Free Republic
Browse · Search
News/Activism
Topics · Post Article

Skip to comments.

Nimda Virus Alert

Posted on 9/18/2001, 11:22:49 PM by Sabertooth

Description

A new worm called W32.Nimda.A@mm has been discovered and is impacting systems around the world. This new worm takes advantage of vulnerabilities left by the recent Code Red worm and its variant - as well as spreading via e-mail and by visiting infected websites (internet and intranet).

Action Required

PLEASE READ AND FOLLOW THESE INSTRUCTIONS:

1. Search your root folder (usually c:\) for a file called admin.dll that has a "modified date" within the last 24 hours.

a. Legitimate files with the same name may appear in other directories, but only the suspect file will appear in your root folder - and have a modified date within the last 24 hours.)

b. If you find admin.dll in your root folder, and it has been modified within the past 24 hours, immediately disconnect your machine from the corporate network.

2. Do not open any attachments with "readme" in the filename.

b. Use extreme caution when checking any non-corporate e-mail accounts (including Hotmail, Yahoo mail, etc.).

Additional Actions

Limit web browsing to critical business need. Browsing impacted sites may compromise your system.


TOPICS: Announcements; Breaking News; Foreign Affairs
KEYWORDS:
Navigation: use the links below to view more comments.
first 1-2021-38 next last
I got this from a friend at Microsoft following attorney General Ashcroft's mention of the "nimda virus" at his press conference today. Ashcroft didn't know if it was some form of cyber-war, and neither do I... But I'm posting here because of the possibility.

If I'm mistaken in this you can let me have it with barrels blazing, because I'm new to the Freeper thing.

Regards,

Sabertooth

ps. One other suggestion: Get a Mac, as we're probably immune again.

1 posted on 9/18/2001, 11:22:50 PM by Sabertooth
[ Post Reply | Private Reply | View Replies]

To: Sabertooth

My dear brother and sister FReepers,

At this, of all times in my lifetime, I would like nothing more than to be able to read these threads and reply to them.  I have much I would like to say.

BUT, I cannot!

Why?

Because I am trying hard to raise the finances needed to keep FreeRepublic up and running so that we can continue to share valuable information and respond to it.

I beg you, if you have not yet donated to FreeRepublic this quarter,  do so now!

"And if you have donated, God Bless You, please ping your friends, and FReep on..."

I realize you are giving to lots of Relief efforts and I encourage you to do so.  But we need to help FR too.  Where would we be right now without it?

If you have no money, please come and bump the Fundraiser Thread.

I would really like to reach our goal quickly so that I and the rest of the dedicated FReepers who are working the Fundraiser Threads can participate in what is undeniably the most important time in FreeRepublic's history.

WHERE WOULD YOU GET YOUR NEWS FROM IF FREEREPUBLIC WASN'T HERE?  <--click here

Support FreeRepublic! Support the U.S.A. <--click here

2 posted on 9/18/2001, 11:32:17 PM by 2ndMostConservativeBrdMember
[ Post Reply | Private Reply | To 1 | View Replies]

To: 2ndMostConservativeBrdMember
The Washington Times!
3 posted on 9/18/2001, 11:35:14 PM by verity
[ Post Reply | Private Reply | To 2 | View Replies]

To: Sabertooth
It nailed my workplace today, they told everybody to get off the Internet and to only send emails within the office, by 4 they said no email whatsoever.
4 posted on 9/18/2001, 11:37:08 PM by motexva
[ Post Reply | Private Reply | To 1 | View Replies]

Comment #5 Removed by Moderator

To: Sabertooth
i got this nasty little bug today because I had a folder on my machine with a public share. This one is proactive.. Most of the worms require that you do something stupid, this one hunts for electronic vulnerablity.
6 posted on 9/18/2001, 11:39:22 PM by IamConservative
[ Post Reply | Private Reply | To 1 | View Replies]

To: Eric Esot
COMPUTER VIRUS WARNINGS..CLICK
7 posted on 9/18/2001, 11:39:57 PM by newsperson999
[ Post Reply | Private Reply | To 5 | View Replies]

To: motexva
I have received 3 contaminated e-mails today. One had "Snow White and the Seven Dwarfs" in the subject line, a second one had "January 20" and the third said "cv-annie". Fortunately, my Norton A/V quarantined all of them.
8 posted on 9/18/2001, 11:44:29 PM by cerberus
[ Post Reply | Private Reply | To 4 | View Replies]

To: newsperson999
Am well aware of this one – I run a Linux network and am affected by the traffic of this thing as it propagates throughout. It started at about 10:00 am pacific and has been escalating at a rapid rate. At present, I'm getting approximately 4000 HTTP port probes (um, web hits), against each one of my Linux boxes(web servers), an hour.

It's really depressing.
9 posted on 9/18/2001, 11:45:50 PM by Eric Esot
[ Post Reply | Private Reply | To 7 | View Replies]

To: Sabertooth
Well, there's no viruses for OS/2 either. I mean, hey, why bother?
10 posted on 9/18/2001, 11:52:04 PM by Jaxter
[ Post Reply | Private Reply | To 1 | View Replies]

To: 2ndMostConservativeBrdMember
Um – what happened to my post #5?
11 posted on 9/18/2001, 11:52:10 PM by Eric Esot
[ Post Reply | Private Reply | To 2 | View Replies]

To: Sabertooth
I got an extemely suspicious e-mail yesterday. It contained only 642 bites, had an attachment, and a return address of "nobody." I deleted it without opening it, because I suspected it contained a virus.

I have deleted many virus messages in the past two months alone. Most were the same virus from different addresses: "Please advise." But I had never previously gotten one without a return address, which makes me believe that this was not random.

Context: The previous day, I had written to an American-based PLO website, mediamonitors.net, asking the editor and founder, Muhammad Ali Khan, if he had any response to a hoax that someone had prepetrated at FR in the name of media monitors. The post had claimed that a (bogus) report had shown that Israel's Mossad had prepetrated the 911 attacks. JimRob deleted the post and shut down the poster (TruthBites (mediamonitors.net), but not before I copied it. I never got a signed response from Muhammad Ali Khan, though I did get an immediate response from someone else I'd written, who was implicated by the bogus report, saying it was news to him.

12 posted on 9/18/2001, 11:54:53 PM by mrustow
[ Post Reply | Private Reply | To 1 | View Replies]

To: cerberus
Hubby got SirCam through his work network share on his laptop. No one even USES outlook in the company. The only way it could have gotten into the company is if someone using their home computer got it through Outlook, then connected with the same computer to their work dialup network connection. *SIGH* when will people ever learn...
13 posted on 9/18/2001, 11:59:00 PM by Terriergal
[ Post Reply | Private Reply | To 8 | View Replies]

To: Terriergal
Hubby got SirCam

I should have said he found Sir Cam files but of course, using lotus Notes none of them were ever opened, so he wasn't actually infected.

14 posted on 9/19/2001, 12:00:10 AM by Terriergal
[ Post Reply | Private Reply | To 13 | View Replies]

To: Sabertooth
This may be a false alarm, but I just called the FBI...

Yemenis Abroad 1157 Entries so far

Name : A.A.A Ali
Currently residing in: america
E-Mail :ysana03@hotmail.com
Homepage :http://www.hackers.com
Describing him/herself and his/her activites A.A.A Ali Says:
hello i am a computer hacker and need another
computer engineer to help me make a virus
get in touch with me as soon as possible i am willing
to pay up to $5,000

Submitted On Saturday, September 08, 2001 at 08:27:11 (CDT) by A.A.A Ali

15 posted on 9/19/2001, 12:11:25 AM by InfraRed
[ Post Reply | Private Reply | To 1 | View Replies]

To: Sabertooth
I have about 500 email accounts and my antivirus proxy server went from catching about maybe 4 or 5 a day on average to over a dozen a day in the past week. Most of these are old viruses that obviously originate from people that do not have English as their native tongue. I mean they spell Snow White - Snowhite. Then again maybe they're college students who hate the draft. Who knows?
16 posted on 9/19/2001, 12:18:56 AM by Jaxter
[ Post Reply | Private Reply | To 1 | View Replies]

To: cerberus
I had Norton put 3 Show Whites into Quarantine, and some months, they later escaped. At the same time, messages that I had deleted reappeared. Had to uninstall and reinstall -- tried a new user name -- lo and behold, what came back but Snow White. I was very careful of adding people back to my e-mail list, too.

This morning, on Google, a notification that the area I was in was infected with the BloodhoundHybrid virus.

17 posted on 9/19/2001, 12:44:37 AM by lakey
[ Post Reply | Private Reply | To 8 | View Replies]

To: Sabertooth
Our ISP got hit with this today--a small guy running a small shop; it sounds like he's about to lost it..
18 posted on 9/19/2001, 12:56:27 AM by farmer18th
[ Post Reply | Private Reply | To 1 | View Replies]

To: farmer18th
or maybe even "lose" it.
19 posted on 9/19/2001, 12:56:52 AM by farmer18th
[ Post Reply | Private Reply | To 18 | View Replies]

To: Eric Esot
wow....sad to hear.... last week at work we had, 'as you requested' type virus. I know not to open up anything I don't know. Updated on the NAV....
20 posted on 9/19/2001, 1:14:26 AM by runningbear
[ Post Reply | Private Reply | To 9 | View Replies]


Navigation: use the links below to view more comments.
first 1-2021-38 next last

Disclaimer: Opinions posted on Free Republic are those of the individual posters and do not necessarily represent the opinion of Free Republic or its management. All materials posted herein are protected by copyright law and the exemption for fair use of copyrighted works.

Free Republic
Browse · Search
News/Activism
Topics · Post Article

FreeRepublic, LLC, PO BOX 9771, FRESNO, CA 93794
FreeRepublic.com is powered by software copyright 2000-2008 John Robinson