|
|
Article: Nimda - how it works. (VIRUS NOTES).
- Article from:
- Database and Network Journal
- Article date:
- October 1, 2001
CopyrightCOPYRIGHT 2001 A.P. Publications Ltd. This material is published under license from the publisher through the Gale Group, Farmington Hills, Michigan. All inquiries regarding rights should be directed to the Gale Group. (Hide copyright information)
|
Nimda, a virus worm has rapidly established itself as another problem. It spreads via the Internet attached to infected e-mails, and copies itself to shared directories over a local network, and also attacks vulnerable IIS machines (Web sites). The worm itself is a Windows PE EXE file about 57Kb in length, and is written in Microsoft C++.
In order to run from an infected message, the worm exploits a security breach. The worm then installs itself to the system, and runs a spreading routine and payload. The worm contains the following "copyright" text string: Concept Virus(CV) V-5, Copyright(C)2001 R.P.China
Installing
While installing, the worm ...