| Removing this patching
vulnerable systems, disabling network shares, and using the latest
DAT files. It can not be removed manually.
Those using DAT versions < 4162 should update to the latest
available DATs and remove any EXTRA.DAT files that they may
be using. These current DAT files fix a problem with certain infected
.EXE files being deleted when they should have been repaired.
Infected systems must:
apply the patches below
close any network shares prior to cleaning
exit any running applications
Stop a running IIS server
Scan and clean each drive
Restore the RICHED20.DLL and MMC.EXE files if they were overwritten
by the virus and deleted by the scanner.
Failure to take these actions may result in reinfection.
Applying patches
All users running Microsoft Internet Explorer (ver 5.01
or 5.5 without SP2), are advised to install this
Microsoft patch for the Incorrect MIME Header Can Cause IE to
Execute E-mail Attachment vulnerability.
All IIS administrators (and Win2K users who may not know they
are running IIS), who haven't already done so, should also install
this
Microsoft patch (August 15, 2001 Cumulative Patch for IIS)
Scanning/Removal
In cases where users with VirusScan and Netshield 4.5, or 4.51
have altered the "default extension list/program files extension
list" the following package is required to scan files with extensions
greater than 3 characters, and is required for complete detection
of this threat where the extension list has been customized.
EXTFIX1.EXE
patch . Please review the README.TXT
file first.
As always, AVERT recommends that users configure VirusScan to
scan all files. If this is not an option in your environment,
the default extension list ("Program files" or "Default files")
should be used.
Additionally Win9x users should remove the text: load.exe
-dontrunold from the SYSTEM.INI file.
Stand Alone Removal Tool
Please note Virusscan and Netshield products will detect and
remove the virus and the associated files the virus affects. It
will NOT remove the network shares or the guest account created
by W32/Nimda@MM.
Users that would like to have these changes removed automatically
can use the AVERT NimdaScan (current version 1.0f) program located
on the AVERT
Tools Page. Please follow the instructions in the README.TXT
when using the program.
VirusScan 4.03 and 4.50 issues
VirusScan 4.03 and VirusScan 4.50 will detect the W32/Nimda@MM
virus if utilizing the correct engine and dat files in all cases,
except when the virus comes on to a machine across a network share.
VirusScan 4.03 and VirusScan 4.50 intercept calls made on the system
to open files, read files, write files, etc. when made from the
local machine. VirusScan 4.03 and VirusScan 4.50 do not intercept
these calls when they are being made via a remote machine as happens
when W32/Nimda@MM infects machines via network shares.
In order to resolve this issue computers must be updated to a
minimum of VirusScan 4.50 Service
Pack 1, current engine, and current Dats and also ensure that
all machines on the network are running virus protection that will
detect and clean this virus. The ability of the virus to travel
via network shares is due to unprotected machines on the network.
Additional Windows ME Info:
NOTE: Windows ME utilizes a backup utility that backs up selected
files automatically to the C:\_Restore folder. This means that an
infected file could be stored there as a backup file, and VirusScan
will be unable to delete these files. These instructions explain
how to remove the infected files from the C:\_Restore folder.
Disabling the Restore Utility
1. Right click the My Computer icon on the Desktop.
2. Click on the Performance Tab.
3. Click on the File System button.
4. Click on the Troubleshooting Tab.
5. Put a check mark next to "Disable System Restore".
6. Click the Apply button.
7. Click the Close button.
8. Click the Close button again.
9. You will be prompted to restart the computer. Click Yes.
NOTE: The Restore Utility will now be disabled.
10. Restart the computer in Safe Mode.
11. Run a scan with VirusScan to delete all infected files, or browse
the the file's located in the C:\_Restore folder and remove the
file's.
12. After removing the desired files, restart the computer normally.
NOTE: To re-enable the Restore Utility, follow steps 1-9 and on
step 5 remove the check mark next to "Disable System Restore".
|