Author Topic: I have got the virus Win32:Nimda [Drp]  (Read 3029 times)

0 Members and 1 Guest are viewing this topic.

heike

  • Guest
I have got the virus Win32:Nimda [Drp]
« on: May 08, 2004, 07:19:41 PM »
I have got the virus Win32:Nimda [Drp], and the message that Avast cannot proceed !! How can I get rid of this virus and does anybody knows if it is a dammaging virus ?

whocares

  • Guest
Re:I have got the virus Win32:Nimda [Drp]
« Reply #1 on: May 09, 2004, 05:22:40 PM »
Hi Heike,
please read the links here:

http://www.virusbtn.com/resources/vgrep/vgrep.cgi?terms=Win32%3ANimda+%5BDrp%5D&product=1
http://www.avast.com/i_idt_133.html

Also try avast's Cleaner: http://www.avast.com/i_idt_171.html

Removal in SafeMode could also work (F8-Boot)
***

what WIN do you have ? Are all ServicePacks and Windowsupdates applied ?

Where exactly was the infected File found (full path/folder/filename, e.g. c:\Windows\system32\virusfile.exe) ?

Sometimes it's enough to
- clear all TEMP-folders (via drive CleanUp AND best also manually)
- empty Temp.Int.Files folder(s) (via IE->Extras-Internetoptions->Delete files, including OFFLINE files) and
- empty java-Cache or
- disable system restore on Win ME/XP INCLUDING a REBOOT!! ( http://vil.nai.com/vil/SystemHelpDocs/DisableSysRestore.htm )
to get rid of it..

test the file with OnlineScanners e.g. from Trend, RAV & KAV (see below) to get a more specific name
(you need to temporarily pause AV-Resident Shield/Monitor/Guard to be able to scan the file online)

-Secure your system:
   change passwords, secure shares, install patches/updates for WIN&IE;
   disable ActiveX and Scripting in IE except for know secure sites - and better use a secure browser like Opera or Mozilla
- scan your whole system with updated avast and maybe a 2nd scanner ,e.g. TrendMicro/RAV to check whether your PC is clean ;)
- If needed, reenable system restore on Win ME/XP


Further Details and Links via the board search above


 ;)

Offline igor

  • Avast team
  • Serious Graphoman
  • *
  • Posts: 11849
    • AVAST Software
Re:I have got the virus Win32:Nimda [Drp]
« Reply #2 on: May 10, 2004, 10:56:27 AM »
Nimda [Drp] is just a small piece of JavaScript code that the Nimda worm appends to HTML files. It's not really dangerous (unless you have the real nimda virus in the same directory).

avast! Virus Cleaner should be able to fix the file.