05 Pacific
Reply: (edit)

the nimda virus works with outlook express it copies the files that the virus is in..like my documents and sends itself out through outlook. so my best advice is to not use outlook cause then it wiont send itself out or copy files. I have nimda on my comp right now andi cant get it off. there is a program you can download from norton but it crashes when you run it. so if you have any ideas email me


Report Offensive Follow Up For Removal

Response Number 7
Name: R dog
Date: October 15, 2002 at 17:21:46 Pacific
Reply: (edit)

What the f--- is going on with this stupid NImba virus, I have the same f---ing problem on my comp. I have tried every virus scanner in the book and not one can detect the f---ing thing. It appears as if it hasn't done anything damaging to my system, but every time I try to get rid of the virus alert message it comes right back up. I am not going to start deleating files and panacking,l because I have read to many peoples articles saying that that dosn't do s---!!!! I have a brand new computer, and havn't downloaded s---. If norton doesn't get there asses together and find a f---ing tool to deleat this f---ing thing, I"m going to be pist. who hears me???????????f--- NIMBA.enc


Report Offensive Follow Up For Removal






Post Locked

This post is quite old and has been locked from receiving new replies. Please create a new posting instead.


Go to Security and Virus Forum Home








Do you have your own blog?

Yes
No
I did before
I will soon


View Results

Poll Finishes In 4 Days.
Discuss in The Lounge
Poll History




Data Recovery Software