//flex table opened by JP

Click to See Complete Forum and Search --> : W32.Nimda.A@mm


izzzy12k
09-18-2001, 02:25 PM
http://www.sarc.com/avcenter/venc/data/w32.nimda.a@mm.html

W32.Nimda.A@mm is a new mass-mailing worm that utilizes email to propagate itself. The threat arrives as a file named readme.exe in an email.

In addition, the worm sends out probes to Microsoft IIS servers attempting to spread itself by using the Unicode Web Traversal exploit similar to W32.BlueCode.Worm. Compromised servers may display a webpage prompting a visitor to download an Outlook file which contains the worm as an attachment.

DVNT1
09-18-2001, 02:30 PM
Sounds similar to the W32/Minda@MM ...


http://vil.nai.com/vil/virusSummary.asp?virus_k=99209


(probably the same thing)

club_med
09-18-2001, 03:30 PM
See also here (http://www.sysopt.com/forum/showthread.php?s=&threadid=83826). Another Sysopt thread about this new worm.